Canonical has released the monolithic distribution Ubuntu Core 26

Canonical has released Ubuntu Core 26, a compact version of the Ubuntu distribution designed for use on Internet of Things (IoT) devices, in containers, and consumer and industrial equipment. Ubuntu Core is delivered as an indivisible monolithic image of the base system, without separation into individual deb packages. The images of Ubuntu Core 26, which are synchronized with the package base of Ubuntu 26.04, are prepared for x86_64 and ARM64 systems. The support period for this release will be 15 years.

Ubuntu Core serves as the foundation for running additional components and applications, which are packaged as self-contained extensions in the snap format. Components of Ubuntu Core, including the base system, Linux kernel, and system extensions, are also provided in the snap format and are managed by the snapd toolkit. The Snappy technology enables the creation of a system image as a whole, without splitting into individual packages. Instead of incremental updates at the level of individual deb packages, Ubuntu Core employs an atomic update mechanism for snap packages and the base system, similar to Fedora Atomic, ChromeOS, Endless, and openSUSE Leap Micro. When updating the base environment and snap packages, there is an option to roll back to a previous state in case of issues identified after the update.

To ensure security, each component of the system is verified by digital signature, which protects the distribution from hidden modifications or the installation of unverified snap packages. Components delivered in snap format are isolated using AppArmor and Seccomp, creating an additional barrier for system protection in the event of compromise of individual applications. The base system includes only the minimum necessary applications, which not only reduced the size of the system environment but also positively impacted security by decreasing potential attack vectors.

The basic file system is mounted in read-only mode. There is an option to use data encryption on the drive with TPM support. Updates are released regularly, delivered via over-the-air (OTA) and synchronized with the Ubuntu 26.04 release. To minimize traffic, updates are provided in compressed form and include only changes relative to the previous update (delta updates). Automating the installation of updates addresses security maintenance issues when used on embedded devices.

By logically separating the base system from applications, the maintenance of the Ubuntu Core codebase is handled by Ubuntu developers, while the relevance of additional applications is supported by application developers. This approach allows for reduced maintenance costs for products built on the Ubuntu Core foundation, as their manufacturers need not engage in releasing and delivering system updates, focusing instead solely on their specific components.

Key innovations:

  • A new build system based on the Chisel toolkit is utilized, allowing for the division and trimming of Debian packages to deliver only the most necessary files. Chisel enables manipulation of not whole packages but slices (subsets of packages) — sets of files formed based on the content and metadata of a package. Each slice can have its own contents and a corresponding set of dependencies linked to other slices. Every file in the Ubuntu Core file system is now tied to a slice and a source code package, improving integrity verification and vulnerability tracking. The application of this new build system has reduced the size of the base system image by 7%.
  • The installation time for updates has been reduced by applying the snap-delta format to decrease the size of data downloaded for most snap packages. For instance, the size of files for updating base snap packages has decreased from 16 MB to 1.5 MB.
  • Compliance with the European CRA (Cyber Resilience Act) legislation requirements has been ensured, which introduces legal liability for failing to meet security requirements.
  • The ability to apply Livepatch technology has been added, allowing for kernel updates to be made without rebooting and without stopping application work.
  • Integration with the COS (Canonical Observability Stack) toolkit, based on the Juju orchestration engine and Kubernetes platform, has been ensured. Ubuntu Core can now send logs and metrics to centralized monitoring systems based on Grafana, Loki, and Prometheus.
  • Support has been added for components that allow snap package developers to distribute additional large or optional resources, such as debug data, translation files, and optional drivers, separately from the core snap package to reduce the size of the base installation. The component is formed as an image in the squashfs format, mounted in the snap package environment.
  • Compatibility with the OpenAPI specification has been provided in the Snapd REST API.
  • In display server Ubuntu Frame, which allows the creation of embedded graphical environments (such as internet kiosks, self-service terminals, information stands, digital signage), has added the ability to place multiple application interfaces on one screen. Support for GPU acceleration in applications has also been added.
  • A system setting, interface.allow-auto-connection, has been added to define rules for automatic interface connection.
  • Support for the Confdb mechanism has been added for centralized configuration definitions that are not tied to specific snap packages and devices.
  • The base set of snap packages has removed the Python interpreter, which should now be installed as a separate plugin.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster