I am somewhat doubtful that this is a good approach security wise. Such a system also means that you have a huge monoculture fleet that can be compromised in the exact same way.
I think declarative systems make a lot of sense when you run a farm of virtual servers that you often spin up and decomission again, or when you are doing research and want your setup to be replicable by other research groups.
But a fleet of government PCs benefit very little from NixOS (or guix), while increasing the risk of catastrophic failure due to monoculture.
More generalized recovery features like A/B booting of immutable system images, and/or automatic snapshot for easy rollback to a functional state seem like the better idea technology wise.
Not sure about the Netherlands but from what I’ve observed in other European countries, it seems that governments like to just give everyone (of course with some exceptions for military and a couple other divisions) the same hp laptop with the same corporate windows 11 installation. In such a setup I’m not sure that the nixOS approach is that much worse.
Centralized configuration is not the same thing as monolithic configuration. The entire field of configuration management and deployment is quite mature at this point.
Also, what do you think the current Windows infrastructure looks like?
I am somewhat doubtful that this is a good approach security wise. Such a system also means that you have a huge monoculture fleet that can be compromised in the exact same way.
You could still decide to provision your systems with different browsers, webserveres, whatever even within nixos.
I am somewhat doubtful that this is a good approach security wise. Such a system also means that you have a huge monoculture fleet that can be compromised in the exact same way.
I think declarative systems make a lot of sense when you run a farm of virtual servers that you often spin up and decomission again, or when you are doing research and want your setup to be replicable by other research groups.
But a fleet of government PCs benefit very little from NixOS (or guix), while increasing the risk of catastrophic failure due to monoculture.
More generalized recovery features like A/B booting of immutable system images, and/or automatic snapshot for easy rollback to a functional state seem like the better idea technology wise.
Not sure about the Netherlands but from what I’ve observed in other European countries, it seems that governments like to just give everyone (of course with some exceptions for military and a couple other divisions) the same hp laptop with the same corporate windows 11 installation. In such a setup I’m not sure that the nixOS approach is that much worse.
Centralized configuration is not the same thing as monolithic configuration. The entire field of configuration management and deployment is quite mature at this point.
Also, what do you think the current Windows infrastructure looks like?
And what do you think gets owned by ransomware gangs all the time?
Badly designed configuration servers that are overly centralized without any regional firewalling or rate limiting?
Also way to ignore my question about the current infrastructure situation.
You could still decide to provision your systems with different browsers, webserveres, whatever even within nixos.