Amazon Linux 2027 Enters Public Preview with SELinux Enforcing by Default
Our take

Amazon’s release of Amazon Linux 2027 into public preview signals a significant, albeit cautious, step forward in the evolution of their operating system offering and, more broadly, in the industry’s approach to security hardening. The move to SELinux enforcing by default represents a notable shift from the permissive mode common in many Linux distributions, prioritizing enhanced security over immediate compatibility. While this change promises a more robust and secure environment, it also introduces potential friction for users accustomed to the more lenient default settings. The decision reflects a growing industry trend towards proactive security measures, as evidenced by the increasing adoption of technologies like confidential computing and zero-trust architectures – topics explored in detail in The State of Cloud Native Security and Understanding Zero Trust. This isn’t simply about ticking a security box; it’s about building a foundation for increasingly complex and sensitive workloads in the cloud.
The lack of immediate details surrounding Amazon Linux 2027 – specifically the absence of an end-of-support date for AL2023, a general availability timeline, and a clear migration path – underscores the preview nature of this release and the potential challenges ahead. This approach, while common for early previews, does create uncertainty for organizations already invested in Amazon Linux. It’s reasonable to anticipate a period of experimentation and adaptation as users assess the impact of SELinux enforcing on their existing applications. The fact that applications behaving flawlessly on AL2023’s permissive mode may encounter issues under enforcing highlights the need for thorough testing and potential code adjustments. We've seen similar transitions in other operating systems, where seemingly minor security configurations can reveal underlying vulnerabilities and incompatibilities. This echoes discussions around container security and the importance of understanding application dependencies, as outlined in Container Security Best Practices.
The choice of kernel 7.1 as the baseline for Amazon Linux 2027 is also worth noting. This relatively recent kernel version incorporates numerous performance improvements and security enhancements, solidifying Amazon’s commitment to keeping its operating system current with the latest advancements. While kernel upgrades always carry some degree of risk, the benefits in terms of stability, performance, and security typically outweigh the potential drawbacks, provided adequate testing is performed. The deliberate build on AL2023 provides a degree of familiarity for current users, but the fundamental shift to SELinux enforcing necessitates a fresh evaluation of application behavior. It’s a calculated move, balancing the desire for innovation with the need to minimize disruption.
Ultimately, Amazon Linux 2027’s public preview is a glimpse into the future of cloud operating systems – a future where security is not an afterthought but a core design principle. The enforced SELinux policy, while potentially disruptive in the short term, will likely become the norm as organizations prioritize robust security postures. The absence of concrete timelines and migration details suggests a long-term commitment to this direction, encouraging users to actively engage with the preview and provide feedback to shape the final release. The question now becomes: how effectively will AWS support users through this transition, and what tools and resources will be provided to facilitate a smooth migration to this more secure, but potentially more demanding, environment?

AWS has released Amazon Linux 2027 in public preview, built on the AL2023 baseline with kernel 7.1 and SELinux in enforcing mode by default. Applications that pass on AL2023's permissive mode may fail under enforcing. The announcement gives no AL2023 end-of-support date, no GA date, and no in-place migration path.
By Steef-Jan WiggersRead on the original site
Open the publisher's page for the full experience