• Zeniv@lemmy.quasarke.net
    link
    fedilink
    arrow-up
    1
    ·
    55 seconds ago

    I’ve been doing a project https://themildtake.com/articles/2026-07-04-a-declaration-of-independence/ ever since Independence Day and I have been shocked by how insane the open-source tooling out there is now. NextCloud and Collabara alone solves 90% of company’s needs. ERPNEXT covers a huge swath in mid-range needs. I combine it with a mailcow server and Authentik for SSO and I am not sure how much else most businesses need. The whole stack is zero cost.

  • brsrklf@jlai.lu
    link
    fedilink
    English
    arrow-up
    1
    ·
    24 minutes ago

    I’m in a local administration in France, it’s rapidly getting closer to home… Our higher-ups somehow decided a thourough Microsoft integration was a good idea like 5 years ago.

    Seems like we’re just one political comment about support to the ICC to be in the same situation. And I mean, fuck it, we should be. But I am not happy about the shit we’ll have to go through to purge it all now.

  • fodor@lemmy.zip
    link
    fedilink
    English
    arrow-up
    33
    ·
    5 hours ago

    Foreign countries using Google, Microsoft, or Apple, would be suicidal not to change platforms. Right now, the U.S. has incredible leverage: it can turn off their government servers, delete their data, and is certainly spying on them right now.

    The only reasonable move is some kind of self-hosted setup, at least for a large chunk of critical infrastructure, with some cloud options for backups, maybe, who knows, if the country is too small or centralized.

    • Squizzy@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      22 minutes ago

      I am in a large (couple thousand staff) company and I cant get why we dont selfhost everything. Like yeah it would have an upfront cost but the savings stack immediately. We spend like 30-50 a user for office access.

      Copilot is so shit and we could build an alternative with relative ease and never pay again. It wouldnt be baked into teams but who gives a fuck.

  • corey931@lemmy.wtf
    link
    fedilink
    English
    arrow-up
    5
    ·
    3 hours ago

    US: You want to cut us off? No! We cut you off!

    NL: How petty are you?

    US: Yes.

  • SabinStargem@lemmy.today
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    1
    ·
    6 hours ago

    Considering the Dutch have ASML, this seems an unwise move for the US. But then, the Dogey Confederates are working towards the destruction of the USA. 😒

      • Jiral@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        edit-2
        4 hours ago

        Tell us, how does “stuff work”? What up and running alternatives do the US have to ASML machines for latest generation high performance silicon? No matter where.

        • bigmamoth@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          24 minutes ago

          Look at asml client. Either us or Taiwan. They can’t skip that market. U dont have alternative to asml yet but asml has no alternative for client either. Also fab are long term devlopement thoses contract are already lock. And asml play by american rule regarding ban export and so more. Asml is never gonna ban the us. The us can but it serve them no purpose. Asml is a public traded company. If u think they gonna loose their biggest client… Idk what to say but that s unreal

  • im_fine_sandy@nord.pub
    link
    fedilink
    English
    arrow-up
    22
    ·
    8 hours ago

    This might just be the best thing that happens in tech (for me) all year.

    I daily drive debian just because boring and reliable. However, fancy package managers like flatpak and appimages and nix have made debian much more vibrant - it’s easy to install new versions of things now.

    That said, nix package manager on debian is just freakin amazing. Being able to just nix-shell -p <obscure cli tool> and exit when I’m done with it is magnificent.

    That’s the gateway drug anyway. The nix based home-manager is pretty cool.

    While I’ve been tempted to jump in with NixOS my experience with nix packages and home-manager has felt kind of bleeding edge or experimental. Loads of things that don’t work as intended on debian.

    A sophisticated well funded user base like a federal government has really good implications for the stability of the project in the future. I’m really stoked about this.

    • pruneaue [she/they]@infosec.pub
      link
      fedilink
      English
      arrow-up
      3
      ·
      edit-2
      2 hours ago

      Personally id say try it in a VM*. Home-manager and nix packages (and even flakes at this point) havent felt like experimental features for a good 5 years for me on NixOS

      Edit: while on Mac yes. Havent played with it that much on other distros

    • AHemlocksLie@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 hours ago

      NixOS is great, but it definitely breaks things. It’s the way it works, though, not whether the software is bleeding edge. Nix lets a package specify its own dependencies, even if those dependencies conflict with those of another package. It does this by breaking the traditional POSIX file system structure that many programs assume they can depend on. It puts all sorts of things where they “don’t belong”, and then uses a small army of environment variables, scripts, and symlinks to stitch it back together so that no individual package realizes what happened. If you only use software from the package manager, this is often (but not always) seemless, but if you download stuff from the web, none of the system libraries it traditionally expects are there. Likewise, if you’re using Nix alongside something like Debian’s apt, I wouldn’t be at all surprised if the two package managers doing things in two different ways causes some issues that are hard to interpret to the uninformed.

  • ouch@lemmy.world
    link
    fedilink
    English
    arrow-up
    44
    ·
    11 hours ago

    US has been building soft power like this for decades, and Trump is pissing it all away.

    If this process to get rid of dependency on US gets well underway, there’s no turning that ship. US won’t recover the position it had in fifty years or more.

    • LilB0kChoy@reddthat.com
      link
      fedilink
      English
      arrow-up
      11
      ·
      6 hours ago

      US won’t recover the position it had in fifty years or more.

      This is not a bad thing. Over dependency on any one nation or even a bloc of nations is a bad thing.

      I can’t help but think the dependency on the US that has been created played some role in what’s happening now.

        • LilB0kChoy@reddthat.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          6 hours ago

          Not even that. I’m thinking too much money, power and influence all consolidated in one place.

          The US has the most billionaires at 989 and I’m guessing of the remaining ~2400 billionaires in the world, a not insignificant amount have substantial interests in the US.

          It’s good the rest of the world is watching it happen. I hope they’re taking notes because it’s not stopping in America.

      • fodor@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 hours ago

        Well of course. The whole point of US trade policy was to maintain global dominance. You don’t think that politicians were sending money to other countries purely out of the goodness of their own heart, do you? … Of course some of them have good intentions some of the time, but let’s not pretend no other reasons came into consideration.

    • Typotyper@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      15
      ·
      11 hours ago

      Nope. The US isn’t teaching people to fish, its forcing them to learn How to to feed themselves. In the past they handed them the fish so they could control them. That power is lost now.

  • rynn@piefed.social
    link
    fedilink
    English
    arrow-up
    54
    arrow-down
    2
    ·
    14 hours ago

    Windows is basically a zombie OS at this point, shambling along and eating brains.

    • NaibofTabr@infosec.pub
      link
      fedilink
      English
      arrow-up
      30
      ·
      13 hours ago

      Windows as a home user desktop is definitely coasting on momentum, though it is also the OS deployed on most new PCs which keeps it going.

      I think the only thing really keeping Microsoft relevant is Active Directory (and Azure by extension) because a lot of organizations are dependent on AD internally, and there still aren’t really any good alternatives that check all the same boxes. You could probably cobble together a working solution for ~90% of it with open source software, but it would be clunky, fragmented and feature-poor compared to an on-prem AD system. It would require a lot more administrative overhead to configure and maintain it, and user management would be a mess.

      • rumba@lemmy.zip
        link
        fedilink
        English
        arrow-up
        6
        ·
        12 hours ago

        I’m starting to see non-AD companies cropping up. If you have to support Mac and Mac is absolute trash on AD, you need to run software to manage the macs which can already manage windows. With all the remote work, even RMM software is on the rise.

      • Kissaki@feddit.org
        link
        fedilink
        English
        arrow-up
        7
        ·
        12 hours ago

        EntraID also seems corporate established. For a modern with system, with zero trust etc, you use EntraID instead of AD now.

        Of course, legacy AD systems, if they exist, are also lock-in.

        • InFerNo@lemmy.ml
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 minutes ago

          Over 10 years ago I deloyed Zentyal, which is a Linux OS that works as a drop in replacement as a domain controller. Active Directory, Outlook mail server and file server out of the box. I can only imagine it got better.

        • NaibofTabr@infosec.pub
          link
          fedilink
          English
          arrow-up
          5
          ·
          edit-2
          6 hours ago

          Sure, but they’ll have to catch up on almost 30 years of feature development (and feature creep). Active Directory is entrenched, by virtue of being the only game in town for decades.

          Not that they’re necessarily irreplaceable, but… a half-competent Windows Server admin can go from cold iron to running HyperV with a local domain (AD forest) with a SAN supporting 200 endpoints (assuming the hardware is already in place) pre-configured with end-user applications and all relevant network & security settings (via group policy), with a print server supporting local network printers, and be ready to enroll new users, in less than a day.

          I’ve seen it done, I’ve helped get it done. And all of that can be done with point-and-click GUIs, and not a dozen different ones, just like 3 (one for server/HyperV deployment, one for HyperV config post-install, and then basically everything else can be done through Active Directory).

          When you’re a sysadmin for a large organization, that kind of operation at scale is non-negotiable. When I say that AD really has no competition, that’s what I mean. You could accomplish all of the same things on Linux, but it would take you a week of punching through terminal commands just to get the server and the domain up and running, and once you were done the user management still wouldn’t be as flexible or feature-complete as it is on AD (especially if you need things like auditing, or physical access token integration like badges for authentication, or remote desktop support, or video conferencing that is linked to corporate email accounts).


          All of that said, if you happen to know of a group that’s actually working on a competitor for on-prem AD (not Azure AD/EntraID, the cloud system is very different and not really comparable) I would be very interested. It’s a problem that’s been on my mind for awhile now, and I’d love to get paid to actually work on it.

          • brimlar@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            5 hours ago

            You should check out JumpCloud. It frankly feels a lot like you’re living in a cloud-first, Microsoft-free future. It’s a dream to use and scales, manages Windows, Mac and Linux as equal citizens. We don’t even maintain on-premises servers (including domain controllers) anymore, we just use IP addressing from the firewall and patch, control, manage all our computers from one pane of glass.

            • NaibofTabr@infosec.pub
              link
              fedilink
              English
              arrow-up
              3
              ·
              5 hours ago

              living in a cloud-first, Microsoft-free future

              Oh really, whose cloud? Oracle?

              We don’t even maintain on-premises servers

              Ah, you’re dependent on someone else’s computers, someone else’s network architecture.

              That sounds awful.

              Nope nope nope, need on-prem only data, on-prem user account control, on-prem domain, absolute positive control of all outbound network connections with as few of those as possible, and no dependence on someone else’s monthly compute fees.

              Local always, remote only when absolutely unavoidable, and then stripped to the bare minimum. I’ll run my own NTP server so that only it has to reach outside for time updates, and every other local device can get time from it.

              NO. CLOUD.

              • brimlar@lemmy.world
                link
                fedilink
                English
                arrow-up
                2
                ·
                4 hours ago

                It’s fine to have these feelings, it just depends on your comfort level. For my home / personal life, I agree very much. For business, not so much (but, depends on your business).

                • Appoxo@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  ·
                  4 hours ago

                  For business you should be able to fully control the VM, back it up and restore it somewhere else.

                  If you can’t do that ypu are chained.

                • NaibofTabr@infosec.pub
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  edit-2
                  4 hours ago

                  OK, maybe no cloud is a bit extreme, I’ll grant that. Maybe your business needs some clunky, minimum-effort, rent-seeking SaaS crapware like Salesforce… fine

                  IaaS? No. Nope. Not for anything we actually need.

                  No cloud for anything required to manage and maintain the local network or user accounts. If the external network goes down, we’re still operational internally, we have our own domain and authentication servers, everyone can still login and run any locally deployed applications (which we prefer, so most of our business needs are served that way). We’re not going to lose corporate data to the latest AWS leak, we’re not going to be dead in the water because AWS East went down again, we aren’t going to have to reasess our budget because AWS raised their monthly fee again.

                  It’s not about “feelings”, it’s about proper risk assessment and mitigation.

                  You can outsource labor, you can outsource storage, you can outsource compute, you can’t outsource risk.

  • schipelblorp@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    158
    ·
    16 hours ago

    US: Let’s sanction everyone everywhere all at once!

    Also US: Why don’t people want to be dependent on US systems? 😭

    • Ech@lemmy.ca
      link
      fedilink
      English
      arrow-up
      27
      ·
      13 hours ago

      Couldn’t undermine the country more if they tried, which makes one wonder.

      • Jaysyn@lemmy.world
        link
        fedilink
        English
        arrow-up
        41
        ·
        12 hours ago

        Yep. Trump’s actions are no different than what any bad actor would do if they wanted to destroy the USA without invading it.

        • Destroy our soft power… check!
        • Turn allies against us… check!
        • Destroy our economy… check!
        • Drastically weaken our military… check!
        • SeductiveTortoise@piefed.social
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          And I’m accepting that he does it because he’s likely a Russian asset, but why the fuck are the rest of them playing along? You can’t tell me they’re all being bought.

          • peathah@fedinsfw.app
            link
            fedilink
            English
            arrow-up
            1
            ·
            4 hours ago

            They want corporate slaves, if the us is governed by the rich and corporations, corporate cities/islands they are trying to build are not needed anymore.

    • CIA_chatbot@lemmy.world
      link
      fedilink
      English
      arrow-up
      47
      arrow-down
      1
      ·
      16 hours ago

      Yea we got a bit of the “inmates are running the asylum” situation over here.

      In the immortal words of the joke (paraphrased) this country needs an enema

    • benjirenji@slrpnk.net
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      1
      ·
      14 hours ago

      I wish. Organizations and countries/municipalities are far too lazy to make the change.

      • shalafi@lemmy.world
        link
        fedilink
        English
        arrow-up
        11
        ·
        13 hours ago

        The time and money involved are both staggering. This isn’t about you switching operating systems on your personal laptop.

        Where are you going to get support staff anytime soon? All those Windows admins magically switching to Linux overnight?

        Hell, Linux offers nothing remotely comparable to the power of Active Directory. That alone will keep Windows in the lead.

        And more. This isn’t about lazy.

        • The_v@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          7 hours ago

          Time + motivation + money can overcome a lot of obstacles. It also helps that template of what is needed already exists in Active Directory. This changes the project from “innovating something new” to “a slightly better copy” and is usually a lot faster and easier.

          All copyright/patents are also void because of the sanctions at least in practice.

        • Valmond@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          12 hours ago

          I have worked in big company where linux and windows coexisted, but we were developers so maybe that’s why (IT was very strict though).

          • timbuck2themoon@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            2
            ·
            8 hours ago

            Red hat IDM, aka freeipa.

            Depending on what youre doing you absolutely don’t need active directory.

            Hell, a lot of orgs are just going entra anyway. If you’re using SSO like that or okta or keycloak you likely don’t need AD.

          • SparroHawc@piefed.world
            link
            fedilink
            English
            arrow-up
            4
            ·
            10 hours ago

            At this point, a lot of entities don’t need AD because their entire workflow runs in a web browser, and practically any SSO provider will work.

            That said, accessing actual computer resources can be managed with groups and ACLs. Perhaps not as elegantly or as well-integrated as AD is, but that’s the price you pay.

  • CapuccinoCoretto@lemmy.world
    link
    fedilink
    English
    arrow-up
    63
    ·
    15 hours ago

    All middle powers need to align and collaborate on this. There is limited programming talent and gaps and especially security (ai) gaps need to be filled. EU, UK, Canada, Aus, NZ, SK, Japan should actively pool resources.

    • Canajan@piefed.ca
      link
      fedilink
      English
      arrow-up
      33
      ·
      15 hours ago

      Now we need to convince Canada to do the same. If everyone leaves Microslop, that would make a huge impact.

      • Bluefruit@lemmy.world
        link
        fedilink
        English
        arrow-up
        28
        ·
        14 hours ago

        From the article:

        Its use of the Nix package manager means that each package is installed in its own directory with immutable and signed contents. That alone means that the setup is incredibly easy to reproduce across multiple machines, something that is an obvious benefit when dealing with different facets of a government.

        Id argue an immutable distro would likely serve the same purpose but maybe its also because nixos isnt as “locked down” so itd be easier to configure for a specific purpose?

        • kubok@fedia.io
          link
          fedilink
          arrow-up
          2
          ·
          3 hours ago

          Thanks. I read Smiletolerantly’s comment as a personal opinion, rather that a summary of the article. I read several articles in Dutch news outlets, but the main message was ‘hurr-durr-Dutch’.

        • punkfungus@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          11
          ·
          11 hours ago

          The big draw is probably that it’s declarative, so you can define installations as code much the same way as you would do with Terraform. Instead of needing a pile of messy Ansible playbooks running custom scripts to change anything (and which can break if the target machine has an unexpected config), you’d just have one that pushes a new version of the config and runs nixos-rebuild. Rollbacks are just as easy if anything breaks. What’s not to like?

          • Bluefruit@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 hours ago

            Right so in that way, its very reproducible. That was my understanding and I appreciate you for the more in depth explanation but is there advantage to that versus an immutable distro? Wouldn’t a immutable distro work in a similar way being reproducible among many machines?

            Rollbacks can be done on immutable distros as well right? I’m just curious why Nix was the first choice and not something immutable.

        • adarza@lemmy.ca
          link
          fedilink
          English
          arrow-up
          2
          ·
          11 hours ago

          nix is on a whole different level than silverblue and other ‘atomic’ distributions.

      • rozodru@piefed.world
        link
        fedilink
        English
        arrow-up
        15
        ·
        13 hours ago

        from a sys admins perspective it’s painfully easy to deploy across hundreds of machines. NixOS is declaritive and immutable. you can take one system configuration of NixOS and throw the same config on as many machines as you want. packages, dotfiles, whatever are all replicated the exact same way on each machine. You can lock all the packages/apps, configs, kernels, etc to a specific version therefore a sysadmin may only need to upgrade the lot once a year. if a user some how breaks their system it’s as easy a fix as rolling back to the previous generation with a single menu option.

        So basically say you have your computer and you want to replicate your exact setup to hundreds of other computers. with NixOS it’s as simple as setting up a git repo for your nixos config, pushing to it, installing nixos on every other computer then cloning your repo to all the machines and rebuilding. done. now you have hundreds of other computers that all behave and work the same way your computer does.

        If something needs updating or a fix needs to be rolled out all a sysadmin has to do is fix it on one machine, push the change, pull it for every other machine and rebuild. done.

        • smiletolerantly@awful.systems
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          Or just configure all the machines to auto-update from the flake at the repo. Doing this for my VMs. I have a CI machine that builds my pinned flake from the repo tip, and about 30 other VMs check nightly if the repo tip has moved, and if so, rebuild from the new tip; which, thanks to the CI machine, means just downloading and activating a new generation, nothing compute heavy.

      • BrianTheeBiscuiteer@lemmy.world
        link
        fedilink
        English
        arrow-up
        51
        ·
        16 hours ago

        My guess would be the deterministic configuration management. If it’s for a personal machine then do what you want to make it your own but if it’s an organization (e.g. government) you want the machines to be as similar as possible to reduce maintenance. Think cattle, not pets.

        • 0x4f1@lemmy.world
          link
          fedilink
          English
          arrow-up
          8
          arrow-down
          9
          ·
          16 hours ago

          Ansible is a thing though. It is also a more complete, mature and easily substitutable solution vs pinning your hopes on a single distro.

          Programmers like NixOS because they are programmers.

          • Godort@lemmy.ca
            link
            fedilink
            English
            arrow-up
            35
            arrow-down
            1
            ·
            16 hours ago

            Ansible is US-owned. Even though it’s open source, Redhat, a US company, is the one that controls its lifecycle.

            NixOS is based out of the EU.

          • NewOldGuard@lemmy.ml
            link
            fedilink
            English
            arrow-up
            12
            ·
            15 hours ago

            I mean they sort of serve different purposes. You can build a NixOS ISO running your exact desired configuration that is good to go immediately upon install. Ansible would require post install configuration, yes it is scripted but it is additional overhead and time. I think a better alternative would be an OCI based distro with a Packer build pipeline, which could include Ansible steps higher up in the build process. But that’s more complexity that Nix wouldn’t require

          • 7EP6vuI@feddit.org
            link
            fedilink
            English
            arrow-up
            8
            ·
            15 hours ago

            i used ansible some years ago and i’m using nixos currently and you can not compare those two.

            i was not fluent in ansible and i’m not fluent in nixos. yes you have to leave your comfort zone for nixos, but your get so so much more.

            the jinja templates in yaml feel like a big hack if you used nixos.

            would really be interesting to hear someone talk who is comfortable to use both of them.

            • qqq@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              7 hours ago

              I’m honestly amazed ansible still exists. I used it regularly like 10 years ago and never liked it. I use NixOS for all my servers and package all my code as nix flakes, and I agree that they’re barely comparable.

              NixOS is a kinda frustrating desktop distro to me though. Sometimes you just wanna type make

    • [object Object]@lemmy.ca
      link
      fedilink
      English
      arrow-up
      4
      ·
      15 hours ago

      The only thing is this doesn’t yet do online user directories, local users only

      Which is a big constraint right now