I’m thinking of setting up multi user nix on a compute cluster. The advantage would be to have a shared storage where common packages are reused, this is a great advantage compared to conda where every environment duplicates storage and inodes.
However, the packages are installed as root. As such I’m a bit wary of whether a user installing something could have the system run malware as root by installing a package.
What are the safeguards in place and how do I know I can trust them?


Thank you, you reassured me quite a bit. I’ll have a good read of the manual.
It is not really a build server, it’s a compute server. I’ll have users installing hundreds of different software packages, most of them using incompatible libraries and thus I was thinking of using Nix. Alternatives would be LMOD, which however requires the administrator to install very single piece of software, which… We don’t really have a dedicated system administrator and I don’t really want to go through the compilation instructions of every single piece of software we use. Alternatively everyone could compile their own software or install it through something like conda, but that eats up a lot of storage space since every library would be duplicated across users.
Well, in that case remember to force everyone to use the same Nixpkgs version (otherwise you’ll still end up with a lot of duplicated packages), and run
nix-store --optimise; nix-collect-garbage -dregularly (ideally via cron or something).