7 ms·
I highly discourage anyone to use Ubuntu Core as part of their solution. It is a secure environment, yes, but it is a nightmare to configure (snaps) and for eve
by yourstruly-br 4y ago
I highly discourage anyone to use Ubuntu Core as part of their solution. It is a secure environment, yes, but it is a nightmare to configure (snaps) and for everything, expect for the most basic stuff, you will need what is called a "brand store", which costs about $20k/year, regardless if you have 1 or 100 devices.
(We could not even make one snap talk to another snap, checking another snap status etc).
We had commercial discussions w/ Canonical and we basically moved away.
- nix23 4y agoI completely sprinting away with anything canonical. SUSE/openSUSE/Micro RHEL/Fedora/CoreOS nothing else...no more canonical, too many disappointments and trickery into pay massive at the end of the day.
- RedShift1 4y agoWhat is Micro RHEL?
- forgotpwd16 4y agoGuess comment is (SUSE/openSUSE/Micro) (RHEL/Fedora/CoreOS).
- yjftsjthsd-h 4y agoNot RHEL; https://microos.opensuse.org/ https://microos.opensuse.org/
- nix23 4y agoYes, "Leap Micro", "MicroOS" and "SLE Micro"
- db65edfc7996 4y agoDoes the snap store server process still still use 300+ MB of memory? That alone would seem to disqualify it for IOT or other embedded use cases.
- brnt 4y agoBeen a huge fanboy since Warthog, but as of 20.04 I've sought refuge elsewhere. Turns out, Ubuntu isn't nearly as user friendly as it was back then, in fact, it's one of the least user friendly distros these days! Everybody progressed and you deserve t check it out yourself!
- tomcam 4y agoWhat’s your new distro of choice?
- capableweb 4y agoNot the one you're replying to, but started my Linux experience with Ubuntu 6.10, was using it all the way up to ~17, and started using Arch Linux after that since during my time of using Ubuntu, I learnt enough Linux that I could setup my own system (and of course, with the help of the awesome Arch Wiki).
- 5e92cb50239222b 4y agoWorth noting that Arch has had something resembling the OpenBSD installer for some time. Trying it out doesn't require reading 20 wiki articles as it did back in my day™. You answer a few questions, wait a few minutes, and it's done. https://wiki.archlinux.org/title/Archinstall https://wiki.archlinux.org/title/Archinstall
- capableweb 4y agoWow, that's great, haven't seen that before! Granted, it was some time ago I did a setup from scratch. Seems that installer is like 90% on the way to be useful as a general installer. At a glance, seems to missing things like networking setup (as most people use WiFi these days, it seems), but at least it takes care of most things you need for a install.
- ab_testing 4y agoLinux Mint for everyday use. It made my 10 year old hot running laptop into a cold mean machine.
- giancarlostoro 4y agoThat is really ridiculous. I'm sure some companies out there will pay it without blinking, but how are the little people supposed to evaluate things, heck a former boss at a Fortune 500 I know for a fact will say no thank you, and move on. I would just use DEB packages and setup a package repository myself, what does snap bring that regular debian packaging does not?
- moffkalast 4y ago> what does snap bring that regular debian packaging does not Snap is like using a python virtualenv, while apt is like using global pip. We all know which one of these usually results in a broken installation. Apt debs more often than not rely on some specific version of a third party package which becomes a headache when there's another package that needs a different version of it. Snap in theory solves that, making the deps local to the package you're installing. If I had a dollar for every time I had apt bullshit me with "requires package, but it will not be installed" or something of the sort I'd probably have something over $20 which isn't that much but still infuriatingly high.
- 2143 4y ago> We all know which one of these usually results in a broken installation. And yet they're promoting snap. Have they given us the ability to stop automatic updates?
- sky-kedge0749 4y agoIt looks like Ubuntu Core lets you disable automatic updates for snaps: https://ubuntu.com/core/docs/refresh-control https://ubuntu.com/core/docs/refresh-control.
- theamk 4y ago"Refresh control can be accomplished by using a gating snap" I bet those only come from brand stores.. so $20k/year for an ability to disable updates?
- traceroute66 4y ago> I highly discourage anyone to use Ubuntu Core as part of their solution. Yup. The guys at Nitrokey did a nice write-up about this last year.[1] (TL;DR in the end, they chose Debian instead) [1] https://www.nitrokey.com/news/2021/nextbox-why-we-decided-and-against-ubuntu-core https://www.nitrokey.com/news/2021/nextbox-why-we-decided-an...
- hda111 4y agoYou can’t really compare the two wrt IoT. For Debian you need an additional OTA update mechanism. Luckily rauc is in the Debian repos but you still need to setup everything yourself: A/B partitioning etc.
- seized 4y agoMender is a nice solution for the A/B partition updates as well. https://mender.io/ https://mender.io/
- jamesgeck0 4y agoI'm surprised they ended up going with a non-immutable distro. They say their Debian-derived system is as robust as Ubuntu Core, but seemingly immediately contradict this by saying they're using apt to manage updates.
- GordonS 4y agoAren't they only using it for security updates though?
- stubish 4y agoapt updates are not transactional, so abort the update mid way and you have a partially applied update. Hopefully the packager was careful enough to ensure your system still boots and reapplying the update cleans everything up.
- 4y ago
- mr337 4y agoWe had the some problem evaluating it for our startup. We were planning on using it to deploy ROS in the field and leverage the benefits. I was quoted $20k/year to get started and I think that also included 10 or 20 devices in the field. Then additional costs for that. There was so many hacks to get it working with ROS since we rely on hardware for robotics to communicate with sensors, actuators, and network. Basically broke the security model to get our application working. We didn't go with it and went Debian as well :D
- GordonS 4y agoI like Ubuntu, and looked into using Ubuntu Core for an IoT architecture a few years ago - but the "brand store", which IIRC is mandatory for private deployments, are complete madness. Plus, while the concept behind Snaps is interesting, in practice they seem to be nearly universally reviled.
- nullcipher 4y agoit's reviled because nobody wants to learn yet another deployment tool. apt has been reliable enough for installing packages and good enough UX that people can't be bothered
- theamk 4y agoNope, it's reviled because of its hostile user experience. Try finding an official, working way to stop automatic snap updates!
- GordonS 4y agoWas going to say the same thing. IMO the snap concept would make it worth learning something new for some use cases - but forced automatic snap updates, high memory usage, long startup times and permission issues are not selling it. Moreover, Canonical is well aware of how snap is perceived, and has done diddly squat to fix it.
- ladyanita22 4y agoI am not aware of the high memory usage issues. Also, rhe permissions issue is related to poor packaging, more than anything else.
- rtp4me 4y agoThe only way I got it working was via: snap set system proxy.http="http://127.0.0.1:1111" snap set system proxy.https="http://127.0.0.1:1111" I started a thread [0] on the LXD container forum in 2019 due to all the issues with automatic snaps https://discuss.linuxcontainers.org/t/disable-snap-auto-refresh-immediately/5333 https://discuss.linuxcontainers.org/t/disable-snap-auto-refr...
- curt15 4y agoBuying a Brand Store is also the only official way to have full control of snap updates. Someone at Canonical must have been taking notes from Microsoft -- take away control from users and sell it back in an "enterprise edition".
- GordonS 4y agoNo issue with Canonical making some money from their OSS efforts, but as-is the pricing seems crazy. At the least, I wish they'd do something like make brand stores free for less than 100 devices. That would also serve to hook people in, then they pay as they grow. Ideally though, Canonical would let anyone run their own "brand store" on their own hardware.
- discreteevent 4y agoIf you've only got one device then it probably doesn't make sense. But if you have a number of devices, you probably have a business and need to make sure that you can reliably and securely update them remotely. How many developer/ops hours do you think that would take? 20k doesn't buy you much in dev hours these days.