Microsoft Releases Azure Linux Distribution 3.0.20241203

Microsoft has released an update for Azure Linux distribution 3.0.20241203. This distribution is evolving as a universal base platform for Linux environments used in cloud infrastructure, edge systems, and various Microsoft services. The project's own developments are distributed under the MIT license. Package builds are available for aarch64 and x86_64 architectures. The installation image size is 750 MB.

Among the changes in the new version:

  • The iptables packet filter has been transitioned to command processing via rule translation into nftables bytecode (by default, the iptables-nft package is used instead of iptables-legacy).
  • For Aarch64 systems, an additional package with the kernel kernel-64k has been proposed, which uses large memory pages of 64KB (the kernel is built with the CONFIG_ARM64_64K_PAGES option).
  • Support for configuring 'installonlypkgs' has been added to the package manager tdnf (analogous to dnf based on C libs), which is used to manage the installation of the kernel kernel-64k.
  • With systemd-networkd in use, livenet rootfs processing from Dracut has been enabled.
  • A driver for Intel Ethernet Connection E800 network adapters has been added.
  • Support for the Lua language has been added to the fluent-bit log handler.
  • Digital signature verification for kernels loaded via the kexec mechanism has been enabled.
  • To identify container builds, the systemd-detect-virt utility is used instead of checking the '.dockerenv' file.
  • Package versions have been updated, including Linux kernel 6.6.57, shim 15.8, SymCrypt 103.6.0, Valkey (a Redis fork) 8.0.1, Go 1.23.3, MariaDB 10.11.10, PostgreSQL 16.5.

The Azure Linux distribution provides a small standardized set of core packages that serve as a universal foundation for building container images, host environments, and services that run in cloud infrastructures and on edge devices. More complex and specialized solutions can be created by adding additional packages on top of Azure Linux, but the base for all such systems remains unchanged, simplifying maintenance and update preparation.

Azure Linux serves as the base for the mini-distribution WSLg, which provides components of the graphical stack to run Linux GUI applications in WSL2 (Windows Subsystem for Linux) environments. Extended functionality in WSLg is achieved by enabling additional packages with composite. proxy server Weston, XWayland, PulseAudio, and FreeRDP.

The system manager systemd is used for managing services and load. Package managers RPM and DNF are provided for package management. By default, the SSH server is not enabled. An installer is provided for installing the distribution, which can work in both text and graphical modes. The installer allows the installation of either a full or a minimal set of packages, offers an interface for selecting the disk partition, choosing the hostname, and creating users.

The Azure Linux build system enables the generation of both separate RPM packages based on SPEC files and source texts, as well as monolithic system images created with the rpm-ostree tool, which can be updated atomically without breaking them into individual packages. Accordingly, two models for delivering updates are supported: through updating individual packages and through rebuilding and updating the entire system image. A repository containing approximately 3000 already built RPM packages is available, which can be used to assemble custom images based on a configuration file.

The base platform includes only the most essential components and is optimized for minimal memory and disk space usage, as well as for high boot speed. The project employs a 'maximum security by default' approach, which implies the inclusion of various additional mechanisms to enhance protection:

  • Filtering of system calls using the seccomp mechanism.
  • Encryption of disk partitions.
  • Verification of packages by digital signature.
  • Address space randomization.
  • Protection against attacks related to symbolic links, mmap, /dev/mem, and /dev/kmem.
  • Read-only mode and prohibition of code execution in areas of memory where kernel and module data segments are located.
  • Option to prohibit the loading of kernel modules after system initialization.
  • Using iptables for network packet filtering.
  • Enabling protection modes against stack overflow, buffer overflows, and string format issues (_FORTIFY_SOURCE, -fstack-protector, -Wformat-security, relro) during the build.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster