“Rings” of access privilege everywhere, enforced across the whole OS. Something like Qubes OS.
Top tier, security audited, prepackaged setups for vllm, llama.cpp, various agenic frameworks and such, something better than a massive docker install for every one.
Multiple versions of patched/optimized Python akin to Clear Linux or CachyOS.
A kernel/scheduler tuned for compute and low IO latency.
Good Nvidia/rocm/Intel support, which Arch does provide, admittedly.
Simple, minimalistic desktop UI that is easy for an agent to interpret in a screenshot, and easy for it to operate. Ideally with integrated hooks.
And an “easy” headless mode for less overhead
Prepackaged, open source agenic browsers and embeddings servers.
Links and guides for more niche machine learning/data processing projects, instead of to the most popular ones that already have official guides.
Omarchy has… precisely none of that? Except for what in inherits from Arch.
Lack of any containerization in particular is one reason OpenClaw (the previous Twitter AI fad) was such a flaming mess.
Seems like their AIs had some of the same ideas you’re having here, since about a week or two ago they had an issue open about moving the basis of Omarchy over to Nix.
That got buried somehow, cannot find it in Github anymore.
I wouldn’t trust an agent outside of a capabilities-based OS, like if Genode was ready for production. I don’t even use AI at all, but if I was actually using agents, I’d want guarantees that not only do you not have access to certain things, you cannot properly conceive of how to access them, it is utterly beyond the agent.
If this was any other computer program that could execute arbitrary system commands unreliably, standard procedure would be to sandbox the living snot out of it.
It’s baffling to me that “AI” is somehow an excuse to ignore this. Hence that’s exactly what I mean: I’d want rock solid guarantees of containerization, and granular scoping.
Well, as we saw with OpenClaw, 95% of users won’t set up containers and scopes if it isn’t a preconfigured default.
So yeah, Arch can do containers just fine. But if this is an “agenic” OS preconfigured to use agents, it better do that by default, out of the box, and MAKE the user scope its access.
…Let’s play devil’s advocate.
Isn’t it a terrible architecture for agents?
The ideal distro would be:
A strictly immutable base configuration.
“Rings” of access privilege everywhere, enforced across the whole OS. Something like Qubes OS.
Top tier, security audited, prepackaged setups for vllm, llama.cpp, various agenic frameworks and such, something better than a massive docker install for every one.
Multiple versions of patched/optimized Python akin to Clear Linux or CachyOS.
A kernel/scheduler tuned for compute and low IO latency.
Good Nvidia/rocm/Intel support, which Arch does provide, admittedly.
Simple, minimalistic desktop UI that is easy for an agent to interpret in a screenshot, and easy for it to operate. Ideally with integrated hooks.
And an “easy” headless mode for less overhead
Prepackaged, open source agenic browsers and embeddings servers.
Links and guides for more niche machine learning/data processing projects, instead of to the most popular ones that already have official guides.
Omarchy has… precisely none of that? Except for what in inherits from Arch.
Lack of any containerization in particular is one reason OpenClaw (the previous Twitter AI fad) was such a flaming mess.
Seems like their AIs had some of the same ideas you’re having here, since about a week or two ago they had an issue open about moving the basis of Omarchy over to Nix.
That got buried somehow, cannot find it in Github anymore.
Wouldn’t switching to Nix nuke existing Omarchy installs?
This is a microcosm of why this is so perplexing to me. If Alibaba really wants an agenic OS, there are far better starting points than Omarchy.
I wouldn’t trust an agent outside of a capabilities-based OS, like if Genode was ready for production. I don’t even use AI at all, but if I was actually using agents, I’d want guarantees that not only do you not have access to certain things, you cannot properly conceive of how to access them, it is utterly beyond the agent.
Well, yes, exactly! You shouldn’t trust it.
If this was any other computer program that could execute arbitrary system commands unreliably, standard procedure would be to sandbox the living snot out of it.
It’s baffling to me that “AI” is somehow an excuse to ignore this. Hence that’s exactly what I mean: I’d want rock solid guarantees of containerization, and granular scoping.
It can’t not have containers, right? Or an I missing something?
Honestly I’ve not delved much into this distro, I only hear bad things about the author and a lot of companies throw money at it
Well, as we saw with OpenClaw, 95% of users won’t set up containers and scopes if it isn’t a preconfigured default.
So yeah, Arch can do containers just fine. But if this is an “agenic” OS preconfigured to use agents, it better do that by default, out of the box, and MAKE the user scope its access.