[HN Gopher] Writing a basic service for GNU Guix
___________________________________________________________________
Writing a basic service for GNU Guix
Author : hermitsings
Score : 87 points
Date : 2025-08-03 03:43 UTC (19 hours ago)
(HTM) web link (tannerhoelzel.com)
(TXT) w3m dump (tannerhoelzel.com)
| einpoklum wrote:
| Two notes from reading the first several paragraphs:
|
| 1. It seems one needs to know some Scheme in order to write these
| files:
|
| https://www.scheme.org/
|
| I don't think it's possible to just "wing it" by copy-and-paste.
|
| 2. I did not understand the introductory paragraph about how
| services "extend" each other. Does every service have hooks for
| possible extensions? What if a new service doesn't fit existing
| extension hooks?
|
| (I can understand service dependencies of course, but it seems to
| go beyond that.)
| foretoldfeline wrote:
| > Does every service have hooks for possible extensions? What
| if a new service doesn't fit existing extension hooks?
|
| No, only few services define service extensions.
|
| It's more common for services to be configured solely via their
| configuration struct.
|
| See the following for docs:
|
| * https://guix.gnu.org/manual/en/html_node/Service-
| Composition...
|
| * https://guix.gnu.org/manual/en/html_node/Service-Types-
| and-S...
|
| This is less flexible-by-default than NixOS module, where any
| module can modify any other module. That is by design. The Guix
| developers see NixOS's approach as failing the principle-of-
| least-authority, where any arbitrary module (even those
| imported via flakes) can add a root SSH key.
|
| I use NixOS, but it's an interesting tradeoff.
| rnhmjoj wrote:
| Does GNU Shepherd support some form of sanboxing?
|
| systemd has many options to reduce the privileges of a service:
| like running as a normal user with only certain POSIX
| capabilities, setting up a mount namespace with a limited view of
| the root filesystem, locking down which system calls can be
| invoked, etc.
| davexunit wrote:
| Shepherd doesn't include this as it is quite lean and
| extensible (service start/stop hooks are functions that can do
| anything) but Guix includes a Linux container implementation
| and an abstraction built on top for use by services. The long
| term vision is to use an object capability security model so,
| rather than "locking down", a service can only interact with
| the resources to which it has been passed a reference. No
| ambient authority, no confused deputies.
| jcgl wrote:
| I really like systemd but am also Guix-curious. This
| sandboxing topic has been a bit of a blocker for me to
| properly go deeper with Guix. Do you know of any good places
| to read more about this vision? Sounds powerful and unique.
| foretoldfeline wrote:
| https://fosdem.org/2025/schedule/event/fosdem-2025-5315-she
| p...
| foretoldfeline wrote:
| GNU Shepherd itself doesn't implement sandboxing, but you can
| use the least-authority-wrapper to do namespaces. There are
| other tools to do more comphrensive sandboxing, which Shepherd
| can use, e.g. nsjail.
|
| least-authority-wrapper:
| https://codeberg.org/guix/guix/src/commit/e3fbaeee1386fd447f...
| lynx97 wrote:
| Uoh, nsjail ha? The namespace for project names seems
| exhausted. No germans on the dev team, ey?
| foretoldfeline wrote:
| https://github.com/google/nsjail
| tempodox wrote:
| From a quick glance, Guix seems to have a similar learning curve
| as Nix (at least it's based on Scheme, which I know). Is that
| impression correct? Anyway, I didn't find this "intuitively
| comprehensible" as an outsider.
| TheFuzzball wrote:
| Correct, and it's Linux-only and more hardcore FOSS (i .e. they
| don't have any blessed way to use non-free software).
|
| I'm not sure why it's being sold as an alternative to Nix/NixOS
| fsflover wrote:
| Because it's an alternative which guarantees freedom?
| Keyframe wrote:
| just not freedom to use propriety software
| davexunit wrote:
| It's easy to use proprietary software with Guix and
| nearly all users do this.
| terminalbraid wrote:
| Cool, I didn't realize I could use it on my Windows or
| Mac machines. That's actually what's been holding me
| back.
| ZoomZoomZoom wrote:
| Only Free Software guarantees that you have the final say
| in a matter of using arbitrary proprietary software.
| graemep wrote:
| If you regard it as an alternative to NixOS rather than Nix
| the package manager then both are Linux.
|
| Some people want FOSS only, some people dislike systemd, some
| people like Scheme....
| grumbel wrote:
| Guix is a reimagining of the concepts of Nix with Guile/Scheme
| instead of the Nix language, so they are very similar in
| overall feel, but differ in the details (e.g. GNU Shepherd vs
| systemd).
|
| As for learning curve, I find Nix substantially easier, since
| the language is much simpler (JSON-like with lazy-functions)
| and doesn't need all that weirdness that result from using
| Scheme as configuration language (lots of quoting, module
| system, etc.)
| potato-peeler wrote:
| For day to day use, what are the benefits for gnu guix? From it's
| website, what I could understand is it provides installation of
| different version of the same package, similar to rbenv or conda.
| Apart from this, is there anything else that will be considered
| useful over something like aptitude?
| bheadmaster wrote:
| Reproducibility, just like Nix.
|
| You can be certain that, if you've managed to get a piece of
| software running with Guix, you can also get it running
| identically on any other machine.
| amelius wrote:
| Except if nvidia cards and embedded systems are involved.
| Then whether you get it running is still a gamble.
___________________________________________________________________
(page generated 2025-08-03 23:01 UTC)