• B0rax@feddit.org
    link
    fedilink
    English
    arrow-up
    26
    ·
    6 days ago

    Nixos is quite a bit different than other Linux distributions. It is a declarative system, as far as I understand (I am by no means an expert, I have never used it), there is basically one config file where you put in what you want to have installed on the system and how it is configured. The system then will figure out how to reach that declared state.

    I imagine this is quite fitting for centrally orchestrated systems in an Organisation.

    • poVoq@slrpnk.netM
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      10
      ·
      6 days ago

      I am somewhat doubtful that this is a good approach security wise. Such a system also means that you have a huge monoculture fleet that can be compromised in the exact same way.

      I think declarative systems make a lot of sense when you run a farm of virtual servers that you often spin up and decomission again, or when you are doing research and want your setup to be replicable by other research groups.

      But a fleet of government PCs benefit very little from NixOS (or guix), while increasing the risk of catastrophic failure due to monoculture.

      More generalized recovery features like A/B booting of immutable system images, and/or automatic snapshot for easy rollback to a functional state seem like the better idea technology wise.

      • Hackerman@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        9
        ·
        6 days ago

        Not sure about the Netherlands but from what I’ve observed in other European countries, it seems that governments like to just give everyone (of course with some exceptions for military and a couple other divisions) the same hp laptop with the same corporate windows 11 installation. In such a setup I’m not sure that the nixOS approach is that much worse.

      • ayyy@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        edit-2
        6 days ago

        Centralized configuration is not the same thing as monolithic configuration. The entire field of configuration management and deployment is quite mature at this point.

        Also, what do you think the current Windows infrastructure looks like?

        • poVoq@slrpnk.netM
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          5 days ago

          And what do you think gets owned by ransomware gangs all the time?

          • ayyy@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            2
            ·
            edit-2
            5 days ago

            Badly designed configuration servers that are overly centralized without any regional firewalling or rate limiting?

            Also way to ignore my question about the current infrastructure situation.

      • brainwashed@feddit.org
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        6 days ago

        I am somewhat doubtful that this is a good approach security wise. Such a system also means that you have a huge monoculture fleet that can be compromised in the exact same way.

        You could still decide to provision your systems with different browsers, webserveres, whatever even within nixos.