FreeBSD, OpenBSD or NetBSD – _that_ is the question.
Wait, maybe DragonFly actually? illumos? ...wait, I mean OpenIndiana, I think... wait, what's OmniOS? Is Darwin a thing, like I could just have BSD and macOS for free or something?
FreeBSD, OpenBSD or NetBSD – _that_ is the question.
Wait, maybe DragonFly actually? illumos? ...wait, I mean OpenIndiana, I think... wait, what's OmniOS? Is Darwin a thing, like I could just have BSD and macOS for free or something?
OpenBSD might not be the best choice for any given use, but it's so remarkably consistent and understandable that I think everyone interested in alternative OSes should try it out at least once.
used it as a webserver and VPN appliance for a couple of years now.
only thing in terms of maintenance is the following when a new release is released.
pkg_add -u ( i usually update extra packages every 6 months, which is mainly lets encrypt). syspatch sysupgrade
reboot:
after reboot
sysmerge to see if i need to do a config diff.
Has been rocksolid and very future rich in base aswell.
Always read the upgrade guide before upgrading.
This release only includes changes related to SNMP, which I imagine are irrelevant to most people, though probably exciting for a subset of OpenBSD users. https://www.openbsd.org/faq/upgrade70.html
The upgrade guide for 6.9 gives a better flavor for how OpenBSD handles and documents subsystem and configuration changes: https://www.openbsd.org/faq/upgrade69.html
Notice how succinct and consistent (across decades!) are the upgrade guides. The above have the same basic format and content as this one from 2004: https://www.openbsd.org/faq/upgrade35.html I've been doing remote upgrades of OpenBSD and Linux (mostly Debian, but also occasionally Red Hat derivatives) for over 20 years. While I've fortunately only rarely encountered significant problems with any of them, OpenBSD upgrades are the only ones where I can have any confidence in understanding and tracking how the system evolves across upgrades. Follow the upgrade guide and delete outdated files (much easier since sysclean(8)), and a 10-year-old OpenBSD box can have a filesystem as pristine as a freshly installed system.
I'm not one of those people who wants pristine for the sake of pristine. But pristine is important when you care about security, and maintenance burden is a huge component of security, as are simplicity and transparency.
For what it's worth, I think OpenBSD is intuitive because of its consistency. It's certainly been more intuitive to me than any other OS; it just makes sense as a whole in a way that no other OS quite does, and that's refreshing in a world where users are expected not to understand what their tools are and how they work.
OpenBSD just builds its intuitive bits on things you may not yet know. Fortunately, it has excellent documentation to get you started.
On OpenBSD, if you're stuck on something in ksh, cwm, pf or any other built in tool, the man page is right there. Easily accessible, easy to read and comprehensive. When I play around on my OpenBSD box, the man pages is often my first choice over a search engine.
Also, not confuse man pages on OpenBSD with Linux man pages. Those two are remarkably different. Many Linux tools have good and comprehensive man pages. On OpenBSD everything has great man pages.
To me, it seems worthwhile to have fewer 0-day bugs to worry about, and more reliable separation between user accounts (fewer privilege escalation bugs, etc etc). (I also recommend setting default umask to 0077 for the same reason, except while using pkg_add -- I have a wrapper script that undoes it temporarily for that due to issues encountered.)
There are reasons people use Windows or Apple (perceived convenience), and reasons not to (long-term cost/benefit decisions for known uses).
In case it becomes useful to anyone: One way to traverse the docs is (occasionally helpful) is using something like http://man.bsd.lv/ for OBSD docs, like putting in an "=" (w/o quotes) in the search field then clicking "apropos" shows all the commands -- a useful way to learn "what is available in the base system"; or doing full-text searches (can be learned locally, I have an awkward script for it if needed),
(Edit: s/what is available/what is available in the base system/ .)
And: I find the ~"only 2 remote holes in the default install since about 1996" to be very impressive.
Edit: Another way to look at it might be by priorities. I have come to see priorities of some systems roughly as:
OpenBSD: security, openness, correctness (including of documentation), portability.
Linux: features, performance, openness, breadth of everything, compatibility, convenience (distributions vary in specifics of course; debian and/or devuan continue to impress me in their own way).
FreeBSD: performance, stability, openness.
NetBSD: portability, stability?, maybe enjoyment for its developers, openness. (I know least here.)
Windows / Apple: profitability while targeting preferences of specific groups who want different specific kinds of convenience, it seems.
To me OpenBSD is similar to what Slackware was, as simple as it possibly can be, with the advantage of a BSD being coherent and consistent.
I'm a long time Linux user and only used OpenBSD recently. I often find myself Googling Linux configs. I did use Google for OpenBSD to get started but found after a day I wasn't and relying on the man pages instead for system settings etc. They really are short, concise and complete, everyone says this but until you use them it's hard to understand.
I use Emacs I don't know Emacs. Emacs is a completely different beast to OpenBSD. Emacs is a huge rabbit hole and you spend as much time building your own Emacs as you do using Emacs. OpenBSD i've set up once which was simple as someone never using it before, and then forgot about it. It's been sat ticking away in a corner, no interruptions.
As much as I really like OpenBSD I don't think I can use it as a primary desktop. There's a few compromises on hardware support, no docker for my day job and I've read the desktop experience is slower than Linux just because it hasn't had the money and people Linux has had with drivers etc.
I'd really recommend anyone try OpenBSD for it's simplicity and educational purposes. If you use it as your main OS you will likely be dissapointed with some of the limitations, as a server / secondary educational device you might be pleasantly surprised.
Unfortunately search engines are unreliable, some "search engine optimized" virus pages could be first, and not some bank or docs website.
Luckily, the manpages are available on your favorite search engine!
These are the folks that brought you the word 'hackathon', and OpenSSH. (Ever use ssh? Thank OpenBSD.)
These are the folks that actually bother to read not just a PR, but actual full codebases, just to make sure their pointers don't dangle.
It's been years since the DevOps space was first told to prefer 'livestock' -- disposable, nearly-identical instances -- to pets -- long-lived customized instances and servers -- but as every farmer knows, if you have lots of sheep, the job is a lot easier if you have a sheepdog. Not quite a pet, but not cattle, either.
OpenBSD is my sheepdog. It keeps my git repos, it runs my wireguard VPN, and it, above all the other systems I touch, is trusted.
But trust is ultimately about people, not about systems. Systems get their trusthworthiness from their creators, the way the moon gets light from the sun.
And in trustworthiness, the OpenBSD community has a breathtaking superpower: They can say no. They are good at saying no. Do you know how hard that is -- to have someone ask for a feature, and just tell them off? That's the hardest thing any manager ever has to do, and these guys are good at it. Rare, in FOSS space.
These are the folks that are so good at saying 'no' that they ship with a literal actual bespoke copy of 'vi', that does exactly what it is supposed to, does not take packages, and also does not have a package manager pulling in raw github HEADs. (I love you, neovim, but you are so trusting!)
OpenBSD has been around for most of my 20+ career in this industry and it's sort of always been this aggressively reliable paperweight of a distro. I'm never quite sure what to do with it (NixOS is my go-to for my workstations -- NixOS + Wayland + Sway + Alacritty + Neovim is as close to godliness as a user interface can come) but OpenBSD finds its uses, and in those uses, it is smooth and heavy and reliable, making it the perfect foil for the rest of my infra: For where NixOS is neurotic and brittle, OpenBSD is saturnine and malleable.
I think of my infra as sort of being like a knife blade, with a glittering Nixos/Wayland/Neovim edge supported by a soft, heavy core of OpenBSD.
If everything else breaks, so long as I have my OpenBSD instances, I can recover.
One final word: At my end, I just finished upgrading my instance at openbsd.amsterdam; big shoutout to that amazing team for their incredible support. (Mischa, in particular, is a force of nature, and I am fan. ;D)
However when I ran OpenBSD on an old Chromebook I did really enjoy using it, I made a point of trying to use just the base system and aside from needing a web browser it was extremely usable. The documentation is universally good all the built in tools are well maintained. In the near future I’m gonna setup a separate firewall/router machine from my NixOS box and I think I’m going to use OpenBSD there too.
Here's what helps me decide: I simulate a disaster. Since I'm just me, I do it on paper (empirical ways are best but are also the most expensive, and in a pinch, a thought experiment can illuminate as well. Not always the same things, but light is light.)
Try it -- open a scratch.txt and write about things that would happen, and then the things that would probably happen as a result of that.
The one that often comes up for NixOS is "I lose network connectivity." While NixOS is phenomenal in its ability to roll changes back, the fact that I need a stable Internet connection in order to make any change whatsoever to the current config makes that little piece of CAT-8 a SPOF for any number of unexpected (and intuitively unrelated) matters, making the overall system hard to reason about.
You can mitigate this by hosting your own NixOS channels, which is sort of the equivalent of hosting your own apt-get repo.
But, as you might expect, that's actually a fair amount of extra work. So I don't, especially not on laptops, where space can (still) be limited.
So, every time I do `home-manager switch` I need a viable network connection.
This is especially galling if you (like me) manage most of your apps with Nix' `home-manager`. Think it through; Nix manages (say) your word processor; you want to change the font size in your word processor; you edit your home.nix and hit `home-manager switch`.
But look at what this entails! My apartment building's fibre-optic cabling should never be a depenency on altering the font size in my word processor, but here I am. Ironically, for the sake of convenience.
Now, none of this is to slag on NixOS. As I mentioned above, it's my favourite way to encounter reality. I'm typing this to you on NixOS right now. For me, the pros outweigh the cons. Provided, of course, I have something less brittle than NixOS to back me up, and for me, that means OpenBSD.
I have an OpenBSD instance in the cloud and a break-glass procedure for getting into it. It backs up via another old-school friend, tarsnap. It hosts the git repos that contain my nixos and home-manager configs. If I can talk to it, I can simply zap my NixOS config onto some new edge device and be back up and running in no time.
I also typically have a NUC running OpenBSD present as well, in case that apartment-building fibre gets troublesome (again,) but not at the moment, because my beloved PCEngines device has apparently become unstable under any OS. But when I get that OBSD NUC set (back) up, it will absolutely have a NixOS channel on it, and it will serve as a firewall, a SAN, serving NixOS channels to the edge devices. It will have an actual serial port and a password on a wax-sealed bit of paper in my fireproof safe. Because I think ahead, and that's what I need to get back up and running under the worst circumstances.
I simply can't imagine a non-hardware-failure disaster that could take out an aggressively boring OpenBSD bastion instance. They are just relentless in their persistence.
As I keep saying, NixOS and OpenBSD pair together like honey and mustard. Contrastive but unexpectedly delicious.
Take-home: If you're building infra, try adding some OpenBSD to the mix. It can make the unrecoverable recoverable.
Cheers, happy donations to the BSD Foundation!
I guess I don’t see a major difference in the complexity of that decision process in the Linux space, which might have been alluded to.
If you compare something like Debian, Alpine, and NixOS, then maybe..
The BSDs all have a common ancestor. The Linux’s tend to all have a GNU user space, the kernels are mostly the same, but the OS layout tends to differ in important ways.
Can you run FreeBSD binaries under OpenBSD? No.
edit: and oddly if you only go with this definition, that is Windows with WSL also a Linux OS? I'm guessing most people wouldn't say yes...
I would presume Linux OS to run Linux kernel on host OS. By default Windows runs Windows kernel.
They have too much disparity in terms of configuration to consider them the same OS for management purposes which is my main focusat work. But I can understand if someone with another perspective feels differently.
FreeBSD for servers and NAS, desktop. FreeBSD has high performance all around, ZFS, jails, bhyve, linux compatability, etc. But it's not as nice to administer as OpenBSD. I want to love it, but it's tedious.
NetBSD is an OK choice for anything, and very capable, but doesn't stand out for anything other than portability. If you enjoy hacking on things, you might find a lot of use in it.
I would personally never use it for a laptop.
I ran OpenBSD on a Thinkpad T450 for over a year, but recently switched to OpenSUSE Tumbleweed, not because of lack of speed, but some missing applications and blutooth support.
Given I don't run a heavy desktop environment, rather just StumpWM, but still I did not in any way feel OpenBSD was slower than Linux, using the same applications.
OpenSUSE is the most solid Linux I have used so far, but OpenBSD was more to my liking setting up and maintaining. It is well thought out, simple, and... just makes sense.
Indeed but I ran it on my Thinkpad and it was a sluggish mess.
And plenty of other OSes have FDE and everything in-between.
Not to imply I don’t like OpenBSD, I love their first class support of old architectures.
Only if you carefully pick your laptop hardware. I tried giving OpenBSD a spin as a daily driver on my XPS13 9343 and was plagued by issues:
1.) The network firmware is not included in the base OS. I had to download the firmware onto a USB storage device since the XPS doesn't have an ethernet port.
2.) 802.11ac isn't supported on my network card
3.) The login manager and window environment are unusable on a 4k screen. Trying to scale using xrandr --scale caused everything to appear fuzzy. I scoured the @misc mailing archives and could not find a suitable way to scale display without causing blur.
4.) Suspend/resume is broken and causes the kernel to panic.
5.) X.org doesn't use the inteldrm driver by default which causes choppy media playback
6.) OpenBSD puts memory limits on processes by default which causes memory hungry applications -- like web browsers -- to run choppy unless you change the memory limits.
None of these issues came up when using Ubuntu on my XPS 13. On Ubuntu it "just worked".
If you want something you can use as a border router/firewall, OpenBSD.
If you want something for more general-purpose computing (like a desktop or home server), FreeBSD.
If you want something you can install on your toaster, NetBSD.
Similarly, on desktop, OpenBSD can be pretty nice if you're a developer comfortable in the terminal; it runs the same graphics drivers as FreeBSD and Linux (other than NVIDIA). It's defaults tend to be a bit more sensible on desktop/laptops too IMO as its developers are more likely to dogfood it. There's been good progress on NetBSD desktops over the past few years as well, but I'm less familiar with it, so I can't comment too much.
With regards to portability, NetBSD supports more systems, but often I've found that OpenBSD is a little bit more stable on the ones they do support as they insist on not using cross compilation: so every system they do support is at least stable enough to build itself, which is a good stress test, especially on older machines.
But if you are looking for more focused projects, then Dragonfly for best out of box desktop experience, openbsd for security and firewall, and netbsd for compatibility and portability across loads of devices.
They're all good. I wouldn't over-complicate it. Just look at the one with known strengths that most match what you most value and dip in. A lot of the knowledge crosses over if you want to try other ones anyway, they're all related.
OpenIndiana: file server (ZFS)
OpenBSD: firewall, router, network services (DHCP, DNS, NAT)
DragonflyBSD: game server
FreeBSD: other general application services
I haven't found a personal use case for NetBSD yet, though I would like to (it is great for embedded systems).