Bottlerocket 1.8, a distribution based on isolated containers, is now available

The release of Bottlerocket Linux distribution 1.8.0 has been published, developed with the participation of Amazon for the efficient and secure launch of isolated containers. The toolkit and management components of the distribution are written in Rust and are distributed under the MIT and Apache 2.0 licenses. Bottlerocket supports launch in Amazon ECS clusters, VMware, and AWS EKS Kubernetes, as well as the creation of arbitrary builds and editions allowing the use of various orchestration tools and runtimes for containers.

The distribution provides an atomically and automatically updatable immutable system image, which includes the Linux kernel and a minimal system environment, containing only the components necessary to run containers. The environment employs the system manager systemd, the Glibc library, the Buildroot build toolchain, the GRUB bootloader, the wicked network configurator, the runtime for isolated containers containerd, the Kubernetes container orchestration platform, the aws-iam-authenticator authenticator, and the Amazon ECS agent.

Container orchestration tools are provided in a separate management container, which is included by default and managed via the API and AWS SSM Agent. The base image does not include a command shell, server SSH and interpreted languages (such as Python or Perl) are not included; administrator tools and debugging are offloaded to a separate service container, which is disabled by default.

The key difference from similar distributions, such as Fedora CoreOS and CentOS/Red Hat Atomic Host, is the primary focus on providing maximum security in the context of enhancing system protection against potential threats, complicating the exploitation of vulnerabilities in OS components, and increasing container isolation. Containers are created using native Linux kernel mechanisms: cgroups, namespaces, and seccomp. For additional isolation, SELinux is used in 'enforcing' mode.

The root partition is mounted in read-only mode, while the configuration partition /etc is mounted in tmpfs and resets to its original state after a reboot. Direct modification of files in the /etc directory, such as /etc/resolv.conf and /etc/containerd/config.toml, is not supported; use the API for permanent settings storage or externalize functionality in separate containers. The dm-verity module is used for cryptographic verification of the root partition's integrity, and in case of any modification attempts at the block device level, the system reboots.

Most system components are written in Rust, which provides tools for safe memory handling, helping to avoid vulnerabilities caused by accessing freed memory, dereferencing null pointers, and buffer overflows. The default build modes include "--enable-default-pie" and "--enable-default-ssp" to enable Position Independent Executable (PIE) address space randomization and stack overflow protection through canary substitutions. For packages written in C/C++, additional flags "-Wall", "-Werror=format-security", "-Wp,-D_FORTIFY_SOURCE=2", "-Wp,-D_GLIBCXX_ASSERTIONS", and "-fstack-clash-protection" are also enabled.

In the new release:

  • The content of the administrative and management containers has been updated.
  • The runtime for isolated containers has been updated to the containerd 1.6.x branch.
  • Background processes coordinating the operation of containers are ensured to restart after changes in the certificate store.
  • The ability to set boot parameters for the kernel through the Boot Configuration section has been provided.
  • The option to ignore empty blocks when verifying the integrity of the root partition using dm-verity has been enabled.
  • The ability for static binding of host names in /etc/hosts has been provided.
  • The capability to generate network configuration using the netdog utility (the generate-net-config command has been added) has been provided.
  • New distribution options with support for Kubernetes 1.23 have been offered. The startup time of pods in Kubernetes has been reduced by disabling the configMapAndSecretChangeDetectionStrategy mode. New kubelet settings: provider-id and podPidsLimit have been added.
  • A new distribution option 'aws-ecs-1-nvidia' for Amazon Elastic Container Service (Amazon ECS) has been proposed, supplied with NVIDIA drivers.
  • Support for Microchip Smart Storage devices and MegaRAID SAS has been added. The support for Ethernet cards with Broadcom chips has been expanded.
  • The versions of packages and dependencies for Go and Rust languages have been updated, along with the versions of packages from third-party programs. The Bottlerocket SDK has been updated to version 0.26.0.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster