Modern edge environments require innovative solutions that are powerful and purpose-built, while also being lightweight and portable.
Whether on the shop floor, in a wind turbine, or inside a POS system, today’s edge deployments require systems that are compact yet capable of doing more than ever before.
As organizations expand their edge footprint, they need solutions that provide performance under industry-specific constraints without adding management complexity or introducing fragility.
Red Hat is supporting this shift with a consistent approach to how operating systems and applications are built, deployed, and maintained at the edge. With new tools and features introduced through Red Hat Device Edge—a flexible platform that supports different workloads across small, resource-constrained devices at the edge—organizations can now apply container-native workflows to the OS itself. This brings new levels of consistency, automation, and flexibility to the edge software lifecycle.
Discover OS deployment using image mode in Red Hat Device Edge
Red Hat Device Edge introduces image mode, an innovative solution that allows organizations to build, package, and distribute an OS just like containers.
Image mode represents a significant evolution from the OSTree-based approach used in earlier Red Hat Enterprise Linux for edge deployments. While OSTree manages OS updates via layered filesystem snapshots, image mode packages the entire OS as a bootable container (bootc) image, allowing for simpler, more streamlined deployments.
This container-based OS image is managed using the bootc tool, which makes sure the image is bootable by embedding necessary bootloader and kernel metadata.
This shift aligns edge OS management with cloud-native DevOps workflows, making it easier for teams familiar with container tooling to build, test, and deploy edge operating systems. Teams can take advantage of the same tooling that is used for application containers (e.g., CI/CD tools), but for the OS.
Using image mode allows teams to:
- Build, test, and deploy edge OSes as open container initiative (OCI)-compliant container images.
- Converge application and OS pipelines into a single GitOps-enabled continuous integration and continuous delivery (CI/CD) workflow, using the same processes and tools for application containers and the OS or base platform.
- Gain reproducibility and portability across hybrid and multicloud environments.
- Streamline updates with better control, security focus, and rollback options.
This modern, declarative approach eliminates the need for manual configuration or master images. Now, edge operating systems can be treated like versioned, traceable, and auditable artifacts, delivering stronger governance and accelerated time to value.
Image mode is the preferred method for edge OS deployment starting with Red Hat Enterprise Linux 10. OSTree-based Red Hat Enterprise Linux for edge remains supported in Red Hat Enterprise Linux 9 for existing workloads but will be superseded by image mode in upcoming releases.
Security is built in
Image mode benefits from cryptographic validation, security-focused provenance, and toolchain consolidation. This means that organizations can confidently deploy updates to remote, disconnected devices knowing the system is verifiable, rollback-capable, and supported by Red Hat’s trusted supply chain process.
The bootc tool also makes sure that security contexts, such as SELinux labels, are preserved within the bootc image, maintaining compliance with strict security policies in regulated environments.
New capabilities at the edge for real-time and AI-enhanced innovation
Since its initial release in 2023, Red Hat Device Edge has evolved to support more advanced and specialized use cases across industrial, retail, and many other industries.
The platform now includes a host of features that give organizations greater performance, precision, and flexibility at the edge.
Real-time performance for latency-sensitive applications
To meet the demands of latency-sensitive edge environments, Red Hat Device Edge introduces a suite of performance-tuning capabilities. These features are designed to deliver deterministic, real-time behavior where milliseconds—or even microseconds—matter most, such as in industrial control systems, robotics, and other safety-critical operations.
- Low-latency kernel support for ultra-fast compute scenarios.
- CPU core isolation to help teams maintain consistent performance for priority workloads.
- Workload partitioning to prevent jitter and resource contention.
- Maximum latency targets of lower than 50 microseconds to allow for demanding workloads like software-defined industrial control systems, robotics, and safety-focused operations.
Advanced networking support
As edge deployments grow more complex, networking flexibility becomes essential. Red Hat Device Edge provides advanced networking capabilities that support multinetwork connectivity, modern addressing standards, and fine-grained traffic control. This allows organizations to tailor networking to meet the needs of their applications, locations, and compliance requirements.
- Multus integration. This open source project allows Kubernetes pods to attach to multiple network interfaces per pod, providing separation of control, data, or sensor networks.
- IPv6 support. Including single-stack and dual-stack configurations, IPv6 allows organizations to address connectivity in modern, high-scale environments.
- Support for use cases. This support includes telcos, industrial automation, and retail environments, where traditional IPv4 addressing may fall short.
FIPS-ready compliance and security
In highly regulated industries and government environments, security and compliance are foundational. Red Hat Device Edge supports stringent security requirements with built-in features that meet cryptographic compliance at the OS level.
When installed on Red Hat Enterprise Linux in Federal Information Processing Standards (FIPS) mode, MicroShift core components use Red Hat Enterprise Linux cryptographic libraries that have been submitted for FIPS 140-3 validation.
This maintains compliance with strict U.S. federal and international standards for cryptographic operations, which is a requirement for regulated industries and government deployments.