Vanilla OS: New, highly secure, immutable Linux distro

Vanilla OS: New, highly secure, immutable Linux distro

????

Vanilla OS installation and demo, including an explanation of what is meant by an immutable operating system, and how this is implemented in Vanilla OS to improve stability and security. Vanilla OS can be freely downloaded from: https://vanillaos.org/ You can find a detailed explanation of abroot here: https://documentation.vanillaos.org/docs/ABRoot/ In the video, I mention Windows CE, which I made a video about here: https://www.youtube.com/watch?v=VES1KHFa_vk I also mentioned some other immutable Linux distros, which were: Bottlerocket: https://aws.amazon.com/bottlerocket/ Talos Linux: https://www.talos.dev/ and Fedora Siverblue: https://silverblue.fedoraproject.org/ Finally, my recent Blender tutorials are here: https://www.youtube.com/watch?v=EsufneMOvWA https://www.youtube.com/watch?v=srogwyiO2mI For additional ExplainingComputers videos and other content, you can become a channel member here: https://www.youtube.com/channel/UCbiGcwDWZjz05njNPrJU7jA/join More videos on computing and related topics can be found at: http://www.youtube.com/@explainingcomputers You may also like my ExplainingTheFuture channel at: http://www.youtube.com/@explainingthefuture Chapters: 00:00 Introduction 00:51 Secure & Stable (what is an immutable OS?) 04:32 Bare Metal Test (installation) 07:59 Vanilla GNOME 13:13 Installing Apps 17:46 A Daily Driver? #VanillaOS #ImmutableOS #Linux #explainingcomputers

Advertisement

LEAVE YOUR COMMENT

LATEST COMMENTS

@dickbrmly Says:
Tough to remove
@sarwerahmed9964 Says:
Sir make a review on garuda linux pls
@ThirtytwoJ Says:
ohhh so its like android in modern phones.
@UniVerseVibes. Says:
Hey will it identify my hhd (which have some files like photos etc and i used it on windows) although zorin os isn’t
@sevenfacedsin Says:
I really wanted to try this as I like the concept, and am very familiar with the Ubuntu/Debian base, but I cannot get the latest version to boot at all on my PC. Every other distro works flawlessly. No clue what is going on.
@umardev500 Says:
Mint still good for minimalism
@Linux4theMac Says:
This was great video Chris; thanks again for amazing content!
@tsvigo11_70 Says:
Можно сделать это самому - отключить обновление apt upgrade и заблокировать общее ядро Линукс и конкретное ядро Линукс и установить distrobox..
@tekki2060 Says:
This version does NOT recognize Adaptec controllers. So, if you're using SCSI then you'd better take a pass and find a more complete version of Linux.
@silverian Says:
Thank you for IT teacher style of explanations! (This is what my instincts tell me.. like in one movie where character says one policeman knows another...) I liked how the basic things were explained very well and where you find all those menu and other things.
@TomAtkinson Says:
My questions would be what about /etc/hosts /etc/sysctl.conf /etc/ssh/sshd_config etc
@jakobw135 Says:
In The Gnome version of this OS that you were testing, when you have the screen where the icons are displayed in the center in several rows and columns and above, at the top, are two panels one next to each other - what are those? Can you install other desktops or workspaces - like KDE Plasma and Cosmic, so that you have: them together in rhis distribution, and can switch between them?
@jakobw135 Says:
What is Vanilla OS BASED on?
@stubaccount Says:
guys, I'm switching from gentoo(not switching actually). Is my prior linux experience good enough for vanilla OS, or no?
@frankfriedlos3721 Says:
Whilst adopting the "empirical approach" (aka tinkering about) I imaged a bootable HaikuOS USB onto an internal HDD using dd from a second bootable MX Linux USB. It worked! I had a vintage old laptop that started straight into Haiku. However it soon became apparent that I could not update this machine because the format was still ISO9660 which is strictly read only, i.e. I had created a pseudo immutable instance. It occurs to me that one could (I think) do this with any Linux distro that can boot into a try-it-out version, which is most of 'em. Set it up with a writable persistence partition (encrypted of course) and you have a secure system. Or not? I was reminded of this whilst reading about the Crowdstrike debacle, hence this comment being a somewhat belated. But hey, 'spect someone's still reading it.
@Triro Says:
This is a very interesting take on Linux.
@LouisBlanchard Says:
I'm on the fence about immutable Linux distros... Almost feel MacOS is like that, I like to tinker under the hood sometimes with my Linux mint 😂I can see the appeal to Linux new comers however👍
@acajoom Says:
Missing minimize and maximize is pure madness 🙂 Is like disabling mouse scroll.
@beetlebopter888 Says:
finally, someone that talks to the common person, without all the technicalities of the terminal.
@AaberPyadeh Says:
They should simplify the manual partitioning option like ubuntu, dual boot is not a very good option for this os
@bonytologna Says:
It’s too bad the developers of GNOME didn’t specify the pronunciation as G-Nome, like the human genome. It would sound so much cooler than what currently sounds like somebody who doesn’t get the concept of a silent G. Gotta love Linux marketing hahaha.
@christopher9727 Says:
Jesus Christ saves He had mercy on me he can save all who all seek him today He made away through calvery repent of all sins today Romans 6:23 For the wages of sin is death, but the free gift of God is eternal life in Christ Jesus our Lord. Come to Jesus Christ today Jesus Christ is only way to heaven Repent and follow him today seek his heart Jesus Christ can fill the emptiness he can fill the void Heaven and hell is real cone to the loving savior today Today is the day of salvation tomorrow might be to late come to the loving savior today Holy Spirit can give you peace purpose and joy and his will today John 3:16-21 16 For God so loved the world, that he gave his only begotten Son, that whosoever believeth in him should not perish, but have everlasting life. 17 For God sent not his Son into the world to condemn the world; but that the world through him might be saved. 18 He that believeth on him is not condemned: but he that believeth not is condemned already, because he hath not believed in the name of the only begotten Son of God. 19 And this is the condemnation, that light is come into the world, and men loved darkness rather than light, because their deeds were evil. 20 For every one that doeth evil hateth the light, neither cometh to the light, lest his deeds should be reproved. 21 But he that doeth truth cometh to the light, that his deeds may be made manifest, that they are wrought in God. Mark 1.15 15 And saying, The time is fulfilled, and the kingdom of God is at hand: repent ye, and believe the gospel. 2 Peter 3:9 The Lord is not slack concerning his promise, as some men count slackness; but is longsuffering to us-ward, not willing that any should perish, but that all should come to repentance. Hebrews 11:6 6 But without faith it is impossible to please him: for he that cometh to God must believe that he is, and that he is a rewarder of them that diligently seek him. Jesus
@MountainParameters Says:
After seeing this, and needing to place a Linux based machine on my network, I installed this, and used it for 4 months. I found the performance on older hardware to be pretty snappy until memory slowly got used up and not released back when the apps that were using it were closed. Last week I had to replace the machine, but decided on Xubuntu instead. THere was not one major issue that led to me giving up on Vanilla, it was more like death by a thousand cuts. THere were things I appreciated, such as it recognizing varous video cards, the Gnome ver II desktop, and finding my printer with ease. The cuts that seemed to give me the greatest annoyances were, dealing with APX, and memory not being released and thus slowing system perfomance and necessitating reoot. Now that I am using Xubuntu, I seem to encounter a number of different issues. For example, where I was annoyed that I had to manually reconned to my SMB network shares every time after a system boot (although autofill did make it easy), in Vanilla my network speeds were correct, whereas I cannot figure out yet why they are down to an average of 259 Kib/sec with Xubuntu. Xubuntu also has other issues that users have been seeking resolve on for years that apparently have not been addressed (for example a common work around for users wanting to connect from a Windows machine is to use an SFTP client such as Filezilla, and the need to install xscreensaver to manage screen power options because the native screensaver does not work beyond the defaults, and has not been fixed in years). Given that I found seeking out support for Vanilla specific issues was difficult, and Xubuntu is similar, I'm starting to think that it may be best to use a distro that has the widest degree of available support if I also give up on Xubuntu.
@SkyFly19853 Says:
They are about to release their newest version. I play offline games from GOG as well as iso and exe. I am curious about how the gaming is on Vanilla OS...
@markgholson9222 Says:
Puppy Linux has immutable system files for more than 15 years.
@GenaDominicano Says:
it's unlogical that I have to move mouse to top left corner and then bottom center - why not put icons on top left vertically or horisontally?
@mnkh-r6i Says:
I need an daily driver. I am fed up with linux mint xfce because its breaking things. Tried in several systems still its unstable.
@mnkh-r6i Says:
Good evening Ladies and Gentlemen. I am an linix mint xfve user, the system is breaking I had installed this in several machines but linux mint in unstable. I have 512 Gb ssd and wants to do manual partitioning I usually do 100Gb for root, 8GB for swap, 1GB EFI partition, 1GB for Grub and Rest available space for Home. My main doubt is If I am installing vanila OS should I create 2 root partition or If I create 1 root partition does this automatically create another root partition. My another concern is Could I install XFCE desktop environment in it like other linux operating system. I also need fingerprint to work. Could any Vanilla OS users reply to my doubts I have lots of data in my system and if its breaking apart I will definitely loose all data.
@zwqcv3jc Says:
Thanks for a great explanation of Vanilla. It reminds me how many nice advances have been made in Linux since my first introduction many years ago. At that time, Linux was a challenge to use. No longer!
@gjforeman Says:
Just found this video, as I am looking for a new distro to replace Mint 21.2, which seems to be having a real problem just freezing randomly on my 10+ year old PC, a 64-bit, Phenom2 with 8G of RAM. Win-10 runs on it just fine, as do other distros I have tried lately. I have 3 switchable SSDs, with one still limping along with Mint 21.2, one with Win-10, and a third empty one, giving me one "bare Metal", (if you can even say that about a SSD), drive to experiment with. I'd really like to find a Linux distro that either incorporates TOR functionality from the start, or will allow it without hours slogging thru the Terminal screen. Anyway, great video, as always. Thanks. Will be giving Vanilla a try.
@GWFO Says:
VANILLA OS 2 VS BLEND OS?
@galihpa Says:
I would at least wait for one more version release before trying it for myself or deciding whether I should make it my daily driver or not, I'm getting bored with my manjaro pc
@AlShurooqi Says:
You have only installed flatpaks you did not use the sube system like Suse or Fedora
@davidwayne9982 Says:
There is NO "flow" as they call it to the Gnome G-arbage!!!
@davidwayne9982 Says:
NO IT IS NOT prnounced G-nome-- that goes AGAINST ENGLISH rules.. no matter what the creators or any other fools say.. not to mention is sounds retarded.
@mebeingme947 Says:
Really don't see the point in it. Things like malware can still make their way as I understand it. Since most distro's install rather easy and fast these days I rather would go for a good protected and backed up seperate home directory. That way you've at least the freedom of installing apps the way you want. Another issue I found with browsers in flatpak is randomly crashing if hardware accelaration is on. Later on I found in flatseal that browsers in flatpak have this standard turned off in the flatpak configuration and turned on in the browser itself. After switching on hardware accelation in flatseal...all problems were gone.
@human__________ Says:
looks like a very good distro and i would be open to using it now that they're moving off of ubuntu for sid. but they would need to offer something other than gnome. personally i would be open to KDE that can be configured(i don't think this is currently possible) or a pre configured window manager setup. (see the distro archcraft as an example of this) wont be holding my breath for any of that though so, i guess i'll just be sticking with my old friend Debian.
@skewty Says:
This was like a car review that says look, the engine starts when I turn the key, it has 4 wheels that aren't flat and never taking it for a test drive.. Amazing.. Not! The big feature is the multi package manager support and that wasn't tested at all. Show's the video creator totally missed the point of the OS. What a shame.
@AntonyShen Says:
Is it possible to install any input methods like fcitx5 on Vanilla OS? It's essential for Asian users but an optional component to westerners.
@KB-yf4mb Says:
ABRoot = Always Booting changes.... Nice try Microsoft.
@tech29X Says:
Yet another Linux Distro; This ones fame to claim is security, yawn...🥱🥱🥱 No such thing as secure OS/computing unless you build your entire computing system from ISA, micro code, BIOS/UEFI all the way to OS and every device driver, all on an open source, peer reviewed platform. Risc-V is a step towards that direction, but not sufficient.
@johnbaldwin143 Says:
Excellent presentation and explanation. Sadly nothing is immutable as some one some where will always find way. It may be through a third party app. Or it maybe (most likely) by social engineering. The reality is the biggest flaw we have is ourselves' we try to shine against our own pride and ego. To put it bluntly? Shut up and remember why you followed this path! Remain the little person; remember why you took a stance?
@limpa756 Says:
it's moving to debian sid, which in my experience is absolutely pointless you might as well move to arch
@moonrock41 Says:
Chris, I noticed that your system drive (SSD, I assume) is running very hot: 210 degrees F! Wow! Shouldn't the fans in this PC keep it cooler? I imagine such high heat is likely to severely damage your drive if you continue to let it get so hot for much longer.
@littlezero6399 Says:
So if the software you installed were flatpaks, are they stored in a writable directory for the user that installed them and only available for that user? Or can all users of the use them as long as they have access to that directory? I am curious how it works with updates or things that are not flatpaks. Does it default system updates to the staged environment? How do you tell the system that you would like to make that new environment the primary? Or am I misunderstanding how it works? I am realizing I probably just need to download it myself and try 😀.
@Masters-rc9sc Says:
Him: Windows CE couldn't be corrupted by malware or user error Everyone else: But it's still Windows....made by Microsoft. Sooooooo
@GP-MB-Baden-WurttembergDeutsch Says:
I used to run long time Fedora 20 and I can see it is straight forward easy to install Vanilla OS. We are in a world nothing is 100% secure. Thank you for awesome video I really appreciate 😊 😉
@Apollo49152 Says:
Did it show your SSD was running at 99c?
@JS-kr7zy Says:
My interest in linux is almost entirely based on having a better desktop environment. Gnome sucks.
@johnostambaugh8638 Says:
A USB drive with a read only OS would be useful. Same with a memory stick with a read only OS.

More Programing Videos