Red Hat resets CentOS Linux and users are angry
zdnet.com
zdnet.com
With CentOS (before this latest news) possibly making a lot of sense for when you don't have the budget for RHEL, or don't yet have it, like for startups. Which then gives an easier upgrade path to nobody-ever-got-fired-for-buying-IBM/RHEL.
I don't have as much confidence in Ubuntu, and the last few months of monitoring security update regressions hasn't reinforced confidence. And the Grub problem this year, which could've bricked some remote devices for me, and where some other distros seemed more earnest and upfront about the problem. I've also grown skeptical of Snap (especially on workstations and servers, though I haven't yet ruled it out for appliances, as an easier path than Yocto).
For personal systems, I've been using Debian Stable for about 20 years (which I initially moved to because the APT network package management experience was vastly better than scouring various RPM sites or building from source, and later decided I also like the principles). And recent Ubuntu experience is making Debian compare favorably for some kinds of production use, though I'm aware of some of the substantial weaknesses of that.
Of course, then there's containers, which sometimes encourages a stripped-down distro within the container, and different requirements for what's hosting or orchestrating those.
One thing that's reassuring: both of us thought immediately of the same incident, from years ago, so there's not like there's a stream of known defects discovered frequently, like in some other other areas of this general kind of system.
Another thing that's reassuring about Debian is that some of their principles or policies align with security. For example, in the past I reported an instance in which upstream code of a package was effectively phoning-home to upstream unnecessarily, and Debian took it seriously, and fixed it. I like that the intent is there, so hopefully they'll catch many problems before I have to, and not introduce new problems on top of upstream.
That was to make it harder for Oracle to offer support for OEL, but made no difference to Centos & the non-commercial clones because they shipped the RH kernel unmodified and didn't need to worry about what any individual patch did.
I'm not sure its been a thing since RHEL6 either.
Literally "Community ENTerprise OS", yes:)
> And then Redhat generously offered to sponsor the project? And then all the trademarks and other minutiae of running the project were transferred to Redhat? And now Redhat changes CentOS to make it less like RHEL?
Correct.
You could pick another distribution, Ubuntu, Debian, etc... though you may have some up front time sink in getting everything re-tooled, depending on what you use the OS for. On large bare metal fleets, this should involve some critical thinking and planning. Some vendor tools may not be available.
You could go BSD. This is an even bigger change from a different distro, as 3rd party library and application support would need to be verified. Hardware support and monitoring would need to be tested. Proprietary (dell, hp) tools will need alternatives. OpenIPMI, static raid controller tools, etc... this is a massive topic on its own.
Other considerations are what reviews and approvals you need from your legal departments, compliance teams, security teams, datacenter build teams, etc...
Surely for servers and sysadmins, building out ones own OS artifact would be trivial in this cloud world.
Perhaps there’s some disruption to be had; Gentoo As A Service.
This means you don't have manage this yourself.