Flock 2026 Fedora Server – What You Can Expect From The Next Two Releases
Watch on YouTubeVideo summary
The video introduces a strategic shift in Fedora Server's development path, specifically addressing the growing demand from users who operate home servers and labs alongside their professional work. Surveys conducted over the last year and a half revealed that approximately 80% of Fedora Server users are leveraging the platform for home contexts, such as media serving or working-from-home environments, rather than strictly enterprise settings. To accommodate this without diluting the focus on professional-grade enterprise usage, the developers decided to create a separate "spin-off" distribution known as Fedora Home Server. This new bootable image is designed to be lightweight and portable, targeting Single Board Computers (SBCs) with ARM architecture to minimize power consumption while maintaining Fedora's core values of up-to-date software, reliability, and community-driven quality assurance.
A significant portion of the discussion focuses on enhancing infrastructure as code capabilities through deeper integration between Ansible and Cockpit. The team has been packaging Ansible roles as RPMs to simplify the deployment of standard services like Apache HTTPD, PostgreSQL, and Cockpit itself. A key technical breakthrough highlighted is the development of a local Kerberos Key Distribution Center (KDC). This innovation aims to eliminate the reliance on the outdated and insecure NTLM authentication protocol by running a standalone Kerberos instance locally via Unix domain sockets. This setup allows for secure, internal-only authentication that mimics corporate environments while supporting modern features like one-time passwords and future integration with FIDO2 tokens for two-factor authentication, all without requiring external network access.
The proposed software stack for the Fedora Home Server spin-off is tailored to meet the specific needs of a home lab environment, featuring pre-configured services such as Samba for file sharing, Postfix combined with Dovecot and OpenDMARC for robust email management, and a reverse proxy web server. The developers also plan to include an integrated ACME server to automate SSL certificate issuance, which is essential for modern applications built around the Let's Encrypt ecosystem. Additionally, there is consideration for integrating FreeIPA to provide users with integrated identity management options within their home labs. While the core software components will remain similar to the professional edition, the primary distinction lies in the default configurations and the curated experience designed specifically for hobbyists and freelancers who need a reliable, secure, and easy-to-manage system that bridges the gap between consumer hardware and enterprise-grade security standards.
Read the full video transcript
Oh, guys, it didn't work
>> [laughter]
>> At least it's over again. Knows how to
work with this stuff.
Okay.
We are missing Alexander, but I think we
should
We should start the moment.
Well, I'm Peter and Peter Boy. This is
Emmanuel and Alexander.
Oh, oh, sorry. Yes.
Oh,
I just have to clean my my glasses.
And what we are speaking about, what we
are speaking about today
is first our
new new latest projects to create a home
server or home lab
spin-off. It's very important term for
us, a spin-off of Fedora server.
Um
And then
two
items for our professional variant of
server.
It's about Ansible support for server
roads. The server road is according to
our technical specification specifically
extraordinary extraordinary supported
services.
And it it may be maybe a mail service in
as combination of
Dovecot, Postfix, OpenDMARC, and all
these things together.
And the latest improvement on security,
not the latest, but latest step in
improvement integrated local KDC.
So, let's start
with the first one, why a home server
spin-off.
We are
all our technical specifications, all
our goals, and all we are
aiming or targeting the professional
context.
And we were very very
sure about continuing doing so.
Last year we had a big
because we detected in our user survey
that about 80% of our users are using
Fedora Server in a home context. Either
as a really home server for media server
or something like that. Or in a home or
in a working-from-home environment.
Or freelance or something like that.
It's not so that 80% of our users are
home
users.
Most of them or many of them use home
use it in in addition to a professional
usage of home server. So yeah.
All our
the
percentage of professional or enterprise
users don't add to 100% but well 150 160
something like that.
Well
we had a long
discussion in the server working group.
If you just
should do it or shouldn't and one of our
issues is
we don't want to lose the focus for a
professional usage of Fedora Server
Edition.
And so we came up with the idea to make
a spin-off. This is a separate bootable
image.
Uh and not part of the
generic Fedora Server distribution
files.
We want to provide the different disk
profile this is profile blurred.
And for me or for us
it's a bit more than it's the the same
time a proof of concept for new ideas or
you know not use for other ideas
for usage scenarios for a professional
professional use of Fedora Server.
What do we want to achieve? Okay.
Um
at the moment it's
Oh okay maybe the order is the order of
order.
Um
There is some um
um
requirements here.
worked on. First is low power
consumption,
portability,
and
specifically because they're home
server,
mostly
is is mostly idle most of the time, so
you don't need any high-powered
uh hardware.
We don't want to provide yet another
boring device,
but we want to
um
keep all these Fedora
um
properties we are so proud of.
Is up-to-date software and always more
or less the latest version, our QA, our
great QA,
uh right resulting in reliable
usability,
and everything built on our own Fedora
infrastructure.
No,
everything under
under Fedora control, so we can not
guarantee, but we can do our but the
best what we can to provide secure and
reliable usable software.
Um
and okay,
other point, I'm
I'm working as a scientist sometimes or
most of the time,
and there's a concept of participatory
software development,
and I tried to start this with the
Fedora server,
and I think with some success because we
had a
big
Okay, sorry.
Um we have a lot of
new new participants in our discussion,
um so
it's the first step and it is it seems
to work. Well, the challenges
are Fedora tools usable? Is
tools it means is Ansible and Cockpit.
Can you use it or make it usable in the
same way or nearly the same way
as professional NAS like Synology
or full
full rated
uh
appliances is FreeNAS advanced
There will always be a difference of
course.
Um
that's part of the concept but
we wanted to make it like as as usable
as as possible.
And that's one of the challenges.
Um
So therefore you want to provide a
ready-to-use installation therefore an
image file
and we use or targeted SBCs as the ARM
single board computers because they
already use in Fedora these copy image
to to a boot disk as kind of
installation and
specific specifically ARM computers
are still those with the smallest
footprint and core power consumption
specifically in situations where the SBC
is most in most cases idle.
Compared with at least the latest Intel
processors.
And then
what we are doing next
currently we are discussing the initial
set of software.
I we invite you to
join the discussion if you are
interested either in our matrix channel
or
in the forge and as part of the ticket.
And currently we are still the mention
public as well as a shared
development server so every member of
our group can
take part of developing
the bootable image.
Well and you have to create the
installation
the the scripts which prepare the answer
software of
And
I have
Okay, what can maybe professional use?
One idea is if it works well
to create a server VM as a virtual
machine host spin-off
with the same contact not contact with
the same intention. So, not a fully
created thing like oVirt or Proxmox, but
more open and more locally better
locally accessible.
Anything which is I
uh working name for a working place. It
is to
create a system where Fedora server acts
as a central installation
configuration installation point
administration point for small
to medium
installations.
It's not brand new
of no neither of that. And in the latter
I was
um committed in a group with IBM 10
years ago.
We made something like that for the
OS/2.
A rest in peace
for the OS/2 um
operating system with some success.
For both things all
all items you need are in are there.
They exist. It's It's only a matter put
everything in together in a working in a
working fashion. Well, that's our idea
with Fedora Home Server.
Oh, yeah. 2 minutes longer as I should.
>> Mhm.
Yep. Okay. So,
uh
Peter was uh talking about a survey that
we did
a year and a half ago.
>> What? Year and a half, yes.
>> Yeah, a year and a half ago and uh we
got
uh
we more far more responses that than we
actually thought we were going to get
and
a lot of these responses
said that they wanted
more integration with
they wanted to practice infrastructure
as code.
So, this means using
Ansible, Puppet, Salt, CF Engine,
whatever whatever you want to deploy and
install
packages
well,
software or services.
At this point, I started
packaging Ansible roles as RPMs.
They are presently in Copper.
I've started submitting them into Fedora
so that they will be available to anyone
without having to activate Copper.
And the goal is to make it
easier to deploy the
the software that we encourage we the
Server SIG encourage you to use
Apache's HTTPD, PostgreSQL,
Cockpit, and so on and so forth.
We have had talks about
Cockpit integration with Ansible with
the
the people who own Cockpit.
And
they
So, we started talking a year ago. We've
had more discussions
here this year because Flock is the
ideal moment to discuss uh
integration with different
Red Hat products.
And while the Cockpit people are not
open to having Cockpit become
a rival to Tower where you would uh
select uh
number of host on your on your
infrastructure and you would deploy uh
you would run Ansible playbooks on those
uh on those uh servers.
Uh they are perfectly willing to have uh
an uh cockpit module that will download
an Ansible uh role
and that will allow you to uh run the
Ansible role on the machine that you are
currently running cockpit on.
And we feel that this is the best way to
provide integration with Ansible and uh
and cockpit.
As as it turns out, the product owner
the product owner for cockpit is the
same person who is the product owner for
uh Red Hat uh system roles,
uh which is a group of Ansible playbooks
already packaged in uh Fedora.
So, that uh means that there would be
one less person to convince uh that
integration is a good thing.
And so, that uh that is the goal for the
the the the coming year.
More more integration between Ansible
and cockpit.
And obviously, for people who are using
the the server spin, they would continue
to use uh AWX or the Ansible command
line to deploy to tens or hundreds of uh
servers
should they should they want to.
Okay.
Alex, I believe it's your turn.
>> Sh- [clears throat] short Umbau.
So, on my side, I'm
going to show you
There's nothing exciting.
>> Yes, at least this part of demo works.
>> [laughter]
>> Um, so what I will be showing is the
local KDC working on Fedora 44.
Local KDC is a Kerberos
KDC, key distribution center running on
a standalone machine. The typically
Kerberos is used for the environments
corporate environments, right?
Um, you use
Kerberos when you log in into Fedora
services.
It's hidden behind
uh
HTTP proxy
uh that hides it from you.
When you run something like FBK init,
that actually talks over HTTPS to the
backend where this Kerberos thing runs.
And but you don't have access direct
direct access to the services that
provided there.
In this demo, uh we will run this
Kerberos KDC locally uh over Unix domain
socket. So, it's never accessible
[snorts]
from outside of the machine.
And on the machine itself is only
accessible by those who have access to
that socket. So, it could be namespaced
if needed.
For example, containers and so on. Uh in
this case, we just run it on the
machine.
And use it as the primary authentication
mechanism for for the machine itself.
Why this is needed? The main
uh need comes from killing NTLM.
NTLM is the last holdout from like 1994
that keeps the
insecure
uh
communication in the Windows world.
For several years, Microsoft wanted to
kill it. They tried different
technologies and they failed and finally
in 2021, they came back and said it will
be Kerberos.
Again, everywhere.
Came back to the technology that was
designed like 27 years ago.
I mean the
the particular extension of Kerberos
that we are using here was designed 27
year ago. Kerberos was designed in 1984.
So, 42 years ago. Still kicking.
Um so, what we have here is the Kerberos
KDC called local KDC
that is configured and running
on this machine.
It's pretty modest.
Um I mean, this is VM, so don't look at
swap. That's my
my VM problem.
Um so, it takes 4 MB of memory, pretty
modest. And
we aim to make it working with the um
self-activation, self-deactivation. So,
it's up on when there is a request
coming to the Unix domain socket.
This all is in the upstream MIT Kerberos
122. Uh we spent like a year or two to
get this polish it and merge it
upstream. So, this part is upstream.
What is not upstream is the Samba
integration yet,
which is waiting for things I will talk
about later.
Um so, this is the
server running.
This is my
unprivileged user.
The user itself is defined it
in
just it's a password. I'm using the
system D's view on the database.
And it's basically just a normal user.
Regular user defined in the Etsy
password. If you don't trust me on this,
I can do this.
And you can see that I'm defined in this
um
Etsy password. This also means that this
user actually has the password in Etsy
shadow.
So, it's normal password, normal user.
Consider this as
you installed Fedora I don't know
Fedora core six and then upgraded every
every release to let's hope Fedora 45
and then you installed local KDC and
local KDC still will pick up your
password.
Something doesn't compute because this
is not how Kerberos works, right?
Um you have to have a special key
for for that to to work. And what we did
is we actually
um get
some integration on the system level
that
Where is this? Oh, sorry. This is
unprivileged so it cannot talk the uh
K admin thing.
We we did some extensions that allow us
to
um basically look up the users in the
normal user databases instead of the
Kerberos.
So, there's bunch of system principles
Kerberos principles like we we create
HTTP ones. This is for cockpit
to use.
Um this is the master key. This is for
anonymous
smart card use. This is for
Samba. This is for
Open SSH, so SSH services, and in
general use, and this is for
administration things. As you can see,
there's no me in this database.
Yet, I can
ask
to retrieve my principal, and it is
there.
So, it's not in the Kerberos database,
but it's synthesized it on fly.
Because it we find it on the system
level.
And actually, we can do some
interesting. We can ask
uh string attributes associated with
this principal, and you can see it's
configured to use one-time password kind
of feature with the um type of local KDC
PAM. So, this will use the same
mechanism we use in Fedora for
two-factor authentication for Fedora
accounts.
Just on the back end, that's the
technical magic that we use there. And
then,
with that one, we call a service called
local KDC PAM, that will use PAM for
authentication. That's how we use uh
this to authenticate normal normal
passwords effectively. So,
if I go back to the unprivileged user
and do kinit,
uh it will use the um
the user
that's defined in the shell, right?
And you can see, we not ask it a
password, we ask it OTP token. That's
artifact of how this OTP authentication
works. But obviously, there is no OTP
like the the real
PIN and and value uh there. There is
only a password defined for this user.
So, I'm entering this password,
and I can look at
that I actually got a ticket
from this
wild long realm
which is local KDC and some unique
stuff. That's the name in
we use. Typically, you don't need to
enter any any of those realms. They will
be discovered automatically. Um so, all
you need to know is the kinit is the
authentication
um and uh klist is to list it. Ideally,
you shouldn't even know about that one.
The tools will simply work as they work
in the um corporate environment. So,
what you can do with this
is that you can use this
ticket for accessing services that are
enabled for um Kerberos use. So, for
example
I have sudo.
And
I can log in there. It asks me a
password, but this is how sudo is built.
Sudo is basically asking for a password.
So, I'm just doing enter.
And I'm there.
And the reason I'm there is because
if I look at the um
configuration
then it's the I'm using SSSD. So PAM
stack actually handled by PAM SSS SSSD
thing and I enabled SSSD to use with
GSSAPI. So, it's using the special PAM
module that
accepts the correct Kerberos
uh key um
tickets
for for the access. In this case, I need
to have host/the
host uh
ticket the same as with the um
um
with SSH access. And the switchable
auth, this is a upcoming new thing for
making rich experience in GTM with with
Kerberos stuff.
So, let me get back.
And you can see that I got the second
ticket.
So, the first one was the the the ticket
that I obtained during
login.
This is the same one.
And the second one is this service
ticket for the local
host. I intentionally did not change the
host name. You can see that the host
name is the one that I got from Fedora
install.
This is like all of this works. So far,
this is all we have. We have a bit more.
We will be able to do
actual two-factor authentication, actual
support for the
FIDO2 tokens, and everything we support
in FreeIPA
just for the standalone deployment. Um
this is going to come to um Fedora
eventually because I don't know how long
the um
bringing new packages will take.
Uh time in Fedora, we already spent 1
month trying to get the um
um Rust packages we we use here uh
accepted as new packages. They're still
review processes.
Um
stuck there. Um if you want more, we
have this talk we gave at the SambaXP
conference
um in April,
which has much more details. Yes, those
are
me and Andreas Schneider.
Um
and you can
go here
at the
sambaexp.org
scroll down and
learn how to get rid of NTLM. Yeah, so
we have been testing this against
custom builds of Windows together with
the Microsoft Windows authentication
team. Yes.
And
there are a few patches that needed here
and there on their side and our side.
So, we're working very close to to get
this finalized. I don't know when
Microsoft will release. They have a lot
of marketing materials that tell that
it's already uh
there and coming and so on. No, it's not
yet there. It's coming.
Um and interoperability is the highest
uh
priority here so that we we have thing
that works from day one.
Yes. Thank you.
>> [applause]
>> 3 minutes probably for
>> Thank you very much. Do we have Yeah, we
have a few minutes. Do we have any
questions?
>> Hello. Um so, you had talked a little
bit about trying to define what software
you want pre-installed in the uh
spin-off for the home server. I'm
curious how you guys are thinking about
that and if there were I know I can go
and read the ticket, but for the sake of
conversation here,
uh
what are you guys thinking of in that
regard about what should be included in
a home lab server versus a traditional
server you've targeted?
>> But,
of course, it is
uh
Samba. Without Samba, you don't have
that Samba in the right.
I think another popular popular service
is mail or mail service, which is able
to collect mail from several
sources.
The modern
the modern net guy has more than more
than one mail address.
And
Postfix preconfiguration, which is able
to
to select the smart host for actually
use a public server depending on the
from address in the mail. So,
um you can safely use this your local
installation to send or to use several
mail addresses including all the
open DMARC open
open something things to
to avoid or to handle these things to
avoid blocking by spam.
And we need of anyway
a web server as a reverse proxy
to
have to
offer various web-based services.
Um
yeah, that's the the basic at the
moment. And of course, we want to have a
media server, but we are still looking
for one.
Yeah, it's a
>> Um on my side, I think there's there
wouldn't be much difference in terms of
software.
It's more in what experience you want to
get and default configurations. Um two
Okay, three components that I I would
say that would be there is um
there will be free IPA um for the
people who want to set up the um
like integrated identity management for
their home lab, for example. Uh but if
you don't do that integrated thing, you
still chances are you still need to
issue certificates for your own
services.
And most likely you would like to use
ACME for doing that. So, we are bringing
new ACME server
in
in 90 minutes, you will know about that.
Um and then um most likely you will need
to handle all of as well. For the year
home services
because that's
stuff like next cloud and the others
they all build now all modern app built
around all of.
So we will be having
a small integrated all of server that
allows to delegate
integrated with the stuff like this.
Which nobody else is doing I mean
Kerberos.
Yep.
>> Thank you very much for our time so
>> Yes.
>> [applause]