So it's basically a SteamOS sibling, just without Steam?
So it's basically a SteamOS sibling, just without Steam?
That might be their target audience.
What appeals to me about linux is the hackability and configurability. This takes it all away in some way, but that's not to say that they won't find a market for it.
You can overlay changes to the read-only rootfs using the sysext mechanism. You can load and unload these extensions. This makes experiments or juggling debug stuff a lot easier than mucking about in /usr used to be.
A lot of KDE Linux is about making updates and even hackability safe in terms of making things trivial to roll back or remove. A goal is to always be able to unwedge without requiring a reinstall.
If you know you can overlay whatever over your /usr and always easily return to a known-good state, hackability arguably increases by lowering the risk.
Immutable distros just one-up that by trying to steer the system in a direction where it can work with a readonly rootfs in normal operation, and nudging you to take a snapshot before/after taking the rootfs from readonly to read-write. (openSUSE has you covered there as well, if that's your thing; it's called MicroOS).
Both of those distros use KDE by default, so the value-add of KDE having its own distribution is basically so they can have a "reference implementation" that will always have all the latest and greatest that KDE has to offer, and showcase to the rest of the Linux world, how they envision the integration should be done.
If I were to set up a library computer or a computer for my aging parents, I would choose openSUSE Leap Micro with KDE, as that would put the emphasis on stability instead.
If you already commit all your changes, anyway, what keeps you from using Nix and running one more command (`nixos-rebuild switch`)?
This is a major reason I ended up with https://getaurora.dev. I layer a few things, but it comes with bells and whistles (like NVIDIA drivers, if you need that).
I can't see myself going back to a "normal" distro. I don't want to spend time cosplaying a sysadmin, I have things to do on my computer.
It doesn't, though - as evidenced by my Steam Deck - it adds enough friction to make me not bother most of the time.
Linux is wonderfully flexible, which allows to create distros like that, among other things. Linux is also free as in freedom, which may be very important for trusting the code you run, or which a governmental official runs.
I bet that past the alpha stage they will offer a configuration tool to prepare the images to your liking, and ways to lock the system down even more. Would work nicely over PXE boot.
> KDE is a huge producer of software. It's awkward for us to not have our own method of distributing it
The idea of a distribution for this specific purpose is best left in the hands of some organization with experience with this specific purpose, not KDE whose experience is developing desktop environments.
How exactly is it “awkward” for them and how exactly does distributing this in any way improve the development process of KDE? They can't even dogfood it obviously.
This really feels like they first decided they wanted to make their own distribution for no reason, and then went to search for the niche for it to fill which is the wrong way to do it. Usually someone, who typically does not do anything else at the moment, realizes there is a certain niche that needs to be filled and then decides to make a distribution that fills that niche.
I am not a fan. It’s a big outage waiting to happen. It’s an enormous data breach waiting to happen. It will inevitable be enshitified.
If the government had already thought about this in advanced (even in 2013 when doctolib was just starting out), then there could be very strong protectiosn for data which would then allay all of these concerns, and we might have had multiple players in this space.
The best use of Doctolib for me is that I can make appointments without having to speak perfect German on phone. I can make appointments in evening when I'm back from office and can relax a little bit. So, doctolib is a godsend for me as an immigrant here. and I'm guessing for a lot of people too. I can look up doctors who are available without having to bother the receptionist. This is much more efficient way of doing things.
What's more, this is a sensitive and regulated field, where trust is essential. They can't afford to mess around if they don't want to quickly find themselves subject to moe restrictive regulations.
They were heavily criticised in France because they allowed charlatans and people with no medical training to register (particularly for Botox injections). As soon as this became known, they quickly rectified the situation.
Seriously. That's the reason that fax is still popular in the medical industry.
1. You get way less faxes than emails.
2. Faxes can't steal credentials.
3. You should be auditing expenses anyway.
What's more, it's Google, so we're not safe from a ‘Lol, we're discontinuing support for Chrome OS. Good luck, Byeeee.’.
Some offices still have bad memories of Google Cloud Print, for example. I'm not saying that being an early adopter of a distribution that's less than a year old is a good solution. Just that Google's business products don't have a very good reputation.
ChromeOS Flex exists, it is free of charge, and it runs on more or less any x86-64 computer, including Intel Macs.
Nordic Choice got hit with ransomeware and rather than paying, just reformatted most of its client PCs with ChromeOS Flex and kept going with cloud services.
https://www.bitdefender.com/en-us/blog/hotforsecurity/nordic...
Sure it's less popular. It came in under 20 years ago, competing against an entrenched superpower that was already nearly 30 years old back then. It's done pretty well.
The Google Apps for Business bundle has outsold by far ever single FOSS email/groupware stack in existence, and every other commercial rival as well.
Notes is all but dead. Groupwise is dead. OpenXChange is as good as dead. HP killed OpenMail.
That's ridiculous.
Their office buys their stuff from a supplier which ships them a Windows box with all the batteries included.
That's why doctors in my country still prefer legacy physical pen and paperwork, versus interactions with the modern digitized equivalents which are universally hated because they're not designed by doctors but by some consultancy who won the government tender.
Adding dealing with an unfamiliar OS and Wine on top of that is not the slam dunk you think it is.
The average user doesn't want (and shouldn't need) to understand technical stuff like file formats (JPEG vs. PNG), the data load of video streaming, what a "driver" is, etc. Forcing them to grapple with these concepts is a fundamental design failure, but I think it’s a difficult pill to swallow for nerds to accept that others just don’t care about these things.
This is why companies like Apple have been so successful: they don't just simplify the interface, they abstract away the complex, technical reality into a language and experience that feels intuitive and friendly for the users.
[EDIT] The core problem, in case the example didn't make it clear, is that these things interrupt a workflow they use often, and are accustomed to having always work the same way, and do so in service, usually, of showing them a bunch of stuff they don't give a fuck about and didn't really need to know. Even the ones that block interaction to highlight new features are really bad—OK, that's nice, but I'm trying to do the thing I always do with this and you're getting in my way, making my program temporarily behave and look weird and confusing, et c.
She has no conceptual understanding of what’s an app and a webpage and why they’re treated differently, she just kinda accepted she uses something called Firefox to do a search and some icon in the phone that has the exact name of the other app she wants to use. She never understood (or cared) what it means to “close” an app if she already does that when she presses home or back, no matter how much I try to explain.
When you think about it, it’s all very confusing for them, and since people making these things already understand them well, they make stuff assuming the users will understand the whole thing as well as they themselves do.
No other buttons (visible on the face, anyway) to confuse it for. It's right in comfortable reach of the thumb. "Which button do I push again? Oh right, there's only one."
(I also think going to "swipe up to unlock" instead of the brilliant slider they had before was a big mistake, as far as reducing the level of comfort for the median user)
But your POS system where you enter in orders? That's Linux. And guess what - it just works, it chugs along and does its thing.
There's no reason that doctors offices couldn't use software that utilizes Linux. And to pretend that windows is low maintenance? Tsk tsk, windows is a time bomb.
It is possible for somebody to make this into a workable bundle targeting specific professions/environments. A doctor would not care if double clicking X icon open an app through wine or not.
However, while I love the approach of having an immutable distribution, I don't see the attack vector of ransomware handled in a good way. It does not help, if your OS is intact, but your data is irrecoverably lost due to a wrong click in the wrong browser on your system.
I think the backup and restore landscape has enough tools to fix this (cloud + restic[2] or automated ZFS snapshots[3]), but it takes a bit time / a script to setup something like this for your parents in your favorite distro.
This is more about preventing the user from messing up their computer than it is about data safety.
I've been using Bazzite for 2 years now (an immutable distro based on Fedora Silver blue) and I just love the fact that I can "unlock" the immutability to try something that could mess up my systemd or desktop environment, and I can just reboot to erase it all away.
I also have a github action to build my custom image with the packages I want, and the configuration I want.
And this makes adding a backup setup even easier, it can be baked-in the distro easily with a custom image ! Your grandparents don't have to do anything, it will auto update and auto apply (and even rollback to the n-1 build if it fails to boot)
I hear you. The problem is, that basically nothing stops you from building anything yourself. The difference is, that there is no easy-to-use build-in solution (like time machine) and ease of use is what makes the difference. Especially a TIME difference. Of course there is software SIMILAR to time machine, but it seems to be hard to write something rock solid and easy-to-use.
In fact I also have built it myself: https://github.com/sandreas/zarch A script that installs Arch on ZFS with ZFSBootMenu and preconfigurable "profiles" which packages and aurs to use. Support for CachyOS Kernel with integrated ZFS is on my list.
I already thought putting together a Raspberry PI Image that uses SSH to PULL backups over the network from preconfigured hosts with preconfigured root public keys and is easily configurable via terminalUI, but I did not find the time yet :-) Maybe syncthing just is enough...
Isn't the main point that you delegate curating and building the system image to the KDE project?
The phylosophy of security in "modern" OSs is to protect the OS from the user. The user is evil and, given so many rights, it will destroy the (holy) OS. And, user data ? What user data ? /s
Looks like they used to, so they have removed the option.
Building your own is an option https://github.com/ublue-os/image-template
But I guess it is best to have the option that not to have it.
However, the only distro I could find where it actually worked was Chimera. Not the gaming-related ChimeraOS but the from-scratch LLVM-compiled all-static APK and Dinit distro with a hodgepodge userland ported from the BSDs.
It's rolling release though so it'll happily install the latest bugs. But it probably does that faster than any other distro.
But some people just want a computer to work.
It's not like you can't try a simple distro and move on to something more complex later.
Immutable/Atomic Linux doesn’t take away any ability to hack and configure it. It’s just a different approach to package and update management.
There really isn’t anything you fans do with it that you can do on other Linux distros.
I’m using Bazzite which is basically in the Fedora Atomic family and all it really changes is that if I want to rpm install something and there’s no flatpak or AppImage then I just need to decide on my preferred alternate method to install it.
I find Bazzite’s documentation on the subject quite helpful: https://docs.bazzite.gg/Installing_and_Managing_Software/
At the very worst case I’m using rpm-ostree and installing the software “traditionally” and layering it in with the base OS image.
Now you might be thinking, what’s the benefit of going through all this? Well, I get extremely fast and reliable system updates that can be rolled back, and my system’s personalization and application environment is highly contained to my home directory.
I’m not an expert but I have to think that there are security benefits to being forced into application sandboxing as well. Applications can’t just arbitrarily access data from each other. This isn’t explicitly a feature of immutable/atomic Linux but being forced into installation methods that are not rpm is.
Seems like a lot of effort and fanfare for such a niche market.
Innovation happens on stable foundations, not thru rug pulls.
Yes, you have the freedom to make your system unbootable. When Debian first tried to introduce systemd, I've replaced PID 1 with runit, wrote my own init scripts & service definitions, and it ran like this quite well, until... the next stable release smashed me in the face.
It's absurd how hackable the Linux distros are. It's also absurd to do this to your workhorse setup.
THIS!
I was pondering putting Linux on my father's ancient machine (still running Windows7; or migrating him to something slightly newer but win10/win11 doesn't rub me the right way) but I was weary of "something wrong happening" (and I'm away right now).
And having immutable base would be awesome - if something goes wrong just revert back to previous one and voila, everything still works. And he would have less options to break something…
But I wouldn't use KDE for the typical cliched (grand)parents: it's just way too complicated for someone who's doesn't have high proficiency in tech.
In fact, from what I understand it is in fact not really Gentoo based but Portage-based, as in they for the most part write their own ebuilds and software and from what I know have their own custom init system and display system that's not in Gentoo but they found that Portage was simply very convenient for automating their entire process. The claim that “gentoo is just Portage” is not entirely true, there's still a supported base system that's configured as offered by Gentoo but it's far more flexible than that of most systems of course, granting the user choice over all sorts of fundamental system components.
Excellent summary. Yes.