Canonical's 'distroless' Linux images are a game-changer for enterprises
Canonical introduces 'distroless' Linux images with long-term support, enhancing security by reducing attack surface. Plans include supporting various platforms and adding open-source components to Ubuntu Pro subscriptions, emphasizing AI/ML tools. Collaboration with Microsoft for .NET containers solidifies Canonical's commitment to rapid security resolutions.
Read original articleCanonical has introduced customized Docker container images called 'distroless' Linux images with 12 years of long-term support, available through its Everything LTS service. These images offer security support for Linux and included open-source applications or dependencies within the container. Canonical's CEO, Mark Shuttleworth, highlighted that this move will provide CVE maintenance for the entire open-source dependency tree, even those not packaged as a deb in Ubuntu. The company aims to support these images on various platforms, including RHEL, VMware, Ubuntu, and major public cloud Kubernetes. By embracing the 'distroless' container paradigm, Canonical aims to enhance security by reducing the attack surface compared to traditional Linux VMs or containers. Additionally, Canonical plans to include thousands of new open-source components in Ubuntu Pro subscriptions, focusing on AI/ML dependencies and tools. The company also collaborates with Microsoft to create chiseled containers for the .NET community. Canonical's commitment to rapid security issue resolution positions it as a reliable partner for organizations seeking secure and cutting-edge open-source technology in the enterprise Linux and cloud computing market.
Related
SUSE Offers Lifeline to Stranded CentOS Users with Liberty Linux Lite
SUSE introduces Liberty Linux Lite as a solution for CentOS 7 users post end-of-life. Priced at $25 per year, it offers ongoing support and security updates until 2028, ensuring business continuity.
CentOS Linux 7 will reach EOL on Sunday
CentOS Linux 7 will reach End of Life on June 30, 2024. Users are advised to migrate to Red Hat Enterprise Linux for continued support, with migration tools and consulting services available for a smooth transition.
Podman Desktop 1.11: Light mode, Kubernetes features, macOS improvements
Podman Desktop 1.11 introduces light mode, Rosetta support for Apple Silicon, Kubernetes enhancements, improved UI, and manifest support. Users can toggle light mode, achieve faster AMD64 builds on Apple Silicon, and benefit from upgraded features.
How eBPF is shaping the future of Linux and platform engineering
eBPF, developed by Daniel Borkmann, revolutionizes Linux by enabling custom programs in the kernel. It enhances networking, security, and observability, bridging monolithic and microkernel architectures for improved performance and flexibility.
Aeon: OpenSUSE for Lazy Developers
The openSUSE project introduces Aeon Desktop for developers, offering automated updates through atomic snapshots. Aeon features a minimal GNOME desktop, automatic updates, and optimized packages, catering to a distraction-free development environment.
We already have this from docker itself.
https://hub.docker.com/_/scratch/
I don't see how adding cannonical to our minimalist null distro adds any value. The idea of minimalism is to take away. What would they be doing anyway?
Sounds like a corp just wanting to get in a business. Antithetical to the idea of removing everything but the kernel.
What does this actually mean and why do they hide it behind a nonsensical term?
> Canonical plans to maintain the 2,000 widely used AI/ML libraries and tools, including heavy hitters such as PyTorch, TensorFlow, and Rapids, as source code instead of as Debian/Ubuntu deb packages.
That's rough. Hopefully the desktop ecosystem doesn't suffer. That said, 12 years sounds amazing! I wish this were applied to their actual desktop LTE and ESM and not commercial docker container using non debian package management.
Already, Canonical keeps pushing updates for "Ubuntu Pro".
Clearaly, this is a Canonical distribution.
Someone has to choose the exact combination of userland s/w to include with the kernel. Whoever/whatever chooses this s/w is creating a distribution.
To this boomer yelling at the cloud, this is just more nonsensical hype, equivalent to "serverless".
Oh, I've no doubt some devs in Silicon Valley Mode and some managers will like it of course, as I've no doubt at a sudden point in future they'll regret.
Ladies and gentleman's it's 2024, the era of containers MUST end for the sake of humanity, similarly to the previous full-stack virtualization on x86, it's about time to go declarative like NixOS/Guix System. The current typical infra is a big load of unmanageable, fragile crap with a so big attack surface that you have only to choose how to get TFU.
Related
SUSE Offers Lifeline to Stranded CentOS Users with Liberty Linux Lite
SUSE introduces Liberty Linux Lite as a solution for CentOS 7 users post end-of-life. Priced at $25 per year, it offers ongoing support and security updates until 2028, ensuring business continuity.
CentOS Linux 7 will reach EOL on Sunday
CentOS Linux 7 will reach End of Life on June 30, 2024. Users are advised to migrate to Red Hat Enterprise Linux for continued support, with migration tools and consulting services available for a smooth transition.
Podman Desktop 1.11: Light mode, Kubernetes features, macOS improvements
Podman Desktop 1.11 introduces light mode, Rosetta support for Apple Silicon, Kubernetes enhancements, improved UI, and manifest support. Users can toggle light mode, achieve faster AMD64 builds on Apple Silicon, and benefit from upgraded features.
How eBPF is shaping the future of Linux and platform engineering
eBPF, developed by Daniel Borkmann, revolutionizes Linux by enabling custom programs in the kernel. It enhances networking, security, and observability, bridging monolithic and microkernel architectures for improved performance and flexibility.
Aeon: OpenSUSE for Lazy Developers
The openSUSE project introduces Aeon Desktop for developers, offering automated updates through atomic snapshots. Aeon features a minimal GNOME desktop, automatic updates, and optimized packages, catering to a distraction-free development environment.