31 ms·
VanillaOS: Immutable Ubuntu-Based Linux
- Squarex 4y agoHow does it compare to Fedora Silver blue? Apart from being based on Ubuntu.
- jacooper 4y agoProbably more user friendly
- ccouzens 4y agoIt says it uses abroot rather than ostree https://github.com/Vanilla-OS/ABRoot/ https://github.com/Vanilla-OS/ABRoot/ https://coreos.github.io/rpm-ostree/ https://coreos.github.io/rpm-ostree/ https://github.com/ostreedev/ostree https://github.com/ostreedev/ostree My impression from the splash page is you're more encouraged to install packages to the base system. Silverblue only has that as the last resort (after flatpak, toolbox and podman).
- forgotpwd16 4y ago>you're more encouraged to install packages to the base system From documentation, I'm not even sure how this is done. The only options for packages documented are platform-independent packages (Flatpak, etc) and apx (distrobox-based toolbox alternative).
- ccouzens 4y agoThis is the command for silverblue. For Chrome to work you'll need to enable it in "Software Repositories" (which you get to through the hamburger menu in the "Software" app). rpm-ostree install google-chrome-stable vim mozilla-openh264 virt-manager libvirt
- Squarex 4y agowouldn't it be better to just use flatpack version?
- ccouzens 4y agoOf Chrome? https://github.com/flathub/com.google.Chrome https://github.com/flathub/com.google.Chrome Maybe. I'm more comfortable signing into my accounts using Chrome packaged by Google than by a third party. I should probably familiarise myself with the linked repo to show I'm worrying about nothing.
- Operative0198 4y agoGoogle only packages Chrome for Ubuntu (deb) officially. If you are not using Ubuntu, you are probably not using Chrome directly from Google. However, if you use flatpaks you might as well trust this one package from flathub since the trust model is the same.
- ccouzens 4y agoThey have both an RPM and deb download https://www.google.com/chrome/ https://www.google.com/chrome/ But I get your point that if I'm enabling it through fedora's interface I'm already trusting more than just Google.
- curt15 4y agoIt not only is packaged by a third party but also uses a community-written patch[1] to replace Chrome's built-in sandbox with Flatpak's own sandbox. It's unclear to me whether Chromium upstream has vetted or is even aware of this modification. [1] https://github.com/refi64/zypak https://github.com/refi64/zypak
- forgotpwd16 4y agoIt doesn't achieve immutability via OStree but just an A/B structure. Simpler but less flexible/powerful(?).
- Klasiaster 4y agoFrom a quick look: The A/B partitions can be modified but it doesn't look like that is carried forward ("rebased") as with rpm-ostree. For package installations independent from the base OS there is something similar to (Fedora) Toolbox, called apx, where you also manage permantent containers for GUI or CLI apps that aren't available through Flatpak/Snap/AppImage or similar.
- bakoo 4y agoJust finished installing it in a VMware Workstation VM: * The installer lags unless you temporarily disable 3D acceleration until open-vm-tools are installed * The Norwegian keyboard layout defaults to Dvorak, which I suspect isn't the most common one ;) * The default installer resolution was a tiny 800x600. Click Activities and type Displays to get to the relevant settings. Now for the more exciting stuff, like testing if Tailscale works out of the box.
- jacooper 4y agoWhy wouldn't it, its just Ubuntu
- saghm 4y agoProbably for the same reasons that they encountered the issues above?
- jyrkesh 4y agoGood data for VM folks, but I really have accepted at this point that the VM experience is almost completely distinct from the bare metal experience. I'm really looking for a dependable pseudo-desktop/server OS for the monolithic legacy box at home. In terms of immutable, NixOS is it right now, but tbh it's had enough random uptime issues as of late, I'm starting to doubt my decision. Though I still haven't narrowed it down to this machine as opposed to some network/routing/storage problem
- nix23 4y ago>dependable pseudo-desktop/server OS for the monolithic legacy box at home. OpenVMS for x86_64 should come out for the community in May ;) However in the meantime, try FreeBSD.
- bogwog 4y agoHave you tried Fedora Silverblue or Kinoite (the KDE version)? They also offer a fully immutable file system. The only hard part is adapting to life with an immutable filesystem, getting used to running things in containers/toolboxes, using flatpaks/appimage/snaps, etc. I've been on it exclusively on my desktop and laptop for the past couple of months and have grown to like it a lot.
- nonrandomstring 4y agoI'm surprised immutable systems aren't more popular. Back in the Knoppix days it was first a novelty, and then a blessing that you had to boot from a CD-ROM, because it led to one amazing outcome: Less tinkering. Or rather - it split use from tinkering. Systems today are designed around the principles of deferral and volatility. You can add or change anything at any time. The user has absolute freedom to tinker, but also the vendor of always-connected products has endless possibilities to update. The result is a mess of dissatisfaction and half-bakery. Nothing is ever finished or fully right. It also, maybe paradoxically, leads to systems that feel less under your control. Systems like TinyCore and Live CD distros take a different approach that the OS is finished. You have two choices, take it or leave it. Unless you are prepared to cross a non-trivial barrier to remix and update the non-volatile image, you are forced to just use what you have. That leads to more productivity because you adapt to the tool rather than constantly adapting the tool to you. I like TinyCore because it's looking to a middle ground of baking immutable systems at key stage points and keeping changes separate from the immutable core. I can change the core if I want to, but rarely. I see that as a separate prospect than "appliance platforms" like Android and a PhoneOS onto which you can only load "apps". What ideas and favourite solutions do other's have for using immutability, or not liking it?
- vinaypai 4y ago> I'm surprised immutable systems aren't more popular Two words. Unpatched vulnerabilities.
- andix 4y agoImmutable doesn’t mean no updates. It just means that the user can’t change the system, and also doesn’t have to. An immutable System can have updates every night, as long as they are compatible. It’s a bit like iOS and android, the system is the same on all devices of the same model, there are just different configurations and different apps.
- vinaypai 4y agoThat doesn't sound like "immutable" to me, more like batched updates. I guess like Windows service packs?
- meatjuice 4y agoThis is good! I can recommend this to someone as an alternative to windows confidently.
- fbnlsr 4y agoSeems interesting but I don't see the difference with another simple distro like PopOS
- vorticalbox 4y ago/ is mounted as read-only.
- jacooper 4y agoIt uses vanilla gnome
- deleted 4y ago[deleted]
- einpoklum 4y ago> core parts of the system are locked down to prevent unwanted changes and corruption from third-party applications or a faulty update. Correct me if I'm wrong, but don't they just mean they mount the root filesystem as read-only, and have a separate partition for /var and /tmp ? That's a reasonable idea, although I'm not sure it merits an entire distribution. Is there anything else to Vanilla or is it just this? > The GNOME Desktop is the perfect environment for your daily tasks Maybe if you're a GNOME developer, and even then I kind of doubt it. > designed to be a reliable But it's based on ubuntu, which uses systemd, which is something not to be relied on, in many respects; see: https://www.without-systemd.org/wiki/index_php/Arguments_against_systemd/ https://www.without-systemd.org/wiki/index_php/Arguments_aga...
- fdiof 4y agoSounds like the only immutable part is the non-writable filesystem of the root partition, which is updated by having a live and non-live copy (A/B partitions) with the live updating the non-live and then switching on reboot. Similar to how Android works with its read-only partitions. From a whole filesystem perspective I think it's not accurate to call this immutable though, as you can presumably work around this with bind mounts that can be used to mutate (but not persist) any part of the read-only filesystem while the system is still running.
- rodolphoarruda 4y agoSuch a great idea. This is the kind of project I'd be happy to support.
- eismcc 4y agoHow does this compare to Nix? I’ve not used either but Nix sounded like what people want here.
- pmarreck 4y agoJust glancing at it (FYI, I run NixOS on my main dev machine), it looks like it uses ABRoot which gives you 1 install to fall back on if 1 fails. I love that NixOS gives me N installs to fall back on (where N is whatever you configure it to be) because I've often needed to go back more than 1 to identify a problem that I didn't notice until 2-3 updates later. Actually, as a natural tinkerer, what I call the "NixOS seatbelts" (being able to pick any of the last N updates via GRUB to boot into) have saved me numerous times already. I no longer feel comfortable using any other Linux distro. The declarative config and per-project dev environments are cake as well (once you get past the Nix language, which is basically just "JSON-like, plus pure functions")
- 3836293648 4y agoThe problem is when you have to package something yourself and it doesn't fully list its dependencies. So painful and time consuming.
- ColonelPhantom 4y agoMy main problem with Nix isn't the language, which is fine. My problem is that Nix shoehorns everything into it; I have to write my nginx config (for example) in Nix for some bespoke nixpkg. I would much rather just version my nginx config written in nginx config, and let Nix pull that up, or something like that. Then you get all the benefits of Nix (I think?) but my configuration is also readable for someone who doesn't know Nix. Plus I can use my existing knowledge (as well as the wealth of online available docs), instead of something obscure.
- jbboehr 4y agoNixOS needs to handle generating the config to make service configurations composable. If you don't want that, you might as well write your own systemd unit. That being said, most services have an option to use verbatim configuration files[0] or fragments[1][2][3]. [0]: https://search.nixos.org/options?show=services.yggdrasil.configFile https://search.nixos.org/options?show=services.yggdrasil.con... [1]: https://search.nixos.org/options?show=services.nginx.config https://search.nixos.org/options?show=services.nginx.config [2]: https://search.nixos.org/options?show=services.bind.extraConfig https://search.nixos.org/options?show=services.bind.extraCon... [3]: https://search.nixos.org/options?show=services.nginx.appendConfig https://search.nixos.org/options?show=services.nginx.appendC...
- Yasuraka 4y agoRunning it over KVM for a few hours now and really liking it so far
- spicyusername 4y agoFedora CoreOS and Fedora Silverblue are mature alternatives, if Ubuntu isn't your thing.
- FireInsight 4y agoThis, heard nothing but good from them. The only difference seems to be that ABRoot saves only one snapshot while OSTree saves multiple.
- lproven 4y agoThe A/B root layout originated in ChromeOS, which is the most widely-used desktop Linux in the world, with somewhere around a third of a billion deployed units now. (It also is where CoreOS got it from, before Red Hat bought them and the product largely disappeared, AFAICS.) As such, I'd say it's an extensively field-tested and well-proven disk structure. :-)
- tiffanyh 4y agoNanoBSD If you like VanillaOS, you’d like https://docs.freebsd.org/en/articles/nanobsd/ https://docs.freebsd.org/en/articles/nanobsd/
- presto8 4y agoIt is great to see immutable distributions becoming more popular. One thing that Ubuntu does very well however is the 5-year standard support for LTS releases (up to 10 years available via extended support). I wasn't able to find any information on VanillaOS's support roadmap. Since the project's goal is to have stability of the underlying OS, it would be great if VanillaOS had an LTS-like support plan in mind.
- kkfx 4y agoA small "operation" note: immutable is an was an ancient kind-of dream, having something that's always in a known state even if it's run for significant amount of time. Formally it should give easy debug due to a real and substantial reproducibility. In practice it never works well though: first immutable means far longer to update and these days updates are a continuous stream, secondly even if the system is really immutable the complete infra tend to be not, making the immutable part next to useless in reproducibility terms. In modern terms a new concept born "idempotent" witch FORMALLY means "you can run it countless of time, it will works the same and do not even re-do already done steps, it ensure consistency of a system final state no matter the initial one". Such concept have more more practical applications, again in theory, but in practice it fail to be really idempotent beside trivial use cases. From mere Ansible Playbooks for an infra to NixOS idempotence is partially there but results tend to be not. Long story short: IMVHO the road have a name DAMN SIMPLER DESIGN, simpler infra, as the sole way to keep anything working and easy to restore when it does not. A bottomline: reproducibility for a server infra have some reasons, for desktops... Well... IMO it's a bit overrated in the era of "endpoint".
- jmbwell 4y agoAnother approach I miss from SmartOS. It boots from a USB stick, loads system to a RAM disk, mounts configuration from a directory, and then hosts VM zones from ZFS datasets. The “root” system remains immutable. To patch or upgrade, you just write a new system image to the USB stick and reboot. It’s great. To skip the USB stick, you can do the whole thing over PXE. After running a cluster on SmartOS for many years, moving back to Linux and installing the OS feels fragile, dirty, and weird.
- nortonham 4y agoI only learned about smartos recently, after using openindiana and learning about illumos based systems. SmartOS is a really neat idea; I'm surprised it's not more popular
- m463 4y agoreminds me of a slightly different scenario - I used to run a rootless Sparcstation SLC that would boot over the network and become an alarm clock.
- pxc 4y agoSome people sort of run their NixOS configurations this way; the root filesystem is on tmpfs https://elis.nu/blog/2020/06/nixos-tmpfs-as-home/ https://elis.nu/blog/2020/06/nixos-tmpfs-as-home/
- yencabulator 4y agoThe A/B-root trick exists purely to avoid having to physically visit a server to change the USB stick. (Can't overwrite in-place, as it might crash in the middle.) PXE is its own hell, having local storage for the OS avoids some horror stories like "my whole cluster booted after a power outage and now PXE fails for everything".
- leke 4y agoWould this require more or less performance requirements from hardware? Or doesn't it make a difference.
- FireInsight 4y agoNo difference, i'd assume. Just a different way to arrange the filesystem.
- giancarlostoro 4y agoI noticed it lets you pick a primary package format to use, I just want a centralized package manager that highlights where my package came from or what format its in. I dont care if I use 5 different approaches thats already quite typical. What I do want to know is what package format is best for my use case: I want latest version of Python and other packages, and I am on Ubuntu, I dont want a new OS or docker. No idea which would be ideal or the pros and cons of each.
- dengolius 4y agoyet another ubuntu fork with gnome shell... at all
- deleted 4y ago[deleted]
- 3836293648 4y agoIt's not a UX distro, it's a package manager/root install experiment distro. Why would they mess with the UX too?
- sedatk 4y ago> Vanilla OS is an immutable operating system, core parts of the system are locked down to prevent unwanted changes and corruption from third-party applications or a faulty update. Can't imagine the HN responses if this was Windows marketing text :)
- deleted 4y ago[deleted]
- intelVISA 4y agodepends, if the Windows text was honest it'd have to mention that the parts it locks down relate to exfiltrating your data and violating user freedoms.
- yjftsjthsd-h 4y agoThe difference is that the user is still in control here, rather than having Microsoft foist another thing on them that makes it harder for the user to control their own machine.
- lloydatkinson 4y agoWonder how this would compare to Ubuntu embedded version?
- deleted 4y ago[deleted]
- lostmsu 4y agoELI13 what is an immutable OS and how does it affect workflow?
- speed_spread 4y agoIt's like booting off a CD-ROM every time. User files are overlaid over the boot image. Installing updates creates a new image from which to reboot. Old images are kept in case of failed update. Prevents some hacking too.
- hestefisk 4y agoOne for Late Night Linux predictions
- alexeiz 4y agoJust tried to install it in qemu and the installer was broken. It couldn't select the vda disk (the selection was disabled). There was no way to proceed further.