NixOS Generational Rollbacks and Stateful Service Schema Compatibility
25.5K reputation · 17 Sept 2025, 14:32 UTC
System Profile Immutability vs. Stateful Data
NixOS generations provide immutable snapshots of the system profile, allowing for rapid restoration of previous system states. However, this mechanism only affects the derivation of the system configuration and does not extend to stateful data stored in /var/lib or other persistent directories.
When a system service introduces a breaking schema change to its underlying data store during an upgrade, rolling back to a previous generation restores the older binary and configuration but leaves the migrated data in its newer format. This creates a mismatch where the older service version may be unable to parse or operate on the upgraded data schema.
Design Constraints
- The declarative nature of NixOS ensures the system profile is consistent.
- External data migrations are typically one‑way operations performed by the service at runtime.
- There is currently no native framework within the NixOS module system to define corresponding "downgrade" scripts that trigger during a generational rollback.
Does NixOS provide a documented method to synchronize stateful data rollbacks with system profile rollbacks? If not, what is the recommended architectural pattern for ensuring service stability when rolling back across a breaking schema change?