Microsoft has renamed the CBL-Mariner distribution to Azure Linux and released Azure Sphere OS 24.03

Microsoft has renamed the CBL-Mariner distribution to Azure Linux. Previously, the name Azure Linux was used for a specialized build installed in Azure Kubernetes Service (AKS), while the overall platform for building distributions was developed under the name CBL-Mariner (Common Base Linux Mariner). A few days ago, Microsoft renamed the CBL-Mariner repository to azurelinux, changed the names of utilities, and replaced instances of CBL-Mariner in the documentation with Azure Linux. Following this, the first release of the platform with the new name was created — Azure Linux 2.0.20240301, which addresses accumulated bugs and vulnerabilities in applications.

The project aims to unify the Linux solutions used in Microsoft and simplify the maintenance of Linux systems for various purposes. Among other things, the distribution is used in cloud infrastructure, edge systems, and various Microsoft services. Project developments are distributed under the MIT license. Packages are built for aarch64 and x86_64 architectures. A bootable ISO image has been prepared (860 MB) for the x86_64 architecture.

The Azure Linux distribution provides a small standardized set of core packages that serve as a universal foundation for building container images, host environments, and services that run in cloud infrastructures and on edge devices. More complex and specialized solutions can be created by adding additional packages on top of Azure Linux, but the base for all such systems remains unchanged, simplifying maintenance and update preparation.

For example, Azure Linux serves as the basis for the mini-distribution WSLg, which provides components of the graphical stack for running Linux GUI applications in environments based on the WSL2 (Windows Subsystem for Linux). Enhanced functionality in WSLg is implemented through the inclusion of additional packages with compositing support. proxy server Weston, XWayland, PulseAudio, and FreeRDP.

The Azure Linux build system enables the generation of both separate RPM packages based on SPEC files and source texts, as well as monolithic system images created with the rpm-ostree tool, which can be updated atomically without breaking them into individual packages. Accordingly, two models for delivering updates are supported: through updating individual packages and through rebuilding and updating the entire system image. A repository containing approximately 3000 already built RPM packages is available, which can be used to assemble custom images based on a configuration file.

The base platform includes only the most essential components and is optimized for minimal memory and disk space usage, as well as for high boot speed. The project employs a 'maximum security by default' approach, which implies the inclusion of various additional mechanisms to enhance protection:

  • Filtering of system calls using the seccomp mechanism.
  • Encryption of disk partitions.
  • Verification of packages by digital signature.
  • Address space randomization.
  • Protection against attacks related to symbolic links, mmap, /dev/mem, and /dev/kmem.
  • Read-only mode and prohibition of code execution in areas of memory where kernel and module data segments are located.
  • Option to prohibit the loading of kernel modules after system initialization.
  • Using iptables for network packet filtering.
  • Enabling protection modes against stack overflow, buffer overflows, and string format issues (_FORTIFY_SOURCE, -fstack-protector, -Wformat-security, relro) during the build.

The system manager systemd is used for managing services and load. Package managers RPM and DNF are provided for package management. By default, the SSH server is not enabled. An installer is provided for installing the distribution, which can work in both text and graphical modes. The installer allows the installation of either a full or a minimal set of packages, offers an interface for selecting the disk partition, choosing the hostname, and creating users.

In addition to changes related to CBL-Mariner and Azure Linux, Microsoft has also introduced a new release of the Azure Sphere platform 24.03, built on the Linux kernel and designed for creating Internet of Things devices based on energy-efficient microcontrollers (MCUs) with integrated peripheral subsystems. One of the platform's features is the Pluton subsystem, designed to provide hardware for encryption, secure key storage, and complex cryptographic operations. Pluton includes a separate specialized processor, a cryptographic engine, a hardware random number generator, and an isolated key storage.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster