惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
GbyAI
GbyAI
阮一峰的网络日志
阮一峰的网络日志
Cloudbric
Cloudbric
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
宝玉的分享
宝玉的分享
I
Intezer
Simon Willison's Weblog
Simon Willison's Weblog
博客园_首页
The Cloudflare Blog
C
Cisco Blogs
AWS News Blog
AWS News Blog
IT之家
IT之家
Cyberwarzone
Cyberwarzone
罗磊的独立博客
美团技术团队
V
V2EX
Project Zero
Project Zero
A
Arctic Wolf
C
Cyber Attacks, Cyber Crime and Cyber Security
大猫的无限游戏
大猫的无限游戏
博客园 - 叶小钗
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 聂微东
有赞技术团队
有赞技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
雷峰网
雷峰网
S
Schneier on Security
P
Privacy International News Feed
V
Visual Studio Blog
量子位
T
Tor Project blog
S
Securelist
腾讯CDC
A
About on SuperTechFans
T
Threat Research - Cisco Blogs
G
GRAHAM CLULEY
B
Blog RSS Feed
D
DataBreaches.Net
博客园 - 三生石上(FineUI控件)
B
Blog
NISL@THU
NISL@THU
L
Lohrmann on Cybersecurity
V
Vulnerabilities – Threatpost
人人都是产品经理
人人都是产品经理
博客园 - 【当耐特】
L
LINUX DO - 热门话题
Recorded Future
Recorded Future

Blog

Confidential computing and the new regulatory focus on data in use | Canonical A day in the life of an Android developer with Anbox Cloud | Canonical Canonical announces the Enterprise Store as part of Ubuntu Pro | Canonical Tracing a memory leak bug in PID 1 and contributing an upstream fix: a Linux support story | Canonical MAAS installation: bare metal provisioning is easier than ever | Canonical Januscape vulnerability CVE-2026-53359 mitigations available | Canonical Ubuntu Server: a platform made for enterprise scale | Canonical Building an open source chain of trust: new research uncovers key blockers and ways forward | Canonical Beyond safety and security: Why automotive open source demands dependability  | Canonical DirtyClone Linux kernel local privilege escalation vulnerability fixes available | Canonical pedit COW kernel local privilege escalation vulnerability mitigations | Canonical Canonical becomes Gold Sponsor of Trifecta Tech Foundation | Canonical Challenges designers face in open source (and how to fix them) | Canonical Hunting a 16-year-old SQLite bug with TLA+: is dqlite affected? | Canonical Anbox Cloud on C4A metal: Android, at scale, without friction | Canonical Canonical announces live kernel patching for Arm64 | Canonical How to use RISC-V custom instructions with Ubuntu | Canonical Ubuntu Summit 26.04: connected by open source | Canonical So you need to add microcontrollers to your fleet: now what? | Canonical Validating real-world skills through Canonical Academy | Canonical Virtualized Android comes to Anbox Cloud | Canonical Template: Streamlining open source design contributions | Canonical Beyond Mythos: responding to a new threat landscape | Canonical A look into Ubuntu Core 26: Building a local AI inference appliance in a virtual machine | Canonical This year we celebrate a decade of Ubuntu Server support on the s390x architecture: marking a long-standing collaboration between Canonical and IBM that began at LinuxCon 2015. The first release happened on April 21, 2016, bringing Ubuntu 16.04 LTS (Xenial Xerus) to IBM Z and IBM LinuxONE platforms.  A first for Ubuntu on IBM That […] AI at the edge: simplifying infrastructure with Cisco and Canonical | Canonical The next era of telco clouds: get open infrastructure choice with Sylva and Canonical Kubernetes | Canonical What is RDMA over Converged Ethernet (RoCE)? | Canonical Beyond tokens per watt – using Ubuntu 26.04 LTS for AI Beyond tokens per watt – using Ubuntu 26.04 LTS for AI | Canonical A look into Ubuntu Core 26: Deploying AI models on Renesas RZ/V series for production | Canonical RISC-V profiles – why is RVA23 significant? | Canonical AI with AMD ROCm on Ubuntu: your questions answered | Canonical When distributed workloads stall because nodes cannot exchange small messages quickly and consistently, the network is the limiting factor. How do you solve that problem? InfiniBand offers one solution. InfiniBand is an interconnect, meaning the end-to-end communication system that links compute, storage, and accelerator nodes. It is impl […] Microsoft has announced the preview of Azure Cobalt 200, its second-generation custom Arm silicon. Learn how Ubuntu and Ubuntu Pro support these new VMs from day one, offering seamless deployment, long-term security maintenance, and Kernel Livepatch without requiring engineering or platform changes […] How Canonical Support solves hard Linux performance bugs  – even in 12-year old code | Canonical Securing AI agent workflows on Ubuntu with the new NVIDIA OpenShell snap | Canonical Canonical announces optimized Ubuntu images for TPU virtual machines by Google Cloud | Canonical VMware hypervisor deployment using MAAS | Canonical Migrating from Apache Spark 3 to Spark 4 | Canonical Introducing Workshop: launch sandboxed development environments on Ubuntu with a single command | Canonical Run agentic workloads on Arm and Ubuntu | Canonical Decoding design: How design and engineering thrive together in open source | Canonical Developing web apps with local LLM inference | Canonical A local privilege escalation (LPE) security vulnerability in the Linux kernel, codename “PinTheft,” was publicly disclosed on May 19, 2026. The vulnerability was fixed in the mainline Linux kernel tree. A proof-of-concept exploit was published along with public disclosure. This has been assigned the CVE ID CVE-2026-43494; other discoverin […] Canonical has announced the general availability of Managed Kubeflow on the Microsoft Azure Marketplace. This fully managed MLOps platform allows enterprise AI teams to deploy a production-ready environment in under an hour, eliminating infrastructure maintenance. […] A look into Ubuntu Core 26: Cloud-powered edge computing with AWS IoT Greengrass and Azure IoT Edge | Canonical CVE-2026-46333 (ssh-keysign-pwn) Linux kernel vulnerability mitigations | Canonical Finding the blind spot: How Canonical hunts logic flaws with AI | Canonical A local privilege escalation (LPE) vulnerability affecting the Linux kernel has been publicly disclosed on May 13, 2026. The vulnerability does not have a CVE ID published, but is referred to as “Fragnesia.” The vulnerability affects multiple Linux distributions, including all Ubuntu releases. The affected components are the Linux kernel […] Rethinking BYOD security: protecting data without trusting devices | Canonical Two local privilege escalation (LPE) vulnerabilities affecting the Linux kernel have been publicly disclosed on May 7, 2026. The vulnerabilities have been assigned the IDs CVE-2026-43284 and CVE-2026-43500 and are referred to as “Dirty Frag.” The affected components are Linux kernel modules. The first vulnerability impacts the modules tha […] Three weeks to go: A sneak peek of the Ubuntu Summit 26.04 experience | Canonical How to use Ubuntu on Windows | Canonical A local privilege escalation (LPE) vulnerability affecting the Linux kernel has been publicly disclosed on April 29, 2026. The vulnerability has been assigned CVE ID CVE-2026-31431 and is referred to as Copy Fail. The affected component is a kernel module that provides hardware-accelerated cryptographic functions: algif_aead. The vulnerab […] Run NVIDIA Nemotron 3 Nano Omni locally in a single command | Canonical Why Web Engineering is great | Canonical Ubuntu 16.04 LTS (Xenial Xerus) reached the end of its five-year Expanded Security Maintenance (ESM) window in April 2026. If you are still running 16.04, it is critical to address your support status to ensure continued security and compliance. Your support options Now that 16.04 is in its Legacy phase, you have two primary paths: […] Understanding disaggregated GenAI model serving with llm-d | Canonical From Jammy to Resolute: how Ubuntu’s toolchains have evolved | Canonical Hybrid search and reranking: a deeper look at RAG | Canonical Canonical expands Ubuntu support to next-generation MediaTek Genio 520 and 720 platforms | Canonical In this article, Keirthana TS, a Senior Technical Author at Canonical, breaks down what leadership means to her and how she understood the power of intentional leadership through her journey at Canonical. […] Ubuntu Pro comes to Nutanix bare-metal Kubernetes | Canonical RISC-V 101 – what is it and what does it mean for Canonical? | Canonical Ubuntu Summit 26.04 is coming: Save the date and share your story! | Canonical How to manage Ubuntu fleets using on-premises Active Directory and ADSys | Canonical Simplify bare metal operations for sovereign clouds | Canonical How to Harden Ubuntu SSH: From static keys to cloud identity | Canonical The “scanner report has to be green” trap | Canonical Modern Linux identity management: from local auth to the cloud with Ubuntu | Canonical Canonical welcomes NVIDIA’s donation of the GPU DRA driver to CNCF | Canonical Hot code burns: the supply chain case for letting your containers cool before you ship | Canonical
Managing Ubuntu on bare metal at scale | Canonical
David Beamonte · 2026-07-09 · via Blog

Modern infrastructure teams are expected to deliver cloud-like speed, consistency, and reliability, even when their workloads run on physical servers.

Bare metal remains essential for many environments: private clouds, Kubernetes clusters, AI infrastructure, edge sites, regulated platforms, and large Ubuntu estates. But operating physical infrastructure at scale is difficult when provisioning, patching, monitoring, and lifecycle management are handled by disconnected tools and manual processes.

This blog will explore how Canonical MAAS and Canonical Landscape can work together to close that operational gap. MAAS provides cloud-like automation for bare metal provisioning and Day 0 operations. Landscape provides centralized management, monitoring and maintenance for Ubuntu systems throughout their operational life. Together, they help organizations build, operate, and repurpose physical infrastructure with greater consistency and control.

The lifecycle gap in bare metal operations

Provisioning a machine is only the beginning. Many organizations have improved the way they deploy infrastructure, but still struggle to manage what happens after the operating system is installed. A server may be provisioned quickly, but then it must be patched, monitored, inventoried, configured, secured, and kept compliant over time.

When these stages are handled separately, several problems appear, including fragmented infrastructure inventory, reliance on manual workflows for patching and maintenance, inconsistent operational visibility across environments, difficulty coordinating security updates, longer times required to rebuild or repurpose machines, and the loss of a cloud-like experience once the operating system is deployed.

MAAS: cloud-like provisioning for bare metal

Canonical MAAS provides the Day 0 foundation for physical infrastructure. It enables teams to discover, commission, deploy, and repurpose bare metal machines through repeatable workflows and APIs. Instead of treating servers as individually managed assets, MAAS turns them into programmable resources that can be allocated and reused as needed.

With MAAS, infrastructure teams can:

  • Discover and inventory physical machines
  • Control the servers through out-of-band management interface
  • Validate hardware before it enters production
  • Deploy operating systems consistently
  • Reuse or repurpose machines when requirements change
  • Integrate bare metal provisioning into infrastructure-as-code workflows

The result is a cloud-like operational model for physical servers. Bare metal becomes easier to automate, easier to rebuild, and easier to integrate into modern platforms such as Kubernetes, private clouds or AI infrastructure. This means your teams spend less time managing infrastructure, and more time delivering value.

However, once Ubuntu is installed and the machine is running, a new set of operational questions begins. Landscape is the answer.

Landscape: centralized operations for Ubuntu estates

Canonical Landscape provides the Day 2 operations layer for Ubuntu systems.

Once machines are deployed, organizations need a reliable way to manage them over time. Landscape gives teams a centralized view of their Ubuntu estate, whether those systems are running on physical servers, virtual machines or containers.

Landscape helps teams manage common operational tasks such as:

  • Software updates and security patching
  • Machine inventory
  • System monitoring
  • Configuration management
  • Remote scripting
  • Operational reporting
  • Integration with third-party tools through an API

This is especially important for organizations managing large Ubuntu estates. Without a central management layer, routine tasks such as patching, auditing, and configuration drift control can become slow, inconsistent, and expensive.

Landscape helps reduce that operational burden by giving teams a single place to see, manage, and maintain their Ubuntu systems.

The operational benefits of using MAAS and Landscape in combination

The real value appears when MAAS and Landscape are used together: MAAS builds the machine, while Landscape manages it once it is live.

A typical lifecycle could look like this:

  1. A new server is discovered by MAAS
  2. MAAS commissions the machine and records its hardware inventory via commissioning
  3. MAAS tests the machine so that it only goes to production if it is in a healthy state
  4. MAAS deploys Ubuntu with the required configuration
  5. The deployed machine is enrolled into Landscape
  6. Landscape keeps the system visible, patched, and manageable
  7. Operational teams use Landscape for monitoring, scripting, and maintenance
  8. When the machine is no longer needed, MAAS releases or repurposes it
  9. The next deployment starts from a clean, repeatable baseline

This closes the gap between Day 0 and Day 2.

Instead of having one process to provision hardware and another disconnected process to operate Ubuntu, teams get a more complete lifecycle model. Physical servers can be built, managed, updated, and reused with greater consistency. This is particularly helpful in environments where physical infrastructure must be provisioned quickly, and Ubuntu systems must be managed consistently over time. For example:

  • Private cloud and virtualization platforms: MAAS provisions the physical servers that form the platform foundation, while Landscape helps manage and maintain the Ubuntu systems that support it. Get more detail on our webpage.
  • Kubernetes on bare metal: MAAS automates the deployment and reuse of Kubernetes nodes, while Landscape provides visibility, patching, and operational control across the Ubuntu estate underneath the cluster. Learn more about Canonical Kubernetes.
  • Edge and distributed infrastructure: MAAS standardizes provisioning across remote sites, while Landscape gives central teams a single place to monitor and manage Ubuntu systems after deployment. Learn more about our solutions for edge and distributed infrastructure.
  • Labs, QA and temporary environments: MAAS makes it easier to build, rebuild, and repurpose physical machines, while Landscape keeps those systems visible and manageable while they are in use.
  • Security-sensitive and regulated environments: MAAS provides repeatable provisioning and hardware inventory, while Landscape supports consistent patching, system visibility and operational control over time. Learn more about how our solutions offer the foundation for regulated environments on our sovereign cloud webpage.

Conclusion: a complete lifecycle for bare metal and Ubuntu

Bare metal infrastructure does not have to be slow, static or difficult to manage.

With MAAS, organizations can bring cloud-like automation to physical provisioning. With Landscape, they can help to keep Ubuntu systems visible, trusted, and manageable throughout their lifetime. Together, MAAS and Landscape help bridge the gap between Day 0 and Day 2 operations. They allow teams to build infrastructure quickly, operate it consistently, and repurpose it when requirements change.

For organizations running large Ubuntu estates, private clouds, Kubernetes clusters, edge sites or regulated infrastructure, this combination provides a practical path toward more automated and reliable operations.

Learn more in our documentation

Related posts


The bare metal problem in AI Factories

MAAS Ubuntu tech blog

As AI platforms grow into large-scale “AI Factories,” the real bottleneck shifts from model design to operational complexity. With expensive GPU accelerators, hardware failures and inconsistent configurations lead directly to lost throughput and reduced return on investment. While Kubernetes orchestrates workloads, it cannot fix broken ph ...


Cut data center energy costs with bare metal automation

Cloud and server Ubuntu tech blog

Data centers don’t have to be power-hungry monsters. With smart automation using tools like MAAS, you can reduce energy waste and operational costs, and make your infrastructure greener, without sacrificing performance or flexibility. ...