Machine – One VM per Project
VM isolation beats containers for security, plus Touch ID git signing from host.

Declarative TOML templates for VMs is a clever take on NixOS reproducibility.
NixOS users and infrastructure engineers
NixOps · Colima · Multipass
VM isolation beats containers for security, plus Touch ID git signing from host.
NixOS profiles for Claude Code autonomy, but it's a personal config repo, not a reusable product.
Full VPS lifecycle management over SSH without ever touching a web browser.
NixOS for hypervisor hosts is genuinely clever — atomic rollbacks beat apt upgrade prayers.
Single-file VMs with network allow-listing beat Docker daemon complexity for simple sandboxing.
Compile-time generated scheduler beats manual match-loop-state hell for complex state machines.