Skip to content
Harobanda

The case

Every OS you can buy is shaped by its vendor. This one is shaped by your solution.

Where this came from, what it is not, and what is wrong with all three of the systems you could run instead.

Where this came from

Where an imported system is a liability, not a help.

This work did not begin at the operating system. It began with real solutions — for shops, clinics, banks, public services — being built for the African context: intermittent power, connectivity that comes and goes, budgets that rule out costly licences and disposable hardware, and data whose sovereignty is not up for negotiation.

In that context an imported ecosystem is a liability, not a help: a cloud you cannot reach when the link drops, support that ends on a foreign calendar, hardware you cannot replace from the shop down the road, and terms you cannot audit — in a language of dependencies you did not choose.

What these solutions actually needed was the opposite: a box that survives the cut, a name that never moves, records that never leave the room. And those guarantees turned out to live one floor below the application — in the machine itself. So that is where the work went.

Harobanda as a bridge: your solution's programs span the promises the machine must keep and the ordinary hardware that keeps them Harobanda as a bridge: your solution's programs span the promises the machine must keep and the ordinary hardware that keeps them

Where this sits

It resembles several things you already run.

Nothing below is wrong, and you probably use some of it every day. The point of this section is narrower than that: to stop you reading the next five pages as a weaker version of something you have already made up your mind about.

a containerDocker, Podman
Packages a program so it runs the same on somebody else's operating system. A declared machine is the operating system — there is no host underneath it to share, to escape to, or to be patched by someone who is not you.
a declarative distributionNixOS, Guix
Declares what is installed, and rebuilds the system from that description. Here the declaration is not a list of what to install — it is what the machine is. What the file does not name is not on the device, and there is no package manager to reach for at run time.
an immutable server OSTalos, CoreOS, Flatcar
The nearest neighbour, and the same instinct: a read-only system, no shell, updated as a whole image. The difference is what happens after the image is written — the machine keeps the declaration it was derived from and judges its own boot against it, and on a device it rolls back by a hardware timer rather than by an orchestrator that has to still be reachable.
an embedded build systemYocto, Buildroot
Turns a recipe into a firmware image for a device. This produces an image too — and then a court that judges the boot against the very file the image came from. The recipe does not stop mattering the moment the card is flashed.
a configuration toolAnsible, Terraform, Puppet
Converges a running machine towards a state you described, and keeps converging it. A declared machine has no state to converge: a change is a new image, tried once, and returned to the version that worked if the box does not recognise its own boot.

Each of those says what to put on a machine. A declaration says what the machine is — and it is still there at boot, to be judged against.