• rumba@lemmy.zip
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 days ago

          It’s not even fully immutable, but it has a lot of the protections of it. The declaritive part is pretty hot and the package system is expansive and extremely safe.

          it’s also really nice to be able to commit new changes without rebooting.

            • rumba@lemmy.zip
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 day ago

              Not everything in the config paths are in the store.

              None of the users are in the store

              Any users can run arbitrary binaries as long as they’re not dynamically linked.

              Root can permanently add and remove arbitrary stuff to/from the store at run time.

              It’s pretty good in a lot of ways you can’t modify hosts and you can’t throw stuff into cron, but a great deal of Nixos is mutable.