1004
you are viewing a single comment's thread
view the rest of the comments
[-] smiletolerantly@awful.systems 100 points 2 days ago

Finally. Been saying for years, NixOS is the obvious choice for a gov distro.

[-] Canajan@piefed.ca 47 points 2 days ago

Now we need to convince Canada to do the same. If everyone leaves Microslop, that would make a huge impact.

[-] einkorn@feddit.org 20 points 2 days ago
[-] BrianTheeBiscuiteer@lemmy.world 63 points 2 days ago

My guess would be the deterministic configuration management. If it's for a personal machine then do what you want to make it your own but if it's an organization (e.g. government) you want the machines to be as similar as possible to reduce maintenance. Think cattle, not pets.

[-] 0x4f1@lemmy.world -2 points 2 days ago

Ansible is a thing though. It is also a more complete, mature and easily substitutable solution vs pinning your hopes on a single distro.

Programmers like NixOS because they are programmers.

[-] Godort@lemmy.ca 36 points 2 days ago* (last edited 2 days ago)

Ansible is US-owned. Even though it's open source, Redhat, a US company, is the one that controls its lifecycle.

NixOS is based out of the EU.

[-] 8uurg@lemmy.world 22 points 2 days ago

Fun fact, Nix, Nixpkg and NixOS have their roots in the Netherlands. For example, Nixpkg was even described in a PhD thesis at Utrecht University.

[-] Axolotl_cpp@feddit.it 2 points 1 day ago

Aren't Nix repos hosted on GitHub which is owned by MacroSlop?

[-] NewOldGuard@lemmy.ml 16 points 2 days ago* (last edited 2 days ago)

I mean they sort of serve different purposes. You can build a NixOS ISO running your exact desired configuration that is good to go immediately upon install. Ansible would require post install configuration, yes it is scripted but it is additional overhead and time. I think a better alternative would be an OCI based distro with a Packer build pipeline, which could include Ansible steps higher up in the build process. But that's more complexity that Nix wouldn't require

[-] 7EP6vuI@feddit.org 8 points 2 days ago

i used ansible some years ago and i'm using nixos currently and you can not compare those two.

i was not fluent in ansible and i'm not fluent in nixos. yes you have to leave your comfort zone for nixos, but your get so so much more.

the jinja templates in yaml feel like a big hack if you used nixos.

would really be interesting to hear someone talk who is comfortable to use both of them.

[-] qqq@lemmy.world 4 points 1 day ago* (last edited 1 day ago)

I'm honestly amazed ansible still exists. I used it regularly like 10 years ago and never liked it. I use NixOS for all my servers and package all my code as nix flakes, and I agree that they're barely comparable.

NixOS is a kinda frustrating desktop distro to me though. Sometimes you just wanna type make

[-] BrianTheeBiscuiteer@lemmy.world 8 points 2 days ago

It's close, but Ansible is often not deterministic.

[-] rozodru@piefed.world 21 points 2 days ago

from a sys admins perspective it's painfully easy to deploy across hundreds of machines. NixOS is declaritive and immutable. you can take one system configuration of NixOS and throw the same config on as many machines as you want. packages, dotfiles, whatever are all replicated the exact same way on each machine. You can lock all the packages/apps, configs, kernels, etc to a specific version therefore a sysadmin may only need to upgrade the lot once a year. if a user some how breaks their system it's as easy a fix as rolling back to the previous generation with a single menu option.

So basically say you have your computer and you want to replicate your exact setup to hundreds of other computers. with NixOS it's as simple as setting up a git repo for your nixos config, pushing to it, installing nixos on every other computer then cloning your repo to all the machines and rebuilding. done. now you have hundreds of other computers that all behave and work the same way your computer does.

If something needs updating or a fix needs to be rolled out all a sysadmin has to do is fix it on one machine, push the change, pull it for every other machine and rebuild. done.

[-] smiletolerantly@awful.systems 2 points 1 day ago

Or just configure all the machines to auto-update from the flake at the repo. Doing this for my VMs. I have a CI machine that builds my pinned flake from the repo tip, and about 30 other VMs check nightly if the repo tip has moved, and if so, rebuild from the new tip; which, thanks to the CI machine, means just downloading and activating a new generation, nothing compute heavy.

[-] kubok@fedia.io 13 points 2 days ago

I am curious, what makes NixOS such a good choice?

[-] Bluefruit@lemmy.world 33 points 2 days ago

From the article:

Its use of the Nix package manager means that each package is installed in its own directory with immutable and signed contents. That alone means that the setup is incredibly easy to reproduce across multiple machines, something that is an obvious benefit when dealing with different facets of a government.

Id argue an immutable distro would likely serve the same purpose but maybe its also because nixos isnt as "locked down" so itd be easier to configure for a specific purpose?

[-] punkfungus@sh.itjust.works 15 points 1 day ago

The big draw is probably that it's declarative, so you can define installations as code much the same way as you would do with Terraform. Instead of needing a pile of messy Ansible playbooks running custom scripts to change anything (and which can break if the target machine has an unexpected config), you'd just have one that pushes a new version of the config and runs nixos-rebuild. Rollbacks are just as easy if anything breaks. What's not to like?

[-] Bluefruit@lemmy.world 1 points 1 day ago

Right so in that way, its very reproducible. That was my understanding and I appreciate you for the more in depth explanation but is there advantage to that versus an immutable distro? Wouldn't a immutable distro work in a similar way being reproducible among many machines?

Rollbacks can be done on immutable distros as well right? I'm just curious why Nix was the first choice and not something immutable.

[-] kubok@fedia.io 2 points 1 day ago

Thanks. I read Smiletolerantly's comment as a personal opinion, rather that a summary of the article. I read several articles in Dutch news outlets, but the main message was 'hurr-durr-Dutch'.

[-] adarza@lemmy.ca 3 points 2 days ago

nix is on a whole different level than silverblue and other 'atomic' distributions.

[-] schipelblorp@sh.itjust.works 6 points 2 days ago

But not curious enough to read the article.

[-] FlashMobOfOne@lemmy.world 1 points 2 days ago

You know, you could simply be helpful.

[-] schipelblorp@sh.itjust.works 10 points 2 days ago* (last edited 2 days ago)

Sure.

It's in the fourth paragraph, starting with

From a technical point of view...

and ending with

... would usually balk at.

[-] panda_abyss@lemmy.ca 4 points 2 days ago

The only thing is this doesn’t yet do online user directories, local users only

Which is a big constraint right now

this post was submitted on 29 Sep 2026
1004 points (99.3% liked)

Technology

88356 readers
3667 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS