Submind YouTube summaries
Thumbnail for Flock 2026 Fedora Server – What You Can Expect From The Next Two Releases

Flock 2026 Fedora Server – What You Can Expect From The Next Two Releases

Watch on YouTube

Video summary

The video introduces a strategic shift in Fedora Server's development path, specifically addressing the growing demand from users who operate home servers and labs alongside their professional work. Surveys conducted over the last year and a half revealed that approximately 80% of Fedora Server users are leveraging the platform for home contexts, such as media serving or working-from-home environments, rather than strictly enterprise settings. To accommodate this without diluting the focus on professional-grade enterprise usage, the developers decided to create a separate "spin-off" distribution known as Fedora Home Server. This new bootable image is designed to be lightweight and portable, targeting Single Board Computers (SBCs) with ARM architecture to minimize power consumption while maintaining Fedora's core values of up-to-date software, reliability, and community-driven quality assurance. A significant portion of the discussion focuses on enhancing infrastructure as code capabilities through deeper integration between Ansible and Cockpit. The team has been packaging Ansible roles as RPMs to simplify the deployment of standard services like Apache HTTPD, PostgreSQL, and Cockpit itself. A key technical breakthrough highlighted is the development of a local Kerberos Key Distribution Center (KDC). This innovation aims to eliminate the reliance on the outdated and insecure NTLM authentication protocol by running a standalone Kerberos instance locally via Unix domain sockets. This setup allows for secure, internal-only authentication that mimics corporate environments while supporting modern features like one-time passwords and future integration with FIDO2 tokens for two-factor authentication, all without requiring external network access. The proposed software stack for the Fedora Home Server spin-off is tailored to meet the specific needs of a home lab environment, featuring pre-configured services such as Samba for file sharing, Postfix combined with Dovecot and OpenDMARC for robust email management, and a reverse proxy web server. The developers also plan to include an integrated ACME server to automate SSL certificate issuance, which is essential for modern applications built around the Let's Encrypt ecosystem. Additionally, there is consideration for integrating FreeIPA to provide users with integrated identity management options within their home labs. While the core software components will remain similar to the professional edition, the primary distinction lies in the default configurations and the curated experience designed specifically for hobbyists and freelancers who need a reliable, secure, and easy-to-manage system that bridges the gap between consumer hardware and enterprise-grade security standards.
Read the full video transcript
Oh, guys, it didn't work >> [laughter] >> At least it's over again. Knows how to work with this stuff. Okay. We are missing Alexander, but I think we should We should start the moment. Well, I'm Peter and Peter Boy. This is Emmanuel and Alexander. Oh, oh, sorry. Yes. Oh, I just have to clean my my glasses. And what we are speaking about, what we are speaking about today is first our new new latest projects to create a home server or home lab spin-off. It's very important term for us, a spin-off of Fedora server. Um And then two items for our professional variant of server. It's about Ansible support for server roads. The server road is according to our technical specification specifically extraordinary extraordinary supported services. And it it may be maybe a mail service in as combination of Dovecot, Postfix, OpenDMARC, and all these things together. And the latest improvement on security, not the latest, but latest step in improvement integrated local KDC. So, let's start with the first one, why a home server spin-off. We are all our technical specifications, all our goals, and all we are aiming or targeting the professional context. And we were very very sure about continuing doing so. Last year we had a big because we detected in our user survey that about 80% of our users are using Fedora Server in a home context. Either as a really home server for media server or something like that. Or in a home or in a working-from-home environment. Or freelance or something like that. It's not so that 80% of our users are home users. Most of them or many of them use home use it in in addition to a professional usage of home server. So yeah. All our the percentage of professional or enterprise users don't add to 100% but well 150 160 something like that. Well we had a long discussion in the server working group. If you just should do it or shouldn't and one of our issues is we don't want to lose the focus for a professional usage of Fedora Server Edition. And so we came up with the idea to make a spin-off. This is a separate bootable image. Uh and not part of the generic Fedora Server distribution files. We want to provide the different disk profile this is profile blurred. And for me or for us it's a bit more than it's the the same time a proof of concept for new ideas or you know not use for other ideas for usage scenarios for a professional professional use of Fedora Server. What do we want to achieve? Okay. Um at the moment it's Oh okay maybe the order is the order of order. Um There is some um um requirements here. worked on. First is low power consumption, portability, and specifically because they're home server, mostly is is mostly idle most of the time, so you don't need any high-powered uh hardware. We don't want to provide yet another boring device, but we want to um keep all these Fedora um properties we are so proud of. Is up-to-date software and always more or less the latest version, our QA, our great QA, uh right resulting in reliable usability, and everything built on our own Fedora infrastructure. No, everything under under Fedora control, so we can not guarantee, but we can do our but the best what we can to provide secure and reliable usable software. Um and okay, other point, I'm I'm working as a scientist sometimes or most of the time, and there's a concept of participatory software development, and I tried to start this with the Fedora server, and I think with some success because we had a big Okay, sorry. Um we have a lot of new new participants in our discussion, um so it's the first step and it is it seems to work. Well, the challenges are Fedora tools usable? Is tools it means is Ansible and Cockpit. Can you use it or make it usable in the same way or nearly the same way as professional NAS like Synology or full full rated uh appliances is FreeNAS advanced There will always be a difference of course. Um that's part of the concept but we wanted to make it like as as usable as as possible. And that's one of the challenges. Um So therefore you want to provide a ready-to-use installation therefore an image file and we use or targeted SBCs as the ARM single board computers because they already use in Fedora these copy image to to a boot disk as kind of installation and specific specifically ARM computers are still those with the smallest footprint and core power consumption specifically in situations where the SBC is most in most cases idle. Compared with at least the latest Intel processors. And then what we are doing next currently we are discussing the initial set of software. I we invite you to join the discussion if you are interested either in our matrix channel or in the forge and as part of the ticket. And currently we are still the mention public as well as a shared development server so every member of our group can take part of developing the bootable image. Well and you have to create the installation the the scripts which prepare the answer software of And I have Okay, what can maybe professional use? One idea is if it works well to create a server VM as a virtual machine host spin-off with the same contact not contact with the same intention. So, not a fully created thing like oVirt or Proxmox, but more open and more locally better locally accessible. Anything which is I uh working name for a working place. It is to create a system where Fedora server acts as a central installation configuration installation point administration point for small to medium installations. It's not brand new of no neither of that. And in the latter I was um committed in a group with IBM 10 years ago. We made something like that for the OS/2. A rest in peace for the OS/2 um operating system with some success. For both things all all items you need are in are there. They exist. It's It's only a matter put everything in together in a working in a working fashion. Well, that's our idea with Fedora Home Server. Oh, yeah. 2 minutes longer as I should. >> Mhm. Yep. Okay. So, uh Peter was uh talking about a survey that we did a year and a half ago. >> What? Year and a half, yes. >> Yeah, a year and a half ago and uh we got uh we more far more responses that than we actually thought we were going to get and a lot of these responses said that they wanted more integration with they wanted to practice infrastructure as code. So, this means using Ansible, Puppet, Salt, CF Engine, whatever whatever you want to deploy and install packages well, software or services. At this point, I started packaging Ansible roles as RPMs. They are presently in Copper. I've started submitting them into Fedora so that they will be available to anyone without having to activate Copper. And the goal is to make it easier to deploy the the software that we encourage we the Server SIG encourage you to use Apache's HTTPD, PostgreSQL, Cockpit, and so on and so forth. We have had talks about Cockpit integration with Ansible with the the people who own Cockpit. And they So, we started talking a year ago. We've had more discussions here this year because Flock is the ideal moment to discuss uh integration with different Red Hat products. And while the Cockpit people are not open to having Cockpit become a rival to Tower where you would uh select uh number of host on your on your infrastructure and you would deploy uh you would run Ansible playbooks on those uh on those uh servers. Uh they are perfectly willing to have uh an uh cockpit module that will download an Ansible uh role and that will allow you to uh run the Ansible role on the machine that you are currently running cockpit on. And we feel that this is the best way to provide integration with Ansible and uh and cockpit. As as it turns out, the product owner the product owner for cockpit is the same person who is the product owner for uh Red Hat uh system roles, uh which is a group of Ansible playbooks already packaged in uh Fedora. So, that uh means that there would be one less person to convince uh that integration is a good thing. And so, that uh that is the goal for the the the the coming year. More more integration between Ansible and cockpit. And obviously, for people who are using the the server spin, they would continue to use uh AWX or the Ansible command line to deploy to tens or hundreds of uh servers should they should they want to. Okay. Alex, I believe it's your turn. >> Sh- [clears throat] short Umbau. So, on my side, I'm going to show you There's nothing exciting. >> Yes, at least this part of demo works. >> [laughter] >> Um, so what I will be showing is the local KDC working on Fedora 44. Local KDC is a Kerberos KDC, key distribution center running on a standalone machine. The typically Kerberos is used for the environments corporate environments, right? Um, you use Kerberos when you log in into Fedora services. It's hidden behind uh HTTP proxy uh that hides it from you. When you run something like FBK init, that actually talks over HTTPS to the backend where this Kerberos thing runs. And but you don't have access direct direct access to the services that provided there. In this demo, uh we will run this Kerberos KDC locally uh over Unix domain socket. So, it's never accessible [snorts] from outside of the machine. And on the machine itself is only accessible by those who have access to that socket. So, it could be namespaced if needed. For example, containers and so on. Uh in this case, we just run it on the machine. And use it as the primary authentication mechanism for for the machine itself. Why this is needed? The main uh need comes from killing NTLM. NTLM is the last holdout from like 1994 that keeps the insecure uh communication in the Windows world. For several years, Microsoft wanted to kill it. They tried different technologies and they failed and finally in 2021, they came back and said it will be Kerberos. Again, everywhere. Came back to the technology that was designed like 27 years ago. I mean the the particular extension of Kerberos that we are using here was designed 27 year ago. Kerberos was designed in 1984. So, 42 years ago. Still kicking. Um so, what we have here is the Kerberos KDC called local KDC that is configured and running on this machine. It's pretty modest. Um I mean, this is VM, so don't look at swap. That's my my VM problem. Um so, it takes 4 MB of memory, pretty modest. And we aim to make it working with the um self-activation, self-deactivation. So, it's up on when there is a request coming to the Unix domain socket. This all is in the upstream MIT Kerberos 122. Uh we spent like a year or two to get this polish it and merge it upstream. So, this part is upstream. What is not upstream is the Samba integration yet, which is waiting for things I will talk about later. Um so, this is the server running. This is my unprivileged user. The user itself is defined it in just it's a password. I'm using the system D's view on the database. And it's basically just a normal user. Regular user defined in the Etsy password. If you don't trust me on this, I can do this. And you can see that I'm defined in this um Etsy password. This also means that this user actually has the password in Etsy shadow. So, it's normal password, normal user. Consider this as you installed Fedora I don't know Fedora core six and then upgraded every every release to let's hope Fedora 45 and then you installed local KDC and local KDC still will pick up your password. Something doesn't compute because this is not how Kerberos works, right? Um you have to have a special key for for that to to work. And what we did is we actually um get some integration on the system level that Where is this? Oh, sorry. This is unprivileged so it cannot talk the uh K admin thing. We we did some extensions that allow us to um basically look up the users in the normal user databases instead of the Kerberos. So, there's bunch of system principles Kerberos principles like we we create HTTP ones. This is for cockpit to use. Um this is the master key. This is for anonymous smart card use. This is for Samba. This is for Open SSH, so SSH services, and in general use, and this is for administration things. As you can see, there's no me in this database. Yet, I can ask to retrieve my principal, and it is there. So, it's not in the Kerberos database, but it's synthesized it on fly. Because it we find it on the system level. And actually, we can do some interesting. We can ask uh string attributes associated with this principal, and you can see it's configured to use one-time password kind of feature with the um type of local KDC PAM. So, this will use the same mechanism we use in Fedora for two-factor authentication for Fedora accounts. Just on the back end, that's the technical magic that we use there. And then, with that one, we call a service called local KDC PAM, that will use PAM for authentication. That's how we use uh this to authenticate normal normal passwords effectively. So, if I go back to the unprivileged user and do kinit, uh it will use the um the user that's defined in the shell, right? And you can see, we not ask it a password, we ask it OTP token. That's artifact of how this OTP authentication works. But obviously, there is no OTP like the the real PIN and and value uh there. There is only a password defined for this user. So, I'm entering this password, and I can look at that I actually got a ticket from this wild long realm which is local KDC and some unique stuff. That's the name in we use. Typically, you don't need to enter any any of those realms. They will be discovered automatically. Um so, all you need to know is the kinit is the authentication um and uh klist is to list it. Ideally, you shouldn't even know about that one. The tools will simply work as they work in the um corporate environment. So, what you can do with this is that you can use this ticket for accessing services that are enabled for um Kerberos use. So, for example I have sudo. And I can log in there. It asks me a password, but this is how sudo is built. Sudo is basically asking for a password. So, I'm just doing enter. And I'm there. And the reason I'm there is because if I look at the um configuration then it's the I'm using SSSD. So PAM stack actually handled by PAM SSS SSSD thing and I enabled SSSD to use with GSSAPI. So, it's using the special PAM module that accepts the correct Kerberos uh key um tickets for for the access. In this case, I need to have host/the host uh ticket the same as with the um um with SSH access. And the switchable auth, this is a upcoming new thing for making rich experience in GTM with with Kerberos stuff. So, let me get back. And you can see that I got the second ticket. So, the first one was the the the ticket that I obtained during login. This is the same one. And the second one is this service ticket for the local host. I intentionally did not change the host name. You can see that the host name is the one that I got from Fedora install. This is like all of this works. So far, this is all we have. We have a bit more. We will be able to do actual two-factor authentication, actual support for the FIDO2 tokens, and everything we support in FreeIPA just for the standalone deployment. Um this is going to come to um Fedora eventually because I don't know how long the um bringing new packages will take. Uh time in Fedora, we already spent 1 month trying to get the um um Rust packages we we use here uh accepted as new packages. They're still review processes. Um stuck there. Um if you want more, we have this talk we gave at the SambaXP conference um in April, which has much more details. Yes, those are me and Andreas Schneider. Um and you can go here at the sambaexp.org scroll down and learn how to get rid of NTLM. Yeah, so we have been testing this against custom builds of Windows together with the Microsoft Windows authentication team. Yes. And there are a few patches that needed here and there on their side and our side. So, we're working very close to to get this finalized. I don't know when Microsoft will release. They have a lot of marketing materials that tell that it's already uh there and coming and so on. No, it's not yet there. It's coming. Um and interoperability is the highest uh priority here so that we we have thing that works from day one. Yes. Thank you. >> [applause] >> 3 minutes probably for >> Thank you very much. Do we have Yeah, we have a few minutes. Do we have any questions? >> Hello. Um so, you had talked a little bit about trying to define what software you want pre-installed in the uh spin-off for the home server. I'm curious how you guys are thinking about that and if there were I know I can go and read the ticket, but for the sake of conversation here, uh what are you guys thinking of in that regard about what should be included in a home lab server versus a traditional server you've targeted? >> But, of course, it is uh Samba. Without Samba, you don't have that Samba in the right. I think another popular popular service is mail or mail service, which is able to collect mail from several sources. The modern the modern net guy has more than more than one mail address. And Postfix preconfiguration, which is able to to select the smart host for actually use a public server depending on the from address in the mail. So, um you can safely use this your local installation to send or to use several mail addresses including all the open DMARC open open something things to to avoid or to handle these things to avoid blocking by spam. And we need of anyway a web server as a reverse proxy to have to offer various web-based services. Um yeah, that's the the basic at the moment. And of course, we want to have a media server, but we are still looking for one. Yeah, it's a >> Um on my side, I think there's there wouldn't be much difference in terms of software. It's more in what experience you want to get and default configurations. Um two Okay, three components that I I would say that would be there is um there will be free IPA um for the people who want to set up the um like integrated identity management for their home lab, for example. Uh but if you don't do that integrated thing, you still chances are you still need to issue certificates for your own services. And most likely you would like to use ACME for doing that. So, we are bringing new ACME server in in 90 minutes, you will know about that. Um and then um most likely you will need to handle all of as well. For the year home services because that's stuff like next cloud and the others they all build now all modern app built around all of. So we will be having a small integrated all of server that allows to delegate integrated with the stuff like this. Which nobody else is doing I mean Kerberos. Yep. >> Thank you very much for our time so >> Yes. >> [applause]