5 ms·
I agree that removing the container would be better on resources. However, most self-hosted software is already "pre-packaged" in Docker containers. It's much
by snowpalmer 2y ago
I agree that removing the container would be better on resources.
However, most self-hosted software is already "pre-packaged" in Docker containers. It's much easier to grab that "off-the-shelf" than have to build out something custom.
- transpute 2y agoNixOS improves the reproducibility of both self-hosted software and configuration state.
- kkfx 2y agoIn NixOS/Guix System there is no need of such package, the configuration language/package manager takes care of anything, configuration included. Let's say you want Jellyfin? jellyfin = { enable = true; user="whatyouwant"; }; # jellyfin under services and you get it. You want a more complex thing, let's say Paperless? paperless = { enable = true; address = "0.0.0.0"; port = 58080; mediaDir = "/var/lib/paperless/media"; dataDir = "/var/lib/paperless/data"; consumptionDir = "/var/lib/paperless/importdir"; consumptionDirIsPublic = true; settings = { PAPERLESS_AUTO_LOGIN_USERNAME = "admin"; PAPERLESS_OCR_LANGUAGE = "ita+eng+fra"; PAPERLESS_OCR_SKIP_ARCHIVE_FILE = "with_text"; PAPERLESS_OCR_USER_ARGS = { optimize = 1; pdfa_image_compression = "auto"; continue_on_soft_render_error = true; invalidate_digital_signatures = true; }; # PAPERLESS_OCR_USER_ARGS }; # settings }; # services.paperless Chromium with extensions etc? chromium = { enable = true; # see Chrome Web Store ext. URL extensions = [ "cjpalhdlnbpafiamejdnhcphjbkeiagm" # ublock origin "pkehgijcmpdhfbdbbnkijodmdjhbjlgp" # privacy badger "edibdbjcniadpccecjdfdjjppcpchdlm" # I still don't care about cookies "ekhagklcjbdpajgpjgmbionohlpdbjgc" # Zotero Connector # ... ]; # extensions # see https://chromeenterprise.google/policies/ extraOpts = { "BrowserSignin" = 0; "SyncDisabled" = true; "AllowSystemNotifications" = true; "ExtensionManifestV2Availability" = 3; # sino a 06/25 "AutoplayAllowed" = false; "BackgroundModeEnabled" = false; "HideWebStorePromo" = false; "ClickToCallEnabled" = false; "BookmarkBarEnabled" = true; "SafeSitesFilterBehavior" = 0; "SpellcheckEnabled" = true; "SpellcheckLanguage" = [ "it" "fr" "en-US" ]; }; # extraOpts }; # chromium Etc etc etc. You configure the entire deploy and get it generated, a custom live? With auto-partitioning and auto-install? Idem. A set of hosts in a network similar (NixOps/Disnix) and so on. The configuration language do all, fetching sources and build if a pre-built binary is not there, setting up a DB, setting up NGINX+let's encrypt SSL certs, there are derivation (package) per derivation options you can set, some you MUST set, defaults etc., it's MUCH easier than anything else, only issue is how many ready-made derivations are there, and in packaging terms Guix is very well placed, NixOS is more than Arch, even if something will be always not there or incomplete as long as devs do not learn alone the system and start using Nix/Guix also to develop, so deps are really tested in dedicated environments and so on, and users always get a clean system, can change and boot in a previous version and so on.
- stackskipton 2y agoSigh Nix users. I need to run uptime kuma, Here is Docker Compose: https://github.com/louislam/uptime-kuma/blob/1.23.X/docker/docker-compose.yml https://github.com/louislam/uptime-kuma/blob/1.23.X/docker/d... What is equivalent in Nix?
- zarzavat 2y agoNix/NixOS and Docker work in fundamentally different ways so you have to decide which method of operation is most suitable for your use case. If you use Docker then each container requires its OS image, which is fine if you’re running on a server and running other people’s software, but if you want to develop your own containers on a laptop then that convenience becomes an inconvenience. Nix is more lightweight.
- kkfx 2y agoservices.uptime-kuma = { enable = true; appriseSupport = true; settings = { ... } # settings }; These are examples, you have to write down the system configuration, meaning picking uptime-kuma, choose what deps you want and so on. No need to "run a oneliner" on a homeserver than ssh and do things by hand to tweaks, with no reproducibility or hoping someone else have already made them in something ready-made. Doing the pick-a-oneliner is a classic developer in Silicon Valley mode move which cause a classic set of disasters, like wasting gazillion of resources for nothing, not seen an image with someone else ssh authorized key, keep running vulnerable software and so on because he/she just need a oneliner, no matter if it pull down 10 images, consuming 1Tb of storage, having stellar CPU requirements etc because you are in SV-mode, you do not care and anyway you do not pay for the iron because it's a company one or it's a cloud service you do not even see how much loads you generate, AWS bill will go to someone in accounting. On the other side of course IT business like that, because they can sell you a ready made image, selling just few line of code can't be priced much, while selling a service who provide a big file set might be priced well. Also selling a VPS and so on "hey devs, you literally just need to click here and we do the rest" pay very well. Those who sell of course. Aside such mindset create an enormous amount of layers who in the long run create so heavy and complex infra no one knows them. Just try to see what Home-assistant do. By default their devs suggest to run it on a dedicated machine (!) so they imaging you buy a single-board computer juts to run a damn app, ending up with this model with a gazillion of single board computer scattering around. Second option containers. So to run HA you need let's say 1-3Gb of stuff, nearly no mention to the simplest pip install. Zero mention that unlike pip install NixOS does not need to download a gazillion of binary basic stuff for python deps, if you have them on your /nix/store you just link them on as many pkgs needs them, keeping just one copy. In the end you craft your system, as a single application, a single configuration, which demand 1/10 of resources used otherwise, have much less thing who can breaks, it's easy to know entirely etc. You might state that's a classic operation vs devs.
- pxc 2y ago> However, most self-hosted software is already "pre-packaged" in Docker containers. It's much easier to grab that "off-the-shelf" than have to build out something custom. Imo, the quality and documentation level of an application's build system is a valuable signal in determining its overall health and competency. It usually (though not always) ends up being that well-maintained software written for modern runtimes is very easy to build from source and run. Even if I do end up using the developer's container image, I generally want to check out their manual deployment documentation.