镜像模式 (Image Mode / bootc)
RHEL Image Mode 是 Red Hat 在 RHEL 9.6 起 GA、并内置于 RHEL 10 的新一代系统交付方式:把整个操作系统(内核、软件包、配置)打包成一个 OCI 容器镜像,用容器工具链构建、分发和更新。核心组件是 bootc(bootable containers)。它没有更换系统底层——软件包、内核、systemd 都和传统 RHEL 相同,变的是交付方式。
为什么要有 Image Mode
Section titled “为什么要有 Image Mode”传统 RHEL 运维的痛点:
- 应用进容器,系统本身却仍靠 RPM + Ansible 一层层配置,两套工件、两套流水线
- 系统状态是”漂移”出来的,难以复现,回滚依赖备份
- 开发、测试、生产环境不一致的排查成本高
Image Mode 的回答:
- 一个工件:应用和操作系统都在容器镜像里,用同一个 registry 分发
- 不可变基座 + 声明更新:系统由镜像定义,更新 = 拉新镜像,天然可回滚
- 熟悉的工具:构建用 Containerfile + Podman/Buildah,不需要学全新的 DSL
| 概念 | 说明 |
|---|---|
| rhel-bootc | Red Hat 官方的可引导基础镜像(registry.redhat.io/rhel10/rhel-bootc) |
| bootc | 安装/引导/更新镜像化系统的工具(host 端 bootc upgrade、bootc status) |
| Containerfile | 与普通容器构建相同,但产出可引导镜像 |
| bootc-image-builder | 把 bootc 镜像转换成 ISO/qcow2/AMI 等安装介质的工具 |
快速上手:构建自定义系统镜像
Section titled “快速上手:构建自定义系统镜像”1. 写 Containerfile
Section titled “1. 写 Containerfile”FROM registry.redhat.io/rhel10/rhel-bootc:latest
# 与普通镜像构建一致:装包、拷配置RUN dnf -y install nginx && dnf clean allCOPY nginx.conf /etc/nginx/nginx.confCOPY app.conf /etc/sysctl.d/
# 需要开机自启的服务用 systemd 单元方式声明RUN systemctl enable nginx.service2. 构建并推送
Section titled “2. 构建并推送”$ podman build -t quay.io/yourorg/rhel-custom:1.0 .$ podman push quay.io/yourorg/rhel-custom:1.03. 安装到机器
Section titled “3. 安装到机器”两条路线:
- 物理机/已有系统:在机器上执行
bootc install to-disk/ 在已运行的 bootc 系统上bootc switch到你的镜像 - 云/虚拟机镜像:用 bootc-image-builder 生成 qcow2、AMI、ISO
$ podman run \ --rm -it --privileged \ --volume ./output:/output \ quay.io/centos-bootc/bootc-image-builder:latest \ quay.io/yourorg/rhel-custom:1.0 --type qcow24. 日常更新与回滚
Section titled “4. 日常更新与回滚”在运行中的 bootc 系统上:
$ sudo bootc upgrade$ sudo systemctl reboot
# 出问题时回滚到上一个镜像$ sudo bootc rollback更新策略由 systemd timer 定期自动执行,等价于一个”由 git 驱动的 yum update”。
与传统方式的对比
Section titled “与传统方式的对比”| 维度 | 传统 RHEL(RPM + Kickstart) | Image Mode(bootc) |
|---|---|---|
| 系统定义 | 包清单 + 配置管理工具 | 一个容器镜像 tag |
| 更新 | dnf upgrade | bootc upgrade(拉镜像) |
| 回滚 | 依赖快照/备份 | 内置上一代系统回滚 |
| 构建产物 | ISO + Ansible playbook | OCI 镜像 |
| 包级变更 | 随时 dnf install | 改镜像重新发布(紧急时 host 上仍可 dnf) |
什么时候用(和不用)
Section titled “什么时候用(和不用)”适合:
- 大规模、标准化的服务器农场(边缘、云、CI runner)
- 需要”系统版本 = 镜像 tag”审计模型的合规场景
- 已有 GitOps/容器流水线,想把系统纳入同一条流水线
暂不适合:
- 单台、多变的实验机(包级操作更灵活)
- 依赖大量第三方内核模块或装机后频繁变更硬件的场景(需验证)
- 还没上容器工具链、纯手工运维的小环境——先用好 Image Builder 和 Kickstart 收益更直接
- 镜像构建 (Image Builder) — 传统镜像定制路线
- Kickstart 无人值守 — 非镜像化自动安装的标准方案
- Podman 入门 — Image Mode 的构建基石
- FIPS 模式配置 — 合规基线在镜像中声明