What are your ‘defaults’ for your desktop Linux installations, especially when they deviate from your distros defaults? What are your reasons for this deviations?

To give you an example what I am asking for, here is my list with reasons (funnily enough, using these settings on Debian, which are AFAIK the defaults for Fedora):

  • Btrfs: I use Btrfs for transparent compression which is a game changer for my use cases and using it w/o Raid I had never trouble with corrupt data on power failures, compared to ext4.

  • ZRAM: I wrote about it somewhere else, but ZRAM transformed even my totally under-powered HP Stream 11" with 4GB Ram into a usable machine. Nowadays I don’t have swap partitions anymore and use ZRAM everywhere and it just works ™.

  • ufw: I cannot fathom why firewalls with all ports but ssh closed by default are not the default. Especially on Debian, where unconfigured services are started by default after installation, it does not make sense to me.

My next project is to slim down my Gnome desktop installation, but I guess this is quite common in the Debian community.

Before you ask: Why not Fedora? - I love Fedora, but I need something stable for work, and Fedoras recent kernels brake virtual machines for me.

Edit: Forgot to mention ufw

  • sntx@lemm.ee
    link
    fedilink
    arrow-up
    14
    ·
    edit-2
    1 year ago
    • NixOS
      • disko + nixos-anywhere (automatic partitioning & remote installation of new systems)
      • stylix (system-wide theming)
      • agenix (secret management)
      • impermanence (managing persistent data)
      • nixos containers for sandboxing applications & services (using systemd-nspawn)
    • TMPFS as /
    • LUKS
      • BTRFS as /nix (might try bcachefs)
      • SWAP partition (= RAM size, to susbend to disk)
    • Greetd with TUIgreet (DM)
    • SwayFX (WM)
    • Kitty & foot (term)
    • Nushell (shell)
    • Helix (editor)
    • Firefox (browser)
    • slackhq/nebula (c.f. self-hosted tailscale, connecting my systems beyond double NATs)

    EDIT1: fix “DE” -> “DM”

    • Lupec@lemm.ee
      link
      fedilink
      arrow-up
      3
      ·
      1 year ago

      Now that’s quite an interesting NixOS setup, I’m especially intrigued by the tmpfs root portion. The link you provided was a great read, and I’ll keep this and honestly most of what you’ve described in mind for when I mess with NixOS again.

      • sntx@lemm.ee
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        There are also these two blog posts by elis on setting up tmpfs specifically. Though these posts rather are setup guides, than “talking about the philosophy” of systems design.

    • KillSwitch10@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      1 year ago

      This is a very interesting setup would you mind providing more explanation / documentation? Also would you mind sharing your nixOS config? I would love to try it.

      • sntx@lemm.ee
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        My system configuration can be found on git.sr.ht/~sntx/flake. I’ve linked the file tree pinned to the version 0.1.1 of my config, since I’m currrently restructuring the entire config[1] as the current tree is non-optimal[2].

        The documentation in the README in combination with the files should cover most of what I’ve described, with the following exception: disko is not present to the repo yet, since I’ve set it up with a forked version of my config and the merge depends on finishing the restructuring of my system configuration.

        • You can take a look at these (non-declarative) installation steps to get an idea on how TMPFS as root can be setup
        • If you’re interested, I can also DM you the disko expression for it

        1. The goal is to provide definitions for desktops, user-packages, system-packages, themes and users. Each system can then enable a set of users, which in turn have their own desktop, user-packages and theme. A system can also enable system-packages for itself, independent of users. If a user is enabled that has a desktop set, the system will need to have display-manager set as well, which should launch the users configured desktop. ↩︎

        2. The current config assumes a primary user, and can only configure a single DE and apply the application/service configs only to that user. ↩︎

        • KillSwitch10@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          1 year ago

          This looks like a whole project. What is the overall goal of this build?

          I am very new to nixOS and am interested in it. Specifically for ansible scripts to build out easily replicateable docker hosts for lab. I have also considered it for switching my primary desktop and laptops as being able to have the same OS with everything the way I like it is also intriguing.

          Sorry for theate response. P.S. I love your wallpaper.

          • sntx@lemm.ee
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 year ago

            What is the overall goal of this build?

            There’s no overall goal to the project. It’s just the result of me tinkering with my systems from time to time (I’m allocating a bit less than three hours each day to coding on personal projects to improve my skills, some of that time flows into my nixos config).


            I am very new to nixOS and am interested in it. Specifically for ansible scripts to build out easily replicateable docker hosts for lab.

            I’ve extensively used docker/compose before I switched my systems to NixOS, since then I’ve barely touched it.

            The thing with Ansible and Docker is that you mostly define the steps you want your systems to automatically go through to reach a specific state.

            Nix[1] approaches the problem the other way around. You define the state you want to have, and Nix solves for the steps that need to be taken to reach that state.

            If you want to try your hands at that concept, I recommend installing just Nix on one of your test machines and trying out development shells/devshells with it.

            For example the SwayFX repo contains a flake.nix providing a devShell. This allows everyone working on the project to just run nix develop in the cloned repo, or nix develop github:WillPower3309/swayfx without cloning the repo to enter the development environment.

            This can be combined with tools like direnv to automatically setup development environments, based on the current directory.

            If you want a more encompassing example of what Nix can provide, take a look at:

            • nixified.ai
            • This presentation by Matthew Croughan on Nix-Flakes and Dockerfiles.

            I have also considered it for switching my primary desktop and laptops as being able to have the same OS with everything the way I like it is also intriguing.

            While I personally think NixOS is one of the most potent software in existence, and a computer without feels less capable for me, I do not recommend it easily.

            Just take a look at hlissner’s FAQ on his system config (which I greatly agree with).

            That said, I initially tried NixOS on my PC and pushed the config to a git-forge. I then installed the base NixOS ISO on my laptop and told it to build the config from git. And that worked flawlessly.

            In leaving the PC unattended for about 20mins, it went from a full Gnome desktop to my Sway setup.

            That’s the point when I was sold.


            Sorry for theate response. P.S. I love your wallpaper.

            Don’t worry about the late reponse ^^

            The wallpaper can be build with nix build sourcehut:~sntx/nix-bg#abstract-liquid btw.


            1. The “package manager” that NixOS is build around. Though I think of it more as a “build system” - not to be confused with Nix, the language the build “scripts” are written in. ↩︎

            • PipedLinkBot@feddit.rocksB
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 year ago

              Here is an alternative Piped link(s):

              This

              Piped is a privacy-respecting open-source alternative frontend to YouTube.

              I’m open-source; check me out at GitHub.

            • KillSwitch10@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              edit-2
              1 year ago

              Humm good points in the articles. I think my goal of building docker hosts makes more sense. It is interesting how the took the declarative concepts of something like terraform and kubernetes and built it into an OS. It’s kind of like fedora silverblue but the two took different approaches. Perhaps fedora makes more sense on a desktop. I have a dev and DevOps background and like the idea of being able to more deeply learn Linux without having to rebuild my system from scratch when I bust it.

              Can you explain home manager? What about things to consider when installing NIX package manager on another distro?

              Perhaps figuring out how to get the wallpaper out of a nix distrobox would be a good learning experience.