‹ BackHN Continuity

Thread

Dutch governments builds alternative for Microsoft based on NixOS

1021 points · 583 comments · fjfaase

  1. sneak · · focus · HN ↗
    I’m really curious to see what the answer for MDM and Group Policy is on Linux. The SSO part is mostly figured out, but the reason places use Windows is often manageability.

    Is there anyone doing MDM or policy enforcement on Linux other than Google Workspace + chromebooks?

    1. ndriscoll · · focus · HN ↗
      It's Nix so you just push the new generation to the device. It's probably the easiest possible way to do device management. It's also generally like two lines of extra config to wrap a block into a container if you want to hide some of the underlying OS tools completely, which I've never tried with a full desktop environment but I'd assume should basically just work if you pass a couple things like GPU?
      1. Muromec · · focus · HN ↗
        The hard part is finding enough people working for the public sector salary who know those two extra lines and where to put them, and then making sure they are not getting bored or disillusioned enough.
        1. ndriscoll · · focus · HN ↗
          You don't need someone who knows those two lines anymore. You can just ask codex to make it so that users can't do whatever. It's highly competent at just reading the nixpkgs source, or it knows how Linux works and can write its own modules.

          Nix happens to also set you up with a working build environment so if a program doesn't expose the necessary options to manage it the way you want, I bet Codex would have no trouble patching it as part of your nix config.

          1. Muromec · · focus · HN ↗
            You still need to have somebody half competent to ask the electric shaitan to the thing and validate the result and also demonstrate this ability during the hiring process. I'm not sure it's easier than actually finding a person who can do those two lines.
            1. ndriscoll · · focus · HN ↗
              If you trust someone to manage IT policy in the first place I'd think they'd be smart enough to be able to learn the basics of Nix? Like 95%+ of it is just declaring obvious settings that are already in nixpkgs. In practice it's mostly an ini file, but with the power to do more if you need it.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.