The Enterprise Linux Tax Is Costing You More Than You Think | Brady Dibble, CIQ
In this TFiR interview, Brady Dibble, Director of Product for Enterprise Linux at CIQ, traces how commercial Linux evolved from free distributions with paid support into per-node and per-core products surrounded by add-ons, variants and services that inflate the bill. He compares it to airline baggage fees and argues that AI workloads, hybrid cloud and compliance demands have outgrown a model that still charges for basics.
Dibble explains who RLC Pro is for and what changes when a team moves from community Rocky Linux: a portal with an installer wizard, long-term supported minor versions for nearly five years, FIPS-certified modules and DISA STIG profiles for FedRAMP-style requirements, and a support path straight to engineers who can ship fixes and CVE remediations independent of the community. Transitioning takes a depot CLI authentication and a dnf update, since the packages are binary compatible and layered on the Rocky Linux base.
The conversation covers backported features like RDMA and the redistributed NVIDIA stack, the upcoming RLC Pro AI overlay pairing an upstream kernel with a stable Enterprise Linux userspace, simple per-node pricing without client-side tracking, data sovereignty through air-gapped operation, public source and SBOMs, and RLC Pro Hardened with preventative hardening led by Openwall founder Solar Designer. Platform and operations leaders evaluating their Linux spend get a clear view of CIQ's alternative.
Key takeaways
- Commercial Linux went from free distributions with paid support to per-node and per-core pricing plus add-ons, making bills eye-watering at scale.
- RLC Pro puts LTS, FIPS certification and bug fixes into one SKU instead of a menu of add-ons, without reinventing the pricing model.
- Moving from community Rocky Linux to RLC Pro takes a depot CLI authentication and a dnf update, since the packages are binary compatible.
- RLC Pro backports features like RDMA and IDPF, supports the latest AMD and NVIDIA hardware, and redistributes the full NVIDIA stack.
- The coming RLC Pro AI overlay pairs an upstream kernel with a stable Enterprise Linux userspace and pre-validated libraries like TensorFlow and PyTorch.
- CIQ publishes all source on GitHub, provides SBOMs for every image and artifact, and collects only repository pull data, supporting air-gapped and sovereign deployments.
Questions this video answers
When should an organization move from community Rocky Linux to RLC Pro?
Dibble says community Rocky Linux is right for students, development and testing, and anyone running Enterprise Linux. Organizations should look at RLC Pro when they need vendor accountability, long-term support on a minor version, FIPS certification, DISA STIG hardened images, or enhancements and ISV and IHV integrations that would not fit in an independent community project.
How is RLC Pro priced?
Pricing is per node, with optional premium support on top. Dibble says CIQ deliberately kept it simple rather than reinventing the model, and does not install client-side tracking to inventory your environment; you report how many nodes you run and that is what you are charged for.
What is RLC Pro Hardened?
RLC Pro Hardened is a variant of RLC Pro that ships pre-hardened for profiles like DISA STIG, CIS and PCI DSS and supports requirements such as FIPS 140-3, FedRAMP and Common Criteria. It adds preventative hardening, including code-level changes and packages like LKRG for rootkit detection, led by Openwall founder Solar Designer to mitigate CVEs and whole CWE classes before patches exist.
About this video
Enterprise Linux was built for a world that no longer exists. Modern infrastructure, AI workloads, hybrid cloud deployments, and tightening compliance mandates have completely outpaced the commercial models enterprises have relied on for two decades. The result: unpredictable costs, infrastructure fragmentation, and a growing stack of add-ons nobody budgeted for.
Brady Dibble, Director of Product for Enterprise Linux at CIQ, breaks down why the traditional per-node, pay-for-everything model is failing modern platform teams, and how RLC Pro delivers a single SKU with long-term support, FIPS certification, SBOM, pre-hardened images, and full AI/HPC stack support built in. No hidden fees. No fragmentation.
This video is part of the RLC Pro playlist. Browse every CIQ video by product and topic.
Transcript
The subscription model for Enterprise Linux has worked for two decades, but here's the problem. Modern infrastructure doesn't look anything like it did 20 years ago. AI workloads, hybrid cloud architecture, and compliance demands have completely transformed what enterprises need from their operating systems. Yet, most commercial Linux models haven't kept up with the time. They're still charging for basic features as add-ons, creating infrastructure fragmentation and unpredictable cost. So, how do you fix a model that has been the industry standard for 20 years? There's saying, "Don't fix what's not broken." But, it seems things are broken. And that's exactly what we're going to explore today with Brady Dibble, director of product for Enterprise Linux at CIQ.
Brady, it's great to have you on the show. >> Thank you for having me. >> Let's start with the fundamentals. What does the established commercial model for Enterprise Linux look like today? And more importantly, where is the misalignment between that traditional model and what modern workloads actually need? >> I mean, when these companies were coming into their own and Linux was growing and making uh strides in the industry as a foundation for running your entire business, these companies, what were building these originally like free distributions, they needed a way to monetize. They needed a way to productize. And the first way that these companies made money was selling support.
And that's also where most enterprises first they take they start with enterprise, you know, with free Linux, which is free as in free puppy when you're doing it at scale. It means at a certain point you run into issues that your team either can't or it's not efficient for them to tackle, so you look for someone to help. And so you start by paying for support from the the experts, the people who build the open source project are using. And then later, um those products started to be wrapped around your entire infrastructure, and so more was uh dependent on them, more was built on them, and companies started saying, "Hey, the product itself is no longer free.
Now you have to pay for the product. And they have to start asking, "Well, how many nodes are you running?" And we're going to start charging you by node. Um when you look in the cloud, it's how they charge you per core hour used. And there's other mechanisms, but at the end of the day, it's being charged by usage. And then over time, customers wanted additional services, additional add-ons, additional variants, and those became uh ways to nickel and dime and expand the overall ticket. They found ways to sell you uh additional services and additional products, and eventually your your bill started to become quite hefty for this free Linux product you're buying.
View full transcriptHide full transcript
Uh and then once you start expanding and growing, you're getting charged that per node cost at an incredibly high scale across all the different features and services. So, it's it's definitely grown from being a free product to I'm getting a free product with support till I'm purchasing an entire enterprise software stack um on what was originally a free product. So, like Oracle, they sell support, and they give away their Oracle Linux for free because they're selling other services. And I think generally what you're seeing in the industry is uh their their emphasis to sell everything around Linux. Linux is the linchpin, and then or or part of the entire stack.
Um and that's that's not bad. Um but it means that these companies that were originally Linux companies uh are starting to look at other parts of their stack which are more profitable as being their primary focus. >> This is really interesting because you are challenging a model that has been around for decades. Is this discussion happening across [clears throat] the entire Enterprise Linux community or is CIQ specifically taking the initiative to put standard features into the base offering instead of treating them as add-ons. What's your vision behind this shift? >> You you go to take a flight and you get charged for an extra bag. And you get charged for food and you get charged for things that previously were free.
And it's very it's very good for the business. It's very good for shareholders. For the customer, you have to start picking through what you purchase or your bill ends up being eye-watering at the end of the day when you get dependent on these services. It also makes it just more complicated for both customers and the company to understand what they're getting. So, we wanted to simplify it and go back to basics with you get one skew and you get everything you need. You need long-term support. That's included. That's not something extra. You need FIPS certification models. You need to ensure that you're getting your bugs taken care of.
These are things baked into one skew and you don't have to look across and pick from a very complicated menu. You know, I'm getting one thing and I can use it wherever I need. We're not We're not completely reinventing the wheel here. Primarily, what we're trying to do is add more value to one skew rather than having to be a bunch of add-ons. That's the major change here for now. >> Now, let's talk about Rocky Linux Community Edition versus RLC Pro. Who is RLC Pro actually designed for? And at what point should organizations start thinking about moving from the community version to RLC Pro? >> In the community Rocky Linux is CIQ is the you know, founding sponsor of Rocky Linux.
It is a fantastic distribution. We encourage everyone to make use of it. It is for anyone where you're running Enterprise Linux. It's for students that are running, you know, or learning. It's for companies that are looking to run an Enterprise Linux equivalent product in development, get spun up, get tested. It's a fantastic distribution. And when a company gets to a certain size or they start depending more on the Enterprise Linux Foundation, they start needing things. As you mentioned earlier, they need accountability from a vendor. Because the community is amazing at being a community, and that's what it should be. It should be a community that's there to um, you know, provide a project that is independent from corporate influence.
And CIQ is the founding, you know, sponsor, but we are not controlling the project. That is a very big difference. They are independent. So, when the customer, an enterprise, does need that accountability or they need features that are incompatible with a community project, that's where they need to come to a vendor like CIQ. They need long-term support or they need changes and enhancements that wouldn't be compatible with a community project, like going through FIPS certification or through you know, incorporating proprietary software or integrations with IHVs and ISVs. That's where you do need a partner like CIQ. >> Can you walk us through what's actually included in RLC Pro versus the community edition?
And you also mentioned FIPS compliance, SBOM, lifecycle management. Can you talk about what does that look like day-to-day for a platform team running RLC Pro versus the community version? >> So, with the community edition, you go to the Rocky Linux website and you grab it and you install it and it's a bug-for-bug rebuild of RHEL. It's, you know, whatever's latest, uh, whatever's newest. But when you need to, um, you know, you need a bit more, that's where you come to RLC Pro. In RLC Pro, you go through CIQ's portal, our customer portal, and you log in, you get access to a an installer wizard where you can pick through the different versions, find the different types of installers you need, get assistance, and then you're looking at, okay, what version am I installing?
Do I want just the latest or do I want LTS? And we have long-term supported versions if you need to stay on that minor version for almost 5 years and you are not ready to move to the new latest version every 6 months. Or you need FIPS certification for Fed Ramp or you need DISA STIG security profiles, we have a path for you to find out how do I get pre-hardened images or how do I integrate or enable FIPS certified modules and then prove for auditing these modules are certified. And I need I have a bug that I need to fix. Who do I go to?
Instead of going to the forum or seeking help and great people there, but if you have an urgent bug that needs to get fixed or you have an urgent escalation and time time is money, you can go straight through our support portal, access our customer support team, you're getting right to engineers that know how to solve the problem. So it's it's a product where CIQ can ship the fixes, the bug fixes, the enhancements, the CVE remediations straight to you independent of the community. >> In most cases, teams evaluate with community edition and then move to production. Can they easily migrate or upgrade from community edition to RLC Pro or does it require a brand new install?
>> It is extremely easy to transition. We're binary compatible, so you just run a little to no modification at all required to transition over. You'll use our depot CLI to authenticate to our repositories and then it's a simple DNF update and boom, you've got all the updated packages that you get from RLC Pro which are layered on top of the Rocky Linux base packages. So you'll get for example a kernel that is built, modified, enhanced, and signed by CIQ with additional enhancements we bring down from the upstream that are help with a particular cloud workloads or you'll get support for the latest Nvidia or AMD hardware out of the box.
Signed by CIQ, maintained and validated by CIQ. >> You mentioned EI and HPC workloads specifically and EI is obviously huge right now. What makes RLC Pro a better fit for these environments compared to traditional enterprise Linux distributions? >> When you're running enterprise AI at scale and getting to the inference part, you are needing stability, but you also need performance, but you also need to be able to utilize the latest hardware. And sometimes it's a trade-off between stability and getting access to the newest features like confidential computing or the latest drivers to maximize performance or support for the latest hardware. And so, you don't have to make that trade-off with RLC Pro.
We do backport key features first features like RDMA and IDPF to support, you know, clusters and performance, but we're also ensuring that the support for the latest K-months and drivers for AMD and Nvidia hardware. We're also redistributing the full Nvidia stack out of the box, so you're not having to deal with dependency issues. That was all handled by CIQ. And then if you're looking for even more performance or if you're looking to reduce your time to first token, we have our overlay variant RLC Pro AI which is coming soon and that has pre-validated dependencies and user space libraries like a TensorFlow, like PyTorch which have already been optimized for working on enterprise Linux.
So, you're getting the same stability in user space with a lot of performance enhancements and pre-validated stack for just running getting them up and running on AI workloads as quickly as possible. And with that one for example, we have a the the upstream kernel on us the primary option. So, we found that with the Enterprise Linux kernel, um because you're frozen in time, it becomes extremely difficult to get access to latest features and performance enhancements and bug fixes that are at the tip of tree kernel. But, especially if you're doing AI at scale or enterprise level, you need features like confidential computing, um like some of the latest uh speed improvements in the upstream kernel.
But, you need also that stability from the Enterprise Linux user space. And so, with RLC Pro AI, we're marrying those two together uh in one package. This is a turnkey golden image you can get up and running with AI out of the box. >> Your announcement also talks about eliminating infrastructure fragmentation. What does that actually look like in practice for platform and operations teams? >> When you're looking at Enterprise Linux today, you can end up as part of that nickel-and-diming and you know, getting a bunch of different combinations of add-ons. You can end up running different uh versions and different uh OSs across different parts of your system.
Uh one of the most common is, well, I'm going to run a particular OS and product in production, but then I'm going to use something entirely different for my development environment. And that while that uh can save money uh up front, it actually becomes more of a pain point, especially again calling out AI workloads, where you're trying to take that same workload from desktop to development to staging up into production. And those subtle differences in environment can cause breakdowns and slowdowns when you're looking at, you know, time to market. So, having one product that you can roll out to all of your environments uh without having, you know, that is what we're talking about what reducing fragmentation.
>> Let's talk about pricing. What does the pricing model look like for RLC Pro? >> Our pricing model is per node, and then there is options for uh premium support uh as well on top of the per node price. We wanted to keep it simple and this is not an area we wanted to reinvent the wheel. Uh definitely when we look towards the future, there's a lot of talk around uh usage models where we're trying to um maximize the uh usage on one machine, but we're trying to keep things simple for now. It's just the per node price. How many nodes you have, that's how many you're using.
And we are not putting client-side uh tracking on your uh your environment to kind of track your inventory uh bit by bit. We do you know, tell us how many nodes you have, and that's how many nodes we're going to uh assume you're using. >> We are living through some of the toughest, most challenging geopolitical shifts right now, and a lot of organizations are thinking about AI sovereignty, data sovereignty, infrastructure sovereignty. How ready is Rocky Linux and CIQ to help organizations in different countries achieve full sovereignty over their infrastructure? >> CIQ is definitely a data sovereignty-first company. We are US-based, uh but we work internationally. And our products are designed to be run in air-gapped environments or in your own environment where you have complete control of the data.
Meaning we do not put tools on that are sniffing information and sending it back home. Um the only information we're collecting is when you are pulling from our repositories. So that helps a lot with uh keeping your information safe and knowing that we are not adding anything else. And then in addition, uh as all of our uh source code is freely available on GitHub, there's no wall behind it. We put all the source code right out on GitHub, so it's a click away. Um so that's something where we don't want to put it behind a wall. We want to make it that uh open source is open source.
And so you have access to see everything that's going in. Um in addition for all of the uh images and uh artifacts we're building, there's an S-bomb provided, so you can track what exactly is going in and so you have control and trust in what is going into your environment, what's coming from CIQ. And so you can trace that all the way back from the artifacts you install in the packages you obtain with back to the source code and back to the upstream. Uh along with this, we have other products um in the CIQ stack which are about enabling you to have that type of data sovereignty and keep things running uh whether uh through Ansible for automation or through Fuzzball for on-premise AI and HPC workloads.
They're all about running on-prem in your own environment where you have control. >> You mentioned air-gapped systems earlier. Can you explain what you mean by that and do you have a specific distributions designed for more security-focused or compliance-heavy industry or it's the same RLC Pro with some more tweaking and hardening? >> Yes. For customers and enterprises that are in heavily regulated or are government or government adjacent, our RLC Pro Hardened product is out of the box hardened not only for security profiles like DISA STIG or CIS or PCI DSS, but it also comes with preventative hardening. We do have some code-level changes along with some extra packages like LKRG which helps prevent against rootkit level up detection and prevention.
So these uh combined with baseline compliance requirements, of course, if you're in a regulated industry, you have requirements like meeting FIPS 140-3, FedRAMP, or common uh criteria, and these are all bundled in one product, RLC Pro Hardened, which is a variant of RLC Pro which you can use to uh have a turnkey image that is just hardened out of the box and saving your team considerable amount of time, but also adding some preventative hardening uh that outright um helps mitigate CVEs and entire CWEs out of the box. >> We have to talk about this topic. It should be mandatory. AI. These days we are living in an API driven world where everything is connected, which means that attack surface is getting bigger and more sophisticated.
How can a hardened RLC Pro help in scenarios where CISOs need to know that at least at the OS level there are processes and tools in place so they are not losing their sleep at night. >> There have been open source projects trying to do things like this. OpenWall is a great example and actually the lead engineer on the RLC Pro Hardened project, Solar Designer, was a founder of OpenWall and he's brought a lot of his learnings from his journey through security and offensive security over the years to create a product that doesn't just wait for CVEs to be patched alone. It's also having offensive security baked in.
It's going to be proactive about mitigating potential CVEs and weaknesses ahead of the time. So especially if you're in an environment where you cannot patch rapidly or you may be exposed for a period of time before a patch is available. Especially in the age of AI where any exploit is going to be attacked immediately, then you need to start being serious about proactive and preventative hardening, which is something RLC Pro Hardened has out of the box. >> Ready, thank you so much for joining me and sharing these insights on how CIQ is rethinking the enterprise Linux model for modern infrastructure. It is quite clear that as workloads evolve, the commercial models need to evolve with them as well.
And that's exactly what CIQ is doing. So thank you so much for your time today and I look forward to our next conversation. >> Thank you. >> And for those watching, if you are dealing with infrastructure fragmentation or looking for an enterprise Linux solution built for AI and hybrid cloud workloads, make sure to check out CIQ and RLC Pro and don't [clears throat] forget to subscribe to TFIR, like this video and share with your team. Thanks for watching.
Built for scale. Chosen by the world’s best.
2.75M+
Rocky Linux instances
Being used world wide
90%
Of fortune 100 companies
Use CIQ supported technologies
250k
Avg. monthly downloads
Rocky Linux
9
Enterprise products
Spanning the kernel to the orchestrator
Have questions about your infrastructure?
Talk to a CIQ engineer about Rocky Linux, HPC, and AI infrastructure.
