Why Use Minimal Templates?

Maybe you could add that using minimal templates is like using a “netinst” Debian/fedora ISO to install a system, and that depending on your use case, you may end up having to add manually a lot of packages, and do a lot of config manually.
Or maybe simply put : “if you’ve never used a netinst ISO or don’t know what it is, don’t use minimal templates”. But maybe in a nicer way ^^
(PS: I assumed the fedora server netinst is like the Debian one, but I’ve never tested it myself)

1 Like

Haha this is exactly me, how fitting, i am perfectionist :smiley: I Am everything or nothing xDD

1 Like

(placeholder for regular liteqube pitch here)

2 Likes

You should really not advise the use of minimal templates randomly:

@parulin I know, you posted this to me a few days ago and I actually read it, but as this thread was about how to remove packages from the defaults I couldn’t hold back. :wink: Your comment is valid and important though ofc. minimal templates are a bit expert focused. But its not that complicated to use them though, imho.

That being said, if you use minimal templates stuff like networking will not work by default, you need to install several qubes-bla packages in order to use them for pretty much anything. Your LLM of choice is your friend here, like “I want to use qubes template based on debian-13-minimal to install firefox, what qubes apt packages do I need if the VM to have networking?”

This is how I look on this. My idea is better something not to work, but to work with security omissions.

So, “learning basics” and “gradually reaching minimals” might be too late - system already compromised. I studied Qubes at least 3 years and sketched my qubes organization that reflected my threat model, before I installed it, and the very first install that ever happened was with all minimals (templates based on them) as defaults. I even waited for PVH, early 4.1 alphas because of hardware security.

Did everything worked out of the box? Nope. Almost nothing. But once it worked it was based on minimal. So I started from building sys-net’s minimal template and sys-firewall’s and didn’t go online from Qubes machine until I built them, sys-whonix is alreday there, and just created whonix-dvm-template which is not minimal by its nature, so got Tor Browser. Once I had that chain, I got access to online resources about how to bulid all other templates based on minimal.

So, I would actually encourage people first to read a lot about Qubes, then about minimals, then to install Qubes for the first time and build up templates with minimals. That is why we have things like this, for example

This is excellent guide what, and more importantly, how to test.

Any user can ask me which packages to install for a specific minimal template. I have my notes about each and everyone of them. For the needs I don’t have in my threat model, the user can open a topic with a specific subject.

For example:

Firefox-minimal

firefox qubes-core-agent-networking qubes-split-browser-disp mozilla-ublock-origin mozilla-https-everywhere mozilla-noscript pulseaudio pulseaudio-qubes qubes-audio-daemon tinyproxy --allowerasing

Even all of those aren’t needed, but they are pretty self-explanatory, so even novice can decide which to omit.

2 Likes