6 ms·
Writing a basic service for GNU Guix
- einpoklum 1y agoTwo notes from reading the first several paragraphs: 1. It seems one needs to know some Scheme in order to write these files: https://www.scheme.org/ https://www.scheme.org/ I don't think it's possible to just "wing it" by copy-and-paste. 2. I did not understand the introductory paragraph about how services "extend" each other. Does every service have hooks for possible extensions? What if a new service doesn't fit existing extension hooks? (I can understand service dependencies of course, but it seems to go beyond that.)
- foretoldfeline 1y ago> Does every service have hooks for possible extensions? What if a new service doesn't fit existing extension hooks? No, only few services define service extensions. It's more common for services to be configured solely via their configuration struct. See the following for docs: * https://guix.gnu.org/manual/en/html_node/Service-Composition.html https://guix.gnu.org/manual/en/html_node/Service-Composition... * https://guix.gnu.org/manual/en/html_node/Service-Types-and-Services.html https://guix.gnu.org/manual/en/html_node/Service-Types-and-S... This is less flexible-by-default than NixOS module, where any module can modify any other module. That is by design. The Guix developers see NixOS's approach as failing the principle-of-least-authority, where any arbitrary module (even those imported via flakes) can add a root SSH key. I use NixOS, but it's an interesting tradeoff.
- rnhmjoj 1y agoDoes GNU Shepherd support some form of sanboxing? systemd has many options to reduce the privileges of a service: like running as a normal user with only certain POSIX capabilities, setting up a mount namespace with a limited view of the root filesystem, locking down which system calls can be invoked, etc.
- davexunit 1y agoShepherd doesn't include this as it is quite lean and extensible (service start/stop hooks are functions that can do anything) but Guix includes a Linux container implementation and an abstraction built on top for use by services. The long term vision is to use an object capability security model so, rather than "locking down", a service can only interact with the resources to which it has been passed a reference. No ambient authority, no confused deputies.
- jcgl 1y agoI really like systemd but am also Guix-curious. This sandboxing topic has been a bit of a blocker for me to properly go deeper with Guix. Do you know of any good places to read more about this vision? Sounds powerful and unique.
- foretoldfeline 1y agohttps://fosdem.org/2025/schedule/event/fosdem-2025-5315-shepherd-with-spritely-goblins-for-secure-system-layer-collaboration/ https://fosdem.org/2025/schedule/event/fosdem-2025-5315-shep...
- davexunit 1y agoJust to be clear, sandboxing is possible with Guix, with least-authority-wrapper as a built-in option. Regarding the long term vision of capability security, you can read the Spritely (the nonprofit I work for) whitepaper about capabilities and the work we're doing in Guile to make it happen [0]. The paper isn't about Guix, but Guix stands to benefit from the effort. Getting to the point where Guix services are capability secure will take many steps, but one step is bringing capabilities to Shepherd, which we have made progress on through an NLnet grant [1]. [0] https://files.spritely.institute/papers/spritely-core.html https://files.spritely.institute/papers/spritely-core.html [1] https://nlnet.nl/project/DistributedShepherd/ https://nlnet.nl/project/DistributedShepherd/
- foretoldfeline 1y agoGNU Shepherd itself doesn't implement sandboxing, but you can use the least-authority-wrapper to do namespaces. There are other tools to do more comphrensive sandboxing, which Shepherd can use, e.g. nsjail. least-authority-wrapper: https://codeberg.org/guix/guix/src/commit/e3fbaeee1386fd447f40ffdf53d964d1f8541d49/guix/least-authority.scm#L44 https://codeberg.org/guix/guix/src/commit/e3fbaeee1386fd447f...
- tempodox 1y agoFrom a quick glance, Guix seems to have a similar learning curve as Nix (at least it's based on Scheme, which I know). Is that impression correct? Anyway, I didn't find this “intuitively comprehensible” as an outsider.
- TheFuzzball 1y agoCorrect, and it's Linux-only and more hardcore FOSS (i .e. they don't have any blessed way to use non-free software). I'm not sure why it's being sold as an alternative to Nix/NixOS
- fsflover 1y agoBecause it's an alternative which guarantees freedom?
- Keyframe 1y agojust not freedom to use propriety software
- davexunit 1y agoIt's easy to use proprietary software with Guix and nearly all users do this.
- terminalbraid 1y agoCool, I didn't realize I could use it on my Windows or Mac machines. That's actually what's been holding me back.
- ZoomZoomZoom 1y agoOnly Free Software guarantees that you have the final say in a matter of using arbitrary proprietary software.
- graemep 1y ago
- potato-peeler 1y agoFor day to day use, what are the benefits for gnu guix? From it’s website, what I could understand is it provides installation of different version of the same package, similar to rbenv or conda. Apart from this, is there anything else that will be considered useful over something like aptitude?
- bheadmaster 1y agoReproducibility, just like Nix. You can be certain that, if you've managed to get a piece of software running with Guix, you can also get it running identically on any other machine.
- amelius 1y agoExcept if nvidia cards and embedded systems are involved. Then whether you get it running is still a gamble.