Oh man, I had to go way down in the comments to find a Manjaro fight. I even saw a fight over Mint on my way here. Mint, ffs.
WTF I though Manjaro was the black sheep of the Arch family.
Oh man, I had to go way down in the comments to find a Manjaro fight. I even saw a fight over Mint on my way here. Mint, ffs.
WTF I though Manjaro was the black sheep of the Arch family.

Don’t even suggest it to the datacenter people. They will laugh at you.
Don’t all the games have to be uploaded to Steam by their rightful developer?
crowdsec has always struck me as a really odd approach to security. You give out your logs to strangers and block IPs based on their say-so.
The cause and effect are so far removed that I can’t wrap my head about how it’s supposed to be efficient. It’s been proven in real-world tests that it lags badly behind the first waves of new vulnerabilities and by the time it starts blocking IPs that were related to those attacks the attackers have moved on and there are also patches available.
The “thousands of IPs blocked” image reminds me of that WWII airplane bullet-holes image.

I’m honestly terrified to use ZFS. Roast me if you must. It has got to be the most arcane filesystem ever. I’ve tried learning it but it looks like a million obscure gotchas just waiting to fuck up your shit. Someone will post an error and people are like “ha ha you fucker yeah you didn’t shprutzle your cache vdevs sideways. Noob mistake. Oh your data is ruined btw”.
I mean look at that shit, “scrub repaired 0b with 5 errors”. I feel like Richmond looking at the server lights in IT Crowd. “Is it good that it’s doing that? Is it bad? I feel like I should be telling someone.”
It doesn’t “bypass your firewall”… it lets you shoot yourself in the foot. You’re asking it to open ports without specifying an explicit network interface so it opens them on all interfaces. Which includes opening up the firewall, because what’s the point of putting up a service and blocking it in the firewall.
Also, doing it by hand would be incredibly tedious. Docker automatically adjusts the rules to match the ports and interfaces to its private container netmasks, and brings them up or down as needed when the containers start/stop.
All you have to do is bind ports to localhost or to a private interface if you don’t want the service to be publicly exposed.
Beginners get bitten by this because they say ports: 9999:9999 instead of ports: 127.0.0.1:9999:9999/tcp like they should. Unfortunately most examples out there use the terse version and never explain why it’s bad.

They actually do… He never does it, for some reason…

Why isn’t this an automated processs for them?
Because manjaro.org is controlled personally by Phil, the CEO of the company, who’s paranoid about letting anybody else handle it. And also can’t figure out how to renew automatically, apparently. People have to remind him on Discord. 🤦
Everything else *.manjaro.org (forums, mirrors etc.) is handled by different people and have never expired afaik.
It’s literally just the main webpage that has this problem, everything else about the distro is never impacted.
If you’re satified you’re probably not missing much.
Most of the Arch-based distros have found a niche of their own and most of them try to offer varying levels of help to the user to sweeten the Spartan experience of vanilla Arch.
Some of them like Endeavour try to keep the interference minimal, they offer some presets and some theming and an installer and stop there.
Distros like Cachy and Garuda are somewhere in the middle, with some quality of life stuff such as graphical package installers, and some custom packages, and streamlined driver install.
A distro like Manjaro or SteamOS takes it to the extreme with a “mommy knows best” setup that only bears a tenuous resemblance to vanilla Arch anymore, and you have to leave it alone to work as intended.