[HN Gopher] Writing a basic service for GNU Guix
       ___________________________________________________________________
        
       Writing a basic service for GNU Guix
        
       Author : hermitsings
       Score  : 87 points
       Date   : 2025-08-03 03:43 UTC (19 hours ago)
        
 (HTM) web link (tannerhoelzel.com)
 (TXT) w3m dump (tannerhoelzel.com)
        
       | einpoklum wrote:
       | Two notes from reading the first several paragraphs:
       | 
       | 1. It seems one needs to know some Scheme in order to write these
       | files:
       | 
       | https://www.scheme.org/
       | 
       | I don't think it's possible to just "wing it" by copy-and-paste.
       | 
       | 2. I did not understand the introductory paragraph about how
       | services "extend" each other. Does every service have hooks for
       | possible extensions? What if a new service doesn't fit existing
       | extension hooks?
       | 
       | (I can understand service dependencies of course, but it seems to
       | go beyond that.)
        
         | foretoldfeline wrote:
         | > Does every service have hooks for possible extensions? What
         | if a new service doesn't fit existing extension hooks?
         | 
         | No, only few services define service extensions.
         | 
         | It's more common for services to be configured solely via their
         | configuration struct.
         | 
         | See the following for docs:
         | 
         | * https://guix.gnu.org/manual/en/html_node/Service-
         | Composition...
         | 
         | * https://guix.gnu.org/manual/en/html_node/Service-Types-
         | and-S...
         | 
         | This is less flexible-by-default than NixOS module, where any
         | module can modify any other module. That is by design. The Guix
         | developers see NixOS's approach as failing the principle-of-
         | least-authority, where any arbitrary module (even those
         | imported via flakes) can add a root SSH key.
         | 
         | I use NixOS, but it's an interesting tradeoff.
        
       | rnhmjoj wrote:
       | Does GNU Shepherd support some form of sanboxing?
       | 
       | systemd has many options to reduce the privileges of a service:
       | like running as a normal user with only certain POSIX
       | capabilities, setting up a mount namespace with a limited view of
       | the root filesystem, locking down which system calls can be
       | invoked, etc.
        
         | davexunit wrote:
         | Shepherd doesn't include this as it is quite lean and
         | extensible (service start/stop hooks are functions that can do
         | anything) but Guix includes a Linux container implementation
         | and an abstraction built on top for use by services. The long
         | term vision is to use an object capability security model so,
         | rather than "locking down", a service can only interact with
         | the resources to which it has been passed a reference. No
         | ambient authority, no confused deputies.
        
           | jcgl wrote:
           | I really like systemd but am also Guix-curious. This
           | sandboxing topic has been a bit of a blocker for me to
           | properly go deeper with Guix. Do you know of any good places
           | to read more about this vision? Sounds powerful and unique.
        
             | foretoldfeline wrote:
             | https://fosdem.org/2025/schedule/event/fosdem-2025-5315-she
             | p...
        
         | foretoldfeline wrote:
         | GNU Shepherd itself doesn't implement sandboxing, but you can
         | use the least-authority-wrapper to do namespaces. There are
         | other tools to do more comphrensive sandboxing, which Shepherd
         | can use, e.g. nsjail.
         | 
         | least-authority-wrapper:
         | https://codeberg.org/guix/guix/src/commit/e3fbaeee1386fd447f...
        
           | lynx97 wrote:
           | Uoh, nsjail ha? The namespace for project names seems
           | exhausted. No germans on the dev team, ey?
        
             | foretoldfeline wrote:
             | https://github.com/google/nsjail
        
       | tempodox wrote:
       | From a quick glance, Guix seems to have a similar learning curve
       | as Nix (at least it's based on Scheme, which I know). Is that
       | impression correct? Anyway, I didn't find this "intuitively
       | comprehensible" as an outsider.
        
         | TheFuzzball wrote:
         | Correct, and it's Linux-only and more hardcore FOSS (i .e. they
         | don't have any blessed way to use non-free software).
         | 
         | I'm not sure why it's being sold as an alternative to Nix/NixOS
        
           | fsflover wrote:
           | Because it's an alternative which guarantees freedom?
        
             | Keyframe wrote:
             | just not freedom to use propriety software
        
               | davexunit wrote:
               | It's easy to use proprietary software with Guix and
               | nearly all users do this.
        
               | terminalbraid wrote:
               | Cool, I didn't realize I could use it on my Windows or
               | Mac machines. That's actually what's been holding me
               | back.
        
               | ZoomZoomZoom wrote:
               | Only Free Software guarantees that you have the final say
               | in a matter of using arbitrary proprietary software.
        
           | graemep wrote:
           | If you regard it as an alternative to NixOS rather than Nix
           | the package manager then both are Linux.
           | 
           | Some people want FOSS only, some people dislike systemd, some
           | people like Scheme....
        
         | grumbel wrote:
         | Guix is a reimagining of the concepts of Nix with Guile/Scheme
         | instead of the Nix language, so they are very similar in
         | overall feel, but differ in the details (e.g. GNU Shepherd vs
         | systemd).
         | 
         | As for learning curve, I find Nix substantially easier, since
         | the language is much simpler (JSON-like with lazy-functions)
         | and doesn't need all that weirdness that result from using
         | Scheme as configuration language (lots of quoting, module
         | system, etc.)
        
       | potato-peeler wrote:
       | For day to day use, what are the benefits for gnu guix? From it's
       | website, what I could understand is it provides installation of
       | different version of the same package, similar to rbenv or conda.
       | Apart from this, is there anything else that will be considered
       | useful over something like aptitude?
        
         | bheadmaster wrote:
         | Reproducibility, just like Nix.
         | 
         | You can be certain that, if you've managed to get a piece of
         | software running with Guix, you can also get it running
         | identically on any other machine.
        
           | amelius wrote:
           | Except if nvidia cards and embedded systems are involved.
           | Then whether you get it running is still a gamble.
        
       ___________________________________________________________________
       (page generated 2025-08-03 23:01 UTC)