4 ms·
> If you are doing something weird it can make your life a living hell. I find it much easier to reliably accomplish non-standard things with systemd unit defi
by Denvercoder9 5y ago
> If you are doing something weird it can make your life a living hell.
I find it much easier to reliably accomplish non-standard things with systemd unit definitions, than it used to be with the ill-defined complex set of shell scripts we had before.
- jcrawfordor 5y agoThis issue is a lot bigger outside of services... I think the systemd service architecture is a clear improvement over SysV. The bigger issues I run into with systemd flexibility are related to the many other aspects of it. systemd-resolved, for example, has a very "opinionated" (to be polite) set of expectations about the environment and the systemd project tends to view any complaints about it not working outside of that environment as being the fault of the complainant. This leads to, well, DNSSEC is basically just broken and split horizon DNS is extremely unreliable. The former is sad but mostly doesn't matter, the latter leads to a lot of corporate networks having to disable resolved (I think configuring it to remove the semi-hardcoded "backup" resolvers reliably fixes this problem but honestly I find it completely ridiculous that resolved has a hardcoded list of DNS servers it just uses instead sometimes. It's unclear to me whether or not that's a bug at this point and I got tired of trying to follow the issues and mailing list threads where the developers were, uh, not amazingly helpful). systemd management of mounts can be similarly narrow about the types of configurations it supports, and systemd-firewalld just sort of openly only claims it can support simple use-cases. systemd-journald is also a net loss of flexibility compared to rsyslog but, on the other hand, rsyslog could quickly turn into an inscrutable mess if you used any of the advanced features (rainerscript...), so this may not be an entirely bad thing. And in general systemd is, well, opinionated. I hate to bang on resolved too much but I just happen to have spent quite a few hours last week figuring out resolved problems. Resolved does not handle "dotless" domains correctly in a lot of existing environments (it's very particular about exactly how the search domain is set up). Poettering has basically responded that it's because dotless domains are stupid and no one should use them, so it won't be changed. I don't necessarily disagree that dotless domains are not a good idea today but it does mean that resolved breaks a lot of older corporate and institutional environments that have been using them successfully for decades. This manifests as "I updated my distro and the intranet stopped working." That kind of breaking change is not very common with core Linux services and isn't going to make many friends in the IT crowd.
- mianos 5y agoI think systemd is OK for a lot of things, I don't even hate journald. The API pretty good. But, I am 100% agreement on the whole resolvd thing. It is a complete fiasco for anything but someone's idea of a standard network. Even the most basic things, like waiting for DNS to be up before mounting a network filesystem has to be done by writing your own units if you don't want to just try and mount and hope for the best.
- crazy_hombre 5y agoThere's no such thing as systemd-firewalld.
- jcrawfordor 5y agoYeah, sorry, I'm blaming more on Poettering than is really fair. But firewalld is closely coupled with the overall systemd architecture and the projects are interconnected.
- panick21_ 5y agoSystemd-resolved has some good ideas but can be a bit confusing. Overall its not bad, but it is a bit strange.