Does making a seperate template for each appvm increase security?

In theory, yes. In practice, not every package installed and passively sitting out there increases the attack surface, and micro-adjusting everything creates enormous overhead. Given “most purposes” today are running yet another web app and do not require more local software…

Well, the fact that I have no idea of which exact overhead you meant on could give a clue of its actual non-existence… At least when I am.

If you feel ok spending serious amount of time hand-picking all the packages and dependencies you need from the scratch before starting every task… I cannot reach the OCD levels required to think of this as “non-existent overhead to natural process” :))

I agree with that. But isn’t that initial “overhead” only? Like, building a house overhead, and after that just maintaining? So, either you want your house properly built, or… you find “more convenient” one for you?

I had that 'overhead" on F36, and years after now I’m on F40/41 never ever had to have it again.

for recurring patterns that definitely makes sense, but when there is not much of that… I have slightly more than 10 templates and it covers most of my use cases. Some VMs have extra stuff installed to private volumes via flatpak, snap or pip. And major part of activity is done in DVMs.

1 Like