14 ms·
Monogon: A Linux userland in pure Go
- cardanome 3y agoWell not the Lisp userland many of us dreamed of but a very interesting project nonetheless. The handbook[0] is a bit more clearer about the goals: > Metropolis is a cluster operating system, meaning its goal is to run on a fleet of machines (be it physical or virtual) and pool their resources together into a unified API for operations and developer teams. > A self-contained operating system: Metropolis is a full software stack, including the Linux kernel, userspace code, Kubernetes distribution and cluster management system. In contrast to traditional cluster administration, there are no puzzles to put together from a dozen vendors. The entire stack is tested as a single deployable unit. > Eliminates state: Metropolis nodes don't have a traditional read-write filesystem, all of their state is contained on a separate partition with clear per-component ownership of data. All node configuration is managed declaratively on a per-node basis, and all cluster operations are all done by gRPC API. Seems like they a specific use case in mind which will help keep the scope in check. Definitely looking forward to learn more about he project. Also golang is a pretty good choice for such a project because it doesn't even have a libc dependency and calls the Kernel directly. So you can indeed have a very pure userland in a garbage collected language. [0] https://docs.monogon.dev/metropolis-v0.1/handbook/index.html https://docs.monogon.dev/metropolis-v0.1/handbook/index.html
- kkfx 3y agoIMVHO it's just another demonstration we need code and production together, we need end user programming and most try to deny that, while all tend to, a very small step at a time. Python popularity, Notebook UIs, WebApps vs widget-based GUIs, this project... are all small examples of the same issue.
- dingnuts 3y agoIs the end user you refer to a highly technical person? Because 1 in 5 Americans do not have the literacy skills to "complete tasks that require comparing and contrasting information, paraphrasing, or making low-level inferences"[0] so if you're describing end user software as something usable by everyone, expecting users to become programmers is simply an unrealistic expectation. The below average person is simply not smart enough to learn a DSL to get something done, and software should be accessible to everyone, even those who weren't lucky in the IQ lottery. 0: https://nces.ed.gov/pubs2019/2019179/index.asp https://nces.ed.gov/pubs2019/2019179/index.asp
- kkfx 3y agoWell, "my" end-user is someone who have studied "computer science" a bit at school or to work, since he/she use computers every days, like he/she drive a car, so it's not acceptable he/she master computer usage less at level of mastery inferior to the one he/she master his/her car. I know very well how illiterate so many people are, but that's not something to be justified but to be corrected. I imaging you do not want a bus driver who can barely make the bus move on the road piloting the bus you are on, why it's normal for you that let's say a tax administration employee is just able to click around while dealing with your taxes? I've made a small experiment few years ago: with the help of some friend we have introduced for their very first time few kids to a desktop, a NixOS one running Emacs/EXWM. In 2 years at 6-8 years old, they was able to deal with emails, create some nicely formatted documents and doing basic math and so on with it. Two of them was presented a classic modern desktop: they became unable to do practically anything. It's a VERY small experiment of course, but to me it's enough to prove that people can learn if they are pushed toward a certain direction.
- skydhash 3y agoPeople can learn. I believe most programmers (who build side-projects) fall on the curious side. They explore stuff and thus discover software capabilities. Most people use software for a specific task, and learn only what is required. Making a software usable does not means making it a minimalist art project. It means making it consistent both in time (do not shuffle stuff around) and space (do not put things together randomly). Learning how to type a letter in a word processor can be done in a day. But learning something like Microsoft Word should take a training. Just like you should buy a book about git or bash if you’re serious about learning them. Let the user figures it out is the wrong direction. As well as reducing the software capabilities (for potential power user) in order to reduce cognitive load for untrained users.
- kkfx 3y agoIt's not that, it's another point: efficiency vs assembly line. Humans are not build to be robots, they are build to evolve. If we learn a classic desktop paradigm computer system at school, while we learn all the basic and less basic cultural stuff we learn at school to became Citizens, we can profit from this knowledge for life. We can choose to dig deeper or not, but we have something useful for our entire life. If we learn the modern desktop paradigm we never evolve. We are not Citizens, we are workers in an assembly line and upon any change from the factory owner our acquired knowledge goes to the bin. I hope to have successfully described the point in my poor English. To give a simple example, I track my bills (well, like many, nothing special), I've crafted a bit of automation (org-mode notes + BeanCount + a bit of py automation), it took two/three days, MUCH more than most users do with modern tools, BUT thereafter anything goes nearly autonomously so I've spent 2/3 days + few seconds looking at my org-agenda regularly vs few minutes to start than keep spending few minutes all the time. In the short term the classic model is not good, in the middle term it's equivalent but demand more intellectual work, in the long term outshine the modern one so much that's like comparing a runner by feet against one on a jet in a speed race. Actually the effort spent in automating my bills notes it's also useful (at least in some parts) to automated other stuff, a bit at a time, an evolutionary step at a time I've built and keep up my PIM, again all the effort put pay back and I've gained valuable knowledge from doing that. The modern approach seems cheaper at first but it's much more expensive in the long run and gives little to no valuable knowledge at all. The same model apply to any other aspects of our life, one to remain in economics the "ownership model" vs the "rent model", owning a home seems to be much, much more complex than rent one, it demand much more resources, much more computations and projection up front etc BUT it pay back much more thereafter. The rented home is just a regular expense that pile up year after year and at the end you have nothing. The owned home in most cases (essentially all, with insurances) have a final value, normally a big enough one to pay back the capex + opex of the time passed. Since we are not made to live a single life but to evolve, doing better things a generation after another, passing knowledge and anything we can to newer generation, the modern paradigm is the slave paradigm, he/she produce a new generation that have no benefit from the old one, get nothing, leave nothing in the end. The classic is the human model, where we build families, passing what we have built and the accumulated knowledge, improving a generation after another.
- ritonlajoie 3y agoThis looks interesting. However I can't find any documentation on how to program for it ? Where is their documentation about how we use this "unified API" which pools resources between nodes ?
- q3k 3y agoIt's somewhere in my git stack :). Until I get to publishing it, the proto/gRPC definitions for node management are a good enough start: https://github.com/monogon-dev/monogon/blob/main/metropolis/proto/api/management.proto https://github.com/monogon-dev/monogon/blob/main/metropolis/... And the top level API to actually deploy workloads is plain Kubernetes.
- timmg 3y agoAm I the only one who thinks it would be fun to try/put this on a Raspberry Pi cluster for fun?
- deleted 3y ago[deleted]
- 65a 3y agoIsn't u-root also basically this?
- the_panopticon 3y agoIt looks similar to u-root https://github.com/u-root/u-root https://github.com/u-root/u-root, yes, used as part of host firmware. There's a description of u-root in chapter 6 of https://link.springer.com/book/10.1007/978-1-4842-7939-7 https://link.springer.com/book/10.1007/978-1-4842-7939-7, too.
- visualphoenix 3y agoStill reading the handbook but this reminds me of Talos Linux[0] - which is also a pure golang k8s focused linux distro. [0] https://www.talos.dev/ https://www.talos.dev/
- rhaps0dy 3y agoThank you for sending this, Talos looks cool! I would not recommend actually running it in production though -- it does not seem possible to set up in a secure way. (unless you have an out-of-band VPN to the machine?) See this: https://www.talos.dev/v1.6/introduction/getting-started/#modifying-the-machine-configs https://www.talos.dev/v1.6/introduction/getting-started/#mod... The first time you send the machine config, you have to use the --insecure flag to avoid verifying its TLS cert. More concerning, there seems to be no way for you to authenticate yourself to the new machine. Anyone (most likely an automated scanner) could come in and make it theirs at this point. Is there a solution for that?
- lifty 3y agoHow can you bootstrap a PKI without having a trusted out of band channel?
- rhaps0dy 3y agoYou can’t, but other commenters pointed out that the OOB is specialized to each cloud and in another part of the guide.
- MathiasPius 3y agoYou can build a custom iso with a "talos.config" kernel parameter set which instructs Talos to download and apply a configuration on boot.
- HHad3 3y agoSure, there are solutions presented in the installation guide [1]. It usually involves using the cloud or virtualization platform's out of band channel, which Talos all supports, to securely provision a config on first boot. You can also generate a custom installation medium or cloud image that pulls config from your trusted machines if you cannot use out-of-band provisioning. You can also securely use the insecure maintenance mode when there is a firewall in front of the machine, which prevents access by non-administrator clients to the API ports on IP level. I'm not a fan of Talos booting into insecure maintenance mode without config w/o prompting for at least a PIN displayed on-screen, but the problem you're describing in no way prevents production use. [1] https://www.talos.dev/v1.6/talos-guides/install/ https://www.talos.dev/v1.6/talos-guides/install/
- chasil 3y agoIs this busybox in Go? What am I looking at? A sqlc compiler? Why not use sqlite, which is proven beyond doubt? A POSIX.2 userland in Go would not be unwelcomed in any way.
- clktmr 3y agoThere is also gokrazy[^1], which isn't focused on k8s, but on deploying on a rpi. [^1]: https://gokrazy.org/ https://gokrazy.org/
- justinsaccount 3y agogokrazy can also be used to build little VM images: https://gokrazy.org/userguide/qemu/ https://gokrazy.org/userguide/qemu/
- SrslyJosh 3y agoHuh, interesting...oh wait, bazel. closes tab
- szszrk 3y agoI'm not familiar with it, can you elaborate why it's controversial?
- rockemsockem 3y agoBazel is the externalized version of Google's internal build system. I think it has likely been overused by the overzealous in situations where its complexity is unwarranted and so a lot of people dislike it. However it is absolutely fantastic at what it's intended for, providing a single build system across a large multilingual codebase, and building/running quickly, with extras for running tests, etc.
- maxcoder4 3y agoIt also, AFAIR, gives you full reproducibility which is nice.
- devaiops9001 3y agoeww, gross
- pjmlp 3y agoBasically Inferno + Limbo revisited.
- tyingq 3y agoOr VMS even.
- neonsunset 3y ago[flagged]
- pjmlp 3y agoI for one, celebrate it, regardless of my dislike for Go's type system. Every step helping taking C out of the picture is a welcome one. At least it isn't like Microsoft where not matter what, .NET can't displace COM and C++ role on Windows, and isn't even used on new Azure Kubernetes samples. https://learn.microsoft.com/en-us/samples/azure-samples/aks-store-demo/aks-store-demo/ https://learn.microsoft.com/en-us/samples/azure-samples/aks-...
- throwway120385 3y agoI wouldn't mind Go if their executables didn't take hundreds of megabytes to do something a C/C++ executable could do in less than 2 megabytes. There are a bunch of executable size issues languishing on their issue tracker and from what I understand it has to do with how some core features of the language are implemented that causes a combinatoric explosion of entries in a table in the executable. They also made an adjustment to stop compressing that table, which makes sense from a startup time perspective but there are also no levers I can pull to compress the table or disable the feature. .NET executables have the same issue but I can always dynamically link them against a single runtime.
- neonsunset 3y agoFunnily enough, .NET's NativeAOT took the opposite route and various tables have dehydrated form in the binary which will be hydrated at startup (with the size wins observed up to 30-35% depending on publish contents) If you're interested, here's the PR history for the feature: - https://github.com/dotnet/runtime/pull/77884 https://github.com/dotnet/runtime/pull/77884 - https://github.com/dotnet/runtime/pull/79209 https://github.com/dotnet/runtime/pull/79209 - https://github.com/dotnet/runtime/pull/78545 https://github.com/dotnet/runtime/pull/78545 - https://github.com/dotnet/runtime/pull/79732 https://github.com/dotnet/runtime/pull/79732 - https://github.com/dotnet/runtime/pull/78546 https://github.com/dotnet/runtime/pull/78546 - https://github.com/dotnet/runtime/pull/78688 https://github.com/dotnet/runtime/pull/78688 - https://github.com/dotnet/runtime/pull/78748 https://github.com/dotnet/runtime/pull/78748 And if anything, you can always UPX them except on macOS where it is broken for some reason. There also exists a package that adds it as a build step: https://www.nuget.org/packages/PublishAotCompressed https://www.nuget.org/packages/PublishAotCompressed
- q3k 3y agoHello, I'm one of the contributors to Monogon OS (codename Metropolis). We didn't expect to go public with our project for a few more months, which is why the end-user documentation is still very bare, sorry! But fixing that is something we're prioritizing over the next few quarters. But I guess the cat's out of the bag, so I might as well stay around and answer any questions that pop up. We've also quickly set up a public Matrix room, which was long overdue: https://app.element.io/#/room/#monogon-os-community:matrix.org https://app.element.io/#/room/#monogon-os-community:matrix.o...
- themerone 3y agoHow does this compare to gVisor?
- q3k 3y agoWe actually provide gVisor as the default runtime for Kubernetes workloads. Monogon OS implements the layers underneath Kubernetes and gVisor - it's the operating system which runs on your nodes/machines and which comes together to form a cluster.
- kardianos 3y agoThis looks really nice. How do you handle Ingress and network policies? How do you handle multiple clusters on a single physical machine (if I read the docs correctly) for ingress?
- q3k 3y agoNetwork policies are currently not implemented. Bring your favourite Ingress controller. We support NodePort services, with plans for a LoadBalancer Service controller given the right network topology (a la MetalLB - either BGP to TOR switches to announce /32 / /128s, or maybe ARP/NDP-based annoucements for simpler deployments). We don't support colocating multiple Kubernetes clusters on a single machine, or even within a single Monogon OS cluster. If you want multiple Kubernetes clusters, run multiple Monogon OS clusters.
- deleted 3y ago[deleted]
- djaouen 3y agoI used to be very anti-Go, but I am coming to like it, especially the projects built with it. Nice work!
- seanw444 3y agoHow can one be anti-Go? It's a solid, fairly resource unintensive language.
- 3836293648 3y agoZero abstractability, extremely imperative. It's very good at what it's for, but it's absolutely terrible for anyone who prefers a declarative or even functional style
- DSingularity 3y agoIs there an advantage to language designed to mix the styles?
- gonzo41 3y agoPython, Java and C++ do attempt to support all styles to varying degree's. Some of those languages have had varying success. :P
- Zambyte 3y agoThe tradeoff is being able to decide how your project should be organized rather than someone else deciding for you. Sometimes you want that, sometimes you don't. The advantage of mixing paradigms in a single technology is the ability to switch / decide on paradigms without switching technologies.
- ForHackernews 3y agoI dislike Go. It's almost anti-expressive. It's fine if you want a dull language that your junior devs will find hard to shoot themselves in the foot with. It's like a safer C.
- pbronez 3y agoThis bears passing resemblance to Aurae [0]. Both projects are trying to reimagine the space between the Linux kernel and the cluster using modern languages for improved safety. Beyond that, I can’t confidently compare and contrast the projects at this time. [0] https://aurae.io/ https://aurae.io/
- deleted 3y ago[deleted]
- ynx 3y agoBoneworks-inspired name?
- nxobject 3y agoPerhaps they could merge into systemd, so we can finally be done with it and get to systemd/Linux.