5 ms·
My problem with NixOS is the second you try to go "outside the guardrails", the difficulty increases 100x
by Dedime 10mo ago
My problem with NixOS is the second you try to go "outside the guardrails", the difficulty increases 100x
- ivanjermakov 10mo agoKind of the same for docker? Plopping a docker compose file and setting up few environment vars vs writing dockerfiles from scratch.
- cromka 10mo agoNot really. No. You can easily checkout repo containing the Dockerfile, add a Dockerfile override, change most of the stuff while maintaining the original Dockerfile instact and the ability to use git to update it. Then you change one line in docker-compose.yaml (or override it if it's also hosted by the repo) and build the container locally. Can't imagine easier way to modify existing docker images, I do this a lot with my self-hosted services.
- Ambroisie 10mo agoI'll be honest, that does not sound "easy". It is straightforward, but so is the NixOS module system, and I could describe writing a custom module the same way you described custom Docker images.
- maccard 10mo agoIf that’s not easy I don’t know what is.
- Xraider72 10mo agoThis is a familiarity problem. I've never used NixOS and all your posts telling me how simple it is sounds like super daunting challenges to me versus just updating a Dockerfile or a one liner in compose that I am already familiar with, I suspect its the inverse for you.
- jerf 10mo agoIt isn't the absolutely easiest process. But it works on Ubuntu, it works on Debian, it works on Mac, it works on Windows, it works on a lot of things other than a Nix install. And I have to know Docker for work anyhow. I don't have to know Nix for anything else. You can't win on "it's net easier in Nix" than anywhere else, and a lot of us are pretty used to "it's just one line" and know exactly what that means when that one line isn't quite what we need or want. Maybe it easier after a rather large up-front investment into Nix, but I've got dozens of technologies asking me for large up-front investments.
- KolenCh 10mo agoIt only works on Mac and windows as a VM. Nix is for reproducibility. Nix and docker are orthogonal. You can create reproducible docker image via nix. You can run nix inside docker on systems that doesn’t allow you to create the nix store.
- newsoftheday 10mo agoIf it wasn't easy, I wouldn't be using it. I'm the laziest of programmers or users.
- conradev 10mo agoI find the granular nature of dependency sharing in NixOS to be really nice. In particular, I like systemd as my hypervisor. With systemd I can still isolate and lock down processes, but they can still, for example, share memory pages of `glibc`. It is certainly less "secure", and with Docker at least you're sharing the same kernel. It's also hard to share resources between Docker containers. Getting 4 Docker containers to use the same instance of Avahi, for example, requires explicit configuration. Docker containers also don't have a "standard" for where to put binaries (outside of CMD/ENTRYPOINT), how to configure users/uids (many still run as root?), whether to put multiple services in one container or separate containers, where to put user data, etc. NixOS coordinates this centrally like any distro, assigning paths and UIDs and ports.
- conradev 10mo agoI have found Nix and NixOS to be able to absorb any amount of complexity I throw at it with grace. If a Docker image truly is the best way to use a bit of functionality (like Home Assistant), then I will just configure NixOS to run it in podman as a systemd service with host networking. I have not come across something that I could not package. The trick is that Nix composes functionality in a way that Dockerfiles or docker-compose configs cannot, because it's one language, one system, one abstraction.
- lilyball 10mo agoIs it? Why? If a NixOS module doesn’t support what you need, you can just write your own module, and the module system lets you disable existing modules if you need to. Doing anything custom this way still feels easier than doing it in an imperative world.
- maccard 10mo ago> you can just write your own module, and the module system lets you disable existing modules if you need to That sounds about 100x more difficult to me
- Scandiravian 10mo agoI can see your point that it can be daunting to have all the pain upfront. When I was using Ubuntu on my servers it was super simple to get things running The problem was when I had to change some obscure .ini file in /etc for a dependency to something new I was setting up. Three days later I'd realise something unrelated had stopped working and then had to figure out which change in the last many days caused this For me this is at least 100x more difficult than writing a Nix module, because I'm simply not good at documenting my changes in parallel with making them For others this might not be a problem, so then an imperative solution might be the best choice Having used Nix and NixOS for the past 6-7 years, I honestly can't imagine myself using anything than declarative configuration again - but again, it's just a good fit for me and how my mind works
- onionisafruit 10mo agoIn the NixOS scenario you described, what keeps you from finding an unrelated thing stopped working three days later and having to find what changed? I’m asking because you spoke to me when you said “because I'm simply not good at documenting my changes in parallel with making them”, and I want to understand if NixOS is something I should look into. There are all kinds of things like immich that I don’t use because I don’t want the personal tech debt of maintaining them.