3 ms·
I agree on customizing the package flags, and features. When using Gentoo in production it became an important part of our security posture to omit the features
by TrueDuality 3y ago
I agree on customizing the package flags, and features. When using Gentoo in production it became an important part of our security posture to omit the features and integrations with unused software.
That being said we've always had a build host dedicated to producing binaries, but the actual support for binaries in Gentoo hasn't been great. Unsigned serving over HTTP or NFS of compiled artifacts is about all you get. I'm really pumped to see that the new package format adds in cryptographic verification that really should have been there all along even for internal only serving.
- zymhan 3y ago> omit the features and integrations with unused software. That's one of the most compelling cases I've heard for running something like Gentoo in prod. There are so many plugins, connectors, protocols, and often the old neglected ones turn into attack vectors.
- darkwater 3y ago> There are so many plugins, connectors, protocols, and often the old neglected ones turn into attack vectors. Practically speaking this is probably true but theoretically a distribution's job should be to somehow guarantee that a specific package built their way gets the security fixes for the way they built it. This is anyway tangential to the fact that in security "less is more".