Alpine Linux 3.8.0 released
alpinelinux.org
alpinelinux.org
Very often critical security issues will not be patched for weeks and desktop software like Firefox can go months without being updated.
I would really love to use Alpine Linux again for my servers and desktops if the situation improves, but now it's simply too dangerous to depend on it.
I was not writing the post to criticise Alpine as I really like it, but people need to take the missing security updates into consideration before they start to depend on Alpine for important things.
Or there's the fork [1] where that is the default.
I tried Alpine Linux and was very impressed, but have always resisted using it for container images because they do not publish CVEs or seem to have much process around security.
As a regular user of systemd (I use arch linux as my main and therefore was one of the first adopters of systemd) I am subjected to irregular and weird irreplicable bootup bugs and timing problems. Alpine reminds me of a simpler time when my computer's bootup was deterministic, and a hang at boot was only ever caused by a disk problem, rather than something trivial like having to wait 3 minutes because it can't connect to the network.
I totally understand the reason for there to be 'bloat' in projects like systemd, GNU libc, etc. And I understand that often that bloat is needed, to cover the edge cases in the thousands of use cases for which they are deployed. However, it's only really when I moved to Alpine that I understood just how much of it there was, and how much of an impact it had on not only my interactions with the computer, but other concerns like my energy usage, etc. It was a like a breath of fresh air for me, and it reminded me that computing could be good, again.
Edit: Forgot url -_-
I liken it more to my fond days with FreeBSD and OpenBSD. A narrowly scoped base image and userland, but easy access to a vast array of packages/ports, but each explicitly listed and installed.
It's "batteries included" but "pick your batteries" vs "here's a kitchen sink full of batteries."
(Just be aware of the differences between glibc and musl... DNS resolution in particular will bite you if you don't understand the implementation)
- If your resolvers are VIPs for the same process or machine, you can triple you DNS load and overload some crappy DNS dispatchers
- If you try to use multiple resolvers that resolve the same names with different records, you can kind of make it work with glibc but you will have severe problems with musl. This is a bad idea in the first place though
.End of support for hardened kernel (unofficial Grsecurity)
doesn't that contradict?
It’s still better than selinux though haha.
The submission of it to the official images repo: https://github.com/docker-library/official-images/pull/4501
Even though I'm a Gentoo user, I still prefer void's runit or openbsd's rc.d system when it comes to simplicity, over OpenRC.
Also, dinit looks really promising as well:
[I had a cute one where a daemon (emacs, actually) set to start-up on boot with systemd ended up failing, which somehow caused the rest of the systemd modules to fail, with all of the modules failing silently (so the systemd tools themselves didn't tell me anything about failed units).]
"systemctl list-units"
What's wrong with?
"systemctl list" or "systemctl units" or "systemctl ls" ?
Then there's the output, which is borderline unreadable. The entire systemd design is like this. It seems like it's designed by people who enjoy arcane hard to read and hard to type stuff.
I can never, ever remember the magic incantations required to get it to load a new unit file. I can also never recall where they go without Googling and it seems to vary across distributions. People always joke that the first step to doing anything with git is to Google it. Systemd is worse since its commands are bizarre and non-memorable.
Over the years I've grown to hate intentionally arcane software. It wastes your time to no benefit. I tolerate git because it's powerful and it does have rational reasons for how it does things, but systemd is just annoying.
* http://uselessd.darknedgy.net/ProSystemdAntiSystemd/
It's also an outright ahistorical falsehood in the case of Fedora and Ubuntu.
When should I use which to control system resouces?