ืืžื–ื•ืŸ ืžืคืจืกืžืช ืืช Bottlerocket 1.0.0, ื”ืคืฆืช ืœื™ื ื•ืงืก ื”ืžื‘ื•ืกืกืช ืขืœ ืงื•ื ื˜ื™ื™ื ืจื™ื ืžื‘ื•ื“ื“ื™ื

ื—ื‘ืจืช ืืžื–ื•ืŸ ืžื•ืฆื’ ืžื”ื“ื•ืจื” ืžืฉืžืขื•ืชื™ืช ืจืืฉื•ื ื” ืฉืœ ื”ืคืฆืช ืœื™ื ื•ืงืก ื™ื™ืขื•ื“ื™ืช ื‘ืงื‘ื•ืง ื‘ืงื‘ื•ืง 1.0.0, ืฉื ื•ืขื“ ืœื”ืคืขื™ืœ ืžื›ื•ืœื•ืช ืžื‘ื•ื“ื“ื•ืช ื‘ื™ืขื™ืœื•ืช ื•ื‘ื‘ื˜ื—ื”. ื”ื›ืœื™ื ื•ืจื›ื™ื‘ื™ ื”ื‘ืงืจื” ืฉืœ ื”ื”ืคืฆื” ื›ืชื•ื‘ื™ื ื‘- Rust ื• ื”ืชืคืฉื˜ื•ืช ืชื—ืช ืจื™ืฉื™ื•ื ื•ืช MIT ื•- Apache 2.0. ื”ืคืจื•ื™ืงื˜ ืžืคื•ืชื— ื‘-GitHub ื•ื–ืžื™ืŸ ืœื”ืฉืชืชืคื•ืช ื—ื‘ืจื™ ื”ืงื”ื™ืœื”. ืชืžื•ื ืช ืคืจื™ืกืช ื”ืžืขืจื›ืช ื ื•ืฆืจืช ืขื‘ื•ืจ ืืจื›ื™ื˜ืงื˜ื•ืจื•ืช x86_64 ื•-Aarch64. ืžืขืจื›ืช ื”ื”ืคืขืœื” ืžื•ืชืืžืช ืœืจื•ืฅ ืขืœ ืืฉื›ื•ืœื•ืช Amazon ECS ื•-AWS EKS Kubernetes. ืžืกื•ืคืงื™ื ื›ืœื™ื ืœื™ืฆื™ืจืช ืืกืžื‘ืœื™ื ื•ืžื”ื“ื•ืจื•ืช ืžืฉืœืš, ืฉื™ื›ื•ืœื™ื ืœื”ืฉืชืžืฉ ื‘ื›ืœื™ ืชื–ืžื•ืจ ืื—ืจื™ื, ื’ืจืขื™ื ื™ื ื•ื–ืžืŸ ืจื™ืฆื” ืขื‘ื•ืจ ืงื•ื ื˜ื™ื™ื ืจื™ื.

ื”ื”ืคืฆื” ืžืกืคืงืช ืืช ืœื™ื‘ืช ืœื™ื ื•ืงืก ื•ืกื‘ื™ื‘ืช ืžืขืจื›ืช ืžื™ื ื™ืžืœื™ืช, ื”ื›ื•ืœืœืช ืจืง ืืช ื”ืจื›ื™ื‘ื™ื ื”ื“ืจื•ืฉื™ื ืœื”ืคืขืœืช ืงื•ื ื˜ื™ื™ื ืจื™ื. ื‘ื™ืŸ ื”ื—ื‘ื™ืœื•ืช ื”ืžืขื•ืจื‘ื•ืช ื‘ืคืจื•ื™ืงื˜ ื ื™ืชืŸ ืœืžื ื•ืช ืืช systemd manager systemd, ืกืคืจื™ื™ืช Glibc ื•ื›ืœื™ ื”ื”ืจื›ื‘ื”
Buildroot, ื˜ื•ืขืŸ ืืชื—ื•ืœ GRUB, ืชืฆื•ืจืช ืจืฉืช ืจืฉืข, ื–ืžืŸ ืจื™ืฆื” ืขื‘ื•ืจ ืžื™ื›ืœื™ื ืžื‘ื•ื“ื“ื™ื ืžื›ื™ืœ, ืคืœื˜ืคื•ืจืžืช ืชื–ืžื•ืจ ืžื›ื•ืœื•ืช Kubernetes, aws-iam-authenticator ื•ืกื•ื›ืŸ ืืžื–ื•ืŸ ECS.

ื”ื”ืคืฆื” ืžืชืขื“ื›ื ืช ืžื‘ื—ื™ื ื” ืื˜ื•ืžื™ืช ื•ืžื•ืขื‘ืจืช ื‘ืฆื•ืจื” ืฉืœ ืชืžื•ื ืช ืžืขืจื›ืช ื‘ืœืชื™ ื ื™ืชื ืช ืœื—ืœื•ืงื”. ืœืžืขืจื›ืช ืžื•ืงืฆื•ืช ืฉืชื™ ืžื—ื™ืฆื•ืช ื“ื™ืกืง, ืื—ืช ืžื”ืŸ ืžื›ื™ืœื” ืืช ื”ืžืขืจื›ืช ื”ืคืขื™ืœื”, ื•ื”ืขื“ื›ื•ืŸ ืžื•ืขืชืง ืœืฉื ื™ื™ื”. ืœืื—ืจ ืคืจื™ืกืช ื”ืขื“ื›ื•ืŸ, ื”ืžื—ื™ืฆื” ื”ืฉื ื™ื™ื” ื”ื•ืคื›ืช ืคืขื™ืœื”, ื•ื‘ืจืืฉื•ื ื”, ืขื“ ืœื”ื’ืขืช ื”ืขื“ื›ื•ืŸ ื”ื‘ื, ื ืฉืžืจืช ื”ื’ืจืกื” ื”ืงื•ื“ืžืช ืฉืœ ื”ืžืขืจื›ืช, ืืœื™ื” ื ื™ืชืŸ ืœื—ื–ื•ืจ ืื—ื•ืจื” ืื ืžืชืขื•ืจืจื•ืช ื‘ืขื™ื•ืช. ืขื“ื›ื•ื ื™ื ืžื•ืชืงื ื™ื ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™ ืœืœื ื”ืชืขืจื‘ื•ืช ืžื ื”ืœ ืžืขืจื›ืช.

ื”ื”ื‘ื“ืœ ื”ืขื™ืงืจื™ ืžื”ืคืฆื•ืช ื“ื•ืžื•ืช ื›ืžื• Fedora CoreOS, CentOS/Red Hat Atomic Host ื”ื•ื ื”ื”ืชืžืงื“ื•ืช ื”ืขื™ืงืจื™ืช ื‘ืžืชืŸ ืื‘ื˜ื—ื” ืžื™ืจื‘ื™ืช ื‘ื”ืงืฉืจ ืฉืœ ื—ื™ื–ื•ืง ื”ื’ื ืช ื”ืžืขืจื›ืช ืžืคื ื™ ืื™ื•ืžื™ื ืืคืฉืจื™ื™ื, ืžื” ืฉืžืงืฉื” ืขืœ ื ื™ืฆื•ืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืจื›ื™ื‘ื™ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื•ื”ื’ื‘ืจืช ื”ื‘ื™ื“ื•ื“ ืฉืœ ืงื•ื ื˜ื™ื™ื ืจื™ื. ืงื•ื ื˜ื™ื™ื ืจื™ื ื ื•ืฆืจื™ื ื‘ืืžืฆืขื•ืช ืžื ื’ื ื•ื ื™ ืœื™ื‘ืช ืœื™ื ื•ืงืก ืกื˜ื ื“ืจื˜ื™ื™ื - cgroups, ืžืจื—ื‘ื™ ืฉืžื•ืช ื•-seccomp. ืœื‘ื™ื“ื•ื“ ื ื•ืกืฃ, ื”ื”ืคืฆื” ืžืฉืชืžืฉืช ื‘-SELinux ื‘ืžืฆื‘ "ืื›ื™ืคื”", ื•ื”ืžื•ื“ื•ืœ ืžืฉืžืฉ ืœืื™ืžื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ืช ืฉืœ ืชืงื™ื ื•ืช ืžื—ื™ืฆืช ื”ืฉื•ืจืฉ dm-verity. ืื ืžื–ื•ื”ื” ื ื™ืกื™ื•ืŸ ืœืฉื ื•ืช ื ืชื•ื ื™ื ื‘ืจืžืช ื”ืชืงืŸ ื”ื—ืกื™ืžื”, ื”ืžืขืจื›ืช ืชืืชื—ืœ ืžื—ื“ืฉ.

ืžื—ื™ืฆืช ื”ืฉื•ืจืฉ ืžื•ืชืงื ืช ืœืงืจื™ืื” ื‘ืœื‘ื“, ื•ืžื—ื™ืฆืช ื”ื”ื’ื“ืจื•ืช /etc ื ื˜ืขื ืช ื‘-tmpfs ื•ืžืฉื•ื—ื–ืจืช ืœืžืฆื‘ื” ื”ืžืงื•ืจื™ ืœืื—ืจ ื”ืคืขืœื” ืžื—ื“ืฉ. ืฉื™ื ื•ื™ ื™ืฉื™ืจ ืฉืœ ืงื‘ืฆื™ื ื‘ืกืคืจื™ื™ืช /etc, ื›ื’ื•ืŸ /etc/resolv.conf ื•-/etc/containerd/config.toml, ืื™ื ื• ื ืชืžืš - ื›ื“ื™ ืœืฉืžื•ืจ ื”ื’ื“ืจื•ืช ืœืฆืžื™ืชื•ืช, ืขืœื™ืš ืœื”ืฉืชืžืฉ ื‘-API ืื• ืœื”ืขื‘ื™ืจ ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืœืงื•ื ื˜ื™ื™ื ืจื™ื ื ืคืจื“ื™ื.

ืจื•ื‘ ืจื›ื™ื‘ื™ ื”ืžืขืจื›ืช ื›ืชื•ื‘ื™ื ื‘-Rust, ื”ืžืกืคืง ืชื›ื•ื ื•ืช ื‘ื˜ื•ื—ื•ืช ืœื–ื™ื›ืจื•ืŸ ื›ื“ื™ ืœืžื ื•ืข ืคื’ื™ืขื•ื™ื•ืช ื”ื ื’ืจืžื•ืช ืขืœ ื™ื“ื™ ื’ื™ืฉื” ื—ื•ืคืฉื™ืช ืœื–ื™ื›ืจื•ืŸ, ื”ืคื ื™ื™ืช ืžืฆื‘ื™ืข ืืคืก ื•ื—ืจื™ืคืช ืžืื’ืจ. ื‘ืขืช ื‘ื ื™ื™ื” ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืžืฆื‘ื™ ื”ื”ื™ื“ื•ืจ "--enable-default-pie" ื•-"--enable-default-ssp" ืžืฉืžืฉื™ื ื›ื“ื™ ืœืืคืฉืจ ืืงืจืื™ืช ืฉืœ ืžืจื—ื‘ ื”ื›ืชื•ื‘ื•ืช ืฉืœ ืงื‘ืฆื™ ื”ืคืขืœื” (PIE) ื•ื”ื’ื ื” ืžืคื ื™ ื”ืฆืคืช ืžื—ืกื ื™ืช ื‘ืืžืฆืขื•ืช ื”ื—ืœืคื” ืงื ืจื™ืช.
ืขื‘ื•ืจ ื—ื‘ื™ืœื•ืช ื”ื›ืชื•ื‘ื•ืช ื‘-C/C++, ื›ืœื•ืœื™ื ื“ื’ืœื™ื ื ื•ืกืคื™ื
"-Wall", "-Werror=format-security", "-Wp,-D_FORTIFY_SOURCE=2", "-Wp,-D_GLIBCXX_ASSERTIONS" ื•-"-fstack-clash-protection".

ื›ืœื™ ืชื–ืžื•ืจ ืžื›ื•ืœื•ืช ืžืกื•ืคืงื™ื ื‘ื ืคืจื“ ืžื™ื›ืœ ื‘ืงืจื”, ื”ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื•ื ืฉืœื˜ ื‘ืืžืฆืขื•ืช API ื•ืกื•ื›ืŸ SSM ืฉืœ AWS. ืชืžื•ื ืช ื”ื‘ืกื™ืก ื—ืกืจื” ืžืขื˜ืคืช ืคืงื•ื“ื”, ืฉืจืช SSH ื•ืฉืคื•ืช ืžืคื•ืจืฉื ื•ืช (ืœื“ื•ื’ืžื”, ืœืœื Python ืื• Perl) - ื›ืœื™ ื ื™ื”ื•ืœ ื•ื›ืœื™ ื ื™ืคื•ื™ ื‘ืื’ื™ื ื ืžืฆืื™ื ื‘ ืžื™ื›ืœ ืฉื™ืจื•ืช ื ืคืจื“, ืืฉืจ ืžื•ืฉื‘ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”