Skip to main content
Software Engineering Daily

Flox, Nix, and Reproducible Software Systems with Michael Stahnke

55 min episode · 2 min read
·
Michael Stahnke

Episode

55 min

Read time

2 min

Topics

Productivity, Leadership, Artificial Intelligence

AI-Generated Summary

Key Takeaways

  • Cross-platform reproducibility: Flox locks dependencies for Linux and Mac on x86 and ARM simultaneously, ensuring developers on M1 Macs and Linux x86 laptops use identical versions, eliminating version mismatch issues between brew and apt installations.
  • Secure by construction approach: Starting with deterministic developer environments rather than end-stage security scans creates complete bill of materials tracking from development through runtime, reducing attack surface by including only necessary dependencies in the closure.
  • Agentic development optimization: Deterministic environments amplify AI coding effectiveness by reducing variables agents must handle, allowing context windows to focus on business logic rather than dependency resolution failures, similar to how consistency benefits human developers.
  • CI efficiency through determinism: When inputs and outputs are mathematically provable as identical between local and CI environments, tests run locally don't need re-execution on blessed systems, cutting CI time and costs while maintaining quality assurance.

What It Covers

Michael Stahnke explains how Flox builds on Nix package manager to deliver cross-platform reproducible development environments with complete software supply chain tracking, addressing the complexity of modern multi-OS, multi-architecture development workflows.

Key Questions Answered

  • Cross-platform reproducibility: Flox locks dependencies for Linux and Mac on x86 and ARM simultaneously, ensuring developers on M1 Macs and Linux x86 laptops use identical versions, eliminating version mismatch issues between brew and apt installations.
  • Secure by construction approach: Starting with deterministic developer environments rather than end-stage security scans creates complete bill of materials tracking from development through runtime, reducing attack surface by including only necessary dependencies in the closure.
  • Agentic development optimization: Deterministic environments amplify AI coding effectiveness by reducing variables agents must handle, allowing context windows to focus on business logic rather than dependency resolution failures, similar to how consistency benefits human developers.
  • CI efficiency through determinism: When inputs and outputs are mathematically provable as identical between local and CI environments, tests run locally don't need re-execution on blessed systems, cutting CI time and costs while maintaining quality assurance.

Notable Moment

Stahnke describes his initial reaction to Nix as a bunch of Haskell developers deciding packaging was not complicated enough, highlighting the academic complexity Flox aims to abstract away for enterprise adoption.

Know someone who'd find this useful?

Episode Transcript

Modern software development is more complex than ever. Teams work across different operating systems, chip architectures, and cloud environments, each with its own dependency quirks and version mismatches. Ensuring that code runs reproducibly across these environments has become a major challenge that's made even harder by growing concerns around software supply chain security. Nix is a powerful open source package manager that builds software in controlled, declarative environments where dependencies are explicitly defined and reproducible. Its functional approach has made it a gold standard for reproducible builds, but it can also be difficult to learn and adopt. Flox is a company that builds on top of NICS with increased supply chain security and abstractions that streamline the developer experience. Michael Stankey is the VP of engineering at Flox and formerly worked at companies including Caterpillar, Puppet, and CircleCI. He joins the podcast with Kevin Ball to talk about Flox, building on top of nicks, how reproducibility underpins software security, the concept of secure by construction, how deterministic environments are reshaping both human and AI driven development, and much more. Kevin Ball, or K Ball, is the vice president of engineering at Mento and an independent coach for engineers and engineering leaders. He cofounded and served as CTO for two companies, founded the San Diego JavaScript meetup, and organizes the AI in action discussion group through Latent Space. Check out the show notes to follow Kbal on Twitter or LinkedIn, or visit his website, kball.llc. Michael, welcome to the show. Alright. Thanks for having me. Yeah. I'm excited to get to dig in. So let's maybe start a little bit with you. So can you introduce yourself, your background, and how you got to Flox? Sure. Yeah. My name is Michael Stonke. I'm currently the VP of engineering at Flox. And I've been involved in packaging and automation for most of my career. And so kind of what Flox does was a culmination of a lot of previous experiences. I had worked at big enterprise at Caterpillar, the construction company running data centers and system administration, doing a lot of automation there. Eventually, I left that company to go work with some friends who founded a company called Puppet. And Loved that back in the day. Yeah. It was pretty early on there. I really enjoyed it. Let's not have this bespoke automation. Let's have a framework for this and and really leverage out at scale when you're working with thousands of servers per administrator, things like that. Really enjoyed that. Did a lot of packaging, built a lot of things, and ended up doing a lot of porting and packaging, I guess. And packaging has been my passion for software the entire time. I love putting bits into nice orderly things that other people can consume. I founded a package repository called EPEL, which was the extra packages for enterprise Linux on top of Red Hat enterprise Linux in 2005. It was me and six other people that basically got …

Get the full transcript (13,411 words) + summary by email — free

One-time email with the complete transcript and AI summary of this episode. No account needed.

One email, no spam. We’ll also show you what SignalCast does.

Browse all Software Engineering Daily transcripts →

You just read a 3-minute summary of a 52-minute episode.

Get Software Engineering Daily summarized like this every Monday — plus up to 2 more podcasts, free.

Pick Your Podcasts — Free

Keep Reading

Books, tools, and gear mentioned in this episode

SignalCast may earn commission on purchases via these links.

Tools

  • Michael Stahnke explains how Flox builds on Nix package manager to deliver cross-platform reproducible development environments with complete software supply chain tracking, addressing the complexity of modern multi-OS, multi-architecture development workflows.
  • FloxBy guest
    Michael Stahnke explains how Flox builds on Nix package manager to deliver cross-platform reproducible development environments with complete software supply chain tracking, addressing the complexity of modern multi-OS, multi-architecture development workflows.

More from Software Engineering Daily

We summarize every new episode. Want them in your inbox?

Similar Episodes

Related episodes from other podcasts

Explore Related Topics

This podcast is featured in Best Cybersecurity Podcasts (2026) — ranked and reviewed with AI summaries.

Read this week's AI & Machine Learning Podcast Insights — cross-podcast analysis updated weekly.

You're clearly into Software Engineering Daily.

Every Monday, we deliver AI summaries of the latest episodes from Software Engineering Daily and 192+ other podcasts. Free for one show.

Start My Monday Digest

No credit card · Unsubscribe anytime