Own your Enterprise Linux lifecycle without hand-managing content views

Own your Enterprise Linux lifecycle without hand-managing content views

Contributors

The CIQ Team

Enterprise Linux teams make the same decision every time they update, whether they run 200 hosts or 20,000. The cadence is managed by the team, daily for some fleets and one Tuesday a month for others. Every update, whether it is daily or quarterly, some packages should reach production, some should wait for testing, some should be excluded, and every group of nodes needs to receive the right combination. Before you trigger updates across your entire fleet, you need the confidence that the right packages and updates are going out, and the wrong packages and versions are not.

CIQ Enterprise Linux Manager (ELM) is where a team makes that decision and carries it out. Pin the release each host group runs today, stage the next one behind it, promote when it is ready, and roll back to a prior version when a change misbehaves. Every step runs on infrastructure the team controls.

ELM is provided at no additional charge to all RLC Pro subscriptions.

Answer the package question once per host group

A content view is how a team answers that question once and for every host that shares a stage. It is a named, frozen snapshot of the package repositories your hosts install from. You choose which repositories go into it and which package versions to hold. Once an operator publishes the view, its contents cannot change, and hosts install from the view instead of from the internet.

That single object turns cadence into a decision. Every host in a stage installs the same packages at the same versions until an operator publishes a new content view.

Control content, curation, risk, and cadence in one place

What a fleet consumes is decided by four controls. Teams that hold all four set their own upgrade windows and size their spending to the fleet they run.

Content starts with a mirror, which is a local copy of the package repositories your subscription entitles you to, plus any open repositories you use. Mirrors sync onto storage you own, on a schedule you set. A sync that stops partway resumes where it left off and verifies what it pulled.

Curation is the work of building a view out of that mirror. An operator adds packages, removes them, or holds versions back, or introduces custom builds, then publishes. ELM signs every view at the moment of curation, so the packages a host receives are the ones someone approved. Views assemble from a hard-link content store, which means a new view points at package files already on disk rather than copying them. A view costs little storage and builds fast even when it spans many repositories.

Risk surfaces while a view is still a draft. Dependency resolution checks that every package in the view has the other packages it needs, at versions that work together, so conflicts appear during curation. You see outstanding Common Vulnerabilities and Exposures (CVE) exposure on the packages you held back. Errata, the vendor advisories that carry security and bug fixes, reach a host only through a view someone promoted.

Cadence is the fourth. A view moves through versioned lifecycle stages, usually something like development, test, and production. Operators snapshot along the way, revert, and roll back to a prior published version. Major-version timing follows the same principle, and long-term support in RLC Pro carries a three- to five-year planning horizon.

Watch the four controls run in a single week

A representative rollout runs like this. An operator syncs the mirror on Monday and forks a new view from the one production runs today. Dependency resolution flags a package that would pull an incompatible library, so the operator holds the prior version back and signs the view again. The view promotes to a test stage midweek, where a subset of hosts installs it. Production promotion lands in the Friday window as a version change. The earlier view stays in place, so a rollback is a promotion in the other direction.

Both views sit side by side in the content store, so production holds steady while the team curates, signs, and stages the next release behind it.

More about CIQ Enterprise Linux Manager (ELM). ELM is included with all RLC Pro subscriptions.

Keep entitlement where the subscription already lives

Entitlement in that sequence settles once, and it settles early. Depot, the CIQ service your subscription authenticates against, governs which repositories you can mirror. The check happens at the mirror, and hosts then pull from your own infrastructure. Operators run no subscription-enforcement service.

Adding capacity is therefore a provisioning task. An operator boots a bare-metal node over iPXE network boot, which installs a machine over the network with no removable media, points the node at the mirror, and the node installs the content view for its stage.

Run every step on infrastructure you own

Mirroring, curation, dependency resolution, promotion, and rollback all execute on infrastructure you operate. The control plane runs on-premises and does not call home, so it also works in a network segment that has no route to the internet when that is what your environment calls for.

An operator in a disconnected segment imports content from local ISO media instead of syncing from a remote source, then curates, promotes, and rolls back exactly as a connected team does. Signed content moves between a connected instance and a disconnected one by offline import and export, so an air-gapped segment stays current without a route to the internet.

In a representative deployment, a team running a large Enterprise Linux fleet curates a view, sees dependency conflicts surface before rollout, and deploys it in a disconnected environment, keeping the content-view workflow it already knows. Federal, defense, and regulated-finance teams run the same weekly cycle inside a disconnected segment as they run in a connected one.

Call every operation from your own automation

ELM exposes an API that covers the whole weekly cycle: sync, curate, compose, roll back, assign, provision. A platform team scripts that Monday-to-Friday sequence and keeps every guardrail.

Signing at curation, the audit log, and rollback to a prior published version all hold when a script drives the promotion.

Curation, dependency resolution, and errata handling cover Enterprise Linux, while mirroring covers any RPM-based distribution. Teams that run a mixed estate scope against that line.

Move toward one control point across your estate

ELM covers content, curation, staging, and provisioning. Configuration management, monitoring, and execution route to Ascender Pro, the commercially supported build of the open source Ascender project CIQ develops upstream. Teams that run both consolidate toward one control point for the estate.

Subscribe to our newsletter

Related posts

Leaving Amazon Linux 2: AL2023 or Enterprise Linux?

Leaving Amazon Linux 2: AL2023 or Enterprise Linux?

Migrate Amazon Linux 2 to RLC Pro: Free toolkit and 60-day plan

Migrate Amazon Linux 2 to RLC Pro: Free toolkit and 60-day plan

CIQ launches RLC Pro: redefining the Enterprise Linux standard

CIQ launches RLC Pro: redefining the Enterprise Linux standard

Every era has an infrastructure gap. This one is yours to close.

Every era has an infrastructure gap. This one is yours to close.

Built for scale. Chosen by the world’s best.

2.75M+

Rocky Linux instances

Being used world wide

90%

Of fortune 100 companies

Use CIQ supported technologies

250k

Avg. monthly downloads

Rocky Linux

Have questions about your infrastructure?

Talk to a CIQ engineer about Rocky Linux, HPC, and AI infrastructure.

Talk to an Expert