Re: Server installation over the network

Anshuman Aggarwal <[email protected]> Thu, 13 Apr 2017 14:08:28 +0530
Newsgroups gmane.linux.distributions.gobo.general
Message-ID <CAK-d5dbeubo1vPa66+NCZcwmhc_d+bDzbr+kOTf3coMS7Sq9cQ@mail.gmail.com>
Lucas/Hisham,
 These are definitely valid points but maybe for the next release we
could think of making a start around making a server version of Gobo
available?

We can attract my kind of user who loves the idea of Gobo and has
tried their hand with Gobo as a desktop replacement.

But hardware compatibility/usability in desktops that they require or
are used to on a daily basis are too many to give up on over a
commercial distro like Ubuntu or even (gasp) a Mac like commercial OS.

A server version would be great for a SOHO (Small Office Home Office)
server (and we can publish disclaimers as required which are
understood in the linux world anyways, especially for smaller distros
like Gobo)

I see the following tasks primarily.
- Installer to allow a minimal/gui stripped down version (possibly
some sort of netbooting installer while we are at it and do the rest
as a network install (binary and/or source as is currently possible))
- Freshen to have a -security option (or a new program as required)
which updates security related packages (this will require an
Overseer)
- Individual Maintainer(s) for packages that have services that are
exposed to the internet (We can publish the list of packages for which
we are providing security updates?)
 Typically a start on this list of packages can be:
 - Kernel
 - Firewalls
 - OpenSSHD
 - Webservers?

Happy to volunteer to help with any or all of the above though not the
most informed for developing a new installer. But I can help maintain
the security updates packages which we will require.

Even a well funded distro like Ubuntu found the server/cloud space to
be a way to popularity and has given up on mobility/convergence.

Hope I have made a case here.

On 12 April 2017 at 21:05, Lucas C. Villa Real <[email protected]> wrote:
> On Wed, Apr 12, 2017 at 7:17 AM, Anshuman Aggarwal
> <[email protected]> wrote:
>>
>> On 12 April 2017 at 10:34, Hisham <[email protected]> wrote:
>> > On 12 April 2017 at 01:57, Anshuman Aggarwal
>> > <[email protected]> wrote:
>> >> On 10 April 2017 at 23:35, Lucas C. Villa Real <[email protected]>
>> >> wrote:
>> >>> On Mon, Apr 10, 2017 at 2:33 PM, Anshuman Aggarwal
>> >>> <[email protected]> wrote:
>> >>>>
>> >>>> I have started pruning the PackageNames.txt file for a server
>> >>>> install.
>> >>>> Can we split this file into a say ServerPackageNames.txt and append
>> >>>> the GUIPackageNames.txt and the ISO build script can be given an
>> >>>> option to make either one? This will allow us to keep server and gui
>> >>>> ISO builds around without double maintenance?
>> >>>>
>> >>>> Regards
>> >>>> Anshuman
>> >>>>
>> >>>
>> >>> To be fair, I wouldn't like to touch the installer right now. We're
>> >>> going to
>> >>> have a complete rewrite of it very soon, now that our abstraction
>> >>> toolkit
>> >>> (AbsTk) library has been ported to Lua. We'll likely want to go with a
>> >>> different approach to the installation of remote packages instead of
>> >>> the
>> >>> traditional "network install", too.
>> >>>
>> >>> Thanks,
>> >>> Lucas
>> >>>
>> >>
>> >> I suggest that the new installer have multiple installation options
>> >> for packages like minimal, server or at least GUI/No GUI
>> >> (headless/virtual vs desktop/laptop use cases).
>> >
>> > One very important reason we don't advertise Gobo as a server OS is
>> > because we do not publish security patches with the necessary speed
>> > required by a server OS running always-connected network services. I
>> > do not recommend running Gobo as a server, and as a matter of fact, as
>> > of 016.01, I recommend against it.
>> >
>> > If one wants to install it on a server one is free to do so, but one
>> > would have to track security updates for all installed packages by
>> > hand and that is really risky business.
>> >
>> > -- Hisham
>>
>> That is a very good point that got overlooked. Although in todays day
>> of high speed internet available on even desktop/laptops/mobiles they
>> are quite vulnerable but mostly they are behind a NAT router which
>> acts as a firewall.
>>
>> However if one has a good linux firewall (say shorewall) installed,
>> then only the linux kernel, the firewall and other open services need
>> to be kept up to date right? That may be doable for a SOHO server,
>> IMHO :-)
>>
>> If we are worried about an out of date application which is making an
>> outgoing connection then all the Gobo desktops would be vulnerable
>> (assuming you spend an 8 hour day working on it)?
>
>
> The difference is that our desktop machines won't be exposing services to
> the Internet (as opposed to a server). I usually bind services to the
> loopback interface only, something which is not possible when you need to
> enable remote access to them.
>
> Lucas
>
> _______________________________________________
> gobolinux-users mailing list
> [email protected]
> http://lists.gobolinux.org/mailman/listinfo/gobolinux-users
>
_______________________________________________
gobolinux-users mailing list
[email protected]
http://lists.gobolinux.org/mailman/listinfo/gobolinux-users