

You’re wrong, containerization is a massive security measure that shouldn’t be ignored. Proper containerization allows you to segment the namespacing of a single server by user and application; this helps massive with esrablishing boundaries that are still very difficult to cross under normal circumstances. Keycloak is an IdP which only provides one layer of security; good swcurity implements defense in depth where every layer of the system has securiry measures. Just because Linux recently had two vulnerabilities that bypass a lot of those doesn’t mean they’re worthless; you still need initial access to a nonprivileged user to exploit those and layered security can help prevent that from happening in the first place.




I personally recommend Fedora KDE. It’s polished and set up reasonably for the average person so you should never need to even open the terminal (you might need to fiddle with some stuff like enabling flatpacks but thats all sone in a GUI application), and it’s reasonably up to date withour shipping broken packages.