finally installed the tpm2.0 hardware, in preparation of #incusos (some other day)

#incus

So I saw a blog post linked on here the other week about someone's homelab where they use #Incus to run all their containers and VMs. And I've fallen into the rabbit hole.

That post: https://linderud.dev/blog/personal-infrastructure-setup-2026/

Anyway, Incus is the fork/successor to #LXD which as recently as last year they released #IncusOS which is a very slimmed down OS for running multiple types of containers and VMs. A bit like #Proxmox in a sense.

What I like about the distro:
- Immutable
- A-side/B-side partition layout for friendlier updates
- Requires Secure Boot + TPM, resulting in encrypted drives by default
- ZFS. I've loved ZFS for many years.

It really seems like this was built for edge type deployments where secure "appliance" like things really excel yet still a net benefit elsewhere.

Since vSphere was killed, this feels pretty damn close to what I liked about it.

Can already run VMs along side "System Containers" (shared kernel + init system) and "App Containers" (what everyone calls "Docker"). I see on the roadmap support for MicroVMs (OCI container + individual kernel).

I run all of my stuff bar storage on #k3s on baremetal but there's times when I need a VM or different container behaviour than it offers.

Personal infrastructure setup 2026

While starting this post I realized I have been maintaining personal infrastructure for over a decade! Most of the things I’ve self-hosted is been for personal uses. Email server, a blog, an IRC server, image hosting, RSS reader and so on. All of these things has all been a bit all over the place and never properly streamlined. Some has been in containers, some has just been flat files with a nginx service in front and some has been a random installed Debian package from somewhere I just forgot.

Morten Linderud
@ignisc @Foxboron and #IncusOS, it's just fantastic 🤩

ミニPCにIncusOSをインストールして、Tailscale経由で接続可能なTalos Linuxによるk8sクラスタを構築

ちょっとこの記事を見つけたので見ていた

https://pf.korako.me/post/14539

ミニPCにIncusOSをインストールして、Tailscale経由で接続可能なTalos Linuxによるk8sクラスタを構築

ちょっとこの記事を見つけたので見ていた 私はめんどくさがり屋なので古い技術にとらわれてあんまり学習の必要があるやつを使わないんですが、ちょっと面白そうかなと ちなみにこれについては全然聞いたことない単語が多かったので、ざっくりChatGPTに利点とか聞いたけど、 > 向いてい…

#Talos and #IncusOS both have "web tools" to "generate" an image that is specifically tailored to your needs (system extensions, plugins, etc.).

That feels super weird to me. I mean, why would I want to share part of my config with the website? Why would I want to download multiple times the whole ISO file when I could download it once, and customize it on my workstation.

Why not a local tool asking the same questions, downloading/caching the requested fragments and building the thing locally???

This feels like an antipattern to collect usage stats or something.

@dzwiedziu I currently plan to test out #IncusOS in addition to Proxmox (as my machines are too low-range for OpenStack...)
Linux Containers - Incus - Introduction

The umbrella project behind Incus, LXC, LXCFS, Distrobuilder and more.

Found out about #incusos. Not going to lie, I'm interested. 😎 I don't like managing the base os for workloads. It's why many immutable os fascinate me.

Going to have to see if I want this over alternatives. 😅

https://discuss.linuxcontainers.org/t/announcing-incusos/25139/5

Announcing IncusOS

A post was split to a new topic: Firewalling in IncusOS

Linux Containers Forum
Linux Containers - Incus - Introduction

The umbrella project behind Incus, LXC, LXCFS, Distrobuilder and more.

🌗 IncusOS:專為運行 Incus 而設計的不可變安全作業系統
➤ 徹底鎖定、原子更新、TPM 加密:IncusOS 簡介
https://linuxcontainers.org/incus-os/
IncusOS 是一個專門為安全穩定運行 Incus 而設計的不可變作業系統。它整合了 UEFI Secure Boot、TPM 等現代安全功能,確保啟動過程安全,並支援無縫的全磁碟加密。系統更新採用 A/B 分割區機制,支援原子更新與輕鬆回退。管理介面僅限於經認證的 REST API,系統本身完全鎖定,不提供本機或遠端 shell,是建置和運行 Incus 基礎設施的理想選擇。
+ 聽起來很棒,尤其是 API 專用的管理方式,感覺安全性提升了不少。期待 Linstor 的整合!
+ 不可變系統加上 A/B 更新聽起來是未來的趨勢,但如果底層作業系統出了問題,回退是否真的能解決所有問題?
#作業系統 #虛擬化 #容器 #Incus #IncusOS
Linux Containers - Incus - Introduction

The umbrella project behind Incus, LXC, LXCFS, Distrobuilder and more.