[HN Gopher] Ubuntu Core 22 is now available - optimised for IoT ...
       ___________________________________________________________________
        
       Ubuntu Core 22 is now available - optimised for IoT and embedded
       devices
        
       Author : pantalaimon
       Score  : 105 points
       Date   : 2022-06-15 12:51 UTC (10 hours ago)
        
 (HTM) web link (ubuntu.com)
 (TXT) w3m dump (ubuntu.com)
        
       | derefr wrote:
       | Annoyingly, along with this, the Ubuntu "Minimal" network
       | installer is dead (no 22.04 release) -- presumably to "encourage"
       | people to move over to this.
        
         | josteink wrote:
         | At this point all my from-scratch installs are usually Debian-
         | based where they used to be Ubuntu-based.
         | 
         | Canonical seems to completely have lost touch with what the
         | community wants, and with the non-free installer, I find Debian
         | working equally well OOB as Ubuntu has done in the past.
         | 
         | The only machines I still keep on Ubuntu are the ones already
         | running it where migrating them will be too much hassle.
         | 
         | For my latest laptop, out of curiosity, I also tried Arch. It
         | seems to work fairly well, but I haven't had enough experience
         | with it yet to "dare" put it on servers.
        
           | cptnapalm wrote:
           | I'm using Manjaro on my laptop and it's been smooth so far,
           | aside from an initial wifi chipset hiccup. I'm using it also
           | on a laptop-as-a-router. Disabled all the graphical stuff.
           | It's been very good, thus far and only 213 MB of RAM being
           | used after disabling some (but certainly not all) unnecessary
           | services. I do with they had a minimal install for x86_64
           | like they do for ARM.
        
         | speedgoose wrote:
         | Yes, I'm more encouraged to move back to Debian personally.
        
       | spicyusername wrote:
       | There seem to be mixed sentiment in this thread around this.
       | 
       | One alternative is Fedora CoreOS.
       | 
       | https://getfedora.org/en/coreos?stream=stable
        
       | psanford wrote:
       | Do you still have to have a canonical sso account just to login
       | to your own devices?
       | 
       | EDIT: The answer appears to still be yes. I don't know who
       | canonical is making this for, but no company is going to want to
       | deploy IoT devices that hand over the root of trust for
       | authentication to a third party. And I have to believe that many
       | individuals/hobbyists that would otherwise be excited to use this
       | will choose another distro for the same reason.
       | 
       | Canonical seems to be out of touch with what people actually
       | want, and is happy to build things it likes that will ultimately
       | be irrelevant.
        
         | tssva wrote:
         | For individuals and hobbyists Ubuntu Server would likely make
         | more sense than Ubuntu Core. I used to recommend it for use on
         | headless Raspberry Pi's over Raspberry Pi OS. Use of cloud-init
         | and netplan made it much easier for deployment of headless
         | RPi's.
         | 
         | Unfortunately for 22.04 they made some changes on the RPi which
         | severely impacted my deployments causing me to move away from
         | Ubuntu on the RPi and to no longer recommend it to others.
        
         | yourstruly-br wrote:
         | They have no clue what the market wants. Nobody is going to
         | shell out $15k-20k to build a solution. We lost about 4 months
         | betting on it and eventually moved away. We are glad we did.
        
           | nix23 wrote:
           | >Nobody is going to shell out $15k-20k to build a solution.
           | 
           | Well that's not true, if the solution is a success 20k is not
           | much....problem is it rarely is with canonical.
        
             | yourstruly-br wrote:
             | In our case we were building a solution from scratch. It is
             | very hard to justify upfront costs like that, involving
             | open-source and early in the project. IoT solution costs
             | should move up according to scale. That's why AWS, Azure,
             | and others have grown their IoT offerings. Nobody starts
             | paying $20k upfront to use AWS IoT.
        
               | nix23 wrote:
               | >Nobody starts paying $20k upfront to use AWS IoT.
               | 
               | You have not written anything about upfront or IoT.
               | 
               | AWS IoT? Is that even a thing? (pun intended)
        
       | yourstruly-br wrote:
       | I highly discourage anyone to use Ubuntu Core as part of their
       | solution. It is a secure environment, yes, but it is a nightmare
       | to configure (snaps) and for everything, expect for the most
       | basic stuff, you will need what is called a "brand store", which
       | costs about $20k/year, regardless if you have 1 or 100 devices.
       | (We could not even make one snap talk to another snap, checking
       | another snap status etc). We had commercial discussions w/
       | Canonical and we basically moved away.
        
         | curt15 wrote:
         | Buying a Brand Store is also the only official way to have full
         | control of snap updates. Someone at Canonical must have been
         | taking notes from Microsoft -- take away control from users and
         | sell it back in an "enterprise edition".
        
           | GordonS wrote:
           | No issue with Canonical making some money from their OSS
           | efforts, but as-is the pricing seems crazy. At the least, I
           | wish they'd do something like make brand stores free for less
           | than 100 devices. That would also serve to hook people in,
           | then they pay as they grow.
           | 
           | Ideally though, Canonical would let anyone run their own
           | "brand store" on their own hardware.
        
         | discreteevent wrote:
         | If you've only got one device then it probably doesn't make
         | sense. But if you have a number of devices, you probably have a
         | business and need to make sure that you can reliably and
         | securely update them remotely. How many developer/ops hours do
         | you think that would take? 20k doesn't buy you much in dev
         | hours these days.
        
         | brnt wrote:
         | Been a huge fanboy since Warthog, but as of 20.04 I've sought
         | refuge elsewhere. Turns out, Ubuntu isn't nearly as user
         | friendly as it was back then, in fact, it's one of the least
         | user friendly distros these days! Everybody progressed and you
         | deserve t check it out yourself!
        
           | tomcam wrote:
           | What's your new distro of choice?
        
             | capableweb wrote:
             | Not the one you're replying to, but started my Linux
             | experience with Ubuntu 6.10, was using it all the way up to
             | ~17, and started using Arch Linux after that since during
             | my time of using Ubuntu, I learnt enough Linux that I could
             | setup my own system (and of course, with the help of the
             | awesome Arch Wiki).
        
               | 5e92cb50239222b wrote:
               | Worth noting that Arch has had something resembling the
               | OpenBSD installer for some time. Trying it out doesn't
               | require reading 20 wiki articles as it did back in my
               | day(tm). You answer a few questions, wait a few minutes,
               | and it's done.
               | 
               | https://wiki.archlinux.org/title/Archinstall
        
               | capableweb wrote:
               | Wow, that's great, haven't seen that before! Granted, it
               | was some time ago I did a setup from scratch.
               | 
               | Seems that installer is like 90% on the way to be useful
               | as a general installer. At a glance, seems to missing
               | things like networking setup (as most people use WiFi
               | these days, it seems), but at least it takes care of most
               | things you need for a install.
        
             | ab_testing wrote:
             | Linux Mint for everyday use. It made my 10 year old hot
             | running laptop into a cold mean machine.
        
               | hoppyhoppy2 wrote:
               | Linux Mint Debian Edition, or the regular version based
               | on Ubuntu?
        
             | 8bitbuddhist wrote:
             | Not OP, but Pop OS is a great Ubuntu derivative.
        
               | nullcipher wrote:
               | Is that not for desktops? What is the alternative for
               | servers?
        
               | kbaker wrote:
               | We switched our base server build OS to Debian. Has been
               | great so far and runs with very low resources / extra
               | fluff.
        
               | 5e92cb50239222b wrote:
               | If you want to set it up and forget about it, just use
               | any RHEL clone (AlmaLinux is by far the fastest with
               | updates: it took them like a week to ship RHEL 9 after
               | the official release). You set up the system, install &
               | enable `dnf-automatic`, and forget that it exists for the
               | next 10 years.
               | 
               | If AlmaLinux (or any other clone) dies for some reason,
               | you can always move to another clone without re-
               | installation (using their tool `elevate`).
        
             | huachimingo wrote:
             | Anything that has a sane package system (apt, etc), and is
             | able to install LXDE and use it out of the box.
             | 
             | Then, put dwm/[your fav. wm] on top of it, with some
             | autoservices for bluetooth, mtp and stuff.
        
         | GordonS wrote:
         | I like Ubuntu, and looked into using Ubuntu Core for an IoT
         | architecture a few years ago - but the "brand store", which
         | IIRC is mandatory for private deployments, are complete
         | madness.
         | 
         | Plus, while the _concept_ behind Snaps is interesting, in
         | practice they seem to be nearly universally reviled.
        
           | nullcipher wrote:
           | it's reviled because nobody wants to learn yet another
           | deployment tool. apt has been reliable enough for installing
           | packages and good enough UX that people can't be bothered
        
             | theamk wrote:
             | Nope, it's reviled because of its hostile user experience.
             | Try finding an official, working way to stop automatic snap
             | updates!
        
               | rtp4me wrote:
               | The only way I got it working was via:
               | snap set system proxy.http="http://127.0.0.1:1111"
               | snap set system proxy.https="http://127.0.0.1:1111"
               | 
               | I started a thread [0] on the LXD container forum in 2019
               | due to all the issues with automatic snaps
               | 
               | https://discuss.linuxcontainers.org/t/disable-snap-auto-
               | refr...
        
               | GordonS wrote:
               | Was going to say the same thing. IMO the snap _concept_
               | would make it worth learning something new for some use
               | cases - but forced automatic snap updates, high memory
               | usage, long startup times and permission issues are not
               | selling it. Moreover, Canonical is well aware of how snap
               | is perceived, and has done diddly squat to fix it.
        
           | josteink wrote:
           | > Plus, while the concept behind Snaps is interesting, in
           | practice they seem to be nearly universally reviled.
           | 
           | It might be worth mentioning that a more open, community
           | driven and decentralized option offering mostly the same
           | concepts exists in the way of Flatpak and Flathub.
        
             | j1elo wrote:
             | And that Linux Mint, a very good derivation of Ubuntu LTS,
             | made the choice to ditch Snap and integrate Flatpak instead
             | in their version of the Software Store.
        
         | nix23 wrote:
         | I completely sprinting away with anything canonical.
         | SUSE/openSUSE/Micro RHEL/Fedora/CoreOS nothing else...no more
         | canonical, too many disappointments and trickery into pay
         | massive at the end of the day.
        
           | RedShift1 wrote:
           | What is Micro RHEL?
        
             | forgotpwd16 wrote:
             | Guess comment is (SUSE/openSUSE/Micro)
             | (RHEL/Fedora/CoreOS).
        
             | yjftsjthsd-h wrote:
             | Not RHEL; https://microos.opensuse.org/
        
         | db65edfc7996 wrote:
         | Does the snap store server process still still use 300+ MB of
         | memory? That alone would seem to disqualify it for IOT or other
         | embedded use cases.
        
           | nix23 wrote:
           | Na snapd need's just about 220, so perfect for a 1G raspi, if
           | it's the only thing you want to run on.
        
           | cptnapalm wrote:
           | That's more than my laptop-as-a-router using Manjaro uses in
           | total.
        
         | traceroute66 wrote:
         | > I highly discourage anyone to use Ubuntu Core as part of
         | their solution.
         | 
         | Yup.
         | 
         | The guys at Nitrokey did a nice write-up about this last
         | year.[1]
         | 
         | (TL;DR in the end, they chose Debian instead)
         | 
         | [1] https://www.nitrokey.com/news/2021/nextbox-why-we-decided-
         | an...
        
           | hda111 wrote:
           | You can't really compare the two wrt IoT. For Debian you need
           | an additional OTA update mechanism. Luckily rauc is in the
           | Debian repos but you still need to setup everything yourself:
           | A/B partitioning etc.
        
           | jamesgeck0 wrote:
           | I'm surprised they ended up going with a non-immutable
           | distro. They say their Debian-derived system is as robust as
           | Ubuntu Core, but seemingly immediately contradict this by
           | saying they're using apt to manage updates.
        
             | GordonS wrote:
             | Aren't they only using it for security updates though?
        
         | mr337 wrote:
         | We had the some problem evaluating it for our startup. We were
         | planning on using it to deploy ROS in the field and leverage
         | the benefits. I was quoted $20k/year to get started and I think
         | that also included 10 or 20 devices in the field. Then
         | additional costs for that.
         | 
         | There was so many hacks to get it working with ROS since we
         | rely on hardware for robotics to communicate with sensors,
         | actuators, and network. Basically broke the security model to
         | get our application working. We didn't go with it and went
         | Debian as well :D
        
         | giancarlostoro wrote:
         | That is really ridiculous. I'm sure some companies out there
         | will pay it without blinking, but how are the little people
         | supposed to evaluate things, heck a former boss at a Fortune
         | 500 I know for a fact will say no thank you, and move on. I
         | would just use DEB packages and setup a package repository
         | myself, what does snap bring that regular debian packaging does
         | not?
        
           | moffkalast wrote:
           | > what does snap bring that regular debian packaging does not
           | 
           | Snap is like using a python virtualenv, while apt is like
           | using global pip. We all know which one of these usually
           | results in a broken installation.
           | 
           | Apt debs more often than not rely on some specific version of
           | a third party package which becomes a headache when there's
           | another package that needs a different version of it. Snap in
           | theory solves that, making the deps local to the package
           | you're installing.
           | 
           | If I had a dollar for every time I had apt bullshit me with
           | "requires package, but it will not be installed" or something
           | of the sort I'd probably have something over $20 which isn't
           | that much but still infuriatingly high.
        
             | broknbottle wrote:
             | As an alternative just package everything up in an AppImage
             | and use a AppRun shim script.. Then just deploy the
             | AppImage to whatever. The LXD Snap bundles quite a few
             | things, there's no reason you couldn't do the same with
             | AppImage.
             | 
             | https://xon.sh/appimage.html#building-your-own-xonsh-
             | appimag...
             | 
             | https://github.com/niess/python-appimage
        
             | quartesixte wrote:
             | >If I had a dollar for every time I had apt bullshit me
             | with "requires package, but it will not be installed" or
             | something of the sort I'd probably have something over $20
             | which isn't that much but still infuriatingly high.
             | 
             | Completely unrelated but the exactness of this turn of
             | phrase here delighted me so much and without your
             | permission I'd like to steal it for my own use in my daily
             | conversations (without credit).
        
               | LeifCarrotson wrote:
               | It's an adaptation of Doofenshmirtz's line from Phineas
               | and Ferb:
               | 
               | > _" Wow! If I had a nickel for every time I was doomed
               | by a puppet, I'd have two nickels. Which isn't a lot, but
               | it's weird that it happened twice. Right?"_
        
             | mrighele wrote:
             | We are talking about IoT devices where (hopefully) the
             | company knows exactly what is installed and what not, so I
             | don't think it is a big issue. There may still be conflicts
             | to solve, but you can manage them when you prepare the deb
             | package, not when you install it
        
             | 2143 wrote:
             | > We all know which one of these usually results in a
             | broken installation.
             | 
             | And yet they're promoting snap.
             | 
             | Have they given us the ability to stop automatic updates?
        
               | sky-kedge0749 wrote:
               | It looks like Ubuntu Core lets you disable automatic
               | updates for snaps: https://ubuntu.com/core/docs/refresh-
               | control.
        
               | forgotpwd16 wrote:
               | Or the ability to make your own snap store.
        
       | former wrote:
        
       | dljsjr wrote:
       | Almost more interesting than this announcement by itself is that
       | Canonical is now providing a PREEMPT_RT patched kernel for Ubuntu
       | in general. That's super cool.
        
       | yourstruly-br wrote:
       | This blog also mentions why Ubuntu Core is a bad choice.
       | https://www.nitrokey.com/news/2021/nextbox-why-we-decided-an...
        
         | aulin wrote:
         | I read that post and as an outsider and one that knows very
         | little about ubuntu core, I seem to understand you need a brand
         | store to access direct hardware functionality, is that so? so
         | you need to pay to be able to use GPIOs, I2C and other hardware
         | peripherals from your snaps? on an IoT OS?!
        
       | cbsks wrote:
       | Can you configure it easily for a read only root file system?
        
       | synergy20 wrote:
       | ubuntu desktop is free for all.
       | 
       | canonical needs to go public and do IPO.
       | 
       | ubuntu core is one approach to make some money out of the (free)
       | ubuntu brand.
       | 
       | Personally I don't use Ubuntu Core, but I understand why it is
       | there.
        
         | d82nsjk9 wrote:
         | > canonical needs to go public and do IPO.
         | 
         | why?
        
           | synergy20 wrote:
           | it's their long term goal, to answer your question: everyone
           | needs more money, after all it's not a charity, canonical is
           | a legit business.
        
       | ravenstine wrote:
       | I really never understood this thing about Ubuntu as a minimalist
       | OS for servers and embedded. Almost no matter what, it's going to
       | be more bloated and complicated than just about any other flavor
       | of Linux you can think of. Sure, it works, and there's the factor
       | of familiarity, but just... why? Make Ubuntu the best desktop or
       | mobile OS it can be. Without the original selling point that it
       | fixed problems downstream from Debian and made install easier,
       | what exactly is the point? Ubuntu does some things well, but
       | they've never been good at keeping anything minimal.
        
         | trufas wrote:
         | I doubt they'll want to compete in the consumer OS space after
         | the ubuntu phone mess.
        
       | barkingcat wrote:
       | For embedded / iot usage, one major issue is device support
       | 
       | https://ubuntu.com/certified/devices
       | 
       | It does contain raspberry pi's but the list isn't all that great.
       | 
       | I had trouble finding 32 bit ARM precompiled binary distributions
       | from ubuntu (that is not a rpi), and had to compile my own kernel
       | + inline it with debian to get 32 bit arm support.
        
         | n00bface wrote:
         | Smallest thing I've found is a FreeScale SOC running a
         | Cortex-A7.
        
           | ngrilly wrote:
           | Can you run Linux on a Cortex-M, which is basically a
           | microcontroller, instead of a Cortex-A that has a MMU? I
           | don't think it's possible.
        
             | glassconclusion wrote:
             | Yes, you can actually. I haven't done this myself, but
             | there are defconfigs for mmu less devices (stm32f4 series
             | for instance). You need some more RAM though, but most
             | evaluation kits don't provide this. Have a look here:
             | https://elinux.org/STM32 I'm planning to give this a spin
             | on an EVK that I got from work if I find the time.
        
               | kissiel wrote:
               | Linux? yes. Popular distro? not really. Lack of MMU means
               | that all the processes (and shared objects) use the same
               | memory space, so unless you have some way of randomizing
               | where things go (like SELinux), two processes will step
               | on each other's data (MPU will not trigger segfault, as
               | both are allowed to r/w same addr - IIUC). But even when
               | using randomizing, you're playing russian rulette.
        
               | glassconclusion wrote:
               | Do you think there is any practical use to it instead of
               | running just an embedded OS? Driver support maybe?
        
           | kissiel wrote:
           | Cortex M* lack MMU, which is necessary for any normal linux
           | distro. Cortex M0 and M4 are just beefy microcontrollers.
        
             | n00bface wrote:
             | You're correct. I'll revise.
        
       | jaywalk wrote:
       | Installation Step 1: An Ubuntu SSO account is required to create
       | the first user on an Ubuntu Core installation.
       | 
       | Yeah... no.
        
         | forgotpwd16 wrote:
         | Is Ubuntu Core closed source? If not, can't someone fork it and
         | remove this requirement?
        
           | jeroenhd wrote:
           | Ubuntu Core seems to be Snap As A Service. Snap is mostly
           | open source (everything except the actual store backend
           | because "it would be complicated" to do that).
           | 
           | If you fork it and remove the connection to Ubuntu's cloud
           | ecosystem, you'd probably be end with a barebones Ubuntu
           | Server install. When all you need is Ubuntu Server with
           | Livepatch, you're probably better off using that.
        
       | la_fayette wrote:
       | Look for balenaOS (http://balena.io) if you want an alternative
       | IoT solution. We looked into ubuntu core, which seems like an
       | overkill in complexity. With balena you can get started
       | immetiately with all the tools you already know, like docker etc
       | and have a solution that works...
        
         | andrewshadura wrote:
         | Another solution would be Apertis (www.apertis.org). Unlike
         | Ubuntu Core, it uses standard technologies like OSTree, Flatpak
         | etc to provide similar features.
         | 
         | Disclaimer: I work on Apertis.
        
           | GordonS wrote:
           | I took a quick look at your landing page, and I've got to say
           | it doesn't do that great a job of telling me what it is or
           | how it works.
           | 
           | Are you able to provide a short summary, and maybe compare it
           | to Ubuntu Core and BalenaOS?
           | 
           | Would it be suitable for shipping appliances? How do you
           | folks make money?
           | 
           | Thanks :)
        
             | andrewshadura wrote:
             | It is a Debian derivative distribution with a stabilised
             | subset of packages and a recent LTS kernel. Target images
             | use non-GPL-3 software, which some industries require. It
             | also comes with infrastructure for building images, atomic
             | updates and so on.
             | 
             | There's a lot of concept documents on the website going
             | into details on those.
        
             | andrewshadura wrote:
             | When using OSTree, you can build images using regular
             | packages installed with apt, and then deploy them
             | atomically while allowing to rollback the update if
             | necessary. Alternatively you can choose to use Flatpak to
             | deploy applications.
        
             | andrewshadura wrote:
             | As for money, we have paying customers.
        
         | mdtusz wrote:
         | While balena is great for getting up and running quick, you'll
         | quickly run into issues when more specific application
         | requirements arise, or you need to tighten down security.
         | 
         | It's fantastic for small-scale IoT deployments, but you very
         | much need to play nice in their ecosystem, and there's many
         | features missing for deployment and version management still,
         | and balenaOS and the balena supervisor can often introduce
         | breaking quirks, and managing networking is a nightmare. We're
         | very happy with how it allowed us to get off the ground and
         | running quickly, but are moving to a more "traditional" build
         | using yocto on its own moving forwards.
        
       | rgreen wrote:
       | For alternatives, I've been running opensuse microos in some test
       | deployments and am really happy so far.
        
       | azinman2 wrote:
       | What IoT devices are running Ubuntu, and how is it optimized?
       | That it has snap containers? I'm guessing by IoT here they don't
       | mean light switches running on an embedded processor, but
       | industrial equipment?
        
       | matthewmacleod wrote:
       | I would also chip in along the same lines as the other comments
       | here and strongly advise against using Ubuntu Core in any
       | application. It's a tempting idea when you first look at it, but
       | in practice it is seriously difficult to build an application
       | with, comes with a lot of constraints, and requires you forking
       | over repeated large sums of money to Canonical with no way out.
       | 
       | We had a much better experience with https://www.balena.io -
       | quite a different service, but achieves a sweet-spot combination
       | of having an open core with good management tooling that I'm more
       | than happy to pay for.
        
         | donmcronald wrote:
         | I've never used anything in the product space, but I've read
         | through some of the docs because IoT deployment interests me in
         | the context of most network devices having terrible deployment
         | and update strategies.
         | 
         | My favorite sales pitch was always Mender (https://mender.io)
         | because it can be as simple as .img files and slice based
         | booting. Unfortunately they changed their pricing a couple
         | years ago and went from a hobbyist friendly pricing structure
         | where you could scale down to $120 / year to charging for scale
         | and features where the minimum cost to use delta updates is $3k
         | per year. If you want something like mutual TLS authentication
         | it's "call us" pricing.
         | 
         | When I looked at Balena I thought the whole architecture looked
         | like a mess of complexity and containers when a simple .img
         | would suffice for most use cases (IMO). It's also too expensive
         | to get into without having a well understood target market for
         | whatever IoT product you're planning to build. IE: No hobbyists
         | or enthusiasts that just want to learn without having something
         | sellable planned out.
         | 
         | IMHO all of the IoT deployment solutions charging tons of money
         | for features _and_ scale are a good example of where platforms
         | like Cloudflare could reshape the industry. I think by going
         | "all in" on Cloudflare Pages/Functions/Workers, etc. someone
         | could build a "Cloudflare Native" platform that can afford to
         | dominate the unserved (low-end) portion of those markets, but
         | with the ability to scale up to accommodate the large
         | deployments these companies are trying to attract as customers.
         | 
         | I would kill for firewalls and switches that use a slice based,
         | watchdog monitored deployment system like Mender has, but with
         | pricing that's closer to the reality of the small business
         | world.
        
           | codewithcheese wrote:
           | First 10 devices on balena are free, its used by many
           | thousands of hobbyists.
           | 
           | For example balenaSound is very popular, for multi-room audio
           | with rapsberry pi's https://sound.balenalabs.io/
           | 
           | There is also balenaHub, which hosts many community projects
           | and introduces the concept of "open fleets", bring your
           | device and join the fleet, instead of managing it yourself
           | https://hub.balena.io/fleets
           | 
           | Disclosure: I am an engineer at balena.
        
       ___________________________________________________________________
       (page generated 2022-06-15 23:02 UTC)