I see we hype about containers, so I've got a few questions.
This post is mainly created in response to a guy, who said, that the future is immutable core system with everything else in containers.
How do you see containers on servers? As of now, there's place for VMs to allow customers to have their virtual systems for their needs. There's place for Docker to create different environments, which cannon access each other for example for development purposes. There's place for Kubernetes, since it is very useful for clouds (along with Docker, yes). But all these examples are about clouds, there containers are the only way stuff can work at all. What about a http server? What about a fpt server? What about server software in general? We do not have such software inside its own container (like with snap or flatpak) because it doesn't make sense.
The place where we can really put every single app inside its own container is desktop. But is it really needed? Are there many vulnerabilities in webm? In odt? png? webp? svg? There's only one thing on your desktop which is a huge security concern and it is your browser, and there container could provide a real new layer of security. Why would I need to containerize my mpv or my LibreOffice? Or my gthumb? Or my geany? Or vim? Or my wm? Perhaps I really should put my qalculate inside a container, since this calculator doesn't seem safe enough (it's too clever)? For now folks justify usage of flatpaks and snaps to have bleeding edge software, but then why not having bleeding edge distro? Do you think you really need a container just to have bleeding edge software? Do you think you really need to put everything in containers in general?
Next, how do you trust snap repos? I can trust Arch Linux repos or Debian repos because they provide me with source code, if need be, I can quite verify if they fooled me or not. But I've got zero idea what the hell runs inside snap. Can I verify stuff? And if yes, then how? Also, isn't it yet additional layer of trust? Isn't it an additional layer of effort for developers?
The same question about flatpak.
Next, have you ever heard that Linux is used in embedded? The huge reason why is because Linux installation can be extremely tiny. That is a considerable advantage. Do we want to get rid of this? And for what? Dependency hell is hell and is painful quite often (even for users), but it gives many important things in return. The fact Linux distro doesn't take much space is a very pleasant thing even for just ordinary users. I know most doesn't care, but could we have Mobian if not this? We cannot afford too many gigabytes for a phone, so each is very valuable. Shared libraries can spare you some RAM usage also.
Now, cultural things. The huge reason why geeks love Linux is because your system is truly yours. Almost every geek I know would jump out of a window if you took this from him. With immutable core system, your system is no longer yours. And this is a very huge concern. I trust developers, but I do not trust companies and corporations. Having immutable systems is very likely to catch us in hideous trap as long as there's capitalizm all around.
What do you think? What are your reasons to put everything in containers and lock core system?
[link] [comments]
SOCIAL SHARE CARD GENERATOR