Hello, I am looking for a well-supported Linux / BSD distribution with focus on following features (in no particular order) -
- Systemd free (found some here)
- Security focused (meaning hardened, not security tools)
- Wayland (preferably without anything X11)
- Lightweight (as much as possible)
- Supports flatpak, containers and VMs (preferably libvirt)
- Atomic (more optional then other requirements)
This is expected to be run on real hardware on desktop (so alpine will not work).
Along with that, what are some good lightweight (but well-known / actively maintained) desktop environments for Wayland?
- I see some here but am looking for opinions or if some are missing.
- Especially ones that support stacking.
The most interesting ones I could find -
- Void Linux (has some X11 stuff, not security focused, will try installing Wayland)
- Kicksecure, OpenBSD, HardenedBSD (yet to explore more for these)
- MXLinux and Artix (seem very niche)?
I am looking for more recommendations/opinions for similar requirements, especially if there are better known ones.
Why not systemd? You seem to want futuristic and secure things like Wayland and flatpak, yet don’t want the security benefits of systemd?
Basically for same reasons that other people have mentioned in this thread + maybe a few more.
I will probably create a separate post about it.Probably because of its compliance with age verification standardization.
You mean the change that was writen as an act of malicious compliance, by someone opposed to age verification laws, in such a way as to make an easy end run around them for all Linux developers, but then everyone went off half-cocked and started sending the author death threats? That compliance?
Dominik sees practical, non-surveillance uses for the field, like tailoring workshop laptops to age-appropriate defaults without restricting access to anything.
No one deserves death threats, but per the quote above, the existence of the setting still encourages distributions to ask for the user’s age at setup, as apps may require the setting to be enabled to know how to handle the user’s data and which experience is best suited for them.
While this may automate the parental control process for parents, many users don’t want their data used by software in ways they don’t consent to, even if it doesn’t leave the device.
Thats kinda the point of the malicious compliance though. It’s an optional field. By default, distros can choose to ignore it or auto fill in 1900-01-01. In places where it’s required by law, adduser can ask and it will accept anything. The same way adduser currently asks for your real name, phone numbers, and room number but does not give a fuck what they are or if you fill them out.
The parental controls issue is actually a bigger deal. I would love to give my kids a Linux laptop that could actually protect their privacy while also giving me good parental control tool, but such a thing does not exists. Yes, if you do a quick search for “Linux parental controls” you’ll find some things, but they are clearly half-assed attempts that don’t really work. This absolutely doesn’t either but maybe it’s a step in that direction. Instead, I do what most schools and parents do and give them a Chromebook because it has a good, though not great, parental control system.
Let me be clear, I am also opposed to age verification laws and have written, called and had meetings with my representatives to oppose them. It’s been somewhat successful, though not as much as I would like.
In the end, malicious compliance that allows FOSS developers plausible deniability is better than ignoring the laws and hoping that you’re not the one they decide to make an example of.
Or the other issues listed at the site posted by the OP: https://nosystemd.org/
Will we ever get to the point where we are too tired to explain why we hate systemd, and the point where we get respect for deciding to not use systemd? To me it’s about the same level of asking me “why be a lesbian” now.
“Ok grandpa let’s get you to bed”
hardened
This is an important keyword but perhaps not sufficiently discussed. I’d reckon focusing on it will be pretty helpful.
So…, what is it you want? Is it
- A. Make a fortress out of a very decent starting point? To daily drive it afterwards*.
- Or B. Daily drive a fortress built by someone else?
- Or perhaps even C. Something else entirely?
By the rest of your post, I’d bet on B. Which, puts us into an interesting situation…
systemd free
Assuming[1] DistroWatch does a decent job at tagging/categorizing, there are only a handful of distros that are both systemd-free and tagged with “security”. Note that half of these don’t survive it upon closer inspection, which leaves us with Alpine, HardenedBSD and OpenBSD.
If you’re well-versed into hardened distros, you’ll note the absence of Linux’ finest in this category; namely Kicksecure and secureblue. Their absence is due to their (heavy) reliance on systemd for additional hardening.
Furthermore, note that DistroWatch doesn’t mention how well the likes of Artix, Gentoo and Void (among others) would function as excellent starting points to build your own fortress from.
To be honest, I don’t see any reason to not grant them the benefit of doubt. As far as I can tell, their lists look complete. ↩︎
Thank you for reply.
By the rest of your post, I’d bet on B. Which, puts us into an interesting situation
Yes, I would be ok with A as well, but I am learning things slowly to get to that point. So B for now would be great.
But it seems like OpenBSD might not be great for running VMs - https://redlib.catsarch.com/r/openbsd/comments/11ev3l4/is/_it/_a/_bad/_idea/_to/_use/_openbsd/_as/_a/_vm/_host/
Could not find much info for virtualization support on HardenedBSD though.
Not sure how well bhyve work there, but it seems like VMs might not work well or be performant enough on either of them.I would try with Alpine, Artix or Void for now.
Thank you for reply.
It has been my pleasure! Thank you for replying back :) .
Yes, I would be ok with A as well, but I am learning things slowly to get to that point.
While I absolutely respect that attitude, it’s worth noting that literally none of the hardened and respected distros are a one-man show. Which is my way of saying that unless you pursuit a career in cyber security, you’re probably better served elsewhere.
So B for now would be great.
Aight. Excellent.
But it seems like OpenBSD might not be great for running VMs
IIRC, it depends. If a TTY/terminal-interface is all you need, then
vmmhandles that pretty well. But if you’d like to run applications that have their own graphical interfaces, then OpenBSD’s solution might not be adequate. At least, it wasn’t the last time I did a thorough check on the distro.Could not find much info for virtualization support on HardenedBSD though. Not sure how well bhyve work there, but it seems like VMs might not work well or be performant enough on either of them.
IIRC, bhyve is pretty good actually. Performance-wise, it is good enough to do gaming even. As HardenedBSD is simply hardened FreeBSD, I don’t have a serious reason to assume it ain’t able to do that.
On that note, I want to mention quBSD as an interesting project. It kinda aims to bridge the gap between Qubes OS and FreeBSD. Its developer hasn’t released anything yet, but it’s worth keeping in mind.
Having said all of that, I want to state clearly that there is a disconnect between what’s out there and what you want:
- Alpine is pretty decent security-wise, but -like literally most other distros out there- security is somewhat of an afterthought. Like, unless it is a platform-wide accepted ordeal, it will not consider pro-active hardening. This also more-or-less applies to the likes of Artix, Gentoo and Void. So, it relies on your expertise for serious hardening.
- OpenBSD’s
vmmdoesn’t do GUIs. - Kicksecure and secureblue while being Linux’ finest security-wise, do rely on systemd. Same applies to NixOS derivatives like SécurixOS and Spectrum OS.
- HardenedBSD. Which, actually looks pretty fabulous otherwise, may not support flatpak. Don’t quote me on this, though*.
- Qubes OS’ system requirements are too high, as you point out elsewhere.
So…, what does that leave us with :P ?
Is an amalgamation between sixos and nix-mineral in which you try to port all systemd-related hardenings the best we can do?
However, I’d argue that a possible eventuality might yield us an actual winner.
Recently, Flatpak’s maintainers/developers noted work on Flatpak Next; a successor to Flatpak, if you will. The hope is that it’ll eliminate some of Flatpak’s glaring issues. However, they also announced that it will depend on systemd.
Granted, the eventual thing we’ll receive might not depend on systemd at all. Heck, even if it will, perhaps some distro maintainers will provide a workaround OR just keep on relying on the old flatpak that might get new maintainers. So, there’s absolutely no reason to go full-on FUD right now.
Yet, an out does exist that doesn’t depend on anything of the above; simply by not requiring flatpak support. In which case, HardenedBSD it is. FWIW, with access to VMs, you can also continue to enjoy your flatpaks through a VM. Which, literally happens to be the simplest fix to salvage an “almost”.
P.S. if you didn’t figure it out yet, your query is something I asked myself a couple of years ago 😅.
P.P.S. I forgot about Chimera Linux. I’m not well-versed into it, but perhaps another interesting one to consider. At least alongside Alpine, Artix, Gentoo and Void.
OpenBSD
It seems like OpenBSD does not have good support for VMs - https://redlib.catsarch.com/r/openbsd/comments/11ev3l4/is//_it//_a//_bad//_idea//_to//_use//_openbsd//_as//_a//_vm//_host/
Wtf so you mean Alpine will not work on real hardware on desktop? I run Alpine on real hardware for a desktop. The only issue you’ll run into is video games not playing nicely with musl, but there’s compatibility layers you can use for that.
Void works fine with Wayland. It isn’t security-focused. Same goes for Artix.
OpenBSD is security-focused, but has limited Wayland support. Sway works on it, but there isn’t much Wayland software, and it’s missing some crucial things like xdg-desktop-portal.
Thank you for reply.
I will checkout Alpine. It sounds interesting.
Video games are not my focus, do you know how do VMs run on Alpine (with Alpine as VM host) - performance wise?
I have not tried running VMs on Alpine. KVM/Qemu does seem to be supported according to the wiki.
Gentoo might be what you’re looking for.
Maybe, but I feel like it would take a lot of effort to make it hardened and daily drive it.
I might try it at some point though.
You might be able to build your own image with Universal Blue
It seems to be Fedora based, so running without systemd might be much harder.
Open BSD, except it doesn’t support flat pack. But it’s everything else you want
But, I wouldn’t recommend using it as a desktop. If you want real security and isolation, look at qubes for your desktop.
Qubes uses xen, a real microkernel, as the hypervisor, which reduces the risk surface of VM escapes tremendously, then you run your untrusted services in their own vms.
Qubes OS has very high system requirements, so that would not work.
I’m using artix with cosmic desktop. It’s light enough for my 15 year old laptop. I haven’t tried it yet, but Chimera Linux seems to fit what you’re looking for.
Thanks, will check it, if not as host then as a VM. It is being recommended by many people.
Artix is great if you don’t mind Arch. Devuan is great if you like lightweight Debian (server install). MXLinux is nice if you want Debian with a usability/UI focus. As for security focused, I don’t know what that means. A machine is either secure or it’s not. Chuck SELinux on there if it helps you sleep at night.
A machine is either secure or it’s not
It can be more secure then others. Security focused (or hardened) means things like less attack surface, more careful review of packages and code, using more secure alternatives then others, among other features like kernel hardening, etc.
I plan to check Artix though, thanks.





