- Cloud Native Applications
- Application Security
- Application Security
- Web Application Security
- Application Security Posture Management (ASPM)
- Microsegmentation
- Python Security
- SaaS Security
- Node.JS Security
- PHP Security
- AI in Cyber Security
- Cybersecurity for Financial Services
- The Principle of Least Privilege (PoLP)
- Identity and Access Management
- Cybersecurity in Banking
- Threat Detection and Response
- Cyber Kill Chain
- Threat Hunting
- Zero Trust Security
- Zero Trust Architecture
- Fileless Attacks
- DSPM
- Container Scanning
- Kubernetes
- Kubernetes
- Kubernetes Alternatives
- Kubernetes Namespace
- Kubernetes Architecture
- Kubernetes Cluster
- Kubernetes Nodes
- Kubernetes Pods
- Kubernetes Jobs
- Kubernetes Workloads
- Kubernetes Monitoring
- Kubernetes Security
- Kubernetes RBAC
- Secret Scanning
- Kubernetes Security Posture Management (KSPM)
- Kubernetes on AWS
- Kubernetes on VMware
- Kubernetes Vulnerability Scanning
- Managing Containers in Kubernetes
- K3s
- eBPF in Kubernetes
- Kubernetes Dashboard
- Kubernetes Operators
- Kubernetes Services
- Kubernetes Devops
- Kubernetes Networking
- Kubernetes ConfigMap
- Kubernetes Management
- Kubernetes Helm
- Kubernetes as a Service
- Kubernetes Serverless
- Kubernetes Tutorials
- Cloud Attacks
- Cloud Attacks
- Malware Attacks
- Zero Day Attack
- Top 10 Cyber Security Threats
- Arbitrary Code Execution
- Cryptojacking
- AI Attacks
- Prompt Injection
- Backdoor Attacks
- Reverse Shell Attack
- Remote Code Execution
- Defense Evasion
- Honeypots in Cybersecurity
- Malware Analysis
- AI Malware
- Lateral Movement
- Advanced Malware Protection
- CNAPP
- AI Security
- Container Platforms
- Containerized Architecture
- Containerized Architecture
- Docker Secrets
- Container Runtime Interface
- Container Images
- Image Scanning
- Container Compliance
- Docker Security Best Practices
- Container Security
- Container Security Best Practices
- Container Security Tools
- ECS Security
- Network Segmentation
- Istio security
- runC
- Service Mesh
- Image Repository
- Container Escape
- Container Runtime
- Docker Container
- OSS Container Image Scanning Tools
- What Is a Container?
- Docker Images
- Containerization 101
- VM vs. Container
- Containerization vs. Virtualization
- Containerized Applications
- Microservices and Containerization
- Registry Scanning
- Docker CVEs
- Docker Monitoring
- Securing Containers with Docker Scanning
- Docker CIS Benchmark
- Seccomp
- Docker Alpine
- Docker API
- Docker Tools
- 100 Best Docker Tutorials
- Docker Alternatives
- Docker Swarm
- Docker Containers vs. Virtual Machines (VMs)
- Docker Architecture
- Docker Networking
- Docker Registries
- Docker Orchestration
- OpenShift vs Docker
- Container Cloud Computing
- Container DevOps
- Docker in Production
- Container Monitoring
- Container Advantages
- Docker Hub
- Serverless Architecture
- Supply Chain Security
- Supply Chain Compliance
- SolarWinds Attack
- Supply Chain Security
- Secure Software Development Lifecycle
- Software Supply Chain Attacks
- Dependency Confusion Attack
- SLSA
- SSDF
- Software Composition Analysis
- Security Misconfigurations
- Repojacking
- Privilege Escalation
- CI/CD Security
- SAST Security
- GitLab Security
- GitHub Secret Scanning
- OWASP Dependency-Check
- Software Bill of Materials
- SBOM Tools
- NPM Vulnerabilities
- Log4j Vulnerability
- Text4Shell
- Secrets Management
- Jenkins Security
- Yarn vs. NPM
- Source Code Leaks
- Container Image Signing
- Open Source Licenses
- Vulnerability Management
- Vulnerability Management Tools
- Vulnerability Scanning Process
- Vulnerability Management
- Vulnerability Scanning
- Vulnerability Prioritization
- Open Source Vulnerability Scanning
- Vulnerability Remediation
- Vulnerability Scanner
- Risk-Based Vulnerability Management
- Vulnerability Exploitability eXchange (VEX)
- Malware Detection
- Fileless Malware
- Attack Vectors
- Malicious Code
- Risk Posture
- Alert Fatigue in Cybersecurity
- Cyber Security Posture
- MITRE ATT&CK
- MITRE ATT&CK Framework
- LLM Security
- Code Scanning
- Attack Surface
- Attack Surface Management
- What Are Indicators of Compromise (IoC)?
- Secure Code
- Configuration Drift
- Trivy
- DevSecOps
- DevSecOps
- DevSecOps Pipeline
- DevSecOps Best Practices
- DevSecOps vs SecDevOps
- Threat Modeling
- Mean Time to Repair (MTTR)
- eBPF Linux
- Cloud DevOps
- DevOps Tools
- GitOps vs DevOps
- Code Security
- Secure Code Review
- DevOps Security
- Infrastructure as Code (IaC) Security
- Infrastructure as Code DevOps
- Executive Order 14028 (U.S. Cybersecurity Executive Order)
- Open Source Security
- Shift-Left Security
- Shift Right Testing and Security
- What Is SecOps (Security Operations)?
- SecDevOps
- DevSecOps Tools
- Linux Security
- Rocky Linux
- Azure DevOps
- Cloud Security
- Cloud Security
- Cloud Security Challenges
- Cloud Security Tools
- Code to Cloud
- Cloud Protection
- Cloud Security Frameworks
- Cloud Security Standards
- Cloud Security Controls
- Cloud Security Posture Management (CSPM)
- AI Workloads
- Cloud Digital Forensics
- Cloud Computing Security Architecture
- What Is Enterprise Cloud Security?
- Virtualized Security
- CSPM Tools
- Vulnerabilities in Cloud Computing
- Top 7 Risks of Cloud Computing
- Cloud Security Assessment
- Cloud Visibility
- Cloud Governance
- Cloud Security Strategy
- Cloud Security Policy
- DFIR
- Cloud Workloads
- Public Cloud Security
- Private Cloud vs. Public Cloud
- Runtime Security
- Azure Cloud Security
- Azure Security Best Practices
- Azure Security vs. AWS Security
- AWS GovCloud: Basics & How It Compares to Azure & GCP
- S3 Security
- Cloud Misconfiguration
- Terraform Security
- Hybrid Cloud Security
- Multi-Cloud Strategy
- Agentless vs. Agent-Based Security & Monitoring
- Cloud Infrastructure Security
- Gartner CSPM
- Cloud Security Scanner
- AWS CIS Benchmark
- Cloud Configuration Management
- Cloud Workload Protection (CWP)
- Cloud Workload Protection Platforms (CWPP)
- Cloud Workload Security
- Cloud Vulnerabilities and Tools that Can Help
- Google Cloud Security
- Shared Responsibility Model
- AWS Shared Responsibility Model
- AWS Cloud Security
- Multi Cloud Security
- Cloud Compliance
- Kubernetes in Production
- Cloud Detection And Response
CentOS Is Dead, Long Live Rocky Linux!
Rocky Linux is a new, open source, RHEL-compatible operating system. It is the go-to replacement for CentOS, which was discontinued by Red Hat in 2021.
What Is Rocky Linux?
Rocky Linux is an open source Linux distribution that supports the Red Hat Enterprise Linux (RHEL) operating system source code. It offers a downstream, binary-compatible release for production-grade RHEL with community support. It was developed by the Rocky Enterprise Software Foundation and was made generally available on June 21, 2021.
In 2021, Red Hat discontinued CentOS, a popular RHEL-compatible operating system, forcing its users to seek alternatives. Many in the Linux community consider Rocky Linux the replacement for CentOS. Former CentOS co-founder, Gregory Kurtzer, is leading the Rocky Linux project, and maintainers of Rocky Linux provide easy, automated paths for migrating from CentOS to Rocky Linux.
This is part of our series of articles about DevSecOps.
In this article:
What Happened to CentOS and Why Is the Community Migrating to Rocky Linux?
Community Enterprise Operating System (CentOS) was an open source Linux distribution designed to be fully compatible, but independent, from RHEL. It was originally released in 2004 and was in wide use until recently. For example, a prominent user of CentOS is Facebook, which runs it on most of its servers.
IBM acquired the CentOS project in 2020. The company later announced that in light of the IBM acquisition of Red Hat, it decided to end support for CentOS. The company has announced that:
- The latest release of CentOS, version 9, will end support at the end of 2021, which is significantly shorter than the 10-year timeline Red Hat had previously promised.
- Support for version 8 will end in 2024 as originally scheduled.
- Going forward, CentOS will be upstream of RHEL, meaning that CentOS users will essentially perform beta testing for new RHEL versions. Previously, CentOS was downstream and inherited the latest stable version from RHEL.
Many data center administrators who rely on CentOS are unhappy with this decision. They now need to find a replacement for CentOS on short notice, which creates cost and complexity.
Many in the community are looking for a new project to take over from CentOS, and there is wide agreement that this project is Rocky Linux. The Rocky Linux project is led by CentOS founder Gregory Kurtzer and is named after CentOS co-founder Rocky McGaugh, showing that it has strong roots among CentOS contributors. Amazon, Microsoft and Google Cloud have sponsored Rocky Linux as well, showing their confidence in the project.
RHEL vs. CentOS vs. Rocky Linux
It is necessary to compare Rocky Linux to CentOS and RHEL to understand its importance. These distributions differ in their support structures, binary execution paths, and how they enable changes to source code.
RHEL
Red Hat Enterprise Linux (RHEL) is a Linux operating system for enterprises. It is open source and has wide support from many vendors and clouds. It provides a reliable foundation across diverse cloud environments and offers all the tools required for fast application delivery.
RHEL’s stability makes it suitable for powering production workloads. Many businesses worldwide use this Linux distribution, leveraging paid RedHat support options.
Advantages of RHEL include:
- RedHat support
- Stable software releases
- Rigorous testing (ensured by step releases)
- High performance and trust
- World-standard, stable operating system
- Source code availability
- Administrator certifications
The drawbacks include:
- Support is not free
- Licensing requirements
CentOS
The CentOS open source project includes two distinct Linux distributions: CentOS Linux and CentOS Stream. The discontinuation of CentOS Linux releases and updates by 2024 means existing users must plan a migration strategy.
Advantages of CentOS include:
- RedHat backing
- Latest software releases
The drawbacks include:
- Limited reliability and stability (due to the bleeding edge)
- Limited contributions (CentOs Stream users can contribute, but Red Hat vets them, while CentOS Linux does not support contributions)
- Unsuitable for rolling releases (the production system can have major bugs)
- Support is dependent on the voluntary contributions of the open source community
- Deprecated model
Rocky Linux
Rocky Linux is a rebuild of RHEL 8, so it benefits from RHEL’s lifecycle with active maintenance guaranteed until 2029. Rocky Linux has many mirrors, providing HTTP/S and RSYNC connections over a global CDN.
Rocky Linux adoption is widespread, meaning it has significant community support and a promising future. It works well as a server because it uses the RHEL stable source code to power production workloads.
Advantages of Rocky Linux include:
- An adequate replacement for CentOS distributions
- Vibrant, growing community support
- Latest software releases
The only potential drawback of Rocky Linux is that it is younger than other stable Linux distributions, but this will likely become less of an issue as adoption continues, and the project matures.
Downloading and Installing Rocky Linux
- Go to the official Rocky Linux website and download the ISO file. You can use this URL: https://rockylinux.org/download.
- After the download is complete, burn the ISO file into a USB or DVD to create bootable media.
- Use your media to boot the installation. It should present you with the Rocky Linux boot screen. Here, choose Install Rocky Linux.

- When prompted, choose your preferred language and select Continue.
- In the Installation Summary window, choose Installation Destination.
- Choose the Network and Host Name option to connect to a network connection, and click Done.
- Choose the Installation Source option and select your Rocky Linux bootable USB. If you have already selected the media, there is no need to do anything at this point.
- Choose the Software Selection option, select the desired base environment and any relevant software, and click Done.
- Go to the Installation Summary window and choose the Root Password option. Enter and verify a password, and click Done.
- In the Installation Summary window, choose the Create User option. Enter the desired responses, and click Done.
- Once the installation completes, choose Reboot System. When prompted, remove the Rocky Linux bootable media. Next, press <Enter>.
- To complete this process, choose Finish Configuration.
How to Migrate to Rocky Linux
You can migrate from CentOS Stream, CentOS, Alma Linux, RHEL, or Oracle Linux to Rocky Linux.
Step 1: Prepare Your Server
To start the migration, you need to get a Rocky Linux script file from the rocky-tools repository. This can be done in several ways.
Retrieving the script manually
Visit the GitHub repo, download a ZIP and locate the file migrate2rocky.sh.

Run the following command to upload the executable to the server using SSH (adjust file paths and domains as needed):
scp PATH/TO/FILE/migrate2rocky.sh [email protected]:/home/
Retrieving the script using git
Install git on your server by running the following command:
dnf install git
Clone the rocky-tools repository using this command:
git clone https://github.com/rocky-linux/rocky-tools.git
Step 2: Running Migration Scripts
Change to the directory containing the script, make sure the file is executable, and give the owner of the file “x” permission:
chmod u+x migrate2rocky.sh
Run the script, using the -r flag to say that it can install everything straight away:
./migrate2rocky.sh -r
If everything is working properly, the output will look like this:

The script will now convert the machine from CentOS to Rocky. This will take some time, depending on your processing power and Internet connection speed.
When the process completes you should see output like this:

Reboot your system when prompted. Then log in again to create a new Rocky Linux server.
To verify that the migration was successful, run the command hostnamectl. If the output looks like this, you are good to go:

Trivy and Rocky Linux
Trivy is a scanner that can detect vulnerabilities and misconfigurations in container images, file systems, and Git repositories. Trivy can detect vulnerabilities in all popular Linux distributions, including Rocky Linux. In addition, it scans package managers like npm and Composer, Infrastructure as Code (IaC) templates such as Terraform and Kubernetes YAML files. Trivy also scans hardcoded secrets like passwords, API keys and tokens.
As you make the move from CentOS to Rocky Linux, Trivy can be an excellent companion tool that helps identify security misconfigurations in the underlying operating system and applications or containerized workloads running on it.
- DevSecOps: 8 Essential Elements for Your DevSecOps Program
- What Is a DevSecOps Pipeline, and How Can You Integrate It with a CI/CD Pipeline?
- Putting DevOps Security Into Practice: 10 DevSecOps Best Practices
- DevSecOps vs SecDevOps: Key Differences
- What Is Threat Modeling?
- What Is Mean Time to Repair (MTTR)?
- eBPF Linux: How It Works, Use Cases & Best Practices
- Cloud DevOps: 3 Ways DevOps and the Cloud Work Together
- Understanding DevOps Tools and Breaking Down the Top 10
- GitOps vs DevOps: Differences and Why They are Better Together
- What Is Code Security?
- What Is Secure Code Review? Process, Tools, and Best Practices
- DevOps Security: Challenges on the Road to DevSecOps
- Infrastructure as Code (IaC): The Complete Guide
- Infrastructure as Code and DevOps: DevOps Automation Reloaded
- What Is Executive Order 14028 (US Cybersecurity EO)?
- What Is Open Source Security?
- Shift-Left Security: What It Means, Why It Matters, and Best Practices
- What Is Shift Right?
- What Is SecOps (Security Operations)?
- SecDevOps in Your Organization: A Practical Guide
- Top 14 DevSecOps tools to secure your SDLC
- Linux Security in a Cloud Native World
- Azure DevOps: Enabling DevSecOps in Azure
- Show more
Aqua Cloud Native Application Protection Platform (CNAPP)
Go cloud native with the experts!