7 ms·
The landing page doesn't really explain what is interesting about Harvey. What does it mean that it's distributed, exactly?
by a1k0n 9y ago
The landing page doesn't really explain what is interesting about Harvey. What does it mean that it's distributed, exactly?
- kruhft 9y agoPlan9 was the 'next version' of Unix made by the people that originally made Unix. It was a small (tiny!) network packet routing kernel (routing 9p, a layer above IP) that is meant to be fully distributed and networked. https://www.quora.com/How-is-Plan-9-OS-different-from-Unix https://www.quora.com/How-is-Plan-9-OS-different-from-Unix
- floren 9y agoI wish the mods hadn't changed the title; I chose the original title to focus more on what's cool about it. Anyway, Harvey is distributed in the same way that Plan 9 is/was distributed: the services are meant to be run across a network. On a properly set up network, you'll have an authentication server which does only authentication, because that's the keys to the kingdom. Similarly, you'll have a file server which ONLY serves files, and speaks to the auth server to manage access. Then you'll have a CPU server which lets remote users connect and do stuff; it mounts its root filesystem from the file server and authenticates users with the auth server. You can also have terminal machines, which typically netboot, get their root from the file server, authenticate with the auth server, and basically act as a personal workstation for whoever sits down; when you're done working, just save your work and reboot the terminal. Of course it doesn't have to be run like that and many people don't, because they don't want to run 4+ systems. You can combine auth, FS, and CPU services onto one machine and just connect from a Windows, Linux, or Mac machine using 'drawterm' (think of it as an ssh equivalent).
- euyyn 9y agoHonest question, not trying to be dismissive: This architecture sounds old to me, as in things were built like that in the 80s or earlier but evolved past. Is that so? If so, what makes those decisions newly relevant?
- deleted 9y ago[deleted]
- floren 9y agoThe architecture does indeed come from the late 80s/early 90s, but I think it's more relevant today than ever. Separation of services is, in my opinion, essential to security. By putting the authentication service off in its own machine, you restrict the attacks that can be made on it; the auth server only talks over a highly restricted protocol. On a standalone Unix system, users log in to the same machine that stores the passwords. They're only a privilege escalation exploit away from getting the hashes of everyone's password, and these days privilege escalations are a dime a dozen. When this scheme was designed, it was frankly a little bit nutty. The CPU, auth, and file servers would be VAX or Sun systems, costing tens of thousands of dollars, and the terminals would be either slightly cheaper Suns or IBM PC-compatibles costing thousands of dollars themselves. Today, you could probably cobble together a passable network for a few hundred dollars, assuming you use cheap Atom boards for everything except the CPU server (which is meant to be a beefy compute box, but let's be honest nothing in Plan 9 uses a lot of cycles). This makes the architecture more sensible than ever.
- ww520 9y agoNumerous centralized authentication services are available for Linux and Windows and others for a long time.
- floren 9y agoYou're absolutely correct, and like I said a lot of people run their Plan 9 systems with all the services on one box, which kills a lot of the security advantages. However, if you compare setting up a Plan 9 auth server to setting up a Kerberos server... well, basically anything to do with Kerberos makes me long for death. The Plan 9 auth system is one of the best things they made and I highly recommend checking out the paper: https://css.csail.mit.edu/6.858/2013/readings/plan9auth.pdf https://css.csail.mit.edu/6.858/2013/readings/plan9auth.pdf
- PuffinBlue 9y agoHuh, that sounds interesting. Does it scale? I mean, it sounds a bit like 'software defined computing' if you'll excuse the terrible metaphor, a bit like SDN which abstracted the physical networking layer. Does Harvey abstract the hardware layer? So it could theoretically scale to a huge amount of machines that look like one giant powerful one? Wouldn't the speed of operation be limited to the speed of the network though? Anyway, sorry if the questions sound silly, I don't know much about this stuff.
- jcoffland 9y ago> you'll have an authentication server which does only authentication > you'll have a file server which ONLY serves files These sound like disadvantages. Decentralization would be better. I'd like to share the storage of all my servers and not have one auth server as a single point of failure. I imagine you can setup up a redundant auth server at the cost of more hardware but why not decentralize? This seems a lot like the old way of doing things.
- ithkuil 9y agoHaving a file server that only stores files does not mean having only one file server.
- SolarNet 9y agoAnd indeed one of them may be local to the computer serving local drives, and another could be the network resources. Heck it could even allow file servers with different security settings (e.g. the USB drives might be mounted in a hostile file server space).
- noblethrasher 9y agoA server is just a name; you can't infer the number of machines (physical or virtual) that are behind a name.
- agumonkey 9y agoread that in Hurd's voice
- sehugg 9y agoThere's a little more context here: https://notamonadtutorial.com/harvey-an-operating-system-with-plan-9-s-shadow-3081414e5f0b https://notamonadtutorial.com/harvey-an-operating-system-wit...
- neopanz 9y agoAgreed, if I have to do a research on Google and Quora, then the landing page failed. I need to be told immediately why Harvey is killer and there are things you can do with it that you can't with Linux, at least not easily. The only standout feature according to the summary is "simplified sys call". Boy, that's worth dropping Linux immediately! Not. Don't get me wrong, I would love to show Harvey some support, but I need a compelling reason to get over the massive switching cost.
- iforgotpassword 9y agoBiggest mistake IMO was not clarifying what a distributed OS is supposed to be. Especially nowadays with all the cloud hype I could think of at least three different meanings right off the bat, then clicked all the links on the landing page and erratically browsed the wiki and didn't find anything, not even an external (wikipedia) link which got me quite annoyed at that point.