Live data from Hacker News

CentOS Project shifts focus to CentOS Stream

lists.centos.org

471–480 of 642 posts

Re: CentOS Project shifts focus to CentOS Stream

#471
post #140

Earlier quoted context omitted.

Wonder if the web hosting industry will rebel and build another RHEL clone project that just gets the 10-year supported patches. Red Hat still has to release the patches, right? A really big chunk of the world's traditionally shared hosted websites run on CentOS, because most commercial control panel packages and hosting automation systems are built for that. A rebadged CentOS is also AWS's default distro. Wonder of…

> Red Hat still has to release the patches, right? I think that's a gray area. For example RHEL has some support branches where they'll produce security updates for minor updates. For example you can pay a lot of money and you'll get RHEL 7.2 with security updates. They won't release sources for those packages unless you'll ask for those packages (you, as a paid client, not you as nobody in the Internet). But if you'…

This is what grsecurity has done as well and I don't understand with people that against the current grsecurity way of licensing.

Re: CentOS Project shifts focus to CentOS Stream

#472

Earlier quoted context omitted.

Oracle Linux is free with optional paid support. "Unlike many other commercial Linux distributions, Oracle Linux is easy to download and completely free to use, distribute, and update. Oracle Linux is available under the GNU General Public License (GPLv2). Support contracts are available from Oracle. " https://www.oracle.com/a/ocom/docs/027617.pdf [PDF]

never, Ever, EVER trust Oracle. Especially with something as important as an open source product. Evidence: Oracle's Sen. VP Glueck statement that "There is no math that can justify open source from a cost perspective." No chance you'll ever see me running OEL.

From their page, does this even read professional? Sounds like some startup wrote it trying to make them look bigger than they're.

Community based sounds better to me.

> But if you're here, you're a CentOS user. Which means that you don't pay for a distribution at all, for at least some of your systems. So even if we made the best paid distribution in the world (and we think we do), we can't actually get it to you... or can we?

Re: CentOS Project shifts focus to CentOS Stream

#473

Earlier quoted context omitted.

>> Imagine if you were running a business, and deployed CentOS 8 based on the 10 year lifespan promise. You're totally screwed now, and Red Hat knows it. The hypothetical you posed is the actual situation, I am now learning, I have apparently forced on my team. We've ramped up labor 3x revenue preparing product launch in 90 - 180 days. We created an image containing centos 8 , Java , postgres and tomcat a year ago an…

I'm wondering, what ties you so strongly to a single OS? Nay, to a single Linux distribution? I have a hard time imagining, and the only scenarios that come to mind are those where things have gone awfully haywire. I'm sure I'm missing something. Enlighten me?

An existing support contract?

If you run a for-profit operation, and downtime is costly, you (or your VP of eng) want a way to pay for immediate assistance from the OS's maker / distributor, when (not if) things go wrong.

Re: CentOS Project shifts focus to CentOS Stream

#474
post #168

Earlier quoted context omitted.

That already exists and is called CloudLinux. It is very cheap but not free. Other RHEL-clones: Oracle Linux (best one), Springdale Linux. Other alternatives: openSUSE Leap and Debian. I am not even listing Ubuntu because I hate it since snaps.

Oh cool. As for CloudLinux, "not free" probably scale for some hosting environments, including non-managed cloud instances. But something like Springdale, given resources, might be able to provide. They're still tracking RHEL 7, though. Debian and Ubuntu, which offer five years of Long Term Support are the next best thing available, and that's already kind of tight for long-term deployments of self-hosted, old-fashio…

> Debian is particularly impressive, since they, on paper, aim to support all packages with security fixes, whereas Ubuntu's main repo is a lot more limited.

What are the track records of the claim?

I'm sure Ubuntu will patch stuff up if some vulnerability shows up outside of main that gets patched upstream or elsewhere.

Re: CentOS Project shifts focus to CentOS Stream

#475
At the risk of getting hit with downvotes... because its oracle..

Oracle Linux actually seems to be the best way out (at least for now)

/me shudders.

Actually just installing it on a new 5900x now after aborting CentOS due to it becoming abandonware and having its name stolen by IBM.

Re: CentOS Project shifts focus to CentOS Stream

#476
It does make sense from RH's perspective that when Fedora is a testing environment for the next major version and RH wants to use CentOS for minor version test environment, so that they can release a new RHEL minor version more confidently to paying customers.

I assume CentOS Stream will be based on the previous RHEL minor version release which would be stable and puts improvements for the next minor version release before RHEL releases it which doesn't sound like the end of the world like some people seem to think.

You actually get improvements earlier than later and you also get to throw feedbacks in before the next minor version gets released which feels more community oriented.

Unless your server needs absolute stability like RHEL (in which case you might as well just pay for RHEL), then it seems ok to use Stream.

For those that need absolute stability but have no decent flow of income, then you might be burned but I suppose a new community supported RHEL clone would come out sooner or later.

Re: CentOS Project shifts focus to CentOS Stream

#477
We use CantOS in production. Our servers are typically replaced once in 3 years. But we update our software stack on bare metal only once in 5 years or so. We however spin up VMs all the time on these servers, and having a single standard operating system base that was extremely stable did not have licensing issues was a positive. This changes the calculus for using RedHat based OSes. So we initiated a migration to Debian.

Re: CentOS Project shifts focus to CentOS Stream

#478

Earlier quoted context omitted.

Canonical are also fairly actively involved in security fixes and among those brought in to the various security embargoes. They usually ship packages the same day embargoes drop.

Interesting, who else are involved in the embargoes? Anywhere I could read more about this?

It depends on where the vulnerability is. Everything is all ad-hoc, each piece of open source software decides how they want to handle it, attempting to juggle the chances of a leak. The fewer you tell, the more likely the secret is to be kept, and you want to keep these things secret until a patch is done.

The linux kernel maintainers have a private list where they co-ordinate some of this stuff, and every major Linux distribution will have engineers on it.

That's partly why you see things like OpenBSD etc. being left on the margins. Certain maintainers have been quite vocal about not adhering to embargoes, which really doesn't help them. It's an idealist vs pragmatist thing going on there.

Re: CentOS Project shifts focus to CentOS Stream

#479

Earlier quoted context omitted.

Out of curiosity why did you decide to deploy your application as a VM image? Is there a reason you didn't go with a Helm chart or other container native deployment?

You're asking why someone who uses CentOS hasn't gone with Helm charts? That's like polar opposites of stability and bleeding edge.

I was curious what drove the decision to deploy that way. I was under the impression most new applications being developed today would choose a more modern deployment method. There’s a lot to maintain in a VM image like that, containers just seem easier to me. Helm chart or otherwise

Re: CentOS Project shifts focus to CentOS Stream

#480
post #245

Earlier quoted context omitted.

That would be cool "stick it to the man" trick, but how do we organize?

Not only does this not "stick it to the man", it's directly addressed in the FAQ. If folks want to boot up another rebuild project, there's nothing preventing that. There are also several existing ones that you could go join.

CentOS started out as just such a project...
Post reply on HN