Thoughts and questions about distrobox/toolbx
Is there anything obviously wrong or bad about the idea to just use whatever distro you like on bare metal. Like rolling release to get the fastest updates or immutable to make it rock solid. And then just use distrobox or toolbx with Debian and maybe Arch to run software your base distro does not provide?
I run Fedora right now but want to switch to something else. I was thinking about Tumbleweed a lot but there is quite a big portion of software which does not ship on Tumbleweed. (Theoretically you could download the .rpm file which quite a few developers provide on and install it on Tumbleweed too? But I am not 100% sure about that so please correct me about that if I'm wrong.) So I thought about Nix but the drama around that distro made me loose interest. Obviously Arch is also an idea but I don't like my base OS to be a project itself so I'd rather not use it for now.
And yes I thought about installing homebrew or nixpkg or pixi or whatever the name of the next new package manager is. But nearly all of them are only installable by executing a script and I don't feel comfortable doing that. Would it be safer to run scripts like that in a distrobox/toolbx?
So yeah, my initial question was wether it is viable to just choose any distro and get along with distrobox to get your software from the AUR or through .deb packages. But the question developed if it would be wise to use distrobox to execute random internet scripts without altering your base OS/putting your data to risk.
19 replies
Just go CachyOS if you can't be bothered with Arch proper. Running an insecure container layer that brings another whole distro so you can run an app is weird when flatpaks exist for this purpose, and are much better suited for this. Seems like you're creating a "problem" that doesn't exist and then coming up with the most complicated way to solve this made up "problem".
But take signal for example, they only provide a .deb package. The flatpak and the AUR package are only community packaged. And how are flatpaks better suited for this?
Distrobox solves a great many problems. I use it in Cachy all the time.
Also, I am not sure what security Podman under Distrobox is making worse. Got an example?
You are suggesting Flatpaks for security? Um. Ok.
And how is calling the entire Freedesktop platform just to run an app better than the much more limited dependencies that Distrobox will pull in? And, if I already use Podman, Flatpak is a lot of extra complexity compared to Distrobox.
What software? I've never found the need for distrobox; any software usually has a package or tarball.
You can install the packages within the box
For example signal only provides a .deb package for Linux. And I must admit I never understood how to handle a "generic" linux package/tarball. Maybe I should dig into that one day.
Distrobox changed the way I use Linux. I cannot imagine going back.
First, you are exactly right that it allows you to separate app repo from the rest of what you live about a distro.
I use an Arch Distrobox with every machine. Using Chimera Linux that uses MUSL, Clang, libc++, and BSD userland? Install anything from the Arch repos or AUR in seconds.
But it is not just package repo size. Using an app that targets RHEL? Install it from a RHEL Distrobox.
Doing dev for a project whose users are Ubuntu people? Build it in an Ubuntu Distrobox.
Want to try something and do not want it to mess up your system? Do it in a Distrobox.
Need some software for a class that will just be cluttering up your system after? Make a Distrobox for that class.
I have a .NET Distrobox. I have a Java Distrobox. Just not having to update the IDE and frameworks all the time is a huge win.
Mature application that I use every day that I do not want to change or break on me? Install from a Debian Distrobox.
Rapidly developing app where I want the latest for features and fixes? Install from an Arch Distrobox.
Tools you like that only Mint offers? Install a Mint Distrobox.
Distrobox is the greatest.
I switched from fedora to silverblue to now aeon (opensuse) and I use a tumbleweed and fedora distrobox. It's almost exactly like silverblue.
Yes, you can choose any distro. But remember that a big part of a distro is the default software and settings. Choose one which fits your likings. I wouldn't use debian or ubuntu. I like podman, selinux, etc. But anyone has different needs.
Since distrobox, the base distro matters less and less.
Because you mentioned it, what exactly is selinux? I saw it a few times on fedora but never really understood what it's useful for.
It's for permission management. Usually the user does not see it really.
Basically, if a hacker gains access to something, selinux secures your system by limiting the scope the attacker can gain.
Ubuntu uses apparmor.
I'm not deep in both topics to judge which one is actually better. I am just used to selinux and it's good. I remember that peoplr claimed apparmor to be easy and selinux to be difficult to handle but I can't confirm that. For my podman containers I simply add ":Z" to the paths which the container shall have access to and I know that it can't gain access to any other location because of this Z and selinux. If I have to debug selinux, I run
sudo setenforce 0and if it then works, I can look deeper into it.This sounds a lot like the Universal Blue distros. They even have homebrew installed by default. If you're already using Fedora it would be a pretty easy transition.
Yes I thought about that too, but I really want to try something else.
I run a pretty barebone Archlinux with several distroboxes. My main motivation for this setup is that I work on a lot of different projects that all have very different setups. Running them in distroboxes make sure I can just drop the box, once the project is finished, and all code and data is just wiped, without having any impact on my main setup.
Exactly! Keeps the core clean. I use use Arch distroboxes on Arch or EOS for exactly this reason.
As a NixOS user, any drama that might be going on doesn't affect my use of the software
Yeah that's not going to work in the general case. A trivial RPM package might be fine but every additional dependency increases the chance that it depends on some package that OpenSUSE doesn't know. There's a reason OpenSUSE is usually considered an independent distro and not a "Fedora-based" one despite some shared components.
I don't think security wise there's much of a difference between running random software directly or via distrobox. Note that distrobox mounts your entire home directory into its containers, which removes any security benefit that containers could theoretically bring. In both cases you either need to audit the software yourself or you need to trust whoever you're downloading the software from.
Out of the third party repositories you mentioned, I would personally consider Nixpkgs the most trustworthy because package specs are actually code reviewed, unlike the AUR into which anyone can publish packages with zero oversight. That doesn't mean it's impossible for Nixpkgs to end up with malware in it, but the AUR sets a low bar. Using Nix (not NixOS) is also not actually that hard, you can just run
nix-env -iA nixpkgs.yaziand it does exactly what you would expect, even if NixOS users would scoff at the "imperativity".That being said, the OpenSUSE repositories really aren't that bad. Especially if you combine them with Flatpak, and especially if you install Firefox and VLC (or equivalents of your choice) from Flatpak so you don't need proprietary codecs in your base system. I used OpenSUSE Tumbleweed for years and got by just fine without Nix, homebrew or distrobox.
Thank you very much for correcting me about the RPM issue!
True, I forgot that distrobox mounts the entire home directory.
But that still leaves the question: How to install Nix in the first place? Without just running the script. Another question: This command just runs the software once without actually installing it right?
Awesome, thank you very much! I really should just try it out for a while!
You can download tarballs with the precompiled Nix, though you'll still need to run an install script (but you can at least read it to convince yourself it's not malicious), see the relevant documentation for that.
Something that slipped my mind is that since OpenSUSE uses SELinux now, that means the recommended multi-user mode won't work. Single-user mode should be fine afaik, but it's a bit less convenient.
The
nix-env -iAdoes actually install the software locally, not completely unlike how azypper inwould. For running a program without installing you would use something likenix-shell -p yazi --command yazi. Of course that still downloads and "installs" the program, it just won't add it to yourPATHor create a GC root, which means the next time Nix does "garbage collection" it will be removed again.And yeah I would recommend just trying OpenSUSE out and then if you realize you actually really do need stuff from third party package managers, then you can worry about whether getting into Nix is a good idea or not. Or fall back to the Arch/AUR in distrobox idea which is probably simpler to do overall, especially since from what I understand that's what you're supposed to do on the immutable spins like Aeon.
Late edit: I'll also note that there are several OpenSUSE specific third party repos too. Packman has some proprietary codecs that OpenSUSE doesn't want to ship (in case you really don't want your browser to be a Flatpak), and the Open Build Service (OBS) which is basically the AUR for OpenSUSE. They're not as useful because they're nowhere near the size of the AUR, but if you just need one specific package (perhaps one with questionable legality like yt-dlp or something) they might just have it. And of course you can also build stuff from source and put it in your
~/.local/bin, which has been common practice since before Linux was able to run on real hardware.I think you can change this if you really want to