Live data from Hacker News

Toolship: A more secure workstation

yann.pt

51–59 of 59 posts

Re: Toolship: A more secure workstation

#51

Interesting approach to maintaining a clean dev environment using containers. This approach reminds me of Fedora Silverblue[1] that I’ve been wanting to try. It leverages OSTree for atomic upgrades and rollbacks. Users can run containers for CLI utils using toolbox[2]. This way, the base OS remains pristine, and there's less risk of "dependency hell" or inadvertent “package upgrades gone wrong”. [1]: https://fedorapr…

I'm running silverblue but running my containers through distrobox. Both toolbox and distrobox are running on podman under the hood, so it's the same technology as far as I understand. However, distrobox has some interesting features relevant to this idea of development isolation. One is that it has an assemble feature[1] built-in. Where you can feed it a recipe file and it will build or rebuild containers accordingly. The other is that it allows setting a custom home directory for the container, among other host/container isolating options[2].

Perfomance wise my containers take a couple MB of rams and no perceptible CPU usage when not in use. At least as far as I can tell.

[1] https://github.com/89luca89/distrobox/blob/main/docs/usage/d...

[2] https://github.com/89luca89/distrobox/blob/main/docs/usage/d...

Re: Toolship: A more secure workstation

#52
post #50
post #49

Earlier quoted context omitted.

Proxmox can use a hypervisor, KVM, or manage containers. It's not a hypervisor. Xen is also hypervisor. Saying proxmox is a hypervisor is like saying virt-manager is a hypervisor.

You're just debating semantics, debatably incorreectly, and for no reason. KVM is not a type-2 hypervisor in this case - Proxmox can be hosted on bare metal and use KVM natively. > Saying proxmox is a hypervisor is like saying virt-manager is a hypervisor. This is... just wrong? Proxmox is much more equivalent to ESXi than to a UI application. -- To grante you the tiniest bit of good faith, I would wager that you and…

Just try it? Didn't want to have a pissing contest, but if you will.

I've have, since late 2000's and used it to deploy production deployments for eden.sahanafoundation.org in Haiti, Chengdu and other places, using Proxmox and KVM.

I've also built public and private clouds using OpenNebula and OpenStack (using KVM/libvirt). I'm also vmware certified (or was, back in late 2000's, when working for a prominent UK ISP).

It's a management framework, it doesn't do virtualisation itself, it uses the libvirt framework. I can use the same kvm hypervisor by using qemu-kvm (or virt-manager, which uses the same stuff). Again it's just a management layer.

Re: Toolship: A more secure workstation

#53
post #52
post #50

Earlier quoted context omitted.

You're just debating semantics, debatably incorreectly, and for no reason. KVM is not a type-2 hypervisor in this case - Proxmox can be hosted on bare metal and use KVM natively. > Saying proxmox is a hypervisor is like saying virt-manager is a hypervisor. This is... just wrong? Proxmox is much more equivalent to ESXi than to a UI application. -- To grante you the tiniest bit of good faith, I would wager that you and…

Just try it? Didn't want to have a pissing contest, but if you will. I've have, since late 2000's and used it to deploy production deployments for eden.sahanafoundation.org in Haiti, Chengdu and other places, using Proxmox and KVM. I've also built public and private clouds using OpenNebula and OpenStack (using KVM/libvirt). I'm also vmware certified (or was, back in late 2000's, when working for a prominent UK ISP).…

I’m matching your energy. Your original comment came in just to say “you’re wrong” as a weird, nitpicky contrarian - so I’m going to fight you on that.

You’re trying to make the distinction KVM is separate - I’m saying KVM is a part of Proxmox making them functionally one and the same.

If you want to be very precise - KVM is the hypervisor. It just so happens to also be a part of the kernel! And Proxmox can also be run on bare metal hardware meaning - it can deploy and manage VMs with access to direct hardware management. As I already gave a reference to - this seems to be a common point people hit disagreement on, like we are precisely having at this moment.

Your nitpick is a muddying of waters in an attempt to “be superior” (and attaching your LinkedIn is pretty odd).

If you’re to be consistent, you’d also be saying ESXi is not a hypervisor - you’d say only vmkernel is. On a tight technicality this might be true, but it’s such a nitpick that unless you’re actively debugging in that layer of the stack the distinction is worthless.

I don’t think you and I will see eye to eye. You are so hyper focused on nitpicking a tiny definition that I’m not willing to concede on.

Re: Toolship: A more secure workstation

#54
post #53
post #52

Earlier quoted context omitted.

Just try it? Didn't want to have a pissing contest, but if you will. I've have, since late 2000's and used it to deploy production deployments for eden.sahanafoundation.org in Haiti, Chengdu and other places, using Proxmox and KVM. I've also built public and private clouds using OpenNebula and OpenStack (using KVM/libvirt). I'm also vmware certified (or was, back in late 2000's, when working for a prominent UK ISP).…

I’m matching your energy. Your original comment came in just to say “you’re wrong” as a weird, nitpicky contrarian - so I’m going to fight you on that. You’re trying to make the distinction KVM is separate - I’m saying KVM is a part of Proxmox making them functionally one and the same. If you want to be very precise - KVM is the hypervisor. It just so happens to also be a part of the kernel! And Proxmox can also be r…

Proxmox doesn't do the virtualisation, that's KVM. That's the hypervisor. I'm not sure why you find this so difficult to understand.

You told me to, "Try It". I have. Many times, I told you about them and you despite that you think I'm attaching a linked in. I'm answering the thing you told me.

Not sure what 'energy' you're going on about, if you reread this you might realise you're the one being a bit obtuse.

You're also making up stuff I might potentially say, whilst also admitting I'm probably right, which says a lot about you imho. Maybe work from the things people say, not what you think they say in your head.

I hope you find inner peace, but for reference, proxmox is a management layer using libvirt, which interacts with the hypervisor, KVM. Jeez...

Re: Toolship: A more secure workstation

#55
post #54
post #53

Earlier quoted context omitted.

I’m matching your energy. Your original comment came in just to say “you’re wrong” as a weird, nitpicky contrarian - so I’m going to fight you on that. You’re trying to make the distinction KVM is separate - I’m saying KVM is a part of Proxmox making them functionally one and the same. If you want to be very precise - KVM is the hypervisor. It just so happens to also be a part of the kernel! And Proxmox can also be r…

Proxmox doesn't do the virtualisation, that's KVM. That's the hypervisor. I'm not sure why you find this so difficult to understand. You told me to, "Try It". I have. Many times, I told you about them and you despite that you think I'm attaching a linked in. I'm answering the thing you told me. Not sure what 'energy' you're going on about, if you reread this you might realise you're the one being a bit obtuse. You're…

> Proxmox doesn't do the virtualisation, that's KVM. That's the hypervisor.

Proxmox has KVM as part of its kernel. You're deliberately ignoring this fact. I've already expressly stated that KVM is the specific part that does the virtualization multiple times and you keep pretending I'm not.

> I'm not sure why you find this so difficult to understand.

I'm not?

> Not sure what 'energy' you're going on about, if you reread this you might realise you're the one being a bit obtuse.

You went out of your way to nitpick a comment I made about the differences in how Proxmox and Qubes OS are being used to say "you're wrong" about a detail that was not only irrelevant to the conversation.

Proxmox, ESXi, etc. are conventionally considered hypervisors.

> You're also making up stuff I might potentially say, whilst also admitting I'm probably right, which says a lot about you imho.

No, you don't know how to read. Let me take you back to first grade for a second.

What I said was that there is some dispute in over if KVM being a part of the kernel that helps constitute an OS makes the OS the hypervisor. I literally gave a reference to this distinction as well, and conceded that if you want to be very technically accurate, that KVM is the hypervisor.

What I'm saying is that KVM is a core part of Proxmox that enables it to function as a hypervisor, and you are going to deep ends to ensure everyone knows that my claim is 100% verifiably wrong even though it's semantics.

> Maybe work from the things people say, not what you think they say in your head.

Let's take a step back. I said:

"proxmox is more traditionally used as the hypervisor for distributed applications... (barring differences in Xen and *KVM*)"

to which you said:

"Proxmox isn't a hypervisor (last time I checked!), it's a management plane to different hypervisors."

In other words - "you're fucking wrong, it doesn't include a hypervisor at all". Which is:

a) Not what I said. I said it is used as the hypervisor. You’re not fucking installing Virtualbox on it. b) Intentionally ignoring the fact that I call out KVM in reference to it. What the hell? c) Inaccurate.

Let’s break it apart.

> it's a management plane to different hypervisors.

Source? I haven't seen any capability of Proxmox to integrate with Xen, vmkernel, Hyper-V, XCP-ng, etc.

It deeply integrates with KVM (which you seem to never address, as if accepting this fact is akin to Voldemort to you.

> It's a management framework, it doesn't do virtualisation itself, it uses the libvirt framework.

Not true. From a developer themselves: https://forum.proxmox.com/threads/how-hypervisors-like-proxm...

> I hope you find inner peace, but for reference, proxmox is a management layer using libvirt, which interacts with the hypervisor, KVM. Jeez...

Again, spreading lies.

I can do this all day with you. I don't think you're just wrong now, I think you're actively lying.

--

Or, you can stop being such a dick. I already gave you an out, which is that this specific topic is actively debated online - just like we are doing now. But instead, you went this route:

> whilst also admitting I'm probably right, which says a lot about you imho

So no, you're clearly a bad faith author. Imagine telling a VI Admin that ESXi is not the hypervisor.

Re: Toolship: A more secure workstation

#56
post #54
post #53

Earlier quoted context omitted.

I’m matching your energy. Your original comment came in just to say “you’re wrong” as a weird, nitpicky contrarian - so I’m going to fight you on that. You’re trying to make the distinction KVM is separate - I’m saying KVM is a part of Proxmox making them functionally one and the same. If you want to be very precise - KVM is the hypervisor. It just so happens to also be a part of the kernel! And Proxmox can also be r…

Proxmox doesn't do the virtualisation, that's KVM. That's the hypervisor. I'm not sure why you find this so difficult to understand. You told me to, "Try It". I have. Many times, I told you about them and you despite that you think I'm attaching a linked in. I'm answering the thing you told me. Not sure what 'energy' you're going on about, if you reread this you might realise you're the one being a bit obtuse. You're…

So, it's not a hypervisor, KVM is the hypervisor, it's a management plane using perl and qemu (fixed it for you, you're right, libvirt isn't used, my bad) to do the same thing libvirt does.

Glad we cleared up that it's not a hypervisor though, KVM is the hypervisor, whatever glue that sits between them (be it perl/qemu or libvirt). Promox is still not a hypervisor.

Re: Toolship: A more secure workstation

#57
post #56
post #54

Earlier quoted context omitted.

Proxmox doesn't do the virtualisation, that's KVM. That's the hypervisor. I'm not sure why you find this so difficult to understand. You told me to, "Try It". I have. Many times, I told you about them and you despite that you think I'm attaching a linked in. I'm answering the thing you told me. Not sure what 'energy' you're going on about, if you reread this you might realise you're the one being a bit obtuse. You're…

So, it's not a hypervisor, KVM is the hypervisor, it's a management plane using perl and qemu (fixed it for you, you're right, libvirt isn't used, my bad) to do the same thing libvirt does. Glad we cleared up that it's not a hypervisor though, KVM is the hypervisor, whatever glue that sits between them (be it perl/qemu or libvirt). Promox is still not a hypervisor.

> So, it's not a hypervisor

No. I disagree for reasons you refuse to respond to.

> KVM is the hypervisor

Yes I’ve said this since the beginning?

> qemu

Thanks for acknowledging you were a liar.

> Proxmox is still not a hypervisor.

I’ve already acknowledged why I see why you think this, because you want to strictly define the line at KVM. I, and many others, disagree with you.

In fact, general Google consensus also disagrees with you. Please, change https://en.m.wikipedia.org/wiki/Proxmox_Virtual_Environment and https://en.m.wikipedia.org/wiki/Hypervisor if this is the biggest hill you must die on.

Your weird pretense that Proxmox is not capable of deploying VMs is objectively wrong. How does it do it? Via KVM - an integral component of Proxmox.

Since you’re a brick wall who can’t see nuance, understand conventional definitions, or even give the slightest amount of understanding to another point of view, then there’s no reason to keep talking with you.

Re: Toolship: A more secure workstation

#58

The best answer to keeping your workstation clean & secure is, in my view, a thin-client paired with ephemeral remote environments: Immutable or chain-of-trust based host OS (e.g. nix or iOS) Minimal software installed (including docker, which itself is heavy and full of vulns or opens the door to them) Do everything on ephemeral remote environments where the configuration is stored in reviewable tools (e.g. GitHub)…

> The best answer to keeping your workstation clean & secure ...

> Immutable or chain-of-trust based host OS (e.g. nix or iOS)

Pegassus ?

Did you notice that Apple fixes vulnerabilities only after they are find by third parties ?

Re: Toolship: A more secure workstation

#59
I do this for years. but instead of docker I use LXD (even for GUI stuff). my base system is always clean and idempotent (chezmoi). all my clients look the same. laptop, desktop workstation, etc.

I even have a portable LXD environment which always looks the same, on a USB flash drive. wherever I go, I have the same environment.

Post reply on HN