What is Rocky Linux from CIQ (RLC)?
In this short conversation, CIQ CEO Gregory Kurtzer and Rose Stein explain what Rocky Linux from CIQ is and why it exists. Kurtzer describes the feedback driving it: adoption of Rocky Linux by large companies has been massive, but most big organizations will not depend on open source software in production without a company behind it that can provide contracts, legal validation and the check marks their infrastructure requirements demand.
Kurtzer explains that RLC is the same base Rocky Linux everyone knows, with indemnification and SLOs on security updates added on top. If the community cannot deliver a particular update quickly, or a zero-day needs immediate remediation, CIQ commits to providing it. He also walks through how updates flow: CIQ mirrors the Rocky Linux repositories, validates and security-checks the packages, and serves them to customers, while any packages CIQ builds to meet its SLO come from a separate repository signed by CIQ.
The video suits IT and security leaders evaluating whether community Rocky Linux can meet their compliance posture, and anyone curious how RLC differs from the support CIQ has offered Rocky Linux since day one.
Key takeaways
- Large enterprises depend on open source but need a company behind it offering contracts, legal validation and compliance guarantees.
- Rocky Linux from CIQ adds indemnification and SLOs on security updates to the same base Rocky Linux the community uses.
- CIQ mirrors the Rocky Linux repositories, validates and security-checks the packages, and delivers them to customers directly.
- Packages CIQ builds to meet its security SLO ship from a separate CIQ-signed repository, while community packages remain signed by Rocky Linux.
Questions this video answers
Where do Rocky Linux from CIQ customers get their updates?
Customers pull updates from CIQ rather than directly from the Rocky Linux community. CIQ mirrors the Rocky Linux repositories, runs internal validation and security checks, and provides mirror services. Packages CIQ produces to meet its SLO come from an additional CIQ-signed repository.
How is RLC different from the Rocky Linux support CIQ already offered?
Kurtzer says the difference is contractual. CIQ has supported Rocky Linux since day one, but RLC adds written guarantees, indemnification and SLOs on security updates so strict enterprise compliance and security teams have the assurances they need in writing.
This video is part of the RLC Pro playlist. Browse every CIQ video by product and topic.
Transcript
we have a special guest with us here today my esteemed CEO of our company at ciq Gregory kurtzer hello and welcome hi so excited for you to be here so we've got something to talk about today that is actually news to me so this is why you here is to explain exactly what is ciq working on right now so one of the things that we've heard from a lot of our our our users a lot of our customers and the community at large is that there's there's a lot of big companies that have decided to use Rocky Linux and the uptake has been ridiculously massive
and the issue that people are running into right now is most organizations most really large organizations don't count on just running opsource software they depend on open source software but they need a company behind it they need a solution where that company can can help them if they get into something that they're not quite equipped to deal with or or uh anything like along those lines so we've been asked many times can can ciq be the company that's kind of standing behind and supporting Rocky Linux now we supported Rocky Linux since day one we do but what they need is they need contracts they need
legal validation they need check bar check marks by uh uh requirements for for their infrastructure that again the open source Community just doesn't provide sure so one one thing that we're doing that's super cool is well you can run Rocky Linux just as it stands from the community and when you get Rocky Linux from ciq it's going to come with indemnification it's going to come with uh slos on security updates so for any reason the the community uh is is is not able to provide a particular update or you need something in addition to make sure that you're running in a secure environment where there's
a zero day that needs immediate remediation y we can do that we will add to that we will provide that guarantee that insurance policy that throat to hold throat to grab throat the choke whatever it is we volunteer to be that and uh so when you get Rocky Linux from ciq you get all of this so so you still get that base Rocky Linux everybody knows and loves but now there's some contractual validation that we can provide as well to mitigate the risks the legal risks and it and security risks that are associated with many times with running open source software awesome um thank you
View full transcriptHide full transcript
for that you know sometimes it can uh be a little bit of a a challenge to decide what are the things that customers are asking for that as a company you want to say yes and move forward quickly with it and what are some of the things that maybe are not in our wheelhouse so um yeah that's great thanks for listening to our customers and really standing up and saying hey you know what this is a a good idea we can do this we want to do this for you and we're going to make it happen so I appreciate that it kind of sounds a
little bit like what we are already doing at ciq with supporting Rocky so tell me how what you just explained is different it we really need to um see it from the customers perspective and the largest the biggest customers that we have are so strict in terms of how they're managing their compliance and their their their V various uh security postures and and stance they need to have guarantees they need to have uh complete confidence and the open source Community is fantastic for Upstream development it's fantastic for collaboration it's not great for GU getting guarantees and it's not great for guaranteeing compliance for these large
organizations so we're trying to figure out how do we uh give our customers what they want which is a a open base something that they can they can build as a foundation which is open it is secure it is um uh compliant but they need that in writing they need that guarantee and so we are providing that and we are becoming that throat to choke if anybody does need something along those lines so customers instead of getting their updates from the rocky Linux Community they would be getting their updates from ciq yeah exactly uh so we would be mirroring our repositories from R from there
we would be doing internal validation uh security check and and and and just giving it a um a once over in terms of compliance to make sure it is exactly what it is that it should be so we're going to be verifying all the packages verifying this everything there and again we will be pulling this directly from Rocky from there our customers will be pulling from us and we will be providing mirror services to them to obtain these the these updates now where it gets a little interesting is because we are guaranteeing that certain updates will come uh you know with within a certain SLO
or or SLA uh those will come from another repository which we will offer to our customers specifically for Rocky Linux and those packages will be available and and secured and signed by us all of the other packages because they're coming from Rocky are going to be signed by Rocky these packages will be signed by us and we will be providing them to make sure that a they're they're in our customer's hands as soon as absolutely possible and they are they are validated and if there's anything that they need over and above what the community is providing that's how we will deliver that to our customer
base
Built for scale. Chosen by the world’s best.
2.75M+
Rocky Linux instances
Being used world wide
90%
Of fortune 100 companies
Use CIQ supported technologies
250k
Avg. monthly downloads
Rocky Linux
9
Enterprise products
Spanning the kernel to the orchestrator
Have questions about your infrastructure?
Talk to a CIQ engineer about Rocky Linux, HPC, and AI infrastructure.
