Correct me if I'm wrong, but the way I read this, CentOS Stream will still serve as a stable clone of RHEL just as it always has. The rolling distro will be tagged at a certain point in time for a RHEL release, and you can still choose to use that state as your production base, and be locked at that tag. Presumably there will be a CentOS Stream 9 tag that you can use for production. The difference will be that CentOS…
It seems that if you do that, you will not get any updates, including security updates?
Q4: How will CVEs be handled in CentOS Stream? A: Security issues will be updated in CentOS Stream after they are solved in the current RHEL release. Obviously, embargoed security releases can not be publicly released until after the embargo is lifted. While there will not be any SLA for timing, Red Hat Engineers will be building and testing other packages against these releases. If they do not roll in the updates, the other software they build could be impacted and therefore need to be redone. There is therefore a vested interest for them to get these updates in so as not to impact their other builds and there should be no issues getting security updates.