Re: Server installation over the network
Anshuman Aggarwal <[email protected]> Thu, 13 Apr 2017 14:08:28 +0530
| Newsgroups | gmane.linux.distributions.gobo.general |
|---|---|
| Message-ID | <CAK-d5dbeubo1vPa66+NCZcwmhc_d+bDzbr+kOTf3coMS7Sq9cQ@mail.gmail.com> |
Lucas/Hisham, These are definitely valid points but maybe for the next release we could think of making a start around making a server version of Gobo available? We can attract my kind of user who loves the idea of Gobo and has tried their hand with Gobo as a desktop replacement. But hardware compatibility/usability in desktops that they require or are used to on a daily basis are too many to give up on over a commercial distro like Ubuntu or even (gasp) a Mac like commercial OS. A server version would be great for a SOHO (Small Office Home Office) server (and we can publish disclaimers as required which are understood in the linux world anyways, especially for smaller distros like Gobo) I see the following tasks primarily. - Installer to allow a minimal/gui stripped down version (possibly some sort of netbooting installer while we are at it and do the rest as a network install (binary and/or source as is currently possible)) - Freshen to have a -security option (or a new program as required) which updates security related packages (this will require an Overseer) - Individual Maintainer(s) for packages that have services that are exposed to the internet (We can publish the list of packages for which we are providing security updates?) Typically a start on this list of packages can be: - Kernel - Firewalls - OpenSSHD - Webservers? Happy to volunteer to help with any or all of the above though not the most informed for developing a new installer. But I can help maintain the security updates packages which we will require. Even a well funded distro like Ubuntu found the server/cloud space to be a way to popularity and has given up on mobility/convergence. Hope I have made a case here. On 12 April 2017 at 21:05, Lucas C. Villa Real <[email protected]> wrote: > On Wed, Apr 12, 2017 at 7:17 AM, Anshuman Aggarwal > <[email protected]> wrote: >> >> On 12 April 2017 at 10:34, Hisham <[email protected]> wrote: >> > On 12 April 2017 at 01:57, Anshuman Aggarwal >> > <[email protected]> wrote: >> >> On 10 April 2017 at 23:35, Lucas C. Villa Real <[email protected]> >> >> wrote: >> >>> On Mon, Apr 10, 2017 at 2:33 PM, Anshuman Aggarwal >> >>> <[email protected]> wrote: >> >>>> >> >>>> I have started pruning the PackageNames.txt file for a server >> >>>> install. >> >>>> Can we split this file into a say ServerPackageNames.txt and append >> >>>> the GUIPackageNames.txt and the ISO build script can be given an >> >>>> option to make either one? This will allow us to keep server and gui >> >>>> ISO builds around without double maintenance? >> >>>> >> >>>> Regards >> >>>> Anshuman >> >>>> >> >>> >> >>> To be fair, I wouldn't like to touch the installer right now. We're >> >>> going to >> >>> have a complete rewrite of it very soon, now that our abstraction >> >>> toolkit >> >>> (AbsTk) library has been ported to Lua. We'll likely want to go with a >> >>> different approach to the installation of remote packages instead of >> >>> the >> >>> traditional "network install", too. >> >>> >> >>> Thanks, >> >>> Lucas >> >>> >> >> >> >> I suggest that the new installer have multiple installation options >> >> for packages like minimal, server or at least GUI/No GUI >> >> (headless/virtual vs desktop/laptop use cases). >> > >> > One very important reason we don't advertise Gobo as a server OS is >> > because we do not publish security patches with the necessary speed >> > required by a server OS running always-connected network services. I >> > do not recommend running Gobo as a server, and as a matter of fact, as >> > of 016.01, I recommend against it. >> > >> > If one wants to install it on a server one is free to do so, but one >> > would have to track security updates for all installed packages by >> > hand and that is really risky business. >> > >> > -- Hisham >> >> That is a very good point that got overlooked. Although in todays day >> of high speed internet available on even desktop/laptops/mobiles they >> are quite vulnerable but mostly they are behind a NAT router which >> acts as a firewall. >> >> However if one has a good linux firewall (say shorewall) installed, >> then only the linux kernel, the firewall and other open services need >> to be kept up to date right? That may be doable for a SOHO server, >> IMHO :-) >> >> If we are worried about an out of date application which is making an >> outgoing connection then all the Gobo desktops would be vulnerable >> (assuming you spend an 8 hour day working on it)? > > > The difference is that our desktop machines won't be exposing services to > the Internet (as opposed to a server). I usually bind services to the > loopback interface only, something which is not possible when you need to > enable remote access to them. > > Lucas > > _______________________________________________ > gobolinux-users mailing list > [email protected] > http://lists.gobolinux.org/mailman/listinfo/gobolinux-users > _______________________________________________ gobolinux-users mailing list [email protected] http://lists.gobolinux.org/mailman/listinfo/gobolinux-users