Elasticsearch end-of-life in Debian Stable
lists.debian.org
lists.debian.org
It looks like ES separates repos by version[0], if that helps at all.
[0] https://www.elastic.co/guide/en/elasticsearch/reference/mast...
At least we're getting security support(1), but it's a little concerning that more and more upstream vendors seem to leave long-term distros in the dust :-/ Is this a new development? I can't remember similar EOL announcements even just a year ago. Although better to actually announce this than letting packages linger unattended/unannounced...
(1) except php security support in wheezy is also already EOL'ed, before the usual wheezy EOL.
In other words (presuming containerization): Debian LTS is the thing you install a Docker daemon onto and then forget about. But Debian LTS is obviously not for use as a container base-image (container-images don't auto-upgrade; and they can be QAed on each app release to ensure the app works with ABI changes of deps.)
Given those two facts, LTS support these days really only has to apply to things that will be run as part of the (from a developer's perspective) black-box abstraction that is "the OS", rather than considered a part of the "service and its dependencies" slug which gets versioned and deployed by the service-owner.
Or, for that matter, since Elasticsearch is written in Java, most Java developers just use Maven to pull in dependencies and don't even bother using the OS package manager.
The modern Linux distribution (the one everybody wants to use) is something which has curl and bash, and can execute ELF binaries.
Also, LTS probably has Linux kernels that are far too old.
Backporting fixes into a 5 or 10 year old version of the software isn't fun. Or, for example you could not port to python 3 fully and drop python 2 if you wanted to support centos 7 easily.
It's messy, but I'd rather support removing the packages and probably even languages or python packages from the distros repos so you're geared towards effort immediately, instead of installing elasticsearch and then ending up vulnerable.
`apt-get install elasticsearch`
in future Debian releases? Or is this something else?
they think it's too insecure to include in stable.
Sure it's not that there are known problems, but security isn't a thing you have or don't have; it's a process. If your process for identifying and fixing security flaws is broken, that's insecure.
Yes you will, it's just an old version without security updates.
> but you will be able to get it in unstable
No you won't, Stretch is the current unstable and elasticsearch is going to be removed from it.
elasticsearch will continue to remain in unstable
* In Debian Jessie, you can still install the Debian Elasticsearch package, but it will not receive security updates any longer.
* In future releases of Debian, this package will not be available in the main repo, but will still be available in the unstable or jessie-backports repos.
* Elasticsearch (the company) maintains its own Apt repositories where they will provide updated versions according to their support policies. If you add this repository to your Debian based systems you can install the (supported) Elasticsearch package with "apt-get install elasticsearch".
It is my opinion that you should not deploy the Debian ES package in a production setting. Use the vendor repo and save yourself a headache.
For what it's worth, I am currently running off the official packages at moderate scale (~30 machines all together) and have not yet had an issue with it, though it's certainly possible that one will arise and I will thereafter curse Elasticsearch forever.
In this particular case though, security updates are critical, so what other choice is there unless you want to package your own?
E: elasticsearch: file-in-usr-marked-as-conffile usr/lib/systemd/system/elasticsearch.service
E: elasticsearch: description-starts-with-package-name
W: elasticsearch: description-too-long
E: elasticsearch: extended-description-is-empty
W: elasticsearch: non-standard-dir-perm etc/elasticsearch/ 0750 != 0755
W: elasticsearch: executable-is-not-world-readable etc/elasticsearch/elasticsearch.yml 0750
W: elasticsearch: executable-is-not-world-readable etc/elasticsearch/logging.yml 0750
W: elasticsearch: non-standard-dir-perm etc/elasticsearch/scripts/ 0750 != 0755
E: elasticsearch: dir-or-file-in-var-run var/run/elasticsearch/
E: elasticsearch: postrm-contains-additional-updaterc.d-calls etc/init.d/elasticsearch
W: elasticsearch: script-in-etc-init.d-not-registered-via-update-rc.d etc/init.d/elasticsearch
W: elasticsearch: executable-not-elf-or-script etc/elasticsearch/elasticsearch.yml
W: elasticsearch: executable-not-elf-or-script etc/elasticsearch/logging.yml
W: elasticsearch: maintainer-script-calls-systemctl postinst:82
W: elasticsearch: maintainer-script-calls-systemctl postrm:72
W: elasticsearch: maintainer-script-calls-systemctl prerm:51
Doesn't look too bad, I'd want to fix the permissions but it's not the worst thing I've seen