6 ms·
Love Tails, but I haven't used it in ten years. I have had Tails and Qubes disposable VMs on my mind though. I switched off of Qubes last year to my own Alpine
by dmwilcox 3y ago
Love Tails, but I haven't used it in ten years. I have had Tails and Qubes disposable VMs on my mind though.
I switched off of Qubes last year to my own Alpine chroot with a hand crafted kernel and initrd that lives only in memory. I find turning off the computer when I'm finished and having it forget everything to be a very peaceful way to compute. I owe the internet a write up.
I feel like ramfs for root filesystems is an underused pattern more broadly. "Want to upgrade? Just reboot. Fallback? Pick a different root squashfs in the grub menu"
- justin_oaks 3y ago> I owe the internet a write up. I would definitely be interested in reading more about this. I love the idea of being able to prevent an application from writing all over my disk to random places. If I can't prevent it, I can at least remedy it by having all those changes go away with a reboot. One of the things I love about Docker containers is that they can be ephemeral or persistent, short or long term, have full network access or no access, allowed to write to the host system or stuck writing to its own file system only. I'm in control instead of the application.
- mixmastamyk 3y agoTypically they can only write to home and temp. That can be improved via sandboxing, and there’s Little/Open Snitch as well.
- tlavoie 3y agoAges ago, I tried out Puppy Linux, that ran from a burned CD. If I made updates, it wrote another filesystem extent to the disc, and I think the loading process just used those to over-write files as needed until the boot completed. I was thinking of it for a home firewall at the time, but in any case, it made for a very ephemeral system.
- omani 3y agoSame here. Dont understand why not more ppl switched to alpine on the desktop. It is my daily driver. Plus LXD for stuff I must do (typically spawn ubuntu, etc.) my whole PDE (Personal Developer Environment) is within a container. Need python? Shell into (via dmenu) python container. All with complete neovim setup. Need a GUI? No problem. Spawn a container. My lxd profile is set up for this. Use chezmoi for heavy automated stuff. My base alpine system always stays clean.
- lannisterstark 3y agoBecause most people don't need a reason to. Why would they switch to alpine?
- bsdnoob 3y agoBy any chance can you share how you do this practically?
- yard2010 3y ago+1 and from which IDE/text processor did you migrate from to neovim?
- coppsilgold 3y agoI also use alpine as the main/root environment. But I rarely use any applications from alpine. For that I have Arch, Fedora and Debian rootfs dirs into which I pivot_root with the help of bubblewrap (bwrap) in shell scripts. There is no overhead and the GPU can be easily attached. You can also dynamically attach ro/rw CWD and target paths (`for arg in "$@"`). Everything that I care about just works and I get a separation of concerns. Use of network namespaces allows further flexibility. For example, I have a netns that is forced through a Tor gateway such that any traffic originating in it can only go through Tor. This type of setup is not hardened against kernel vulnerabilities, the kernel treats applications running in namespaces as if they are isolated from other namespaces but those applications can still interact with broad surfaces of the kernel and therefore potentially exploit it. For kernel safety applications must be denied direct access to the host kernel, this is usually achieved with virtual machines.
- palata 3y ago> For kernel safety applications must be denied direct access to the host kernel, this is usually achieved with virtual machines. And that is what QubesOS does, if I understand correctly?
- deleted 3y ago[deleted]
- analognoise 3y agoIn NixOs it's called Impermanence: https://nixos.wiki/wiki/Impermanence https://nixos.wiki/wiki/Impermanence Also NixOs has absurd levels of control for upgrades, rollbacks, and control over the build and resulting files.
- smoldesu 3y agoBe warned; your hard drive may file for a divorce after a few years of daily-driving NixOS. It is both a blessing and a curse: $ smol@computer ~> du -hcs /nix/store/ 257G /nix/store/
- miniBill 3y agoYou... do regular GC, right? I have 45G, and this computer is more than two years old
- smoldesu 3y agoI have multiple flakes and a lotta CUDA drivers. In fairness though, this is after a few months of no manual GC. I think nix-collect-garbage could bring it down to ~120-150gb. It's totally worth the stability, but maybe not the best choice for the storage-constrained. EDIT: According to nix-tree my current generation is only 45gb right now.
- alex-robbins 3y agoI'm so sick of this claim. Nix allows you to keep old versions of things installed, but you certainly don't have to. When I switched from Debian to NixOS a few years ago, I installed it on a separate subvolume, and it ended up taking almost exactly as much space as Debian did (about 12 GiB with gnome and everything else). And really, what would you expect? It's nearly all the same code, just organized differently in the filesystem. P.S., you can check the store usage of the current system profile with `nix path-info -Sh /run/current-system`.
- samuell 3y agoHow do Tails and Qubes relate, any reuse of functionality? (Tried Qubes as written up in [1] but eventually gave up as it won't allow me to create virtualbox images, and some other caveats, as well as being pretty resource hungry) [1] https://bionics.it/posts/installing-qubes-os https://bionics.it/posts/installing-qubes-os
- paravirtualized 3y ago> it won't allow me to create virtualbox images What's the use case[1] for VirtualBox images in an operating system designed around virtualization with Xen? You can simply create a Xen VM. [1]: Note that I'm asking a question here, not invalidating your experience.
- samuell 3y agoI've been needing to create virtualbox images for use in some courses (teaching data science and the like) at my previous work. This usecase has popped up often enough that I feel O need to be able to do this on my main laptop.
- hedora 3y agoI treat my web browser like this, and similarly have a docker container for all my development stuff. I like the idea of making the computer (almost) completely stateless. How do you deal with stuff you want to store in /home? (Like source code checkouts, ssh keys, etc.)
- deleted 3y ago[deleted]