▲ 188 ▼ Moving away from RHEL based distros, whats good ? (lemmy.ml) submitted 3 years ago by bzImage@lemmy.ml to c/linux@lemmy.ml 213 comments fedilink hide all child comments Hi, mostly i use REHL based distros like Centos/Rocky/Oracle for the solutions i develop but it seems its time to leave.. What good server/minimal distro you use ? Will start to test Debian stable.
[–] blackstrat@lemmy.fwgx.uk 10 points 3 years ago (1 child) Can't really go wrong with Debian or Ubuntu server LTS permalink fedilink source hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 16 points 3 years ago (1 child) You can definitely go wrong with an Ubuntu server permalink fedilink source parent hideshow 2 child comments replies: [–] blackstrat@lemmy.fwgx.uk 6 points 3 years ago (1 child) How? I've run several for years with no issue. They're as stable as a rock permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 3 points 3 years ago (2 children) snaps are pretty insecure. permalink fedilink source parent hideshow 4 child comments replies: [–] sneakyninjapants@sh.itjust.works 8 points 3 years ago (1 child) Snaps are pretty terrible IMO, so I usually end up bootstrapping a custom Ubuntu image without snap for this reason (and others) for my cloud images. Definitely not general purpose though. permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 1 point 3 years ago (1 child) Why not just use Mint, which strips snap outfor you? permalink fedilink source parent hideshow 2 child comments replies: [–] sneakyninjapants@sh.itjust.works 1 point 3 years ago Mint doesn't build cloud images as far as I'm aware. permalink fedilink source parent [–] blackstrat@lemmy.fwgx.uk 5 points 3 years ago (1 child) *citation needed permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 12 points 3 years ago* Go to the snap site and try to find a security section that describes how snap packages are signed. You won't be able to find it because it doesn't exist, and they don't highlight their own security vulnerabilities. What I can cite is how this should work, for example how apt signs all packages by default https://wiki.debian.org/SecureApt Note how in the above doc there's a message WARNING: The following packages cannot be authenticated! ... Install these packages without verification [y/N]? That doesn't exist in snap because snap does not authenticate downloads. It'll just happily install something maliciously modified. permalink fedilink source parent
[–] itchy_lizard@feddit.it 16 points 3 years ago (1 child) You can definitely go wrong with an Ubuntu server permalink fedilink source parent hideshow 2 child comments replies: [–] blackstrat@lemmy.fwgx.uk 6 points 3 years ago (1 child) How? I've run several for years with no issue. They're as stable as a rock permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 3 points 3 years ago (2 children) snaps are pretty insecure. permalink fedilink source parent hideshow 4 child comments replies: [–] sneakyninjapants@sh.itjust.works 8 points 3 years ago (1 child) Snaps are pretty terrible IMO, so I usually end up bootstrapping a custom Ubuntu image without snap for this reason (and others) for my cloud images. Definitely not general purpose though. permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 1 point 3 years ago (1 child) Why not just use Mint, which strips snap outfor you? permalink fedilink source parent hideshow 2 child comments replies: [–] sneakyninjapants@sh.itjust.works 1 point 3 years ago Mint doesn't build cloud images as far as I'm aware. permalink fedilink source parent [–] blackstrat@lemmy.fwgx.uk 5 points 3 years ago (1 child) *citation needed permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 12 points 3 years ago* Go to the snap site and try to find a security section that describes how snap packages are signed. You won't be able to find it because it doesn't exist, and they don't highlight their own security vulnerabilities. What I can cite is how this should work, for example how apt signs all packages by default https://wiki.debian.org/SecureApt Note how in the above doc there's a message WARNING: The following packages cannot be authenticated! ... Install these packages without verification [y/N]? That doesn't exist in snap because snap does not authenticate downloads. It'll just happily install something maliciously modified. permalink fedilink source parent
[–] blackstrat@lemmy.fwgx.uk 6 points 3 years ago (1 child) How? I've run several for years with no issue. They're as stable as a rock permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 3 points 3 years ago (2 children) snaps are pretty insecure. permalink fedilink source parent hideshow 4 child comments replies: [–] sneakyninjapants@sh.itjust.works 8 points 3 years ago (1 child) Snaps are pretty terrible IMO, so I usually end up bootstrapping a custom Ubuntu image without snap for this reason (and others) for my cloud images. Definitely not general purpose though. permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 1 point 3 years ago (1 child) Why not just use Mint, which strips snap outfor you? permalink fedilink source parent hideshow 2 child comments replies: [–] sneakyninjapants@sh.itjust.works 1 point 3 years ago Mint doesn't build cloud images as far as I'm aware. permalink fedilink source parent [–] blackstrat@lemmy.fwgx.uk 5 points 3 years ago (1 child) *citation needed permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 12 points 3 years ago* Go to the snap site and try to find a security section that describes how snap packages are signed. You won't be able to find it because it doesn't exist, and they don't highlight their own security vulnerabilities. What I can cite is how this should work, for example how apt signs all packages by default https://wiki.debian.org/SecureApt Note how in the above doc there's a message WARNING: The following packages cannot be authenticated! ... Install these packages without verification [y/N]? That doesn't exist in snap because snap does not authenticate downloads. It'll just happily install something maliciously modified. permalink fedilink source parent
[–] itchy_lizard@feddit.it 3 points 3 years ago (2 children) snaps are pretty insecure. permalink fedilink source parent hideshow 4 child comments replies: [–] sneakyninjapants@sh.itjust.works 8 points 3 years ago (1 child) Snaps are pretty terrible IMO, so I usually end up bootstrapping a custom Ubuntu image without snap for this reason (and others) for my cloud images. Definitely not general purpose though. permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 1 point 3 years ago (1 child) Why not just use Mint, which strips snap outfor you? permalink fedilink source parent hideshow 2 child comments replies: [–] sneakyninjapants@sh.itjust.works 1 point 3 years ago Mint doesn't build cloud images as far as I'm aware. permalink fedilink source parent [–] blackstrat@lemmy.fwgx.uk 5 points 3 years ago (1 child) *citation needed permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 12 points 3 years ago* Go to the snap site and try to find a security section that describes how snap packages are signed. You won't be able to find it because it doesn't exist, and they don't highlight their own security vulnerabilities. What I can cite is how this should work, for example how apt signs all packages by default https://wiki.debian.org/SecureApt Note how in the above doc there's a message WARNING: The following packages cannot be authenticated! ... Install these packages without verification [y/N]? That doesn't exist in snap because snap does not authenticate downloads. It'll just happily install something maliciously modified. permalink fedilink source parent
[–] sneakyninjapants@sh.itjust.works 8 points 3 years ago (1 child) Snaps are pretty terrible IMO, so I usually end up bootstrapping a custom Ubuntu image without snap for this reason (and others) for my cloud images. Definitely not general purpose though. permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 1 point 3 years ago (1 child) Why not just use Mint, which strips snap outfor you? permalink fedilink source parent hideshow 2 child comments replies: [–] sneakyninjapants@sh.itjust.works 1 point 3 years ago Mint doesn't build cloud images as far as I'm aware. permalink fedilink source parent
[–] itchy_lizard@feddit.it 1 point 3 years ago (1 child) Why not just use Mint, which strips snap outfor you? permalink fedilink source parent hideshow 2 child comments replies: [–] sneakyninjapants@sh.itjust.works 1 point 3 years ago Mint doesn't build cloud images as far as I'm aware. permalink fedilink source parent
[–] sneakyninjapants@sh.itjust.works 1 point 3 years ago Mint doesn't build cloud images as far as I'm aware. permalink fedilink source parent
[–] blackstrat@lemmy.fwgx.uk 5 points 3 years ago (1 child) *citation needed permalink fedilink source parent hideshow 2 child comments replies: [–] itchy_lizard@feddit.it 12 points 3 years ago* Go to the snap site and try to find a security section that describes how snap packages are signed. You won't be able to find it because it doesn't exist, and they don't highlight their own security vulnerabilities. What I can cite is how this should work, for example how apt signs all packages by default https://wiki.debian.org/SecureApt Note how in the above doc there's a message WARNING: The following packages cannot be authenticated! ... Install these packages without verification [y/N]? That doesn't exist in snap because snap does not authenticate downloads. It'll just happily install something maliciously modified. permalink fedilink source parent
[–] itchy_lizard@feddit.it 12 points 3 years ago* Go to the snap site and try to find a security section that describes how snap packages are signed. You won't be able to find it because it doesn't exist, and they don't highlight their own security vulnerabilities. What I can cite is how this should work, for example how apt signs all packages by default https://wiki.debian.org/SecureApt Note how in the above doc there's a message WARNING: The following packages cannot be authenticated! ... Install these packages without verification [y/N]? That doesn't exist in snap because snap does not authenticate downloads. It'll just happily install something maliciously modified. permalink fedilink source parent