I feel like inmutable distros are in a quite good state nowadays, and while solutions like bootc and sysexts are not “mainstream” yet, it’s getting there

when it comes to getting non Flatpak packages, things get interesting, there are a lot of options, really

AppImages, statically linked binaries, tarballs, OCI containers, distrobox/toolbx, Homebrew, VMs, Nix even experimental formats like RunImages, AppBundles and FlatImages

if you need some non-system level package, you’ll have a way to use it yet, still it seems sort of chaotic “which one should I choose? how will I be able to easily manage them?”

GPM, dbin, Soar, AM… and the list goes on

and it’s okay, the so called cloud native approach is still evolving, so this fragmentation is expected so it’s nice to share opinions about this while we’re living this interesting phase any thoughts?

  • novafunc@discuss.tchncs.de
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    2 months ago

    Preface: I have been daily driving Fedora Atomic for the last couple of years and have also used a bit of Aeon and NixOS.

    My opinion is that while atomic/immutable desktops are overall a good idea, they are marred by poor planning, a refusal to fix existing tools, and some cope.

    There are way too many package managers and waste in this space. I think flatpak is a large cause of all this friction due to fact that it is always “sandboxed” and only focuses on GUI apps. The fact that it does not aim to support CLI apps (despite being able to handle them quite well!) means that we must have another tool, traditionally podman via toolbox/distrobox. The sandbox doesn’t play well with certain subsets of apps, notably things like VSCode. At least Flatpak Next seems like it will address this part with its unsandboxed mode.

    I also find it quite strange how some developers revel in wasted space and inefficiency. So many duplicated libraries between the host, flatpak, podman, and homebrew. With better planning, we could’ve had shared runtimes (such as Freedesktop) between the OS, flatpak, and whatever CLI package manager. Instead we have something like Fedora packages for the host OS and podman (not shared), flatpak using Freedesktop, and brew shipping their own stuff.

    I also think that systemd sysexts are poorly designed, it’s crazy they’re being pushed. It’s pretty much a package manager without dependency management. And for what upsides? It has no sandboxing, it’s not portable between distros and distro versions, and must vendor dependencies to work around having no concept of dependencies. And we’re already seeing fragmentation with Fedora and OpenSUSE working on their own frontends to manage sysexts.

  • TheModerateTankie [any]@hexbear.net
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 months ago

    According to this post, once these projects move to bootc, they are going to get rid of layering and allow you to just dnf install what you need.

    Recent discussions upstream has consolidated around doing things the Ublue way. Pulling a base image from an upstream registry and using containerfiles to define a system locally. No custom scripts and unit files. No GitHub. Just writing custom changes to a containerfile and having them automatically apply on reboot. Running dnf install @virtualization would add the following line to the containerfile in the background:​

    RUN dnf install -y @virtualization

    The powerful thing about build time container image layers like this is that you can do deep customizations like switching out the kernel, changing the login manager, use your own custom boot screen, or redistribute your build by pushing it to a public/private container registry or as the Ublue team shown use container based ci/cd workflows for automated vulnerability scanning against public databases like NVD and CVE.

    Seems like it will get rid of a lot of pain points.

  • boredsquirrel (he)@slrpnk.net
    link
    fedilink
    arrow-up
    0
    ·
    2 months ago

    All of the methods have big issues but I would still prefer them over messing with a mutable system

    • snap is likely the most secure by avoiding user namespaces, using AppArmor only and thus being very flexible (also for use for kernels, drivers, browsers …) but it is proprietary, nobody likes it and Canonical doesnt wanna stop somehow.
    • flatpak has the biggest amount of officially maintained packages, but packaging is often really bad, runtime extensions arent really a thing, instead people just put ffmpeg binaries in their packaged and think that is fine. Flatpak does consume quite some disk space and more importantly RAM for the duplicated things
    • nix doesnt have any of these, but sandboxing is hard, there is either stable or unstable, changing and configuring things is very complex. Likely no official packages. Still the method I prefer.
    • homebrew idk? Never tried, mac focused and with more and more linux features like sandboxing. No idea
    • distrobox/toolbox is pretty hacky, relies on entire distros running in parallel with no shared anything (currently, afaik bootc deduplication is kind of planned but kind of difficult too). Updates dont really work so either you go declarative with podman compose or distrobox-assemble, or you use rolling distros. Also they share your homedir by default so they will clutter and mess up your dotfiles which is a problem nobody deals with. Dotfile backup tools exist but are kinda complex. Distrobox has a config but the creator doesnt seem to want to make it the default, neither do downstreams.
    • Appimages just suck, back to the windows way but without developer signature verification (like Windows) or secure updates (like .apk files on Android)

    Also Nix, Flatpak and a few more fully depend on Github. Same with uBlue, Secureblue and a ton of other projects. Really scary actually.