Live data from Hacker News

Fermilab/CERN recommendation for Linux distribution

news.fnal.gov

131–140 of 144 posts

Re: Fermilab/CERN recommendation for Linux distribution

#131
post #101

Earlier quoted context omitted.

I don’t imagine SAP certification would extend to a community-supported fork of RHEL even if it was a 1:1 clone.

Many businesses will use the Forks for their dev environment.

Which is silly because Red Hat will literally give you free RHEL for non-prod if you pay for RHEL in prod.

https://developers.redhat.com/articles/2022/05/10/access-rhe...

Re: Fermilab/CERN recommendation for Linux distribution

#132
post #87

Earlier quoted context omitted.

Then you want Debian. We've had FAR less problems with Debians than anything from Red Hat stable

I've used a bunch of Linux distros over the years and always find myself installing Debian when I just want a desktop.

I’m currently on Ubuntu and have considered Debian. I like the concept of containerisation (snap, flatpack, etc) but the overly pushy snap integration has broken my workflows in multiple situations without much redemption so maybe I will give it a try.

Re: Fermilab/CERN recommendation for Linux distribution

#133

I went through the Rocks Cluster cycles in 3, 4, and 5 with SLC and Scientific until those fell by the wayside. Rocky is the underdog you want to win. Alma is the leader except in terms of security update latency. The problem is that Cent 8/9 Stream has quicker critical CVE patches because it's essentially the source and is closer to mirroring RHEL. It's hard to convince corporate folks to use Alma when Cent is still…

Apperantly stream is the slowest. https://news.ycombinator.com/item?id=33905616

Not exactly. For most CVEs, CentOS Stream gets them months before RHEL and RHEL clones. But CVEs rated important/critical (or otherwise embargoed) are required to go out to RHEL customers first. Once the fix is live for RHEL customers, two things happen more or less simultaneously:

- The RHEL package source with the fix is published, allowing clone distros to start their rebuild work. - RHEL maintainer starts working on the fix for CentOS Stream in public. This may or may not be the same patch as what was released in RHEL, depending on whatever other changes have already happened in CentOS Stream.

These tasks are not the same and take different amounts of time. On top of that, the release pipelines to get the fix out to users are different between the various distros. Sometimes the fix is live for CentOS Stream before the rebuilds, sometimes after. There were some notably slower exceptions with CentOS Stream 8 in the early days, because CentOS Stream 8 is built "inside out".

https://twitter.com/carlwgeorge/status/1439724296742576130

In CentOS Stream 9 going forward, RHEL maintainers own their CentOS builds and things are working much better. There is work in progress to migrate 8 workflows to match 9.

Re: Fermilab/CERN recommendation for Linux distribution

#134

All this time I had thought that Rocky Linux was winning the fork war over Alma (in the fight to be the successor to CentOS), but this post might change that with a good chunk of the science community throwing their weight behind Alma. Do we have anyone else in the audience that has any insights over whether Alma is more prevalent over Rocky or is it the other way around? I know I can run Rocky Linux from DigitalOcea…

Rocky is "winning" if by "winning" you mean more widely used. Here are some graphs charting usage through EPEL statistics: https://rocky-stats.tiuxo.com . The source used to generate the graphs is available at https://github.com/brianclemens/rocky-stats , however please be kind to the Fedora servers and don't download the stats database too often if you use it. Also Rocky Linux is far larger in terms of community siz…

Also note that genuine RHEL users generally don't want to use EPEL that is out of support.

> The EPEL repository is used by a significant portion of Enterprise Linux users. The data they share are unbiased, and it is reasonable to assume approximately equal proportions of users of each Enterprise Linux distribution use the EPEL repository.

From the article but I disagree.

Re: Fermilab/CERN recommendation for Linux distribution

#135

Earlier quoted context omitted.

I've used a bunch of Linux distros over the years and always find myself installing Debian when I just want a desktop.

I’m currently on Ubuntu and have considered Debian. I like the concept of containerisation (snap, flatpack, etc) but the overly pushy snap integration has broken my workflows in multiple situations without much redemption so maybe I will give it a try.

If you want "just desktop" like grandparent, you can try https://linuxmint.com/, it's downstream from Ubuntu LTS, but with bad stuff (snap) removed: https://linuxmint-user-guide.readthedocs.io/en/latest/snap.h...

Re: Fermilab/CERN recommendation for Linux distribution

#136

Earlier quoted context omitted.

I’m currently on Ubuntu and have considered Debian. I like the concept of containerisation (snap, flatpack, etc) but the overly pushy snap integration has broken my workflows in multiple situations without much redemption so maybe I will give it a try.

If you want "just desktop" like grandparent, you can try https://linuxmint.com/ , it's downstream from Ubuntu LTS, but with bad stuff (snap) removed: https://linuxmint-user-guide.readthedocs.io/en/latest/snap.h...

Yeah I’m all for those distros, but as I work in security industry i kind of feel like a ‘nobody ever got fired for buying an ibm approach’ is good.

If I’m hacked it’s not a good look at all, if im hacked and use an esoteric distro like gentoo, it would certainly look much, much worse. My key pain point is trust within repos, Ubuntu audit their repos as best they can (sast/sanity check) so at least there’s some security there.

Im otherwise very supportive of mint/arch/gentoo and similar systems.

Re: Fermilab/CERN recommendation for Linux distribution

#137

Earlier quoted context omitted.

Rocky is "winning" if by "winning" you mean more widely used. Here are some graphs charting usage through EPEL statistics: https://rocky-stats.tiuxo.com . The source used to generate the graphs is available at https://github.com/brianclemens/rocky-stats , however please be kind to the Fedora servers and don't download the stats database too often if you use it. Also Rocky Linux is far larger in terms of community siz…

Also note that genuine RHEL users generally don't want to use EPEL that is out of support. > The EPEL repository is used by a significant portion of Enterprise Linux users. The data they share are unbiased, and it is reasonable to assume approximately equal proportions of users of each Enterprise Linux distribution use the EPEL repository. From the article but I disagree.

While it's true that a good number of RHEL users don't use EPEL due to the lack of vendor escalation, there are many that do use it. In fact, they tell Red Hat that specific EPEL packages being available in the next version of EPEL block them from migrating to the next major version of RHEL. The feedback finally got loud enough that Red Hat decided to provide headcount to the Community Platform Engineering (CPE) group to create an EPEL team focused on improving EPEL (this is my team at work).

https://communityblog.fedoraproject.org/cpe-to-staff-epel-wo...

That said, the "vendor escalate-able only" group is large enough that RHEL is significantly underrepresented in EPEL stats. My guess is that somewhere around 40-60% of RHEL customers use EPEL. For RHEL rebuilds, I would guess that it's probably in the high 90% range, so their numbers in EPEL countme stats are probably fairly accurate. CentOS Stream on the other hand is also underrepresented, as we have countme data for both EPEL 9 and CentOS Stream 9, which shows there are over twice as many instances without EPEL as instances with EPEL.

Keep in mind that the countme data only includes systems connecting directly to Fedora's MirrorManager. Sites that run their own local mirrors are not included. We will never have a complete picture of popularity between these distros. For example, Facebook runs "millions" (a direct quote from their engineers' conference talks, they don't publish exact numbers) of CentOS Stream instances, which is more than everything else in the EPEL countme metrics combined.

Re: Fermilab/CERN recommendation for Linux distribution

#138

Earlier quoted context omitted.

Also note that genuine RHEL users generally don't want to use EPEL that is out of support. > The EPEL repository is used by a significant portion of Enterprise Linux users. The data they share are unbiased, and it is reasonable to assume approximately equal proportions of users of each Enterprise Linux distribution use the EPEL repository. From the article but I disagree.

While it's true that a good number of RHEL users don't use EPEL due to the lack of vendor escalation, there are many that do use it. In fact, they tell Red Hat that specific EPEL packages being available in the next version of EPEL block them from migrating to the next major version of RHEL. The feedback finally got loud enough that Red Hat decided to provide headcount to the Community Platform Engineering (CPE) grou…

Thank you for your number about how much RHEL+EPEL used. I work for old company (with RHEL local mirror) so not sure about whole real usage.

Re: Fermilab/CERN recommendation for Linux distribution

#139
post #11

Earlier quoted context omitted.

I have insights. Alma is done by professionals for professionals (the hosting industry). Those guys were behind CentOS, and are running 70% of the internet. Rocky is an unpaid community effort.

No. Alma Linux is done by CloudLinux, and still uses their infrastructure, secure boot certificate, etc (according to their page at https://web.archive.org/web/20221208102246/https://wiki.alma... ). They have never had anything to do with CentOS. Rocky Linux _is_ community oriented, and _is not_ beholden to a specific company, but it is not necessarily unpaid. The majority of the most active contributors to the proje…

Should be noted that AlmaLinux is a registered non-profit, whereas RockyLinux has not done such a thing and has bylaws that leave open the opportunity of being bought out by a for-profit

From RockyLinux:

> The Foundation is here for the benefit of the public community. We are a self imposed not-for-profit organization[^1] and thus we will never be driven, motivated, or manipulated by profit or monetary gain.

> [1]: This means the Foundation is a Delaware Public Benefit Corporation, with the objectives set forth in this Charter and the Foundation Bylaws. We do not have an objective to make money for shareholders. As of the time of this writing, the Foundation is NOT a 501(c)* US tax-exempt organization.

Also, AlmaLinux has its own infrastructure. It's not using CloudLinux infrastructure.

Re: Fermilab/CERN recommendation for Linux distribution

#140
post #11

Earlier quoted context omitted.

I have insights. Alma is done by professionals for professionals (the hosting industry). Those guys were behind CentOS, and are running 70% of the internet. Rocky is an unpaid community effort.

No. Alma Linux is done by CloudLinux, and still uses their infrastructure, secure boot certificate, etc (according to their page at https://web.archive.org/web/20221208102246/https://wiki.alma... ). They have never had anything to do with CentOS. Rocky Linux _is_ community oriented, and _is not_ beholden to a specific company, but it is not necessarily unpaid. The majority of the most active contributors to the proje…

Cloudlinux was the cPanel partner who provided their CentOS updates and support. They (Igor) were the ones who kept CentOS alive previously.

As nice as RockyLinux is, they can never compete with the dedicated support of the commercial partners from the hosting industry. See what they did: https://almalinux.org/blog/looking-back-leaping-forward-a-lo...

Post reply on HN