Amazon Web Services (AWS) today made available Bottlerocket, an open source Linux-based operating system specifically designed to run containers.
AWS first announced Bottlerocket in March, and in a blog posted today AWS Product Manager Samartha Chandrashekar says the technology improves container security. It does this, in part, “by including only the software needed to run containers,” which reduces the attack surface, he wrote. It also uses Security-Enhanced Linux (SELinux), which supports access control security policies and increases the isolation between containers and the host operating system.
Additionally, Bottlerocket uses Device-mapper’s verity target (dm-verity), which is a Linux kernel feature that provides integrity checking to help prevent persistent threats on the OS such as overwriting core system software. The modern Linux kernel in Bottlerocket includes eBPF, which reduces the need for kernel modules for many low-level system operations. And large parts of Bottlerocket are written in Rust, which is a newer programming language that focuses on memory safety and preventing memory-related errors, such as buffer overflows that can lead to security vulnerabilities.
For debugging, users can run an “admin container” using Bottlerocket’s API. The admin container is an Amazon Linux 2 container image, and it contains utilities for troubleshooting and debugging Bottlerocket. It runs with elevated privileges and also allows users to install standard debugging tools, such as traceroute, strace, tcpdump.
Built to ScaleIn addition to improving container security, Bottlerocket makes it easier to manage large, distributed environments at scale and automate updates, Chandrashekar wrote. “Updates to other general-purpose Linux distributions are applied on a package-by-package basis, and the complex dependencies among their packages can result in errors, making the process challenging to automate,” he explained.
But because Bottlerocket is purpose-built for containers, updates can be applied and rolled back automatically, he added.
While Bottlerocket can run as a standalone OS, it also integrates with any container orchestrators to automate patching of hosts and improve manageability. The AWS-provided builds specifically work with Amazon EKS and Amazon ECS (in preview).
Open Source BottlerocketAWS also launched Bottlerocket as an open source project on GitHub, which allows customers to customize integrations with orchestrators and container runtimes and produce their own builds. GitHub will host all design documents, code, build tools, and tests, and developers can contribute to Bottlerocket source code using GitHub workflows.
Additionally, AWS says ISV partners can quickly validate their software before their customers update to the latest versions of Bottlerocket.
Comments