Unlike some other operating systems, OpenBSD encourages users to split their disk into a number of partitions, rather than just one or two large ones. Some of the reasons for doing so are:
Security:
Some of OpenBSD's default security features rely on filesystem mount(8) options such as nosuid, nodev, noexec or wxallowed.
Stability:
A user or a misbehaved program can fill a filesystem with garbage if they have write permissions for it. Your critical programs, which hopefully run on a different filesystem, do not get interrupted.
Integrity:
If one filesystem is corrupted for some reason, then your other filesystems are most likely still OK.
fsck(8):
You can mount partitions that you never or rarely need to write to as readonly most of the time, which will eliminate the need for a filesystem check after a crash or power interruption.
Edit: verbatim formatI admit I do cargo-cult partitioning. I don't really know whether the recommendations out there are current, outdated, mistaken or what.
I find a lot of recommendations about partitioning, swap, memory etc, at least for Linux, are cargo cult anyway, or at least outdated and/or poorly explained, which amounts to the same.
But really, just having rigid partitions makes me feel uneasy. ZFS datasets all share the same space, and you can set quotas if you want that can be changed anytime.
Flexible/resizable partitions are definitely easier, but I think you could have gotten the fixed scheme right if you had tried.
> create a 10gb EC2 instance
Unlike some other operating systems, OpenBSD encourages users to split their disk into a number of partitions, rather than just one or two large ones. Some of the reasons for doing so are:
Security:
Some of OpenBSD's default security features rely on filesystem mount(8) options such as nosuid, nodev, noexec or wxallowed.
Stability:
A user or a misbehaved program can fill a filesystem with garbage if they have write permissions for it. Your critical programs, which hopefully run on a different filesystem, do not get interrupted.
Integrity:
If one filesystem is corrupted for some reason, then your other filesystems are most likely still OK.
fsck(8):
You can mount partitions that you never or rarely need to write to as readonly most of the time, which will eliminate the need for a filesystem check after a crash or power interruption.
https://www.openbsd.org/faq/upgrade60.html
The wxallowed mount option. W^X is now strictly enforced by default; a program can only violate it if it is located on a filesystem mounted with the wxallowed mount(8) option. This allows the base system to be more secure as long as /usr/local is a separate filesystem.
The base system has no W^X-violating programs, but the ports tree contains quite a few: chromium, mono, node, gnome, libreoffice, jdk, zeal, etc. If you want to run any of these ports on a regular basis, you need to add wxallowed to the mount options for /usr/local in fstab(5), e.g.:
01020304050607.h /usr/local ffs rw,nodev,wxallowed 1 2
Small disks may not have a separate partition for /usr/local. In that case, add wxallowed to the smallest partition containing it: /usr or /.Starting a W^X-violating program from a partition without the wxallowed mount option will produce a core dump and the dmesg(8) will contain an entry such as soffice.bin(15529): mprotect W^X violation. You can temporarily allow W^X-violating ports by issuing mount -uo wxallowed /usr/local.
https://en.m.wikipedia.org/wiki/W%5EX
W^X ("Write XOR Execute"; spoken as W xor X) is a security feature in operating systems and virtual machines. It is a memory protection policy whereby every page in a process's or kernel's address space may be either writable or executable, but not both. Without such protection, a program can write (as data) CPU instructions in an area of memory intended for data and then arrange to run (as executable) those instructions. This can be dangerous if the writer of the memory is malicious.
Generally I use the auto layout as a strong hint on how many partitions to make and the general size suggestions - then alter based on my needs (ie. bumping var instead of home for servers).