This isn't a full NixOS installer — it's the one step that's the same on every fresh machine regardless of what happens next: get it reachable over SSH with the right keys. Run one of the two blocks below on the target, then continue provisioning from the management side.
Bare metal — NixOS live ISO
Boot the live/minimal ISO, get a shell at the console, then:
mkdir -p ~/.ssh && chmod 700 ~/.ssh
curl -fsSL https://jedarden.com/ssh-keys.txt >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys
systemctl start sshd
ip a # note the address to SSH to Stock VPS
Once you have console or password access as root (or a sudo user) on the provider's stock image:
mkdir -p ~/.ssh && chmod 700 ~/.ssh
curl -fsSL https://jedarden.com/ssh-keys.txt >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys Keys
Public keys — safe to publish, safe to append blindly. Raw file for the commands above: /ssh-keys.txt.
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKD/IXQZ9mh3m8pl6QL0dMcnFl5tLn3wmwI7GRZZvGJv
ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAgEAl7+gkJYxBH7LKDMBPbFxLQlIMd+o4yQ2u4IOlb+dNhEJtdCHXkTBF7mZgQtDiHf42XBnU+WVJJfDgGLTxtnccwING/D+AxrZRkEk+OIkNnmc3I08EVxtvBA9Updc6YtLZ5y6FcbMY39nY6WaWex7zUc0BJpeGogBW4S4JntVpUC+3mVfQjNVqxy36+uMqJdeY7HpwSq2F05tCoCBKU/Y9ovsabHHMYjDcbgGN4HdCBtHinyarTNXnrBC+N0sW+MjSRk9FWE912pdJCZs0ocdtrscXfoSQRJq6CmABMkzG/5DZzvTeghfKUHILqcdzdDKuUXgjYx0WgRLK6pD7Tz5t3VGRbLY9ZpLLQjz0AwsZ8DWrujsCgwsYGlIX1CvvAWyhxNxu4HjuYg9kEEmjsGQyu2EfpSey+5sWHXd5F3W8xNRad85YAoZ6bpnxKkTQh0B+oi030M4GKbds0tPSQx9Pmt4Y8URIPzdkxairqlnmnQdX4FjV/UAissLhtDxe8VtXF3oNaF91sAncZw5mxpKJf6rspaMH+RZhsNVdz8/gWDBWIbMtIuCRBOlatGl6zRSnc6XNuwg4tlr7ypJ33KqJFRXxha80RYYL1ivmfxJ5UriOxgyJE0D6xtyMDd71db4eG6rCKlZJjUJBbKgDssTV+GPEgLYnWAuXvS9Ynd+p+M=
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDY+R6m8bkJxP8nh3JhPbSkRCqLUSIUpjtu0ZqXPHQVrNRsOickZu/HNMFyinx/gzLRYpssTpn5OV1JuepmjxCql3esd4vs7PlnwxNHilM3XiGKmvqNiBqt6NOiGaSPTS0if9pCPVWIx1CACP1VGBvWL0Fa05T6RjAqCd8J7lxB0DmsVrr2kk65IeV/8oxfDJpSY/CmnilytCBum/Is418Th/zP5a1VCCxcpLrxLb1eBla9QVD4i29MYf9M+8zPNwU9CsBKJurOEc/DYH8+B8IXIj4cS5aVJ0NekmdoEy0vr+k8r0/DJ/wYUumAZHWq/SKNpasGdNKX4oXYv75ifJSOJ0QRUxmMpgvPUcp76wtpxsV2X97vayg8BC8hJRtp65vwAJnHNFyKIjcBhbRvU1swrJTuSwuLcZ1dcpHklf75dj8fzBR9gUzA0foWYJv00zpQ3cBRZmE3kZGFGkdjqVDezlwo+/rlFMJCE316jxAZl1GbzkRKFZkIxW0NjzSpplM= Next
Once the box answers SSH, provisioning continues from the management machine — join the tailnet, hand it a flake, deploy the real config. That part is host-specific and lives outside this page.