- 158comments
- 9comments
- 39comments
- 370comments
- 16comments
- 11comments
- 100comments
- —discuss
- 32comments
- 120comments
- 227comments
- 48comments
- 60comments
- 3comments
- 88comments
- 3comments
- 40comments
- 386comments
- 626comments
- 162comments
- 154comments
- 31comments
- 416comments
- 400comments
- 18comments
- —discuss
- 57comments
- 25comments
- 129comments
- 51comments
Awesome! I believe NixOS is perfect for systems you just want to work and track reproducibly, like appliances (which a lot of server software is supposed to be). I’m glad people smarter than me are actually able to realize its advantages =)
In the same space, also check out openDesk initiated by the German Government (https://www.opendesk.eu/en) and La Suite by the French one (https://lasuite.numerique.gouv.fr/).
AFAIK, there has been some collaboration with the German government on La Suite, not sure about the others.
This realy would be a great way to foster collaboration within the EU. To create an own independant Ecosystem outside of the microsoft world.
I recently got my feet wet with Nix for the purpose of agent sandboxing, and it's a really great concept!
The issue I have run into is that for running llama.cpp, which is a very actively developed bleeding-edge software, it seems like experimenting with different versions/configs/patches etc. was fighting with the Nix philosophy of immutable software, so I ended up just managing it outside of nix.
But this could be user-error, I've only spent a couple of weeks with it.
For a second I was worried that the actual code behind this was dead in the water ("3 months ago") but it's just one more click away:
https://code.overheid.nl/MinBZK/DAWO-NixOS
A note to the developers in the project, if anyone is reading: your repositories are in violation of the new Codeberg policy that forbids AI-generated code [1].
[1] https://blog.codeberg.org/protecting-our-floss-commons-from-...
Their instance is self hosted right, so this doesn't apply I think.
And Codeberg also blocks real people from accessing it, for who knows what reason. I just get "Access denied." with no more info.
But they do let me visit blog.codeberg.org
Had that issue with HTTP accessed repo, switching to SSH solved it for me.
Is it on Codeberg? I looked self-hosted to me.
https://code.overheid.nl/MinBZK/DAWO-NixOS says:
Does this mean European governments have or will have an alternative(s) to GitHub as well?
Forgejo (the Codeberg-maintained Gitea fork) is essentially becoming an EU-based community of familiar compatible alternatives to GitHub.
It's not quite a federated/decentralised platform in the traditional sense, but the decentralised nature of Git makes it a close enough equivalent, & the fact they're built upon a shared platform makes them very easy to navigate. So setting up public instances for each government or org makes a lot of sense.
Codeberg even maintains a list of alternative pubic Forgejo instances[0], some of which are explicitly pro-AI.
[0] https://codeberg.org/forgejo-contrib/delightful-forgejo#publ...
Fair note, but I'd avoid the cheap shot "more open". You'll just bring up the old flame wars about whether the MIT-style or GNU-style licenses are more open.
The same applies here, is it really "more open" to allow corporations to profit by removing the openness of your work?
Point taken, trimmed that. I do take issue with their position but not the place to start a new discussion.
It’d make the most sense for the Dutch government (or DAWO) to have their own Forgejo instance if the goal is data sovereignty.
edit: looks like this was originally the case and then they moved?
clearly shows the need for federated forges, where you get to decide on your own rules but you still benefit from interacting with a broader set of collaborators.
Yeah, waiting for this too, feels like the final piece of the puzzle. Tracking issue from Codeberg + more general information about the effort around the the ecosystem:
- https://codeberg.org/forgejo/forgejo/issues/59 ("[FEAT] implement federation")
- https://forgefed.org/
Final piece of what puzzle?
We can do big federated/distributed development with git at the project level. See the linux kernel.
If the goal is fancy UI then there are alternatives.
If the goal is to do a big multi-git with cross repo issue tracker, then that implies either:
- you're a public site for random repos like codeberg
- you're a special purpose forge and identity management is a big issue you want full control over.
IMO - For this to work, they should go with the latter and not try to offload identity into some federated scheme.
That's a recipe for drama as shown with mastodon when they got publicity few years ago
That's likely to end up Balkanized like the fediverse, where every instance has a list of other instances they refuse to federate with, often because politics or petty drama. Though to be fair to the fediverse, sometimes it's because those other instances are full of child porn and most people just don't want to see that.
It amuses me that Mastodon Central uses corpo-friendly labels for the sites they won't federate with, e.g. (https://mastodon.social/about)
Whereas the more free-wheeling sites, like the ones Mastodon Central blocks, tell it exactly how it is: (https://tsundere.love/about)
A lot of such issues could likely be resolved by a better thought out protocol. There are certainly plenty of self righteous people who would refuse to federate purely on principle but more typically the issue is simply that one does not wish to be exposed to or traffic in any way the content in question. A well thought out self categorization system could largely address that need - you'd only need to refuse to peer with those who failed to apply it. AI also makes any such effort easier than ever.
weirdly enough that reminds me of wattpad and ao3, where wattpad uses much nicer sounding terms while ao3 uses as accurate terms as possible. (which makes ao3 seem more "degenerate")
They use both. https://code.overheid.nl/MinBZK?q=dawo&sort=alphabetically as the official source, and https://codeberg.org/DAWO for the community parts.
Codeberg are going to have issues in the future when all code is AI generated (except for artisanal code of course, written for the love of the craft but not to achieve anything of merit).
Assuming writing code by hand is slower (which I agree with), why can't it still have merit compared to code written via llm harness?
Because no one is going to hire developers who write code by hand, apart from a few niches. For the same reason that no one hires a courier who delivers by horse anymore, or a miller who uses windmills to grind their grain, or a cooper who continues to use wooden staves and iron hoops instead of forming plastic or metal containers, or...
Yeah yeah, except LLM code is absolute dogshit and is not on a trajectory to ever not be dogshit.
https://knowyourmeme.com/memes/akakichi-no-eleven-redraws
I’m sorry, but this isn’t the case. I don’t like it, on balance, but managed responsibly and steered well, plenty of LLM code is fine.
Huh. For all the "traditional", "organic", "hand crafted", and other "things" I've encountered that isn't one of them. I wonder why no one is advertising fair trade hydropower stone ground organic flour?
Because people generally don't like having bits of millstone in their flour.
Policies are enacted for current reality, not fantasy futures. If your magical fantasy becomes reality (it won't), they can just... change their policy. Of course, you aren't thinking about practical effects of policies on platforms, only on how it's an insult to your LLM-bro way of life.
Keep huffing that copium my friend. I've set an alarm to follow up here in a couple of years.
Sure. You can come gloat about how you're unemployed because nobody needs a prompt monkey when they can just prompt the LLM to produce dogshit code themselves.
I climbed out of the code trenches years ago - I have multiple small companies, I'll be fine.
And yes, they both have moats that will take AI at least 5 years to erode, at which point I'll just retire.
Regarding the dog shit code comment: this is the problem with your whole line of thinking. Customers don't care if the code is dog shit. They care if they get value from the product.
As I mentioned, there will still be some demand for devs who code by hand, similar to how theres still demand for blacksmiths who make ornamental weapons.
Dogshit code doesn't give customers value from the product. You can get away with enshittifying your code/product if you already have an iron grip on the market and network effects make it impossible to escape, eg. Windows/appleOS/Android, Youtube, Facebook, Twitter, Discord, etc. At that point, you're relying on the inertia of community lock-in to replace product quality. However, this strategy does not work if you aren't a FAANG-scale monopolist. If your code and product is dogshit, you will never get off the ground. You need not only a better product but an overwhelmingly superior product to the competition to defeat inertia. And we see this playing out in reality: there are no vibecoded software disrupting the market. At most vibecoded software is carving out a new MLM-style pyramid of vibecoding tools, but it is not replacing hand-crafted software.
This is just wishful thinking.
Building the product was never the hard part. Getting it in front of people is. That will continue to be true, except the build stage will be even easier.
Educating oneself to provide better quality of work still requires writing code by hand, and by extend is an achievement of merit.
Did you actually read through that post you linked? You realize not every project that was ever touched by a LLM is being thrown off? Read the "Some early, but informal guidelines" particularly, as you've seemingly missed that.
They're targeting slop and essentially spam, not everything that could possibly have been built by LLMs.
Not OP, but I stand corrected. Thought it was 100% no generated code. Now I know better, thanks! Looks like codeberg aren't as mad as I thought.
Quoting from the post:
All of the commits I browsed here seem to be LLM-assisted, so these projects are in this category. The policy being fuzzy is in itself a problem - "likely to be tolerated" is not a great policy to have your entire government depend on.
Personally, the refusal on "Projects heavily tied to the LLM ecosystem, e.g. LLM-written tools to ease LLM usage" is enough reason, as that's a good chunk of what I've been working on.
And that's not a bad thing. That's why they are communicating, so if you feel that is you and you're uncomfortable about it, you can move out and it's a win win.
Not everything should service all of us, especially not the smaller services. It's OK for places to have their own rules and them being upfront about this is a *good* thing.
No, the policy being fuzzy is a feature, because they're not 100% against all LLM usage, they're against slop and AI-spam, which is what they're trying to combat.
Laws are fuzzy, and we're doing mostly fine with this, of course there are edge-cases. But that's exactly why laws are fuzzy in the first place.
If you have a "automated software factory" or whatever the vibe-coders are up to today, then yes, Codeberg is probably not for you. But if you sit with a agent TUI in one tab, review things closely and don't just "throw code over the wall" without reviewing it, you have nothing to worry about with hosting code on Codeberg.
Codeberg is trying to solve the right problem with the wrong solution. But hey, it's democratic!
I like Codeberg's solution (hard written policy, light good-faith based enforcement), what would you suggest as a better solution?
Their contention seems mainly focused on the heavy resource use of AI tooling.
They run a service: they could impose limits on the number of submissions, builds, branches, scans, etc, and give additional usage credits to the large community projects they want to encourage.
I predict that Codeberg will soon realize that they have no choice but to loosen and allow AI generated code.
There is no point in being on the extreme end around banning all code generated by AI.
Regardless, there is AI generated code in many repositories on Codeberg anyway.
It may be more a measure against explosive growth than being anti-AI in principle.
I've seen so much commentary on the apparent strictness & extreme nature of Codeberg's approach & no actual examples of it.
They have a strict policy (which many have rightly pointed out is impossible to fully enforce), & their "enforcement" has mostly relied on good faith contributions to date. They're also accounting for the fact the ToS change came without advance notice for many of their users who were already making active use of agents, hence there remains many AI repos (I have yet to hear of any removals).
To me that seems like the best approach one can hope for - a lax policy is a slippery slope (presuming dissuading AI contrib is your goal), & wouldn't satisfy their legal concerns (hosting code of questionable copyright status), & strict enforcement isn't viable in any case (especially at their scale), so this seems to me to be the best compromise.
AI generated code is allowed on Codeberg, but not if it's mostly ai generated
People who act out of ideology very very rarely change their opinions.
It's self-hosted on https://code.overheid.nl/ & they mirror a subset of it on Codeberg.
That might still be in violation but I would imagine it's low on Codeberg's radar since they're not making primary contributions there (& if I were DAWO I'd also be interested in limiting direct community agentic contrib).
They have "migrated to codeberg" which is written in the repo itself.
However Codeberg actual "fuzzy" policy is less strict than "no LLM used ever".
This is great, would love to understand why Nix over Lix or Guix.
1. You can run NixOS with Lix (I do)
2. Because Guix is less mature and more, ehm, opinionated, than *ix + nixpkgs
Guix users can just add the Fearware Guix channel which is just the nonfree firmware and blobbed vanilla Linux kernel, no propietary software it's added, just the necessary firmware to run your hardware (3D Radeon support, Nouveau+reclocking, some audio chipsets, and most of non-ant9k WiFi cards). That's it.
Site doesn't work for me.
www.dawo.community took too long to respond.
Are you in the US? Hehe
No, Sweden.
Nixpkgs should reduce package count. Waiting 2 days for unbound CVE patch merge is unbearable.
You don't have to wait? You just have to compile matter yourself
They could improve that speed if they had more hardware to do the needed rebuilds.
I hope you are paying them something.
Ask your favorite LLM to write an overlay for whichever package you need patches applied for before they hit Nixpkgs.
Use nixos-unstable-small branch or backport the change and build yourself.
What is it that they need/add above NixOS defaults?
They likely offer at least some of:
* typical deployments
* training/consulting
* compliance with Ditch regulations
* shared infrastructure for custom builds, and CVEs
Any move away from the abusive big tech that exists in USA is a good move in my book. Microsoft just recently made a new patent where they will monitor you via camera and microphone to block your program/game to show you ads, and per ads viewed, you then earn credit to be able to use your program/game. It is absolutely wild to me how a corporation can be so toxic and abusive to its users and still be in business.
Black Mirror has unwittingly been offering a lot of nice, horrible ideas.
https://en.wikipedia.org/wiki/Fifteen_Million_Merits
Too many people seem to have taken it as a todo list instead of a warning...
I'm sure Black Mirror could offer up a cautionary tale like Don't Create The Torment Nexus
(https://twitter.com/AlexBlechman/status/1457842724128833538)
https://xxcancel.com/AlexBlechman/status/1457842724128833538
Well I'd like to think Charlie Brooker, like many of us, could clearly say where humanity was heading. Some of the episodes that were considered far fetched 15 years ago are probably considered plausible at best and likely at worst now.
Some episodes are currently being played out live in Ukraine.
Seems like many films and books have been taken as inspiration for making "hypothetical futures" true. E.g. Her - take AI as your girlfriend... was creepy then, still is now.
It's easy: The choice was made from someone else, and you just accepted it as normal. Hardware vendors shipping PC's with Windows 11, corporations who went all in to Microsoft's tooling shove Microsoft Teams down your throat because "the company uses it", and the list goes on.
Well of course I wouldn't expect corporations to know what ethics or human decency is even if it stared them straight into the eyes, but I would expect governments to establish laws and regulations such that the psychopaths wouldn't be able to abuse people to no end.
Currently it looks more and more like goverment itself consists of a lot of psychopaths who want to abuse people. Like abusing people is the main reason people go into politics. And then voters select those who want to abuse the outgroup, but don't know that politicians consider everyone as underclass, therefore even their own voters are ripe for abuse.
One of the most telling quotes of our political era is this one from 2019:
They voted for him to do “good things” where the expectation was he’d hurt the right people. This person stated it a little more plainly than most but I think this view explains the last 10 years or so.
https://www.vox.com/policy-and-politics/2019/1/8/18173678/tr...
Corporations need to deliver lots of value to their customers to get somewhere in the first place. If you want power it's much easier to become a politician and just blame corporations and spend the money they make and take the credit.
I refuse to use 'teams', it's a pile of garbage and spyware to boot.
I recently found out that several researchers, departments... buy a personal subscription for zoom (out of the own project money) even as our university as a MS Teams subscription. Despite if it is effectively "free" for them, they do not use it. So much on public money spend wisely and the quality of the MS Teams software...
a lot of companies migrated to teams purely because it was already included in the subscription, IIRC they were forced to take it out by EU in 2023 for being anti-competitive.
Can confirm, my boss has his own paid Zoom while I’m using Teams to save research money. Another assistant professor I know pay for Slack ad well.
I think Teams improved and Zoom regressed in the last 3-4 years to the point the garbage level is not that different nowadays. Most of the annoyance is related to finding your way in a different interface.
I hope you're aware AI vendors are running the exact same playbook these days. Don't want AI? Fuck you here's some AI on your toothbrush
Yeah, although, the word “just” is doing a lot of work here.
(as usual)
Error! Please drink a verification can.
My pet peeve is changes in 'user agreements' for paid services that add increasing amounts of adverts and tracking, but if you decline, you can't use the service, but the service continues to charge you. For the service they're no longer supplying.
Just the kind of thing that the EU could regulate if it chose. Decline -> Your subscription will be terminated, no further monies will be debut from your account, are you sure?
I'm more interested in the cases where you buy your phone, for example, and after purchase you are asked to agree with terms and conditions. Money is paid already. If you do not agree, you cannot use the device. Worse still, if 2 days after thre is mandatory update that forces you to agree to new version. If you don't like them, you should be compensated for it, as it is hidden information from you as a buyer.
Remove/changing functionality in a way that the original use case you had for the device, no longer applies, because of a forced software update or user agreement you have to accept, should let people return the hardware regardless of when it was purchased. Bananas that this is still legal for companies to do.
I've always viewed those as entirely invalid, at least from the standpoint of the spirit of our various legal systems and cultures. I recognize that any "binding arbitration" bits are enforceable (and an injustice). But the rest of it? Literal make believe. I will do as I please with the hardware that I paid for, its firmware, and any software that it came with. I will actively aid and abet anyone who seeks to reverse engineer same, circumvent associated technical measures, or evade the law while doing so. And all of that is good and virtuous behavior that improves society as far as I'm concerned.
In other words - go ahead and click "I agree" without reading it, then proceed to dump the firmware or whatever else it is that you want to do. You aren't lying or otherwise doing anything wrong. The legal system is just broken.
The fact that such a legal reality has been permitted to reach this point has to be one of the clearest illustrations that western systems of government remain highly flawed despite all that they get right.
Well, you can always return the phone. For online purchases you have 14 days to return it just because (you don't need to provide a reason).
Where in the UCC does it say that? There may be a State regulation or a company policy, but I don't recall anything in the UCC about a "free" 14 day return policy. I can return a used car, no questions asked, after 14 days? Good luck with that.
That's an European thing. Anything bought remotely (mail, phone or the internet) can be returned up to 14 days for a full refund.
Some minor exclusions apply, eg hygiene products can't be returned after they've been opened.
Well, not really. If you have unpacked the iphone - I'm pretty sure it's not gonna be easy to return even within the 14 day window. You can return unpacked though, which is not the point of what I'm saying. Also for the benefit of the argument, change 2 days to 15 and you end up at the same place- you cannot legally return the device, User agreement has changed in ways you don't accept and you are forced to use device, for which you have paid or accept loss and buy another device. Oh and also, you cannot change OS to the alternative one for which terms might be more acceptable to you. How is this not a subject of investigation- I don't know.
This is why it would be so nice to have an EU that actually made law, instead of just handing over the right to oversee things to the commission.
Imagine if we actually had real regulations, instead of these negotiated things. Then we could just sue and normal courts could handle it.
Does that need new law? The problem we have in the UK is that Trading Standards has been starved of funding for the last 16 years so they can't do their job. If they had funding I'm pretty sure they have the power to tackle this.
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...:
“Where the contract provides that the digital content or digital service is to be supplied or made accessible to the consumer over a period of time, the trader may modify the digital content or digital service beyond what is necessary to maintain the digital content or digital service in conformity in accordance with Articles 7 and 8, if the following conditions are met:
[…]
2. The consumer shall be entitled to terminate the contract if the modification negatively impacts the consumer's access to or use of the digital content or digital service, unless such negative impact is only minor. In that case, the consumer shall be entitled to terminate the contract free of charge within 30 days of the receipt of the information or of the time when the digital content or digital service has been modified by the trader, whichever is later.”
I feel compelled to mention Oracle at this point. Isnt their entire business model suing their customers?
In addition to being the plot of a Black Mirror Episode¹, Sony also owns a similar patent².
I wasn’t aware of the Microsoft patent but was able to find it³. It was published less than a month ago.
¹ https://en.wikipedia.org/wiki/Fifteen_Million_Merits
² https://www.snopes.com/fact-check/sony-patent-mcdonalds/
³ https://image-ppubs.uspto.gov/dirsearch-public/print/downloa...
I make dystopian adds for my game- and one of them is a company called MacroSoft, which has a product that makes you sing add jingles to measure "engagement" performance before opening a program on its operating System (called BARs). Its really insane, how my dystopian crap regularly gets overtaken by reality.
You can patent a black mirror episode?
This makes me happy. The more enshittification the sooner the first pillar of Big Tech will fall down.
Meta and Google will follow soon after.
P.S.: just because they take a patent on something doesn't mean they will actually use it.
That's true, of course, but the fact that there are people in the company thinking like that to begin with, enough to think it's worth patenting such anti-human stuff, is plenty enough for me to never want anything to do with them.
https://www.tomshardware.com/video-games/microsoft-patents-s...
Patent: https://patents.justia.com/patent/20260260258
The mic/camera aspect doesn’t appear on that patent, it seems to be from an abandoned Sony patent filing from 2006 https://patents.google.com/patent/US20070261077A1/en?oq=US20...
"Drink verification can to continue"
It's just a patent.
It's just a delousing room
Indeed - delousing rooms are not evil.
Here's a (bit dated) list of the US companies which rake in the most bucks:
https://en.wikipedia.org/wiki/List_of_largest_companies_in_t...
Looking at the 13 which rank higher than Microsoft - how many would you describe as treating their users/customers well?
Theory:
Treating your customers well is part of one strategy for corporate growth and profit. There are other strategies, which also can work very well - and don't require all the hassles and expense and non-evil of treating your customers well. Naturally, Capitalist propaganda stresses that first strategy, and doesn't talk so much about the others.
I don't like this idea, but I do like to get my facts right. If it is the patent linked elsewhere on this page, then
Apart from "we inserted some ML into the ad pipeline" there's really nothing new that I can see here.
There is a couple more wild things here:
1) That there is an agenda, demand and total legal abetment from the top of the power/monetary hierarchy for such corporate policies
2) That there is a horde of individual employees working to those ends without any shadow of doubt, often even vice signaling their intent to be the first to attain the figurative A-bomb or full-blown BB telescreen.
To save anyone else I asked Claude
"NixOS is a Linux distribution where your whole system is defined in one configuration file."
I didn't get that from looking at their website...
NixOS is also unnecessarily complicated and it's easy for someone that doesn't want to read 1000 pages of documentation to brick your system.
Probably has its uses, tried it twice myself and both times were a lot of struggling.
For me even Arch was easier to configure than Nix.
The history of the Netherlands is all about making things unnecessarily complicated.
When lesser nations rally around the flag and elect dictators we have meetings and consultations.
Literally.
Elk nadeel heb se voordeel.
Each nixos rebuild creates a snapshot. While I also eventually moved off of nixos, I've yet to get a system that was as stable as it.
The problem with Arch is that configuration is by hand so you have to do it every time. With Nix you configure it once and then you can deploy it anywhere. Also it's pretty much impossible to break since the system is immutable and you can boot to a different revision any time.
I managed to brick my revisions/snapshots before
Sure you can make a bad one, but you can always switch to a different one.
Yeah I also wonder about going for NixOS for this. For servers maybe, but for user focussed desktops? The support requirements will be complicated.
That's the nice part, as an admin you are familiar with the complexity and use it for good. As a user, you never have to see it. (And you can even have some freedom for installing apps using flatpack/snap if needed.)
How would you role out the same config to thousands of Arch systems? Sure Valve does it, but I still think that is a "bolted on top" solution. Bootc could be another option though, but Nix solves reproducibility more elegantly, imho. Nix went back and asked "how can this be done better", where many modern solutions took what was already there.
I can imagine. Those are often the sort of projects that struggle to put a one line description of what they are on their homepage. I inferred it was an OS, inferred it was Unix adjacent...but no answer on the rest. It could have been BSD or open Solaris based for all I could tell.
So far I have broken every Linux distro I used except NixOS.
And if I were to break it, i could just reboot into the previous system snapshot.
And I haven't read 1000 pages of docs - from my experience id doubt it even has that many docs.
I would image in corporate / government deployment, declarative configuration is more efficient.
When you have that many users, you don't really configure individual system, you deploy up some per-configured module or setup.
Repeatable builds also make troubleshooting lots easier - and you can hand those task to front-tier helpdesk staffs.
https://meatproxy.me/
Well what I wrote was not on the homepage of nixos.com, or obvious after a few clicks. Claude summarised it very nicely. I now know I don't need NixOS.
Perhaps the real meatheads are the ones who spam threads with anti-ai memes, rather than looking at the utility of what the ai provided?
That's the wrong domain...
The nix website doesn't have the sentence that Claude gave you above, but it does describe the declarative approach to package management that nix is known for. "Having a single config file" doesn't really even describe what makes nix unique. Perhaps you should have read the website instead of skimming and asking Claude.
Hopefully the config is a little more descriptive than their README.md
Workplace is such a confusing overloaded term.
They also have "Mijn Bureau" which I tried out and wrote about here [0] which is the MS Office alternative.
I take it this is the layer below that, an operating system?
But it all looks quite fragmented still from what I can see, especially now that it's also split across GitHub and CodeBerg as well as being split across different organizations, and trying to collaborate with other efforts by other European countries while still remaining distinct.
[0] https://techstackups.com/articles/is-it-feasible-to-self-hos...
[1] https://github.com/MinBZK/mijn-bureau-infra
[2] https://code.overheid.nl/MinBZK/DAWO/src/branch/main/compone...
France government has announced NixOS based systems some months ago:
- https://github.com/cloud-gouv/securix a hardened/secured os
- https://github.com/cloud-gouv/bureautix-example an example to use securix to build an office deployment (with some packages https://github.com/cloud-gouv/bureautix-example/blob/main/co... )
I’m glad multiple European agencies are giving this a whack - hopefully we’ll end up with a synthesis of the best aspects.
The same Dutch who voted on the eAIDS... ahem, sorry, eIDAS and ADDW car spyware? I'm not particularly excited about our new benevolent OS.
eIDAS is federated login between countries in EU. What is wrong with that?
I’m really curious to see what the answer for MDM and Group Policy is on Linux. The SSO part is mostly figured out, but the reason places use Windows is often manageability.
Is there anyone doing MDM or policy enforcement on Linux other than Google Workspace + chromebooks?
The highest problem is the office suite. If you think Libreoffice/Collabora can replace Microsoft 365 without friction the project could be a success. Honestly I do not think so as of today.
Completely agree. Before that I would have add the Adobe Suite as well for a lot of people but it's less a problem now fortunately.
But fails to state what the letters in D.A.W.O. stand for
digitally autonomous workspace (for the) overheid
"Digitaal Autonome Werkomgeving Overheid", ie ~government digitally autonomous workplace.
See https://code.overheid.nl/MinBZK/DAWO
Do we even need to have a suite of tools for users to create spreadsheets, paste images into them, save them as a PDF, download to their local machine, sync to sharepoint, change permissions to include everyone in the entire universe to be able to see the file, email the link to another human in the company who opens it, uses a PDF editor to copy paste it back into excel, barely scratch the surface of tools within Excel to sum a column, reply back in a password protected word doc saying looks good to me.
I would much prefer to be using something like NixOS and not be depending on Microsoft etc but I can't imagine what the stack will look like if we don't revolutionise the work. Sensitivity labels, DLP, etc. are relics of people treating information on computers as if they are physical documents, and I can't see how I will have been paying for BP/E3/E5 licenses for users and then suddenly start to argue we don't need those features anymore after spending so long insisting users need to use them.
Guix has reproducibility. Instead of Nonguix, which bundles tons of propietary software, they can just add the Fearware repo, which just has the tainted non-free vanilla Linux kernel with closed blobs and firmware, just enough to function your machine well (especially with 3D support for Radeon cards and wireless devices) and nothing more.
FINALLY. I have been seeing other projects based on eg Fedora and I just think: why. Declarative, open source, and reproducible is the future.
Thanks Trump, Europe was never this united before.
Not by your choosing, but still.
I hope someone is security scanning all those NixOS provider modules.
I wonder if Claude could go from NixOS spec to actual config without the Nixos provider. The provider becomes a natural language description and some links to the docs/source code and then a verifier is all you need.
The link doesn't work for me.