Nix Observability Daemon
observability nix
README.md

nod #

A daemon that collects Nix build and substitution statistics using structured JSON logs.

requirements #

  • Nix 2.30 or later (json-log-path support)

building #

cargo build --release

usage #

Start the daemon (binds /tmp/nod.sock by default):

nod daemon

Point Nix at the same socket. --socket and json-log-path must match or no events arrive.

Multi-user Nix (default on macOS and most Linux), in /etc/nix/nix.conf:

json-log-path = /tmp/nod.sock

Restart the Nix daemon to apply: sudo systemctl restart nix-daemon (Linux) or sudo launchctl kickstart -k system/org.nixos.nix-daemon (macOS). Single-user Nix: same line in ~/.config/nix/nix.conf.

Then use Nix normally. Query accumulated stats:

nod                          # aggregate stats, all time
nod -s 30d                   # last 30 days (units: h, d, w, mo, y)
nod -s 3mo                   # last 3 months
nod --drv firefox            # filter to derivations matching "firefox"
nod --exclude gcc            # exclude derivations matching "gcc"
nod --sort name -n 20        # sort slowest builds by name, show 20
nod --bucket day             # time series by day
nod --bucket month           # time series by month
nod --bucket day --output csv    # CSV output
nod clean                    # delete all events
nod clean --before-days 90   # delete events older than 90 days

NixOS #

{
  services.nod = {
    enable = true;
    retainDays = 180;  # default
  };
}

The module sets nix.settings.json-log-path automatically and exports NOD_DB into /etc/environment so every session (login, SSH, scripts) can query the database without --db. Add any user that should run queries to the nod group.

configuration #

flag env default
--socket NOD_SOCKET /tmp/nod.sock
--db NOD_DB $XDG_DATA_HOME/nod/nod.db (else ~/.local/share/nod/nod.db)

When using the NixOS module these are pinned to fixed system paths and NOD_DB is exported so clients find the database.

how? #

Nix 2.30 added json-log-path, which writes a stream of structured activity events (start/result/stop) to a file or Unix socket while a build runs. The daemon listens on that socket, tracks in-flight activities by ID, and on each stop event inserts a completed row into a local SQLite database.

Queries run directly against the events table, served by covering indexes; at per-machine volumes this is fast without any pre-aggregation. Events older than the retention window are pruned periodically.

Relevant Nix source: logging.hh