14 ms·
Are Immutable Linux Distros right for you?
- javitury 2y agoI totally see the advantages of immutable distros, particularly in a professional or cloud environment. Even as a hobbist, I feel tempted to use immutable distros if it were not because of: - Learning. Figuring out how to migrate a setup even to the most mainstream-like immutable distro (fedora silverblue) can take a while, and to niche distros like talos even longer. However, a k8s-friendly setup with low customization requirements would help to speed up the migration (but it requires more powerful machines). - Long term support. Regular distros like Debian and AlmaLinux offer free 5 and 10 year support cycles which means maintenance can be done every 1 or 2 years. On the other hand, immutable distros would require much more frequent maintenance, once every 6 months. A weekend every 6 months is a sizeable part of my time budget for hobbies. One aspect in which immutables distros have improved a lot is in resource usage. They used to require significantly more disk space and have slightly higher minimum requirements than regular distros, but that doesn't seem to be the case anymore.
- tayo42 2y agoI dont see how it helps in a cloud environment? With correct permissions users aren't making changes to live servers or even logging in and if you want to roll out upgrades you can do it with OS images already? Maybe it would help in a datacenter
- zuntaruk 2y agoIn some aspects, I'd hope that there are potential benefits on the security side of things as well. Since the host FS is generally read only in these type of distros, there is the potential to make some security teams happy.
- immibis 2y agoExactly, and if it's immutable, you know they aren't. Not through SSH, and not through a vulnerability either. I assume there's something you can hash to determine prove that you haven't been hacked, as well.
- javitury 2y agoImmutable distros typically use a declarative configuration that is easier to manage with terraform
- plagiarist 2y agoI found Fedora is terrible at documentation, or at least around rpm-ostree they are. It has made learning more of a struggle than necessary. I think the basics are that there is some sort of container image builder that can work from a manifest, then some way to create a distro out of a container image. All of the content I can find is fragmented across many sites and not complete enough to actually use. Extremely frustrating.
- gavindean90 2y agoYea the docs on the Fedora side are rough. I would help but I don’t know enough because the learning was so hard.
- eraser215 2y agoFair call. In any case I think you'll find things moving towards bootc and away from having to know rpm-ostree at all. The bootc documentation for fedora is pretty good and the Universal Blue project has built some awesome distros that use bootc.
- mikae1 2y ago> Long term support. Regular distros like Debian and AlmaLinux offer free 5 and 10 year support cycles which means maintenance can be done every 1 or 2 years. What's maintenance in the context if immutable distros? Running "ujust upgrade"? That's done automatically in the background for my Aurora installation. Also, they're working on CentOS based LTS versions of Bluefin: https://universal-blue.discourse.group/t/call-for-testing-bluefin-lts-alpha/5841/2 https://universal-blue.discourse.group/t/call-for-testing-bl...
- javitury 2y agoYes, system upgrade is the main maintenance task. With some monitoring, security updates can be automated but after system upgrades I must check manually that everything is working. E.g. incompatible configuration files, changes in 3rd party repos, errors that surface one week after the upgrade, ... There are also smaller maintenance tasks that are tipically ad-hoc solutions to unsolved problems or responses to monitoring alerts. One of this ad-hoc routines was checking that logs do not grow too large, which used to be a problem in my first systemd centos, although not anymore. PD: thanks for the bluefin read, it made me discover devpod/devcontainer as an interesting alternative to compose files
- flomo 2y ago> Long term support Intuitively, this seems opposite, because you could obviously 'mutate' (or mutilate) your Debian system until the updates break. Isolating user changes should make updates easier, not harder. Also MacOS uses a 'sealed' system volume and updates are like butter there.
- talldayo 2y ago> Also MacOS uses a 'sealed' system volume and updates are like butter there. Smooth as in "no data loss", sure. Smooth as in "supports the software I buy and use for long periods of time" is most certainly not true, even despite half the software for Mac being statically linked. Windows and Linux arguably do better at keeping system functionality across updates even with their fundamental disadvantages.
- Groxx 2y agoWhile true, this isn't even slightly related to the os being "immutable" or not. Immutable-OS upgrades can and do break things - that's the reason it's even a thing. They just give you a reliable rollback.
- heresie-dabord 2y ago> the advantages of immutable distros The high availability of ChromeOS is a good example of these advantages in a business of educational context.
- toprerules 2y agoYou’re missing the whole point of an immutable distro. If you have a hobby project on a regular distro, you run apt-get update or whatever, it installs 200 packages and half of them run scripts that do some script specific thing to your machine. If something goes wrong you just bought yourself a week’s worth of debugging to figure out how to roll back the state. If you update using an immutable distro, you rebase back on to your previous deployment or adjust a pin and you’re done. Immutable distros save you tons of time handling system upgrades, and the best part is you can experimentally change to a beta or even alpha version of your distro without any fear at all.
- bmicraft 2y ago> If something goes wrong you just bought yourself a week’s worth of debugging to figure out how to roll back the state. But that basically doesn't happen between release upgrades, not unless you're doing something with third party repos at least. > If you update using an immutable distro, you rebase back on to your previous deployment or adjust a pin and you’re done I genuinely don't know, but can you do security updates without rebasing? Just keeping some working version pinned sounds like bad idea to me, and doesn't even save you time because you'll need it resolve that problem eventually anyways.
- ChocolateGod 2y ago> But that basically doesn't happen between release upgrades Nvidia would like a word
- bigstrat2003 2y agoI have an Nvidia card and I've never had it cause problems.
- ChocolateGod 2y agoMany people install Nvidia drivers by using their shipped .run binary (which is a bad idea) and thus breaks when the kernel is updated to something higher than the DKMS module supports.
- mrbluecoat 2y agoIsn't NixOS immutable? If so, surprised it wasn't mentioned.
- phire 2y agoI certainly consider it to be immutable. But NixOS is immutable in a very different way to all the mention distos, which are focused on containers, isolation, and layers; Maybe the author doesn't consider it to be in the same category? Personally, I've decided that NixOS is not for me. The concept is great, but the actual experience seems to be held back by Nix (the language and the tool) being hard to understand and debug.
- brnt 2y agoI think openSuse also calls their rpm+btrfs snapshots solution immutable, but afaik it doesn't use containers.
- globular-toast 2y agoTried Guix?
- whateveracct 2y agoHave you ever used the nix repl? I find between that and having the failing build keep its working directory around for inspection, it's always easy to debug thing. I guess the third tool is overlaying the equivalent of debugging into derivations but that's rare.
- phire 2y agoI did. The problem with nix repl, is that it only seems to help if you already understand both nix and how the derivations are actually implemented in nix. It's pretty useless as a learning tool.
- whateveracct 2y agoI don't think that's true. Because the main way I learned those things was poking in the repl. Hitting tab and stuff. And reloading changes to files or overlays and debugging what happened by inspecting things. It's the same as learning Haskell. Outside of syntax and some basics, you don't need to have deep knowledge to use ghci. And Nix and Haskell are both just substitution-based evaluation (lambda calculus) which imo is 80% of understanding them.
- KyleSanderson 2y agoOpenWRT is pretty much the oldest still running (and popular) with UCI. There's the classic nvram ones, but those are hardly manageable manually.
- colordrops 2y agoWhat is UCI?
- fragmede 2y ago> The abbreviation UCI stands for Unified Configuration Interface, and is a system to centralize the configuration of OpenWrt services. > UCI is the successor to the NVRAM-based configuration found in the White Russian series of OpenWrt. https://openwrt.org/docs/guide-user/base-system/uci https://openwrt.org/docs/guide-user/base-system/uci
- rollcat 2y agohttps://openwrt.org/docs/guide-user/base-system/uci https://openwrt.org/docs/guide-user/base-system/uci Also the web UI counterpart, LuCI: https://openwrt.org/docs/guide-user/luci/luci.essentials https://openwrt.org/docs/guide-user/luci/luci.essentials I've been running OpenWRT on my home router since ca 2017, and I found LuCI both quite intuitive, and immensely powerful. Simple things are simple, complex or difficult things are possible, with just clicking around. Unfortunately if something can't be done with LuCI, you're pretty much on your own - the documentation for the internals is scarce and expects you to be an expert/developer.
- deleted 2y ago[deleted]
- RalfWausE 2y agoI am now running EndlessOS for a while and i love it: Its a bit like going back to the home computer days when the OS was residing in a ROM and you didn't really have to care.
- evanjrowley 2y agoMy first immutable distro was Illumos-based SmartOS. Everything the system needs is read from a read-only USB stick and run from RAM. I wish more distros worked that way. A recent submission on here gives me hope: https://news.ycombinator.com/item?id=42428722 https://news.ycombinator.com/item?id=42428722 I suppose TinyCore Linux in its default configuration also counts.
- yjftsjthsd-h 2y agoThe whole illumos family has degrees of this; SmartOS is of course full immutable with a ro OS that can be replaced to update, but even ex. OpenIndiana applies core OS updates to a clone of the root filesystem and you can always roll back to a snapshot.
- dagmx 2y agoI’m honestly surprised Immutable distros is so controversial. I get why people choose not to do it, but I don’t know why I see so much hate towards them in a lot of Linux communities. SteamOS is immutable and incredibly successful. macOS (not Linux of course) is also immutable and very successful. As long as the OS’s have a concept of overlays, an immutable system rarely gives up much in the way of flexibility either.
- imcritic 2y agoSteamOS is not a general purpose OS, yet you mention it as if it is one. macOS is not immutable at all.
- fragmede 2y agoFor a couple of years now, macOS has an RO System volume image, and then mounts an RW data volume on top of that, similar to how overlayfs works on Linux. That system volume isn't modifiable. If it is, then the system won't boot. So I'd say it's a little bit immutable. https://eclecticlight.co/2021/10/29/how-macos-is-more-reliable-and-doesnt-need-reinstalling/ https://eclecticlight.co/2021/10/29/how-macos-is-more-reliab...
- dagmx 2y agoHow would you define an immutable distro that would exclude macOS with SIP? And steamOS is totally a general purpose OS, it’s just got a non-general purpose frontend it defaults to.
- TheCapeGreek 2y agoFor most users, including many developers, SteamOS absolutely can be general purpose. There are two main "daily driver" usability issues on SteamOS by default if you need to do technical work: - Limited software availability via the flatpak repositories. - Not being able to install certain programs as easily without needing containerisation of some kind (if that even solves the problem in some cases). Distrobox solves a good amount of both issues on SteamOS, for coding work at least. Slap a virtual Ubuntu on and you're off to the races.
- 2y ago
- bjoli 2y agoYes. I am already running and Aeon desktop base system with gnu guix for the userland. It's great.
- swaits 2y agoBeen running Kinoite for a good bit (~1 year). I'm a bit over it. Love the idea of immutability, but rebooting every time I get a new system image via rpm-ostree, which is often, is tiresome. Of course, I could update less frequently; alas, habits formed from years of using rolling releases. I switched to EndeavourOS. Between flatpak and brew and mise, I have relatively well sandboxed applications. This gives me most of the benefits of the immutable OSes, although nowhere near as rigorous, obviously. For a technologist, though, it's fine.
- pimeys 2y agoYou might be interested in Serpent OS, which offers immutability but without reboots after each upgrade. https://serpentos.com/ https://serpentos.com/ They just hit their first alpha release, but it has been under development for years already. They focus on rust-based tooling, so even their coreutils are the rust versions instead of GNU. I read the alpha announcement yesterday, and might give it a spin later next year. So far I've been very happy with Kinoite. I upgrade the base system once a week, but everything is installed in my Arch based container, so updates are fast and do not require a reboot. On my workstation I use the Aurora Linux, a spin of Kinoite with extra tools such as tailscale added to the base image. On that machine I haven't needed to use rpm-ostree at all. https://getaurora.dev/ https://getaurora.dev/
- swaits 2y agoThanks for pointing met to Serpent! I gave Aurora a quick spin before going back to Endeavour. Didn’t work well for me.
- LeFantome 2y agoSo, from a userland perspective, you are actually running Arch.
- pimeys 2y agoArch, Nix, Debian, Fedora and Windows. Just switch between them from the terminal new tab menu. If one container breaks, just dump the list of installed packages and start over. The base system is rock solid.
- okasaki 2y agoYou don't need a whole new distro $ apt search btrfs apt Sorting... Done Full Text Search... Done apt-btrfs-snapshot/noble,noble 3.5.7 all Automatically create snapshot on apt operations
- tmtvl 2y agoI've been meaning to fully commit to GNU Guix one of these days, now that Plasma has fully landed. I've tried Fedora Kinoite in the past, but I can't handle Plasma without Oxygen. I know that Kinoite has some kind of a way to force packages to be installed into the base system, but it kinda feels like it defeats the purpose.
- jillesvangurp 2y agoI've been on Manjaro (arch based) for the past four years. It's mostly been fine but I've had to recover it from a botched Grub update once (an update randomly self destructed its configuration), which wasn't fun. But after four years it's in good shape, everything works, I run the latest kernel, etc. I have zero reason to wipe its installation and reinstall it again. Most other Linux distributions never lasted four years until I found a need to reinstall them or install some newer version. And it's Linux so regardless of the distribution you'll be dealing with some amount of weird shit on regular basis. Has been true since I cycled home with a stack of slackware floppies almost thirty years ago. There's always configuration files to fiddle with, weird shit to install, etc. But an immutable base OS makes a lot of sense and it's not mutually exclusive with that being updated regularly. Containerization is the norm for a lot of server side stuff. Effectively, I've been using immutable server operating systems for almost a decade. It's fine. All the stuff I care about runs in a container. And that container can run on anything that can run containers. Which is literally almost anything these days. I generally don't care much about the base OS aside from just running my containers hassle free on a server. Containerization would make sense for a lot of end user software as well. IMHO things like flatpak and snap would be fine if they weren't so anal/flaky about "security". Because they are protecting a mutable OS from the evil foreign software. Running a bit of software that needs a GPU isn't a security problem, it's the main FFing reason I'm using the computer at all. Or own a GPU. This needs to be easy, not hard. And it shouldn't need a lot of manual overrides. If I run a browser or things like Dartable, I usually have no reason to run them in crippled/unaccelerated mode. Sorry that's not a thing. It's the main reason I bypass flatpak on Manjaro for both packages. And I bypass PAC as well because I trust Firefox to have a good release process. So, I use the tar ball and it self updates without unnecessary delay. Which considering a lot of its updates are about security is exactly what I want. Same with development tools. I use vs code and intellij. Both can self update. I have no need for a third party package manager second guessing those updates or dragging their heels getting those updates to me.
- johnny22 2y agoI still use containers for all that stuff that is not yet suitable for flatpaks (or perhaps never will be), just via distrobox or toolbox while leaving the host OS untouched
- lrvick 2y agoIf you also need determinism and full source bootstrapping (you care about supply chain security) check out https://codeberg.org/stagex/stagex https://codeberg.org/stagex/stagex
- deknos 2y agoI like immutable distros. What i do not like is that developers and maintainers do not give possibilities to admins and powerusers to build a immutable core themselves. This removes choice and learning experiences for the customer/user/admin. Maybe this will finally change.
- pimeys 2y agoCould the Universal Blue image builder solve this for you? https://github.com/ublue-os/image-template https://github.com/ublue-os/image-template
- cprecioso 2y agoFor CoreOS, you can create immutable images as easily as you can create Docker containers: https://coreos.github.io/rpm-ostree/container/ https://coreos.github.io/rpm-ostree/container/ You can later just point the installer to your OCI image and it will just work
- nullify88 2y agoConfiguration as code has come as long way too along with these immutable OSs. For example I do not miss messing with preseed or kickstart files (I preferred working with kickstart files). Ignition / butane I find is much easier to work with and is a core part of configuring the OS.
- xorcist 2y agoThe term "stability" should not be used outside of the major Linux distributions such as Debian and Fedora. For a distribution to be stable over the long term it needs a large enough community, a stable governance model, and a reasonable build system where one maintainer cannot take unilateral action without it being discovered. A cute name and a university student somewhere does not constitute stability, no matter how good the intentions. It's not a bad thing, but you have to know what you get yourself into. Most of the distributions listed in the article belong to the latter category. Immutable systems are great for embedded, network equipment, appliances and industrial applications, and specialized distributions for those applications have largely been immutable for a long time already. Nobody really wants an immutable system for their main desktop, because working is all about mutating state. You write may write documents, save bookmarks, install plugins, or try new software. Those are the things really immutable systems like kiosks wants to disallow. So in order to make for usable software these desktops generally split your system into a mutable user part and an immutable system part. That's basically how unix-like desktops have worked since forever. Stuff in /bin and /sbin is only changed by the package manager. So the fit is quite good, but it also means it really isn't as useful as it's made out to be. That's why most people don't use them. The use case is mostly for rolling back updates, not really running from readonly filesystems or preventing change in other ways, but most distributions already do that. You can roll back updates with both dnf and apt. It's not perfect and doesn't always work, but mainly from a lack of testing. With snapshots it's pretty much infallible though. My recommendation if you really want something that "just works" is to install one of the major and time tested distributions. Pick Debian if you don't know what to choose. And then learn how to use it. Anything these tiny experimental distributions offer, such as running off read only filesystems or rebuilding it for your brand of cpu, or testing a new desktop environment, is likely possible in Debian too. With the added benefit of it being around in 20 years. And the core distribution is less likely to break in some way because some maintainer found inspiration for something. As long as you don't run untrusted stuff as root, stay out of the system files, and generally let the package manager do its job, you're going to be fine. What I would like to see a desktop distribution work on is basically the same things as 20 years ago which still isn't really done outside some exploratory work (probably because it's actually hard): - Packages on a user level where it is easy to install new stuff without touching the system area. More tricky in practice than in theory because of state changes to configuration files, saved file formats etc. But some should be easier than others. - Desktop software service accounts, just like we do for server software. Mostly relevant for larger packages such as Firefox, Libre Office, movie players. - Integration with popular third party package managers from the language ecosystems. Most language packages are anemic. All the powers that a package manager gives, reporting, listing untracked files, listing changes, rolling back updates, should be available for them by integrating directly with them. Package definitions should be able to be imported without manual work. - Package managers should have at least some knowledge of an application's access patterns to help with application confinement. Still today things like selinux policies are packaged are separate entities and managed with external tools, which brings a lot of complexity since all possible configurations must be supported there. A package manager knows more about the system and could handle these files. Confining desktop software is a usability problem more than a technical one, but it is clear that desktop environments needs something to build on to make it practical.
- shatsky 2y agoAnother opinion: immutability is required to guarantee software integrity, but there is no need to make whole system or "apps" immutable units. NixOS also consists of "immutable units", but its "granularity" is similar to packages of traditional Linux distros, each unit (Nix store item) representing single program, library or config file. This provides a better tradeoff, allowing to change system relatively easily (much easier than in immutable distros described here, and in many cases as easy as in traditional Linux distros) while having advantages of immutability.
- UltraSane 2y agoImmutable distros are a good fit for very mature Infrastructure as Code setups. They make drift from the original config impossible.
- packetlost 2y agoIME you don't need a mature IaC setup to have it work well, especially if you've bought into containerization
- shatsky 2y ago>make drift from the original config impossible NixOS makes that too, its whole "system output path closure" is as immutable as every single store unit within it. But NixOS "reuses" units which are unaffected by NixOS config changes when applying new config, making its "system rebuild" super fast and light on resources when something like a single config file is changed in NixOS config. And possible to be done "in place", unlike with "conventional immutable distro"
- toprerules 2y agoYou don’t understand what immutable distros are for. Imagine you need to upgrade 500k machines and your options are either run an agent that has to make the same changes 500k times and hopefully converges onto the same working state no matter the previous state of the machines its running on, or you pull a well tested image that can be immediately rolled back to the previous image if something goes wrong. Saying it’s just about integrity is like saying docker images are just about integrity… they absolutely are not. They give you atomic units of deployment, the ability to run the same thing in prod as you do in dev. Many other benifits.
- amelius 2y agoIs this how embedded folks make sure that a device starts with exactly the same installation every time a machine is booted? I wonder why embedded products like Nvidia Jetson do not come with an immutable Linux (and instead are based on Ubuntu which updates itself on every opportunity via apt and snap and whatnot).
- chrisdalke 2y agoThere are lots of companies using NixOS for this, BalenaOS (Yocto + Docker), or building their own bespoke tooling on top of a minimal Linux setup. Although many places start with Ubuntu or Debian in my experience it’s common to invest a lot of time and energy in getting out of that unmanaged setup once the company scales.
- amelius 2y agoThe hardware usually comes with vendor-specific libraries (e.g. cuda in the case of nvidia) which are based on a specific version of libc, so then you will have to build your entire alternative OS around that version also.
- chrisdalke 2y agoWhich is… never trivial. I’d say 25-50% of my career so far has been repeatedly “fixing” clunky deployments of ROS, OpenCV, L4T, CUDA, cudnn, libc, etc. in Docker and Nix. Fun stuff!
- throwaway173738 2y agoIt’s common for hardware vendors to provide a working system for demonstration purposes so you can evaluate the hardware without having to learn an immutable OS toolkit. Then when you pick hardware you also do the bring up work to get the kernel compiling from source and integrated with your userspace of choice. At that point you’ll switch to an immutable system. Hardware vendors in this space can’t be trusted, so you need to make sure the board is actually fit for purpose. Outside of the hobbyist space you have to be really careful. There are often business objectives that rely on the board working a certain way.
- sys_64738 2y agoThis just sounds like a problem solved a long time ago in the embedded space for using squashFS for the bootable Linux image.
- wkat4242 2y agoFor me: no. I want full control over my system. Immutability means leaving part of that to the OS developer. Definitely don't want that. Even though it's ostensibly better for security (though it's only really making one step in the kill chain harder, which is establishing persistence).
- toprerules 2y agoFirst, you don’t have full control of your system. Your system is running an unknown amount of code as binary firmware blobs even if you’re using a completely open source kernel. Hopefully you’re compiling every package yourself and not using pre-compiled binaries from your distribution’s repositories. Second, immutable distros are primarily a distribution and update mechanism that vastly improves the current model of running X number of package updates and scriplets on every machine and hoping it works. There’s nothing that stops you from remounting a filesystem as rw at least on any of the distributions that I know of. There’s also plently of stateful, rw holes for data and configuration on “immutable” distros.
- akikoo 2y agoHe's talking about the management of his system, not the development of his system.
- wkat4242 2y agoI like the traditional package system, I don't like containerising everything (though I know that is not necessarily coupled with immutable distros). Because then every package can have different library versions and the dynamic loader can't do its thing. But it's more the configuration that I want to be able to adjust, or to recompile things. As a typical example, on alpine I always need to recompile sudo as their standard version doesn't allow PAM which I need. On an immutable system such tools would usually be in the immutable part. I had problems with macOS when they switched to immutable (and if you turn off the protection it turns off a whole load of other things too). If I as much as changed the /etc/ssh/sshd_config it would revert with updates. And really the traditional package system works totally fine for me.
- AMD_DRIVERS 2y agoI run Fedora Kinoite full time on my primary machine, and it's great. Obviously a bit of a learning curve, but if your workflow can be achieved using Flatpaks and Toolbox, it's fine. You can (and I do) layer packages but I have only 3 or so I need to layer (asusctl, supergfxctl and asusctl-rog-gui). My only real gripe is that Firefox still ships as an rpm in the base image. I understand that they want to include a working web browser at all costs, and I don't think they can distribute the Flatpak version with the base image, but it's annoying that I have to mess with the image (removing Firefox) to then re-install the (more up to date) Flatpak.
- bogwog 2y agoAnd if you have an nvidia card and want to use cuda, Bazzite offers the same experience as Kinoite, but with nvidia drivers preinstalled out of the box. A cuda dev environment is a 'toolbox create' away
- toprerules 2y agoThere’s a lot of comments in here about desktops, but IMO why even discuss Linux on the desktop… 99.9999% of Linux deployments are not Arch installs on old Thinkpads. Immutable distros *are* becoming a de-facto standard for server deployments, IoT devices, etc. They improve security, enable easy rollbacks, validation of a single non-moving target for systems/hardware developers… There’s also been a ton of very advanced development in the space. You can now take bootable containers and use them to reimage machines and perform upgrades. Extend your operating system using a Dockerfile as you would your app images: https://github.com/containers/bootc https://github.com/containers/bootc
- smilliken 2y agoEvery professional programmer needs a desktop OS, and NixOS is really hard to beat. Switching to NixOS is like going from a car that is breaking down all the time to one that's reliable and easy to mod and repair. I don't recommend it to family members, but I do recommend it to programmers that care about their tools. Of course there's many more Linux servers out there than there are programmers, but the OS the programmer uses to develop on is just as important as the OS they deploy to.
- bsder 2y agoNix the idea is fantastic. Nix the implementation is currently a disaster. I liken Nix to source control in the time of CVS. We need two more implementation iterations before its going to be useful to the general public.
- yoavm 2y agoCan you elaborate? Why is it a disaster? I've only used Nix as a package manager when my work distro doesn't have some tools I wanted to install, but the few people I know that use NixOS seem to swear by it.
- clvx 2y agodebugging and error messages are still hard to deal with. Also, flakes should become standard at this point. Documentation on how to load modules and explore modules using nix repl is also lacking and/or frustrating. It definitely has rough edges. I do hope it will improve.
- jmclnx 2y agoThey are not for me, but I am glad they exist.
- udev4096 2y agoA new breed of distros for sure but how immutable is it, really? What I'm interested in knowing is the mechanisms and techniques in place for making sure no one can change any core components of the system. It's just like randomness. At first, it sounds super secure but we all know nothing is truly random
- linsomniac 2y agoAround 2000 I made a firewall-oriented Linux distro that made use of immutable bits and SELinux and various other security hardening. The bulk of the filesystem was immutable, and the system was then put into multi-user mode, where the kernel enforced that the filesystem couldn't go back to mutable. During boot time, a directory was checked for update packages, and if the public key signature of the package matched, the updates would be applied before the filesystem went into immutable mode. This update directory was one of the few mutable directories on the system.
- Fnoord 2y agoBack around that time I remember running such a firewall OS on a floppy disk. You would set the floppy readonly, and you could update the floppy by taking it out. It ran entirely in RAM. I forgot the name, it was either Linux 2.0.x or 2.2.x. I don't even remember if settings were kept after reboot. I installed it for a friend of a friend in his student apartment. Years later, I gave a daughter of a friend of my mother my old PC. It would boot up a Linux live CD. That, too, is immutable, and you'd update it by burning a new live CD. But where did we arrive to this? Well, computers had all services enabled for some reason (not with big bad internet in mind, but LAN). And updates were distributed via CDs or different media. Some airgapped environments are still going to work akin to that. Now, if the devices are connected to internet, they have to be updated because security vulnerabilities are going to have been discovered.
- tcrenshaw 2y agoI don't think most immutable distros are designed to prevent users from mounting the root filesystem as read write. They're instead designed around delivering a core system that's guaranteed to work
- Modified3019 2y agoI went to check and see if proxmox had any immutability proposed for it yet, and I came across this: https://github.com/ashos/ashos#proxmox https://github.com/ashos/ashos#proxmox I’m not quite sure what’s going on here yet, but seems interesting
- kccqzy 2y agoI was about to ask why openSUSE Aeon when the normal Tumbleweed supports immutable mode where / is mounted read only, when I realized that they actually removed it in https://bugzilla.opensuse.org/show_bug.cgi?id=1221742 https://bugzilla.opensuse.org/show_bug.cgi?id=1221742 But I'll share my experience: I think an immutable / really is the way forward. Just the ability to roll back and boot using an older snapshot is great: I have had an update break the boot, but I have the option of running a single command to roll back while I investigate the issue. At the time the issue happened I was busy with life and I simply rolled back and used that version for three months before I had time to investigate. Strictly speaking this does not require the current / to be mounted read only, but merely requires periodic bootable snapshots be taken and these are available to be used as a read-only /.
- irunmyownemail 2y agoI don't use Snap on my Ubuntu Desktop systems because I don't like apps secretly updating without my awareness and also for the immense amount of additional disk space used by Snap. Having said that, no, I don't see any usage of immutable Linux in my future.
- rlpb 2y ago> I don't use Snap on my Ubuntu Desktop systems because I don't like apps secretly updating without my awareness https://snapcraft.io/docs/managing-updates#p-32248-pause-or-stop-automatic-updates https://snapcraft.io/docs/managing-updates#p-32248-pause-or-...
- irunmyownemail 2y agoUnfortunately that creates a choice between an app that updates in an aloof manner or allowing it to exist in an insecure, not updated state.
- rlpb 2y agoWhat do you mean by "aloof manner"? As far as I'm aware, snaps' updating mechanism is quite reasonable and doesn't suffer from the many update related issues that apt/debs have, especially when users want packages not included by their distribution.
- amelius 2y agoYou can also block the updater's internet access by adding this to your /etc/hosts file: 127.0.0.1 api.snapcraft.io And for other updates: 127.0.0.1 archive.ubuntu.com 127.0.0.1 security.ubuntu.com 127.0.0.1 mirrors.kernel.org 127.0.0.1 deb.debian.org 127.0.0.1 ppa.launchpad.net 127.0.0.1 flathub.org 127.0.0.1 dl.flathub.org Use at your own risk of course.
- setuid 2y agoOr you can just avoid hacking your hosts file and breaking other tools, and set your Snap and Apt proxy configuration to a non-existent value, or firewall their ability to reach those hosts. Or configure them properly by disabling auto-updates, configure unattended-upgrades appropriately for your needs, and only update your apt packages from a known, internal mirror endpoint that doesn't change until you point it to a new timestamp. That's how it works in the real world, in production. It's not 1994, we don't hack hosts files anymore.
- nilslindemann 2y agoI worked a while with Silverblue, it is great, but they should use Distrobox instead of Toolbox. In Distrobox one can also encapsulate the home folder and one can export a link to a software running in a box to the outer system. The last one is pleasant for example with VS Code, which will only work properly when installed in a box.
- cosmic_cheese 2y agoAre there any immutable distros that cleanly divide system/desktop and end-user programs, with only the former being immutable and the latter being business as usual for desktop Linux? So the kernel, drivers, and KDE/GNOME would be fall into the immutable “core”, but apps like Firefox, Krita, and Anki would be in a mutable space managed by a traditional package manager like apt. Just wondering because it’s really just the system itself and my desktop environment that I find the benefits of immutability most pertinent, whereas it’s something of a bad fit for applications with the woes flatpak and friends bring for desktop integration and such.
- zamalek 2y agoSilverblue and family are like that. The user bits are installed with flatpak.
- einsteinx2 2y ago> Just wondering because it’s really just the system itself and my desktop environment that I find the benefits of immutability most pertinent, whereas it’s something of a bad fit for applications with the woes flatpak and friends bring for desktop integration and such.
- tcrenshaw 2y agoSilverblue also has really good distrobox integration. Anything not available via flatpak (or things I don't want via flatpak for whatever reason) goes in an arch or debian container. You can then export apps or binaries from the container and have it show up in your desktop menu or path. Silverblue also supports package management via brew, which works pretty well for CLI utilities
- phendrenad2 2y agoI don't really understand the exact problem that immutable distros solve. Seems like it's some vague "instability" in normal distros? > An immutable Linux distribution has its core system locked as read-only. This ensures the base operating system remains untouched during normal use, protecting it from accidental changes, unauthorized modifications and corruption. So, in other words, I'm using an immutable system already! (Windows 11)
- cosmic_cheese 2y agoThe places where immutability is a benefit for most people are protecting against cases where the package manager gets confused and screws things up (as famously happened to Linus of LTT years ago when installing Steam on Mint rendered the system unbootable) and for the ability to cleanly roll back the system when an update does something like break video or networking drivers (surprisingly common with some hardware).
- pxc 2y ago> as famously happened to Linus of LTT years ago when installing Steam on Mint rendered the system unbootable The system booted fine! It just didn't have a graphical desktop environment installed anymore. But it was up and running, not crashing or anything like that! It was no more 'unbootable' for lacking a GUI than the server hosting this website is. :) But yeah rollbacks are a great way to handle situations like that, so it's a great feature for a package manager to have.
- et1337 2y agoI just went all-in on Bluefin DX. It’s my first time using Linux where almost everything worked out of the box, even my 4070. Had to disable Bluetooth to get suspend working, but otherwise, this is the year of Linux on the desktop for me.
- vondur 2y agoHaving to disable Bluetooth seems like a big deal to me in order to get the computer to sleep correctly.
- sphars 2y agoI know that bug, Bluetooth has been messing with sleep since installing the 6.11 kernel on my Fedora 40 desktop. And I've seen many users reporting the same thing. My current solution is a script that disables BT on sleep
- 3eb7988a1663 2y agoNever heard of this, but I just rebuilt my machine, which is still having issues with sleep. Seeing as how I have zero bluetooth devices (wires never fail me!), I will be disabling bluetooth immediately to see if this resolves my woes.
- eraser215 2y agoI'm all in on bluefin-dx too, and Bluetooth is working fine for me in my lenovo x1 carbon. Fingers crossed you can sort your issue out.
- devops99 2y agoSomething about the Bluefin artwork and outward communication really turns me off. The project is using some good concepts, for sure. Though, Bluefin will never be eligible for production in the way that other commercially supported Linux based user endpoints, Linux based systems with immutable patterns, have been for a while.
- xrd 2y agoI'm not seeing any discussion about disk space when using immutable distros. I was running nix for a while and generally loved it. I know I can run nix-gc to clean up unused components. But, when I'm using docker I'm constantly running out of disk space. Again, I know how to use docker system prune, but it's an annoyance. The discussion in the article talks about using containers and flatpak and snap and all those things bundle dependencies and really swell the disk usage requirements. Is there a good solution other than owning a massive SSD? It isn't as big a problem for servers which don't change as often and where you need instant rollbacks, but I'm using immutable (or atomic distros like nixos) on my laptop and having trouble. It makes me think I'm not using these systems correctly.
- nicksbg 2y agoExactly. I think this is a massive problem, and also as someone that works on one of Ubuntu distributions, I always wonder how much strain it introduces together with flatpaks and snaps.
- YorickPeterse 2y agoMy `~/.var/app` directory is 14 GiB in size, 12 GiB of which is used by Signal (which is mostly photos and videos) and 1.8 GiB by Firefox. All other programs only take up a few MiB of space. In terms of installation size it's not a problem either, as one can verify using `flatpak list --columns=size,name`: 1.3 MB Flatseal 2.9 MB Extension Manager 47.7 MB Celluloid 604.6 MB Freedesktop Platform 680.0 MB Freedesktop Platform 533.8 MB Mesa 533.8 MB Mesa (Extra) 469.8 MB Mesa 469.8 MB Mesa (Extra) 46.9 MB Intel VAAPI driver 50.9 MB Intel VAAPI driver 20.3 MB FFmpeg extension with extra codecs 790.0 kB openh264 763.9 kB openh264 243.7 MB GNU Image Manipulation Program 7.7 MB HEIC 17.6 MB Characters 14.2 MB Connections 25.4 MB Image Viewer 946.7 kB HEIC 25.5 MB Sushi 39.8 MB Papers 941.3 MB GNOME Application Platform version 46 1.0 GB GNOME Application Platform version 47 794.1 kB Fonts 137.7 MB gThumb Image Viewer 1.1 MB adw-gtk3 Gtk Theme 269.6 MB Firefox 482.3 MB Signal Desktop The duplicate entries is because certain Flatpaks may require different versions of e.g. the Freedesktop platform (that being possible is one of its big selling points). In short, storage isn't a problem at all for any computer produced in the last 20 years.
- maztaim 2y agoSomehow I managed to answer no to all the questions…
- Lariscus 2y agoI am using Fedora Kinoite for a year now. It is finally the stable desktop Linux experience I was looking for. The limitations people are constantly talking about really don't seem like a big deal to me. For everything not available as a Flatpak there is distrobox and there is always layering as an escape hatch.
- amluto 2y agoI’m in the process of installing Kinoite, and the installer is awful. There are two different manual partitioning tools and one automatic one, none of which work well at all. For some reason, immutable Linux distros seem to struggle with the idea that a single physical disk might contain both volumes owned by the distribution and persistent volumes owned by the user that are not managed by the distro. Last time I checked, Talos was basically unusable on a single-disk system if you want persistent volumes. Sadly, most M.2 NVMe devices don’t seem to support namespaces, which would otherwise be a decent way to kludge around this problem.
- Lariscus 2y agoI don't understand half of the stuff you just wrote. I just selected the SSD in the installer and told it to install the OS. Why make things more difficult?
- amluto 2y agoBecause I want a data partition that I can keep if I decide to switch to a different distro. Or because I already have a data partition I want to keep. Or because I’m doing something that requires some space backed by a different filesystem. Most old distros can do things like this with no particular difficulty. But the Kinoite installer (which is presumably the same as the Silverblue installer) is half-baked and buggy.
- Lariscus 2y agoHave you submitted a bug report?
- johanneskanybal 2y ago10k lines quick browsed the top 500 meanwhile all everyone cares about 2024 in the year of reducing costs is arm64 not distro flavor.
- cybercatgurrl 2y agoi don’t feel like immutable distros are ready for prime time because there are still some really big limitations with flatpaks that will take time to resolve. using a secondary drive on steam is still painful and works inconsistently. 1password can’t talk to firefox to unlock it. applications like steam can’t share rpc status with discord
- robador 2y agoAfter a couple years of running manjaro I ended up switching to bazzite, a fedora silverblue based distro. For the past years, I stopped being a tinkerer, and started turning on my personal laptop less and less. But when I did, I'd find that doing an update would break things, and lead to hours of figuring out what broke, or why an update wouldn't install. It was so incredibly frustrating. My personal circumstances just changed so that I don't have the time to spend on those shenanigans anymore. I looked at Nixos for a long time, but the steep learning curve always held me back. And a fedora atomic desktop started to look pretty good, but it took me to get so fed up with the not being able to do an update after a couple months without things breaking again that I got over the fact that I would probably need to switch to GNOME or KDE to run a well supported atomic desktop. I got over that and settled on bazzite with gnome, because it's promise of setting up my hardware for casual gaming without effort. I've changed a couple months ago and honestly, it's made Linux fun for me again. The things I don't want to have to tinker with, the ui, desktop, software, it all just works and seems very stable. Software is installed with flatpaks, appimages, or in distrobox. If I want to tinker, I do what I always used to do; use docker (podman and distrobox on fedora). Its been an absolute pleasure so far, with hardly a learning curve for me (based on previous experience and practices I suppose). Highly recommend.
- kissgyorgy 2y agoNot sure how NixOS didn't make it to the list.
- dismalaf 2y agoI've been using immutable distros for a couple years right now (Silverblue and openSuse MicroOS/Aeon now), and all I can say is they're much, much better than "normal" distros. Containerized apps are nice, containers for development is nice, but you can have those in "normal" distros with a lil work setting things up. The real killer feature is you can have a bleeding edge system with zero fear of breakage.