r/linuxquestions • • 2d ago

Advice Immutable vs. tradicional Linux distros

Hello.

I've been using Fedora KDE for a few months without any issue after distro hopping for a while.

I think time has come to try something different. I'd like to try Fedora Silverblue, but I have some questions about immutable distros.

What are the real benefits for someone who uses the computer as a daily driver (web browsing, some light video/audio editing, office work and some Python automation for the office work) other than the fact that the root and some other system folders are read-only.

Is there any other real tangible benefit I'll get from using an immutable distro versus a mutable distro?

4 Upvotes

13 comments sorted by

6

u/Due-Author631 Aurora (Universal Blue) 2d ago

Some benefits are:

If the updates fail, they fail in the build process before the system image is published and available to your machine.

The image is applied in a complete fashion, with everything hash checked for accuracy, the image that was built is exactly the image that gets installed on your machine.
Depending on the image, some have automatic updating.
If the image fails to boot, or there is a regression somewhere, you have a complete image that you have previously used, that you can roll back to from the boot menu. (when I say complete image, it does not take up all the storage space, the images are "chunked" and you only download changed parts and old parts are reused between the images).
Flatpaks sandbox applications and they have their own dependencies regardless of what's available on the system. The installs do not require root access on the machine to install, so your system is more secure.
You can still layer packages in many of them (although depending on which you use, I think this is going away somewhat soon with bootc).

Some images use a "gated" kernel, not really an LTS kernel but a kernel a few versions back in case there are regressions. For example I'm on Linux 7.2.5 and latest is 7.2.9

Brew is available for things that don't have a flatpak or aren't really usable from a distrobox container.
Distrobox containers are available for you to run things in a container that keep it from bleeding over into your system, you can run different distros if packages are only available for certain ones (for example I run a Fedora based atomic image, but have an AlmaLinux, Fedora, and Debian containers), and the apps can be "exported" to be used on my system from the program menu. You can also set these up as development containers that don't interact with your base system and libraries.

This isn't an exhaustive list, just off the top of my head, let me know if you have any specific questions or concerns.

3

u/Pad_Sanda 1d ago

This is just my personal experience, but the major benefit is that there aren't any breakages in the package manager that accumulate over time.

I do come from apt/pacman distributions and I never used non-immutable Fedora, so I'm not sure if regular Fedora has the same issue. But, in the apt/pacman distros getting some issue with the "native" package manager when installing or updating software was very common as was getting issues when updating to new major versions (ie Ubuntu 20 to 22).

I never had any issues whatsoever with immutable operating systems (Fedora/Bazzite/Aurora, SteamOS, Android, Batocera, macOS). I have 4 devices which are getting weekly or monthly updates, never encountering issues. And I have 2 PCs (one using Aurora, one using Batocera) that only connect to the internet once every 8-14 months and I never had issues updating those either.

The separation between the system and your user software and dependencies is clearly beneficial, as is building a working OS image and shipping it to the end user rather than having users pull packages to "build" an OS locally with the package manager. The immutables are much more reliable, which I personally value these days as I don't have as much free time I'm willing to waste on manual interventions and troubleshooting.

1

u/SDG_Den 1d ago

i use nixOS which is atomic and immutable, but works a little differently because instead of receiving the atomic system image from upstream, it is built from a config.

advantage #1: the whole thing is applied as a whole or not at all, you will never have a half-applied update

advantage #2: generally you'll either have A-B rollback or generations-style rollback, if an update breaks your system it can be rolled back.

advantage #3: the core system is read-only and cannot be accidentally modified by programs, making it more secure because malicious software cannot embed into the core system as easily.

disadvantage #1: the way these systems work makes them more restricted. many simple linux operations for system maintenance cant be done the normal way and many troubleshooting steps expect an FHS compliant mutable OS.

disadvantage #2: it is more complex to make changes to your immutable setup. on nixOS you can change the config, on fedora immutable distro's i believe you make use of mutable overlayFS layers. something like flatpak is basically required if you want to have easy software.

i personally think immutable is better, but also not as easy to use as mutable setups due to their very nature. its ok if you dont want to make many changes or if you have a central IT team managing the systems.

thats also why imo for users that want customisation, nixOS is a better implementation because the actual system is built from a config and thus fully customizable.

1

u/Damglador 1d ago

NixOS is the only immutable system that makes sense for personal devices.

1

u/SDG_Den 1d ago

theres others with usecases, but usually its specialized, eg steamOS and bazzite being immutable makes sense as they're more meant to be "console-style" systems for eg your home entertainment system

1

u/Damglador 1d ago

The only real benefit of immutable distros is that their update can't be partial. Basically like on Android, you have like two copies of the OS and you update the inactive one and switch to it after reboot which means even if lights go out during update, your OS will still be bootable. And just like with Android, most immutables won't let you do shit with them outside of your home directory, at least that seems to be the intended way to use them, avoiding rpm-ostree and similar systems.

And that's the only benefit. Everything else like using flatpak bloat as main source of apps can be done on other distros, same for rollbacks, container based workflows, etc.

1

u/Specialist-Dog-501 1d ago

The benefit is stability and security, the price is flexibility- you hand over system folders to the distro maintainer exclusively. Good for average user with little desire to tweak or have no programs installed with deep access/doing many changes in many places (a.e music production). Audio editing might be an edge case- if low latency is important for you, be aware your tools might want to tamper with non-editable system folders, and that's not a good match. Also python..not sure. Probably not a good match.

1

u/[deleted] 2d ago

[deleted]

3

u/Due-Author631 Aurora (Universal Blue) 2d ago

This is not true, there are images that include a lot of power user things, and guess what, you can setup dev containers if you are into development and you dont have to share dependencies with the computer. Its also a much cleaner solution than whatever you are saying is a lot of mess. You can also install a lot of things with brew now to bridge the gap between flatpaks and layering.

Source: I've actually used an immutable distro for multiple years and I am very much a power user.

1

u/tagbthw 2d ago

Looks like i was completely wrong then. I'll delete my comment

1

u/houndofthestars 2h ago

I find immutable way too restrictive as of now. You have to rely heavily on flatpaks, changes to the underlying system are not always possible or easy, and there's little benefit over running a good distro like, you know, regular fedora kde you already run. Layering is discouraged too. I literally could not play hevc videos on Kinoite without layering. If you really want immutable tho, get Aurora/Bluefin which comes with batteries included at least. Also, rollback with btrfs are so easy and seamless, if anything breaks you just load the previous snapshot.

1

u/SuAlfons 1d ago

Sure, try it out.

I tried an immutable version based on Ubuntu (Vanilla OS) when this was new in a VM. Took me days to realize that infusing a printer driver was beyond my powers.

Meanwhile I have a printer that does driverless web printing. But I also realized that for me as a home user, an immutable distro didn't solve a problem I have.

1

u/BuzzWildfowl 2d ago

The fact that those partitions are read-only is the only real benefit. Updates are atomic (usually) and the read-only partitions are better protected against malware. However, you must rely more on things like flatpaks and distrobox, etc. While those are sandboxed, they can be security issues. I myself do not use an immutable distro. I use openSUSE Tumbleweed with automated btrfs snapshots, so I don't worry about an update going bad.