4 ms·
> Need to work inside a container because it's 2025 and we don't need to clutter our local machine with 100s of dependencies and env managers... “Can I tell yo
by rounce 11mo ago
> Need to work inside a container because it's 2025 and we don't need to clutter our local machine with 100s of dependencies and env managers...
“Can I tell you about our lord and saviour Nix?”
Kidding, but seriously though I’ve found having to work in a container to be a bit clumsy, even with good tooling around it. As you said it’s 2025, and there are other ways to have reproducible toolchains that don’t pollute the rest of your system environment Nix or otherwise.
- adastra22 11mo agoIn the case of AI tools it is for security reasons, not just reproducible toolchains.
- viraptor 11mo agoWe need more selinux and sandbox-exec in daily dev lives. There's no reason to bring a whole new system along just to restrict some access.
- adastra22 11mo agoDocker is just a shim on kernel isolation APIs. It’s not any different, but better packaged. But irrelevant in this case. I dev on macOS. I’m not aware of any other options.
- viraptor 11mo agosandbox-exec. It's not great, but it's usable. https://igorstechnoclub.com/sandbox-exec/ https://igorstechnoclub.com/sandbox-exec/ > It’s not any different It's very different. With docker on Mac you're running a VM which runs a wrapped up complete system that runs your app. With selinux/sandbox-exec you run just your app and can skip the extra packaging needed for docker and mounts. (And get the extra performance)
- internet_points 11mo agoAny references to how you use selinux? I've used bwrap and firejail, but I don't feel confident that I'm not leaving holes open?
- viraptor 11mo agoHonestly - no. To use selinux you need to commit to actually learning how it works and experimenting a bit. I don't think there's an easier way than reading both redhat (https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/using_selinux/getting-started-with-selinux_using-selinux https://docs.redhat.com/en/documentation/red_hat_enterprise_...) and NSA (https://www.nsa.gov/portals/75/documents/resources/everyone/digital-media-center/publications/research-papers/configuring-selinux-policy-report.pdf https://www.nsa.gov/portals/75/documents/resources/everyone/...) docs. If you're happy with firejail, make sure you use whitelists only and you'll be 90% there with what's possible to achieve.
- traceroute66 11mo ago> “Can I tell you about our lord and saviour Nix?” The "just use Nix" people are just like the "write it in Rust" brigade. And the things both groups promote share exactly the same problem ... A stupidly enormous learning curve. That's why your average person prefers to just the job done in a container vs Nix, or in Go vs Rust. I'm sure Nix is awesome, just like I'm sure Rust is awesome. But honestly, I've got enough going on in my brain at $work and $home without having to wrangle some obscure config syntax (Nix) or obscure low-level language complexities (e.g. Rust's infamous borrow-checker). Every time I go back and look at Rust or Nix my brain is just like .... no, thanks.
- tempaccount420 11mo agoSo you rather stay comfortable doing what you were always doing, which is fine but programming is everything but that...
- miroljub 11mo agoComplexity for the sake of complexity is not a goal everyone should be striving for.
- traceroute66 11mo ago> Complexity for the sake of complexity is not a goal everyone should be striving for. THIS ! Go's well maintained stdlib just lets me get on with it. With Rust meanwhile, I have to decide which of thousands of third-party Rust crates is sufficiently en-vogue and well maintained. Most of my coding work is backend stuff that calls a lot of HTTP APIs, parses a lot of JSON and does a lot of crypto. All that is ready-to-go "out of the box" with Go stdlib and on top of that is faster to get to production in Go than in Rust. I don't need or want Rust's complexity. As I said I have enough going on at $work...
- flashgordon 11mo agoI always feel like choosing between rust and go is like picking between node (ts/js) and python when it comes to stdlib out-of-the-box-ness!