Considering the Dutch have ASML, this seems an unwise move for the US. But then, the Dogey Confederates are working towards the destruction of the USA. 😒
This might just be the best thing that happens in tech (for me) all year.
I daily drive debian just because boring and reliable. However, fancy package managers like flatpak and appimages and nix have made debian much more vibrant - it’s easy to install new versions of things now.
That said, nix package manager on debian is just freakin amazing. Being able to just
nix-shell -p <obscure cli tool>andexitwhen I’m done with it is magnificent.That’s the gateway drug anyway. The nix based home-manager is pretty cool.
While I’ve been tempted to jump in with NixOS my experience with nix packages and home-manager has felt kind of bleeding edge or experimental. Loads of things that don’t work as intended on debian.
A sophisticated well funded user base like a federal government has really good implications for the stability of the project in the future. I’m really stoked about this.
US has been building soft power like this for decades, and Trump is pissing it all away.
If this process to get rid of dependency on US gets well underway, there’s no turning that ship. US won’t recover the position it had in fifty years or more.
US won’t recover the position it had in fifty years or more.
This is not a bad thing. Over dependency on any one nation or even a bloc of nations is a bad thing.
I can’t help but think the dependency on the US that has been created played some role in what’s happening now.
Honestly, I can see that. America has been top dog for so long, it doesn’t value what it has.
Not even that. I’m thinking too much money, power and influence all consolidated in one place.
The US has the most billionaires at 989 and I’m guessing of the remaining ~2400 billionaires in the world, a not insignificant amount have substantial interests in the US.
It’s good the rest of the world is watching it happen. I hope they’re taking notes because it’s not stopping in America.
Nope. The US isn’t teaching people to fish, its forcing them to learn How to to feed themselves. In the past they handed them the fish so they could control them. That power is lost now.
And nothing of value was lost
in fact, things got better
Windows is basically a zombie OS at this point, shambling along and eating brains.
Windows as a home user desktop is definitely coasting on momentum, though it is also the OS deployed on most new PCs which keeps it going.
I think the only thing really keeping Microsoft relevant is Active Directory (and Azure by extension) because a lot of organizations are dependent on AD internally, and there still aren’t really any good alternatives that check all the same boxes. You could probably cobble together a working solution for ~90% of it with open source software, but it would be clunky, fragmented and feature-poor compared to an on-prem AD system. It would require a lot more administrative overhead to configure and maintain it, and user management would be a mess.
I’m starting to see non-AD companies cropping up. If you have to support Mac and Mac is absolute trash on AD, you need to run software to manage the macs which can already manage windows. With all the remote work, even RMM software is on the rise.
EntraID also seems corporate established. For a modern with system, with zero trust etc, you use EntraID instead of AD now.
Of course, legacy AD systems, if they exist, are also lock-in.
EntraID is just a rebranding of Azure AD
Azure AD, the cloud version, still isn’t as feature-complete (or possibly feature-bloated) as the original on-prem AD, which is a big reason large organizations won’t switch away from it.
Sounds like there’s a startup opportunity here.
Sure, but they’ll have to catch up on almost 30 years of feature development (and feature creep). Active Directory is entrenched, by virtue of being the only game in town for decades.
Not that they’re necessarily irreplaceable, but… a half-competent Windows Server admin can go from cold iron to running HyperV with a local domain (AD forest) with a SAN supporting 200 endpoints (assuming the hardware is already in place) pre-configured with end-user applications and all relevant network & security settings (via group policy), with a print server supporting local network printers, and be ready to enroll new users, in less than a day.
I’ve seen it done, I’ve helped get it done. And all of that can be done with point-and-click GUIs, and not a dozen different ones, just like 3 (one for server/HyperV deployment, one for HyperV config post-install, and then basically everything else can be done through Active Directory).
When you’re a sysadmin for a large organization, that kind of operation at scale is non-negotiable. When I say that AD really has no competition, that’s what I mean. You could accomplish all of the same things on Linux, but it would take you a week of punching through terminal commands just to get the server and the domain up and running, and once you were done the user management still wouldn’t be as flexible or feature-complete as it is on AD (especially if you need things like auditing, or physical access token integration like badges for authentication, or remote desktop support, or video conferencing that is linked to corporate email accounts).
All of that said, if you happen to know of a group that’s actually working on a competitor for on-prem AD (not Azure AD/EntraID, the cloud system is very different and not really comparable) I would be very interested. It’s a problem that’s been on my mind for awhile now, and I’d love to get paid to actually work on it.
I heard OVH is at it. Maybe among others.
Neet, if NixOS get used more and more then the skills I acquired making my config will become marketable.
Microsoft: “No, not like that!”
So ironic after bending over time and time again for the US. Think ASML, think Nexperia. Fuck Rutte and Jette - mini Rutte wannabe.
Microsoft office is still their best product but many words apps such as only office are becoming comparable. Microsoft Access and excels cross compatibility with other office apps is unmatched
They don’t even need to be comparable. Majority of people just need the basics or what Office 2013 had to offer. Now Office does too much and now copilot… if anything it’s getting worse now.
Yup. I haven’t bought any new Office keys since like 2020, and I never will. Keep the CoPilot away from my thoughts, geesh. I feel like a schizo when I use them.
I’m on Mac Office Business 2019. I just found out that blocking Microsoft traffic on my firewall, stops the ability to save doc as PDF. I installed Collabora Office on OpenCloud.
All middle powers need to align and collaborate on this. There is limited programming talent and gaps and especially security (ai) gaps need to be filled. EU, UK, Canada, Aus, NZ, SK, Japan should actively pool resources.
US: Let’s sanction everyone everywhere all at once!
Also US: Why don’t people want to be dependent on US systems? 😭
Couldn’t undermine the country more if they tried, which makes one wonder.
Yep. Trump’s actions are no different than what any bad actor would do if they wanted to destroy the USA without invading it.
- Destroy our soft power… check!
- Turn allies against us… check!
- Destroy our economy… check!
- Drastically weaken our military… check!
Destroying what (appearance of) democracy they had as well
Yea we got a bit of the “inmates are running the asylum” situation over here.
In the immortal words of the joke (paraphrased) this country needs an enema
we would lose about a third of our human biomass
Oh well
I wish. Organizations and countries/municipalities are far too lazy to make the change.
The time and money involved are both staggering. This isn’t about you switching operating systems on your personal laptop.
Where are you going to get support staff anytime soon? All those Windows admins magically switching to Linux overnight?
Hell, Linux offers nothing remotely comparable to the power of Active Directory. That alone will keep Windows in the lead.
And more. This isn’t about lazy.
Time + motivation + money can overcome a lot of obstacles. It also helps that template of what is needed already exists in Active Directory. This changes the project from “innovating something new” to “a slightly better copy” and is usually a lot faster and easier.
All copyright/patents are also void because of the sanctions at least in practice.
I have worked in big company where linux and windows coexisted, but we were developers so maybe that’s why (IT was very strict though).
What is the alternative to AD, and are there currently companies running that, big or small?
Red hat IDM, aka freeipa.
Depending on what youre doing you absolutely don’t need active directory.
Hell, a lot of orgs are just going entra anyway. If you’re using SSO like that or okta or keycloak you likely don’t need AD.
At this point, a lot of entities don’t need AD because their entire workflow runs in a web browser, and practically any SSO provider will work.
That said, accessing actual computer resources can be managed with groups and ACLs. Perhaps not as elegantly or as well-integrated as AD is, but that’s the price you pay.
Finally. Been saying for years, NixOS is the obvious choice for a gov distro.
Now we need to convince Canada to do the same. If everyone leaves Microslop, that would make a huge impact.
I am curious, what makes NixOS such a good choice?
From the article:
Its use of the Nix package manager means that each package is installed in its own directory with immutable and signed contents. That alone means that the setup is incredibly easy to reproduce across multiple machines, something that is an obvious benefit when dealing with different facets of a government.
Id argue an immutable distro would likely serve the same purpose but maybe its also because nixos isnt as “locked down” so itd be easier to configure for a specific purpose?
The big draw is probably that it’s declarative, so you can define installations as code much the same way as you would do with Terraform. Instead of needing a pile of messy Ansible playbooks running custom scripts to change anything (and which can break if the target machine has an unexpected config), you’d just have one that pushes a new version of the config and runs nixos-rebuild. Rollbacks are just as easy if anything breaks. What’s not to like?
Right so in that way, its very reproducible. That was my understanding and I appreciate you for the more in depth explanation but is there advantage to that versus an immutable distro? Wouldn’t a immutable distro work in a similar way being reproducible among many machines?
Rollbacks can be done on immutable distros as well right? I’m just curious why Nix was the first choice and not something immutable.
nix is on a whole different level than silverblue and other ‘atomic’ distributions.
But not curious enough to read the article.
You know, you could simply be helpful.
Sure.
It’s in the fourth paragraph, starting with
From a technical point of view…
and ending with
… would usually balk at.
Why?
Honest question.
from a sys admins perspective it’s painfully easy to deploy across hundreds of machines. NixOS is declaritive and immutable. you can take one system configuration of NixOS and throw the same config on as many machines as you want. packages, dotfiles, whatever are all replicated the exact same way on each machine. You can lock all the packages/apps, configs, kernels, etc to a specific version therefore a sysadmin may only need to upgrade the lot once a year. if a user some how breaks their system it’s as easy a fix as rolling back to the previous generation with a single menu option.
So basically say you have your computer and you want to replicate your exact setup to hundreds of other computers. with NixOS it’s as simple as setting up a git repo for your nixos config, pushing to it, installing nixos on every other computer then cloning your repo to all the machines and rebuilding. done. now you have hundreds of other computers that all behave and work the same way your computer does.
If something needs updating or a fix needs to be rolled out all a sysadmin has to do is fix it on one machine, push the change, pull it for every other machine and rebuild. done.
My guess would be the deterministic configuration management. If it’s for a personal machine then do what you want to make it your own but if it’s an organization (e.g. government) you want the machines to be as similar as possible to reduce maintenance. Think cattle, not pets.
Ansible is a thing though. It is also a more complete, mature and easily substitutable solution vs pinning your hopes on a single distro.
Programmers like NixOS because they are programmers.
Ansible is US-owned. Even though it’s open source, Redhat, a US company, is the one that controls its lifecycle.
NixOS is based out of the EU.
Fun fact, Nix, Nixpkg and NixOS have their roots in the Netherlands. For example, Nixpkg was even described in a PhD thesis at Utrecht University.
I mean they sort of serve different purposes. You can build a NixOS ISO running your exact desired configuration that is good to go immediately upon install. Ansible would require post install configuration, yes it is scripted but it is additional overhead and time. I think a better alternative would be an OCI based distro with a Packer build pipeline, which could include Ansible steps higher up in the build process. But that’s more complexity that Nix wouldn’t require
i used ansible some years ago and i’m using nixos currently and you can not compare those two.
i was not fluent in ansible and i’m not fluent in nixos. yes you have to leave your comfort zone for nixos, but your get so so much more.
the jinja templates in yaml feel like a big hack if you used nixos.
would really be interesting to hear someone talk who is comfortable to use both of them.
I’m honestly amazed ansible still exists. I used it regularly like 10 years ago and never liked it. I use NixOS for all my servers and package all my code as nix flakes, and I agree that they’re barely comparable.
NixOS is a kinda frustrating desktop distro to me though. Sometimes you just wanna type
make
It’s close, but Ansible is often not deterministic.
The only thing is this doesn’t yet do online user directories, local users only
Which is a big constraint right now
So we did this because we didn’t like what the court said about not us but Israel and its war crimes? This is the hill the admin is going to die (and drag us with them) on?
This great news! Away with USA!
Next up, convince everyone to drop Meta, including WhatsApp and IG!
Phones when?
I’ve got a Jolla Phone this summer. Sailfish OS. Probably not something you can sell to the mainstream but it is a perfectly daily driveable phone for some target groups, and I belong to them.
The main issue to date is that security related stuff on phones is basically exclusively dependent on US American companies (Google, Apple), this is pretty much madness if we want to protect Europe against hostile actions by the US. So maybe things are starting to move.











