upvote
I love NixOS and use it on my work and home machines, but I balk at seriously suggesting anyone pick that as their first choice for a stable Linux distro to move to. It's filled with sharp edges, and more to the point, the project leadership and governance seems mired in drama constantly. Not a system I would feel comfortable suggesting any org should adopt without a lot of consideration, especially if stability and long-term planning are important.
reply
If it’s good enough for the Dutch and French governments to be adopting, it’s good enough for some, but not yet all, corporate orgs (I argue). Sharp edges will get ground down over time. Migration decisions have inertia that is measured in half decades.
reply
The French government did not adopt it, it's a 250 users POC.
reply
Governments always make such good, long term, well thought through technology decisions. For sure their decisions are great ones to adopt. /sarcasm
reply
It's not just a distro. RedHat used to host quite a bit of free software projects. The mailing lists that used to be now just bounce. Sourceware has been abandoned for GitLab. But I'm not sure if everything else has succesfully migrated away. It would've meant something really good if IBM would just continue to provide services for free software, but I'm not seeing them do that so I guess that means pretty much the exact opposite.
reply
I'll stick with Fedora and RHEL.

From what I can tell NixOS still has no support for AppArmor or SELinux.

reply
I'll wait until AI has translated all the nix scripts to a more user friendly language, thank you.
reply
You can just use AI to configure Nix. The “user friendly language” is English (or whatever natural language you want to use.)
reply
Last time I evaluated NixOS (Mar 2021) the project didn't care a whit about desktop security. Has that changed?

Fedora at least tries relatively consistently—and has been for decades.

reply
What exactly do you mean by desktop security? Security from websites, installable software, physical access?
reply
> Security from websites, installable software, physical access?

All those would be important, but don't let the perfect be the enemy of the good. We could start from the Vulnerability Of The Year: supply chain attacks.

reply
Being able to visit a web page, open a PDF or download and inspect a git repo without the web page, PDF or git repo's being able to completely pwn the entire machine including the bootloader and the firmware for all the hardware subsystems.

Desktop Linux is very bad at that compared to ChromeOS and MacOS, but some distros are much better than others. For a few decades now, Fedora has been one of the better ones.

reply
[dead]
reply