Operating systems battle: OpenBSD vs. NixOS
dataswamp.org
dataswamp.org
I'm currently building out a NixOS-based router to replace an old and dying Ubiquiti Edgerouter Lite. BSD would be perfect for the job but the ability of NixOS to have the entire system configured declaratively is enough of a killer feature to get me to use it over something BSD-based.
if anyone is interested in pursuing something similar, I'm using [0] as my hardware base and [1, 2] as example configurations.
0: https://amazon.com/QOTOM-celeron-Processor-Fanless-pfSense/d...
In theory, an OpenBSD NSH configuration would have a large overlap of features and functionality with the Nix-based router configuration you've been working on. Btw, NSH allows one to configure OpenBSD in a similar CLI shell as that of a Cisco, ProCurve, or similar device. The shell commands make up a configuration file that can be exported / imported. NixOS & BSD is something I thought of but hadn't mentioned when someone recently submitted[0] a link to NSH. Coincidentally, another user brought up NixOS as a potential solution, only for the comment to trigger some friction[1].
I've been dreaming about more integration between Nix and BSD for a while now, but unfortunately, my skills and knowledge to actually implement something like this are nowhere close to where they need to be to actually create anything in this vein. That being said, there are others who have done more, and so Nix is available on FreeBSD[2]. Nix on FreeBSD has a long way to go before it's as useful as it is on Linux/macOS - the latest discussion on it is in the NixOS Discourse forum[3].
Appreciate you linking to the blog post and GitHub repo for nixos-router. FYI, one other option available for Linux is the Debian-based VyOS[4] which provides a familiar command-line interface like OpenBSD NSH.
[0] https://news.ycombinator.com/item?id=30942489
[1] https://news.ycombinator.com/item?id=30966266
[2] https://www.freshports.org/sysutils/nix/
[1]: https://www.amazon.com/gp/product/B09PHHVWZ8/ref=ppx_yo_dt_b...
Disclaimer: I use NixOS every day and I love functional programming. But boy do I wish Nix had picked Haskell, OCaml, or Lisp instead of inventing a programming language.
I also used nix for a while and found the transition painless on my non-nvidia machine
Does GUIX have some similiar thing which can provide a standard formal structure and lock resouces? Thx.
edit: to be clear, I'm taking about flakes, Guix does have plenty of mechanisms and utilities regarding direnv-esque project manifests, lockfiles, and even "inferiors" which let you install outdated packages that the distribution has otherwise moved on from by actually building and using the version of guix that the package would have been built with at the time
Besides that, I look forward to giving it a chance.
Compared to NixOS, Chef's design allows for flexible deploy time decisions, but it comes at a price. With Chef, it's hard to ever predict everything that's going happen during deployment. Chef code takes a bunch of external inputs in the form of Chef attributes and also has full visibility into server state. All of this happens during deployment. So to make sense of what would happen during deployment, you'd have to run your Chef code in the exact same environment as your target server. To make things even more challenging, Chef code can easily mutate server state irreversibly unless you go to extreme lengths to prevent it.
NixOS, on the other hand, prioritizes predictability and reproducibility. It builds the files required for deployment beforehand in a sandboxed environment before the deployment phase, with all the necessary inputs fed upfront. During deployment, it mostly copies those files into an isolated location under /nix/store and creates symlinks to them in /etc and elsewhere to activate the system. Figuring out what would happen during deployment beforehand is a matter of inspecting the built files.
Furthermore, unlike Chef configuration, NixOS configuration doesn't concern itself with deploy time actions. Its focus is on expressing static configuration. The Nix language is used for this purpose, so comparing it the against unrestricted general purpose programming languages is a mistake. A better comparison would be languages like JSON, YAML, Jsonnet, and Dhall.
Thanks for the links!
This, a million times over please!
FreeBSD has nix the package manager. I too would love if all of FreeBSD was declarative.
Define a zone with a Nix derivation, the Nix Daemon installs all its dependencies into a shared Nix store, which then gets mounted read-only into all the zones. It would have eliminated all the copying things around they were doing with pkgsrc, speculatively installing a bunch of stuff in case you need it, Manta etc. Alas!
NixOS on the other hand: while I really like the idea of declaratively managing your entire system, the whole functional programming schtick isn't for me. I cannot for the life of me understand half the stuff I read (the Nix language, that is). I still don't see why all this couldn't have been written in say, Lua for example. Nix (and NixOS), is overwhelming.
That said, it's the least-shit of all Linux distros because it brings about the cohesion that others lack. I will continue to use it, at least for now.
It's because you're still thinking about this imperatively, when you should be thinking declaratively. I was in the same boat as you, but everything has recently begun to gel and it's much easier to read Nix configs.
The language is definitely intimidating but once I wrote a few small derivations for my own use, everything became clear almost immediately, much to my surprise. Try to do everything as declarative as possible (use flakes) and you'll have a considerably more consistent experience.
Or rather, I’ve never seen “declarative” code that I’ve liked. I watched a YouTube video once wherein two bits of code achieved the same thing, but one was imperative and the other declarative. I preferred the “imperative” code every time because I could actually read it, see what was going on. The “declarative” code seemed like it was obfuscating something or engaging in a bit too much magic for my tastes.
All the cool kids prefer declarative though, so I’m wondering what I’m missing.
I find declarative programming like functional better for higher level programming, while Torvalds for example likes C for Linux development because it is closer to how computers work (while providing the needed abstraction than programming in assembly for example).
but i don't think the argument for it really makes any sense for OP's comment. As an user or even packager you hardly use actual functional concepts. You're mostly dealing with a JSON with some functions for declaring the system, not some crazy Haskell shit. It is just that it takes time to learn new stuff, and stuff that have concepts you're unfamiliar with takes a bit longer. And it is true that the curly braces, function arguments, and some other stuff can look kind hard to decipher, but in general it's a familiarity thing.
I find this[1] in the area of Nix as and OpenBSD guest, but I've barely glanced at it for applicability.
[1] https://dataswamp.org/~solene/2021-05-08-openbsd-vmm-nixos.h...
I see some reference to Ubuntu with a nix package manager installed on it.
FYI typo. Should be “works”. Nice article!