The third prototype of the ALP platform, which is set to replace SUSE Linux Enterprise

SUSE has released the third prototype of the ALP platform "Piz Bernina" (Adaptable Linux Platform), positioned as a continuation of the SUSE Linux Enterprise distribution. The key difference of ALP is the separation of the base distribution into two parts: a stripped-down 'host OS' for operating directly on hardware, and a layer for application support focused on running in containers and virtual machines. ALP is initially being developed using an open development process, where intermediate builds and testing results are publicly available to all interested parties.

The third prototype includes two separate branches, which are currently similar in terms of their core, but will evolve towards different areas of application with different provided services in the future. The Bedrock branch, aimed at use in server systems, and the Micro branch, designed for building cloud-native systems and running microservices, are available for testing. Ready builds are prepared for the x86_64 architecture (Bedrock, Micro). Additionally, build scripts (Bedrock, Micro) are available for Aarch64, PPC64le, and s390x architectures.

The architecture of ALP is based on the development of the 'host OS' environment, which is the minimum necessary to support and manage hardware. All applications and user space components are suggested to run not in a mixed environment, but in separate containers or in units executed on top of the 'host OS' and isolated from one another. This organization will allow users to focus on applications and abstract workflows, separating them from the low-level system environment and hardware. virtual machines, executed on top of the 'host OS' and isolated from each other. This organization will allow users to focus on applications and abstract workflows, separating them from the low-level system environment and hardware.

The SLE Micro product, based on the MicroOS project, serves as the foundation for the 'host OS'. For centralized management, configuration management systems Salt (pre-installed) and Ansible (optional) are offered. For launching isolated containers, tools such as Podman and K3s (Kubernetes) are available. Among the system components moved into containers are yast2, podman, k3s, cockpit, GDM (GNOME Display Manager), and KVM.

Among the features of the system environment is the default use of disk encryption (FDE, Full Disk Encryption) with the option to store keys in TPM. The root partition is mounted in read-only mode and is not modified during operation. An atomic update installation mechanism is used in the environment. Unlike atomic updates based on ostree and snap used in Fedora and Ubuntu, ALP utilizes the standard package manager and snapshot mechanism in Btrfs instead of building separate atomic images and deploying additional delivery infrastructure.

A customizable automatic update installation mode is provided (for example, it is possible to enable auto-installation only for critical vulnerability patches or to revert to manual confirmation of update installations). Live patches are supported for updating the Linux kernel without rebooting and without interrupting operations. To maintain system resilience (self-healing), the last stable state is recorded using Btrfs snapshots (if anomalies are detected after applying updates or changing settings, the system automatically reverts to the previous state).

The platform uses a multi-version software stack — thanks to the use of containers, different versions of tools and applications can be utilized simultaneously. For example, applications that depend on different versions of Python, Java, and Node.js can run concurrently, isolating incompatible dependencies. Base dependencies are provided in the form of BCI (Base Container Images) sets. Users can create, update, and delete software stacks without affecting other environments.

The D-Installer is used for installation, where the user interface is separated from the internal components of YaST and various front-ends can be used, including a front-end for managing installation through a web interface. Clients of YaST (bootloader, iSCSIClient, Kdump, firewall, etc.) can be run in separate containers.

Key changes in the third prototype of ALP:

  • Providing a Trusted Execution Environment for confidential computing, enabling secure data processing through isolation, encryption, and of virtual machines.
  • The application of hardware and runtime attestation to verify the integrity of executed tasks.
  • The basis for supporting Confidential Virtual Machines (CVM).
  • Integration of NeuVector platform support for container security verification, detection of vulnerable components, and identification of malicious activities.
  • Support for s390x architecture in addition to x86_64 and aarch64.
  • The option to enable full disk encryption (FDE) during installation, storing keys in TPMv2 without requiring a passphrase during the first boot. Equivalent support for both standard partitions and LVM (Logical Volume Manager) partitions.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster