We're pleased to announce that Red Hat Enterprise Linux Atomic Host 7.4 is now generally available. Red Hat Enterprise Linux Atomic Host is a lightweight, container-optimized version of Red Hat Enterprise Linux. Red Hat Enterprise Linux Atomic Host couples the flexible, modular capabilities of Linux containers with the reliability and security of Red Hat Enterprise Linux in a reduced footprint, to decrease the attack surface and provide only the packages needed to light up hardware and run containers. Here's a look at some of the major changes in 7.4.
OverlayFS now fully supported with SELinux
After being introduced in Red Hat Enterprise Linux 7.1 as a technology preview, OverlayFS is now fully supported in Red Hat Enterprise Linux 7.4 and Red Hat Enterprise Linux Atomic Host 7.4 when used with docker as the docker graph driver under the conditions described in the release notes.
As the name implies, OverlayFS is a type of file system that allows users to overlay a file system on top of another file system. When changes are made to a file, they are stored in the "upper" file system and the "lower" file system remains unchanged. This is used for Linux containers to allow writes to container images, which may be shared among multiple running containers. This will also convey performance benefits when using OverlayFS, particularly for container builds. Red Hat recommends using the overlay2 graph driver with Linux containers.
With 7.4, OverlayFS now has SELinux support and is fully supported as a graph driver for Linux containers. Note that OverlayFS is still only supported with XFS as the underlying file system, and is not supported for persistent storage for containers. Persistent storage for containers should still be placed on non-OverlayFS volumes to be supported.
LiveFS brings updates without reboot
We introduced package layering with rpm-ostree in Atomic Host with 7.3, and the 7.4 release brings this to fully supported. Package layering allows you to add packages that aren't part of the original install to the system permanently. This is useful for adding diagnostic tools, monitoring tools, or packages that add support for hardware.
Previously, using the atomic host install and atomic host uninstall commands (aka package layering) with Atomic Host required a reboot to take effect. In this release, we're delivering LiveFS functionality to allow users to let package changes take effect without a reboot. This is currently in technology preview stage with 7.4, and a reboot is still required for rpm-ostree updates (kernel & user space).
Namespace support
With Red Hat Enterprise Linux 7.4 and Red Hat Enterprise Linux Atomic Host 7.4, we now offer user namespaces with Linux containers. This means that processes inside a container have their own namespace that maps to unprivileged namespaces outside the container. So a root user in the container does not map to the root user outside the container.
Package signing, Container Health Index, and more
Red Hat's work on Linux containers goes far beyond RHEL Atomic Host. We are constantly working to improve the end-to-end delivery of Linux containers from the base image, to the host platform, to orchestration and more. In addition to the new features present in RHEL Atomic Host 7.4, here's a few noteworthy improvements beyond RHEL and RHEL Atomic Host for Linux containers.
In May, we announced the addition of the Container Health Index to the Red Hat Container Catalog. The Container Health Index is an easy-to-understand grade (A to F) detailing how images should be consumed and evaluated for production systems, based in part on the age and impact of unapplied security errata across all components of a container.
Last week, we delivered signing for all Red Hat images in the Container Catalog. As Aaron Weitekamp wrote last week, "customers can now configure a Red Hat Enterprise Linux host to cryptographically verify that images have come from Red Hat when they are pulled onto the system. This is a significant step in advancing the security of container hosts, providing assurance of provenance and integrity and enabling non-repudiation." Be sure to check out Aaron's post for the full details on using and verifying the signatures in your environment.
As you can see, there's a lot of container goodness in Red Hat Enterprise Linux Atomic Host 7.4. Watch this blog in the next few weeks for more details on using some of the new features in 7.4.
Sobre o autor
Joe Brockmeier is the editorial director of the Red Hat Blog. He also acts as Vice President of Marketing & Publicity for the Apache Software Foundation.
Brockmeier joined Red Hat in 2013 as part of the Open Source and Standards (OSAS) group, now the Open Source Program Office (OSPO). Prior to Red Hat, Brockmeier worked for Citrix on the Apache OpenStack project, and was the first OpenSUSE community manager for Novell between 2008-2010.
He also has an extensive history in the tech press and publishing, having been editor-in-chief of Linux Magazine, editorial director of Linux.com, and a contributor to LWN.net, ZDNet, UnixReview.com, and many others.
Navegue por canal
Automação
Últimas novidades em automação de TI para empresas de tecnologia, equipes e ambientes
Inteligência artificial
Descubra as atualizações nas plataformas que proporcionam aos clientes executar suas cargas de trabalho de IA em qualquer ambiente
Nuvem híbrida aberta
Veja como construímos um futuro mais flexível com a nuvem híbrida
Segurança
Veja as últimas novidades sobre como reduzimos riscos em ambientes e tecnologias
Edge computing
Saiba quais são as atualizações nas plataformas que simplificam as operações na borda
Infraestrutura
Saiba o que há de mais recente na plataforma Linux empresarial líder mundial
Aplicações
Conheça nossas soluções desenvolvidas para ajudar você a superar os desafios mais complexos de aplicações
Programas originais
Veja as histórias divertidas de criadores e líderes em tecnologia empresarial
Produtos
- Red Hat Enterprise Linux
- Red Hat OpenShift
- Red Hat Ansible Automation Platform
- Red Hat Cloud Services
- Veja todos os produtos
Ferramentas
- Treinamento e certificação
- Minha conta
- Suporte ao cliente
- Recursos para desenvolvedores
- Encontre um parceiro
- Red Hat Ecosystem Catalog
- Calculadora de valor Red Hat
- Documentação
Experimente, compre, venda
Comunicação
- Contate o setor de vendas
- Fale com o Atendimento ao Cliente
- Contate o setor de treinamento
- Redes sociais
Sobre a Red Hat
A Red Hat é a líder mundial em soluções empresariais open source como Linux, nuvem, containers e Kubernetes. Fornecemos soluções robustas que facilitam o trabalho em diversas plataformas e ambientes, do datacenter principal até a borda da rede.
Selecione um idioma
Red Hat legal and privacy links
- Sobre a Red Hat
- Oportunidades de emprego
- Eventos
- Escritórios
- Fale com a Red Hat
- Blog da Red Hat
- Diversidade, equidade e inclusão
- Cool Stuff Store
- Red Hat Summit