• 5 Posts
  • 62 Comments
Joined 3 years ago
cake
Cake day: September 1st, 2023

help-circle






  • I’m not sure what you want to achieve… do you want NixOS running in podman containers as a service? Do you want to have some kind of package that starts up podman with nix packages in it?

    Could you provide your usecase(s)? “As a X I want to Y”. “As a X when I do Y I expect Z to happen”.

    It’s just confusing to see flakes and home manager mentioned and some “backported” podman output to be desired. Individually those words make sense but together I’m lost.




  • I think the root would be a distributed reproducibility program. Sources should have mirrors worldwide and the expected hash of inputs would have to be provided by a group of trusted builders. I’m afraid to say it but a blockchain might actually be a viable solution for agreeing upon and storing those hashes.

    If nix were input addressed, it would actually remove the need for agreement on the input hashes. That might actually be the best thing to start with, honestly. Then it won’t matter where things come from as long as the hash is right. Inputs could then be hosted anywhere.




  • Yunohost is probably more secure than you figuring everything out yourself. More people have a vested interest in keeping it secure. They have a minimal page on security but they have fail2ban, unattended upgrades,and a secure SSH configuration. If something is discovered, you might be vulnerable but at least there will be knowledgeable people fixing it.

    Security is always difficult and nothing is 100% secure. The three letter agencies around the world have been hacked and they are in the business of hacking others. Hackers themselves get hacked on the regular. Using yunohost as a noon probably reduces the chance of you getting hacked.

    If you have something only you need to access, you can also host yunohost for yourself and make it accessible only via a VPN. Headscale, tailscale, maybe even your router provides a VPN service, or setup wireguard yourself. If others have to access it… I dunno. That’s a good question to ask on /c/selfhosted






  • I want to be optimistic about nix but the main community on discourse is a travesty. It’s a more a political arena than a coding forum and actively hampers nix development. Any important decision is either made in isolation (a small group of high up people) or on the forums, and the forums are a mined battlefield. Code and words don’t matter, only who wrote or said them.

    Nix has had many opportunities to be the basis for something amazing and supported by a large company. Valve could’ve used nix to have dependency locking. Imagine bazzite, the most gamer friendly distro, being built on nix. That would’ve propulsed nix at least onto a mountain to visible to many Linux users. But if I were Valve and had a single look at the forums and documentation, I too would’ve chosen something else.

    I’ll also just mention nix flakes and its experimental yet widespread use with no official documentation or support. Imagine joining and being told to use flakes then being pointed to blog posts from 2019, example repos, and YouTube videos to start using it. That isn’t a good look at all.

    Nix has potential but the community squanders it in favor of culture wars, pride, principle, and just anything unrelated to Nix.