‹ BackHN Continuity

Thread

Dutch governments builds alternative for Microsoft based on NixOS

1021 points · 583 comments · fjfaase

  1. sneak · · focus · HN ↗
    I’m really curious to see what the answer for MDM and Group Policy is on Linux. The SSO part is mostly figured out, but the reason places use Windows is often manageability.

    Is there anyone doing MDM or policy enforcement on Linux other than Google Workspace + chromebooks?

    1. ndriscoll · · focus · HN ↗
      It's Nix so you just push the new generation to the device. It's probably the easiest possible way to do device management. It's also generally like two lines of extra config to wrap a block into a container if you want to hide some of the underlying OS tools completely, which I've never tried with a full desktop environment but I'd assume should basically just work if you pass a couple things like GPU?
      1. Muromec · · focus · HN ↗
        The hard part is finding enough people working for the public sector salary who know those two extra lines and where to put them, and then making sure they are not getting bored or disillusioned enough.
        1. ndriscoll · · focus · HN ↗
          You don't need someone who knows those two lines anymore. You can just ask codex to make it so that users can't do whatever. It's highly competent at just reading the nixpkgs source, or it knows how Linux works and can write its own modules.

          Nix happens to also set you up with a working build environment so if a program doesn't expose the necessary options to manage it the way you want, I bet Codex would have no trouble patching it as part of your nix config.

          1. Muromec · · focus · HN ↗
            You still need to have somebody half competent to ask the electric shaitan to the thing and validate the result and also demonstrate this ability during the hiring process. I'm not sure it's easier than actually finding a person who can do those two lines.
            1. ndriscoll · · focus · HN ↗
              If you trust someone to manage IT policy in the first place I'd think they'd be smart enough to be able to learn the basics of Nix? Like 95%+ of it is just declaring obvious settings that are already in nixpkgs. In practice it's mostly an ini file, but with the power to do more if you need it.
            2. bigyabai · · focus · HN ↗
              Nix is declarative, the sum of work required to proliferate these updates is typing "git push" into your terminal.
              1. Muromec · · focus · HN ↗
                That's before it is introduced into the government or a bank. Those environment tend to turn every trivial thing into a multi year project.

                It takes three really nice and cleverly designed things that are all very easy to use separately. Then you put those things into the hands of smart, bored and slightly undercompensated people and divide those people into four separate departments so they don't ever talk with each other.

                Then you introduce a fourth thing into the mix, let it ferment for a while and make sure some people dealing with the first three leave the building and are replaced with total imbeciles who have no idea what they are doing and also never say no to any silly idea of their boss.

                Then you ask to change something. Anything really. And it for some magical reason unbeknown to anybody involved at this point takes a few years.

                1. ndriscoll · · focus · HN ↗
                  What does any of this have to do with Nix and how does using a more difficult to manage OS like Windows make it easier?
                  1. Muromec · · focus · HN ↗
                    Windows will not make it easier, but the institution choosing it, including all the people they hired on the market will have pre-existing and agreeing with each other beliefs of how much a shitshow this will be and will happily watch it happen paid by your taxeuros.
      2. sneak · · focus · HN ↗
        I’m not talking about software install/updates, that is easy and straightforward on every major enterprise distro. I’m talking about Group Policy specifically, that is, the ability to enforce many settings across the whole OS/DE.

        Minimum password lengths, maximum screen saver delay, screen saver password requirement, disk crypto enforcement, a million other little things. All of them can be done by customizing linux sure but organizations won’t want to maintain a separate distro for each business unit that needs different policies.

        1. ndriscoll · · focus · HN ↗
          Nix does more than software install/updates. It also manages system wide config (e.g. files in /etc, systemd units, timers/cron jobs, firewall, etc.) or even user preferences with home-manager. You can also organize your config into modules to have e.g. a base for everyone + special settings for different BUs that need it. And it does all this declaratively with the ability to rollback to previous working config if needed since it can handle multiple versions of packages all being present until you choose to garbage collect old generations of the system config (which you can also set to automate, of course).

          It's basically what people think they want from Docker but don't actually get from Docker.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.