What's new in Red Hat Enterprise Linux 9
developers.redhat.com
developers.redhat.com
Given margins are often so good on subscription models in a redhat type world, I really wish they had gone a bit heavier on cloud focus (AWS / GCP / Windows in my case). Some free / base images container / vm focused pushed hard for everything from docker to cloud.
I thought ubuntu executed very well here (given their commercialization has always felt somewhat weak). They got images for docker / aws / gcp all first class and available at the basic level. They are also doing some deals with Microsoft and Windows Subsystem for Linux.
Not sure if anyone has done the docker image download weighted by base distribution analysis, but my own experience went from the centos / rhel was like everywhere to ubuntu and amazon's linux stuff.
Would be great to have an offering as the basic base image for docker containers (outside of UBI).
They let Project Atomic die.
Then they let CoreOS Container Linux die I think?
They have a Fedore CoreOS but don't seem to promote it at all and I can't find images on docker hub for it.
The RedHat stuff is generally paywalled. CentOS is gone.
I know they are pitching the IBM cloud - I don't care about the IBM cloud - though they keep on advertising Watson to me as the solution to every issue.
The OpenShift brand was hurt by the enormous mess of complexity it was compared to K8 and things like ECS and Fargate etc.
Fedora Silverblue is also comparable to Project Atomic for the traditional non-container installed OS scenario.
Do you buy Red Hat Enterprise Linux? Or Ubuntu? Just based on the name I think RHEL as an advantage personally.
I just went on docker hub. I search for Redhat Enterprise Linux and RHEL.
I get ubuntu with 1B+ downloads. I get oraclinux, amazonlinux (?!?), alpine, debian and more. If they are releasing docker base images they are doing an absolutely terrible job getting them distributed. I'm honestly kind of shocked to see amazon here, are people developing against Amazon outside of just spinning up hosts on EC2 etc? Amazing. I might do that myself.
Edit: Amazon Linux looks fedora based for 2022 forward, but with 5 years of support - that's not a bad combo if they can deliver. I'm going to try it for my next project. Their Amazon Linux support has been poor in the past at times.
https://catalog.redhat.com/software/containers/search?q=ubi9...
red hat has some sort of partnership with docker to have them available in docker hub, i guess it's just not there yet...
https://www.redhat.com/en/about/press-releases/red-hat-bring...
* No more KVM virtualization on IBM POWER (e.g., Raptor's Talos and Blackbird systems)
* SPICE is removed in favor of VNC, even though VNC doesn't yet support a bunch of SPICE's functionality, such as audio, smart card sharing, and USB redirection
* No more taking snapshots of VMs
* virt-manager is removed in favor of a new Web console, even though it doesn't have all of the features of virt-manager yet
* SSHFS is gone (it's in EPEL now, but a lot of places have ridiculous rules that only official RHEL packages are allowed)
Are you sure about that it was 'removed'? I have CentOS Stream 9 installed and virt-manager shows as a CentOS package (not epel). CS9 is not RHEL 9 but I believe virt-manager's support was depreciated.
EDIT: At the risk of sounding like "that guy" I'd like to clarify that I don't fault my former colleague for what he said; for nearly 20 years "Red Hat" has been colloquially synonymous with RHEL (vice CentOS and Fedora) and I merely thought this was an amusing anecdote.
And so many years later, I am yet to see Linux 6.
Seeing a proliferation of container-first, immutable, and atomic distributions like Fedora CoreOS would be a good middle ground between bare-metal and Kubernetes.
All of my Fedora CoreOS hosts automagically upgrade themselves via rpm-ostree and Zincati, and the fact that the OS is atomic and disconnected from the containers I'm running on top of it gives me a lot of peace of mind in terms of stability.
when billions is on the line, companies doesn't want you to google/stackoverflow for days. they want the problem solved in hours. that's where RedHat come in.
its like auto insurance, you are paying for nothing until a fatal crash happened.
What are the benefits and costs?
The main thing I liked about RHEL was its stability. Not a lot of churn, and for running any other vended software, support for RHEL was never a question.
Converted everything to CentOS. When Red Hat killed that distro, that was a bridge-burning event. We use Ubuntu now.
Compared to other Linux distros: some COTS software requires RHEL, risk adverse orgs probably need to layer RHEL support with their COTS support contracts to meet SLAs/support requirements.
As a developer, I love working with it.
But now nearly everything we deploy is on AWS Fargate and our images are Debian based.
plenty of activity each day that is not in that category
If you take a look at the Fortune 500, it wouldn't surprise me if Red Hat was in use by at least 490 of them.
How did CentOS fit into that? I guess I would have naively expected you to be on RHEL to begin with.
And devs often used CentOS when playing around (ie, setting up VM's etc at home or just randomly) because you didn't need to talk to anyone to do so.
There used to be a $99/yr "support in name only" option, with no ability to file service requests (community discussion boards only). The basic level of support was $500/yr.
It now appears that basic support is $1,200/yr. Of course, ISO downloads and yum support are still free, but the support contract is now much more expensive.
Oracle also still offers free KSplice kernel updates for Ubuntu, but it appears that Fedora support was removed.
Having a support contract in place was often a requirement for the clients, perhaps due to regulatory reasons.
I never saw this "support" actually used. The benefits are more a CYA thing.
RedHat is stable: Which has the benefit that it's stable, and the cost that it's always behind the times.
Security is deadly serious, and RedHat make it easy. STIGs are available for RHEL; they're also available for SuSE [very recently] and Ubuntu LTS releases, but we're heavily invested in RHEL infrastructure, training, etc, so switching to Canonical would be expensive and hard. A few years ago I earnestly looked at us coming up to speed on Ubuntu, but with Canonical's recent behaviour around packaging I'm kind of glad we didn't.
We rolled with CentOS in a few places for a while [all the benefits of the training and experience], but the recent changes in that make it useless for our needs.
I've been around for long enough that I remember when Linux sucked; I started using it around 1997. Nowadays, I find that all modern distros are in the same ballpark of "pretty much work pretty much all the time"; so while I don't love RHEL, it's been a safe stable choice and doesn't bite me in the ass.
I think this was linked on HN the other day, and it basically covers anyone using RHEL: https://boringtechnology.club/
I think this was linked on HN the other day, and it basically covers anyone using RHEL: https://boringtechnology.club/
God, I think you can tell the real engineers that have gone through the trial by fire and the ones that haven't simply by how much they agree with that presentation. At some point in your career, at 2AM when your debugging that fantastic new opensource library, for the 10th time, that you rewrote everything because it did exactly what you needed, and made you a hero for a week, you switch from gabbing the latest cool thing to picking those old technologies that everyone knows why they suck.Because knowing why something sucks when you pick it, is more important than knowing why its good.
RHEL sucks because in 10 years you will be running some horrendously "outdated" software. Its fantastic because over those 10 years you will have made a pile of money selling your product and adding features rather than spending cycles being an upgrade monkey for things you didn't know you needed until someone sold them to you. And your customers, they don't care what OS your running as long as its reliable. Which is something RH provides in spades.
(This can even happen between various old and established things; if you know MySQL and all its warts well, perhaps switching to the relatively unknown PostgreSQL "because it's better" isn't the best use of your time. You should be able to explain why and why not before making the switch. When in doubt, do what everyone else is doing - unless it's your differentiator.)
Release notes: https://nodejs.org/ko/blog/release/v16.0.0/
Wonderful.
In Europe it's Debian or SUSE, and in the states it's RHEL. I don't have a preference (but Slackware is awesome).
I was on the forefront of this when they were backporting container tech to their 2.6.32 kernel.
I've also seen them break userspace repeatedly with kernel changes for selinux within a stable kernel.
But as you say, you can pay for support so you have someone to scream at when things go south.
When it comes to ABI stability, I'd trust the vanilla kernels more than RHEL.
Yelling at RH is about as effective as screaming at paint to dry faster in my experience. Their support can be very effective, but it's so slow it's mostly useless. They put you through afew layers of "are you this dumb" before you can get anywhere.
One of the reason, at the place were we ran about 100's of RHEL/CentOS instances, he stayed with RHEL-ish installs was to maintain API compatibility through out the lifecycle of the OS version.
I've now moved on to places were that isn't that specific need. But I still have a few smaller projects that I use RHEL/CentOS/Rocky/etc. because of the stability that those built into the releases.
Never heard of this before. Looks like it's called kpatch: https://github.com/dynup/kpatch
canonical pay walled the second (free for "personal" use):
https://ubuntu.com/security/livepatch
Kpatch was/is the open, not-patent encumbered version (IIRC) - i thought RedHat had offered some version for years?
Ed: Only rarely touch RedHat for the past few years - and generally prefer "know that system boots correctly after (kernel) updates" to "its running new (presumably secure) kernel, but might not boot if power fails". It's a trade-off - but rarely do I need kernel live patching. Services probably need a restart due to new SSL library anyway...
CONFIG_SECURITY_LANDLOCK=y
CONFIG_LSM="landlock,lockdown,yama,..."
CONFIG_LSM="lockdown,yama,integrity,selinux,bpf"
on kernel 5.14.0-70.13.1.el9_0.aarch64
So not on ARM at least
That's a big deal when you run a big business.