The first stable release of Fedora CoreOS

Fedora project developers announced on stabilizing the distribution Fedora CoreOS and its readiness for widespread use. Fedora CoreOS is promoted as a unified solution for running environments based on isolated containers, replacing Fedora Atomic Host and CoreOS Container Linux products. Support for CoreOS Container Linux will cease in 6 months, and Fedora Atomic Host support is expected to end in late November.

Fedora CoreOS aims to provide a minimal environment that is atomically updated automatically without administrator intervention and is unified for mass deployment of server systems designed exclusively for running containers. The distribution provides only the minimum set of components necessary for running isolated containers—Linux kernel, system manager systemd, and a collection of utility services for SSH connections, configuration management, and update installation.

The system partition is mounted in read-only mode and is not changed during operation. Configuration is transmitted at boot time using the Ignition (an alternative to Cloud-Init). Once the system is up and running, changing the configuration and contents of the /etc directory is impossible; only modifying the settings profile and using it to replace the environment is allowed. In general, working with the system resembles working with container images, which are not updated in place but are rebuilt from scratch and relaunched.

The system image is indivisible and is created using OSTree technology (individual packages cannot be installed in such an environment; the entire system image must be rebuilt, expanding it with new packages using the rpm-ostree tool). The update system is based on using two system partitions, one of which is active while the other is used for copying the update. After the update is installed, the roles of the partitions are switched.

From the CoreOS Container Linux distribution, which transitioned came into the hands of Red Hat after acquiring CoreOS, the Fedora CoreOS project borrowed the initial boot configuration tool (Ignition), the atomic update mechanism, and the overall product philosophy. The package management technology, support for OCI (Open Container Initiative) specifications, and additional container isolation mechanisms based on SELinux have been carried over from Atomic Host. In the future, integration with Kubernetes is planned for container orchestration on Fedora CoreOS (including on the basis of OKD).

The first stable release of Fedora CoreOS is built from repositories Fedora 31 using the rpm-ostree package.
The package includes the Linux kernel 5.4, system manager systemd 243, and Ignition toolkit 2.1. Runtime support for containers is provided by Moby 18.09 (Docker) and podman 1.7. By default, cgroups v1 support is enabled for compatibility, but cgroups v2 can also be activated optionally. The ability has been implemented to install on various platforms, including standard servers, QEMU, OpenStack, VMware, AWS, Alibaba, Azure, and GCP. The provided iso image can operate in live mode with booting into RAM. Network booting via PXE (netboot) is supported.

Three independent branches of Fedora CoreOS are offered, for which updates addressing vulnerabilities and serious bugs are created:

  • testing with snapshots based on the current Fedora release with updates;
  • stable — the stabilized branch, formed after two weeks of testing the testing branch;
  • next — a snapshot of the developing future release (currently just planned).

Future plans mention the inclusion in Fedora CoreOS the sending of telemetry using the service fedora-coreos-pinger, which periodically collects and sends non-identifiable system information to the Fedora project servers, such as the OS version number and installation type on the cloud platform. The transmitted data does not include information that could lead to identification. Only aggregated data is used in statistics, which allows a general assessment of the usage of Fedora CoreOS. If desired, users can disable telemetry sending or expand the default information sent.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster