EasyOS: An experimental Linux distribution designed from scratch for containers
easyos.org
easyos.org
- It has a "How and why are we different" page. In the age of "I made a meta package on top of Ubuntu and called it a new OS", it's refreshing to see a Linux distribution come right out and say "here's what we do that separates us from the other 700".
- It actually is different. Recognizing the nigh-uselessness of separate user accounts (for personal computers), embracing of simple GUI tools over terminal wankery, eschewing of the legacy UNIX file hierarchy.
- They use the ROX filer, the only file manager for Linux with AppDir support and the centerpiece of the unfortunately long-defunct ROX Desktop.
I'm anxious to find out more.
> Puppy heritage
> [...] it must be stated that Easy is also very different, and should not be thought of as a fork of Puppy. Inherited features include the JWM-ROX desktop, menu-hierarchy, run-as-root, SFS layered filesystem, PET packages, and dozens of apps developed for Puppy.
container linux is forked off my the community as flatcar linux. Redhats container linux is getting rolled into fedora silverblue or something? This paragraph I'm not really sure about.
Do you know what the situation is?
I also looked a bit at RancherOS today, which looked pretty cool, but it seems to use 10x the memory of CoreOS...
A quick look shows the ISO as ~4GB, which is a bit concerning though - CoreOS is around 450MB, and RancherOS only 135MB (although it's a bit difficult to compare, since they both download stuff during boot).
Red Hat ships a variant of RHEL called RHEL CoreOS, but the only way to run it is as part of OpenShift (for instance via https://try.openshift.com) where it is the default OS for machines which are managed as part of the cluster, so it’s not a real ContainerLinux equivalent (which you can run individually).
So you're telling me I have no tools and no existing tools are going to work.
Good to get that out in the open, I suppose.
Not to mention the ability to easily support different build tool chains combinations, etc. Right now, my preferences are flatpak, snap, ppa, repo in that order.
Not really looking to play with a new linux, Manjaro is next on my list. Currently running Pop!_OS, which has been nice (just jumped this past month, haven't tried a linux desktop in 5+ years before that). I've been relatively happy.
That said, my biggest issues so far:
* need to update kernel and new mesa drivers before putting the 5700 XT video card. * needed to update kernel for wifi support (intel ax). * rainbow puke from RGB controllers, the Gigabyte (X570 Aorus Master) support is all but worthless, and the open-source project I saw was actually for windows. For the Lian Li o11 Dynamic Razor edition case, there's open-source Razor drivers, but I'll need to setup a windows drive in order to capture some data in order to support the specific device. I haven't even looked into the Corsair ram yet (which is actually the biggest eye sore at the moment).
I really regret not building another black box. My first two choices of cases without windows were sold out, so I went for the "pretty" case option. Which would be great if I were running windows, but I have no intention to. A lot of money on RGB fans (all matching), water cooling, ram, etc... and none of the controllers have good linux support. Would switch to another controller, but the only one I keep finding is a German company and doesn't seem to actually be sold anywhere. Which wouldn't cover the ram or case.
And a large portion of my computer is command line tools, sure. But I'm also running EXWM, I'm also running Firefox, I'm also running Tiled, and Blender, and so on, and so on. I don't want to get rid of my command-line tools, but I'm not only running command line tools. I want to be able to download a game, put it in a container, mess around with my drivers until it runs well, and then delete the container when I'm done and know 100% all of the customization just went away.
This was what originally got me excited about Docker, until I dug into it and realized Docker kind of didn't work particularly well for that.
My understanding is if I sat down and did the research, I could build something like that with regular Linux tools, but it's time consuming and as interested as I am in the underlying tech, I just know very, very little about how this stuff works.
But I always perk up whenever I hear someone talking about running graphical applications in containers, because in the back of my head I'm mapping that to some kind of fictional computing utopia where I can have complete isolation between processes and treat my computer like a Git repo.
Crostini can spawn gui apps through Wayland instead of pure X. That takes effort and I wish they would contribute it back.
I was so happy when ROX Desktop was still active and alive. It had exactly all features necessary to use a file browser, blazing fast and the UI was really intuitive. Actually it inspired me for years to maintain a ~/Apps folder, so reinstalling my system mostly just meant copying over my home folder.
https://fedoramagazine.org/what-is-silverblue/
https://docs.fedoraproject.org/en-US/fedora-silverblue/toolb...
Container just homogenise the paradygm for all resources: strict isolation by default, else explicit sharing.
Of course it makes sense. Running applications as restricted users has been standard practice for decades, precisely because it makes sense.
...as a way of preventing users from interfering with the system or other users in multi user systems. Running applications as a user different from yourself is an ugly hack we've started doing because we don't have actual control over what our applications can access, so things like ransomware are possible despite not having system level access. Since Plan9 never took off, containerization of applications is the next best thing.
What I'm saying is, running in a restricted user account does absolutely nothing to protect the user running in the restricted account from malicious applciations. That's how the user/group model fails in personal computing.
* in the real life, there is “sudo hole”, but this can be fixed within the current user concept.
I was under impression that even with zero days, using modern distribution and auto updates will minimize the amount of time the system is vulnerable, so for most of time, it will be sufficient.
Also, current isolation technologies on desktop tend to be a lot less secure than mobile. If you assume Fuchsia, Android, iOS to be the next generation of OSes, then the trend is definitely to "secure by default". Whitelisting permissions instead of everything being allowed out of the box. Even the current generation of Linux containers is more of a bunch of resource management hacks, compared to e.g. hypervisor sandboxing or to a lesser extent, BSD jails.
Hopefully we won't go back to the Win95/98 era of everything running as single user!
Having services run isolated as their own users is not merely a good security mechanics, it provides for a clear and simple mental model of what is what. A clear permissions barrier that's enforced pretty strictly by the OS.
Moreover we see separate user accounts more and more; even on small devices like phones it makes sense to have, for example, separate "private" and "business" accounts.
>does that mean processes have failed?
Nah, that's too general of a take. There are two more specific failures. First up, people fail to realize the present-day crop of containers are re-inventing processes. "Those who do not learn history, etc, etc."
Secondly, there's a significant failure of certain key features (like IP stack, FS handlers, etc. - in general, NAMESPACES) having been provided almost exclusively in kernel, and thusly requiring either superuser access or complex work-arounds (like FUSE) to manage. Plan 9 did it the right way; on P9, processes == containers.
How is that a clear and simple model? Are email or printing users?
I think the whole discussion is futile without having a common understanding of what we are talking about. That is:
- What is a user?
- What is a group?
- What is a role?
- What is an account?
- What is a service?
- What is a job?
- What is a process?
- What is a container?
- What is a namespace?
Moreover, you cannot say whether an abstraction is good or bad without knowing what our goals, use cases or target users are.
In the case you're making, a user (a real actual human user) has different settings when _using_ the phone in two contexts. In the latter case, applications are restricted to sandboxes with well-defined interactions between each other's memory, processes, devices, sockets, and files.
Lxc can improve a bit on this, as can "containers" (lxc or otherwise restricted processes).
So no.. processes haven't failed. Anything that runs on your system is or is part of a process.
I've always been annoyed how Unix systems treat the system as "their property" with the user just being a temporary guest (if not an intruder).
Because that is how we make progress. Try different approaches, learn and evolve the ecosystem. That is how we got usable containers in the first place, it's not a new idea and variants have been around for decades. But only now we've seen it evolve in to something usable.
At least they are trying to solve problems. It might not be the best/right solution, hell it might not be an improvement, but if we don't try, we will never learn.
If anything, Docker just made containers trendy (they gave more talks at more conversations, etc) when before it was seen as a niche toy compared to virtualisation which few had heard of and fewer had bothered to look into. However being trendy doesn’t mean better nor easier to use.
Yeah, no thanks.
You have individual account for individual people. Use sudo if you need to elevate permissions - that gets fired over to your syslog server, so if you screw up you know what you did. If someone else screws up, you can see who it was and either fix it, or contact them to find out what they were trying to do (likely both)
It feels like Linux and windows are converging into a single OS
It's also much easier to manage each application with it's own root for everything, rather than multiple applications installed into a single root.
No cgroups ?
Even Kali Linux has a container image at https://us.images.linuxcontainers.org/
edit: If anyone at EasyOS wants to add a container image, see as an example the PR for Kali, https://github.com/lxc/distrobuilder/pull/179