Fedora CoreOS and SilverBlue Templates

Hello,

Would it be possible to explore the idea of having CoreOS and SilverBlue templates? These distros

are designed for containerization and would increase security and flexibility of the current template scene

1 Like

They’re rather designed to provide the functionality of transactional updates to a system that runs predominantly containerised user software. I’m curious how you see this as being any flexible and whether people more knowledgable about Qubes see containerisation as bringing anything meaningful security-wise to an already compartmentalised operating system.

1 Like

You can create your own templates. It won’t be easy but here are some links:

1 Like

Why would creating a qube with Fedora Silverblue require so many steps — can’t an iso file be installed on a qube more simply such as in VirtualBox?

Having an immutable OS makes it more difficult for an adversary to escalate privileges within the OS and could help to prevent them from escaping the virtual machine.

I think immutable OS’s is one of the changes @demi (from the Qubes team) noted as important as well in her talk from the 2023 Qubes summit (on youtube). But I can imagine there are some implementation challenges that make it hard to implement.

Feel free to watch Demi’s talk. I can recommend.

1 Like

Thanks for sharing! Is this the video? There are several 8 hour 2023 summit videos.

1 Like

This is it https://www.youtube.com/watch?v=_UxndcxIngw (I think it’s the same)

It starts at 2h22m.

2 Likes

It’s actually really interesting! I’m going to go through the whole presentation :blush:

1 Like