Skip to content
InfoQ·

💻Amazon Linux 2027 Preview: SELinux Enforcing Mode

Your apps might break with new Linux preview

TL;DR

Amazon Linux 2027 enters public preview with SELinux in enforcing mode by default. Teams must validate their apps against this new security setting before migration.

Amazon Linux 2027 is now in public preview, shipping with SELinux in enforcing mode by default. This change could break applications that run on AL2023 if their file contexts, ports, and access patterns don't match the new policy. The preview's main purpose is to help teams identify and fix these issues before the official release. AL2027 runs on kernel 7.1 or later, with updates until LTS. No in-place migration path exists, so teams must replace root volumes or hosts. The preview is available in all commercial regions and on Amazon ECR Public Gallery.

Amazon Linux 2027 Preview: SELinux Enforcing Mode — InfoQ

Key Points

1

Amazon Linux 2027 ships with SELinux in enforcing mode by default, a change from AL2023's permissive mode.

2

AL2027 runs on kernel 7.1 or later, with updates until LTS, starting from 7.1.

3

No in-place migration path from AL2023 to AL2027; teams must replace root volumes or hosts.

4

AL2027 preview available in all commercial regions and on Amazon ECR Public Gallery.

5

Amazon Linux team plans to release on-premises images soon, currently only available in x86-64 and ARM variants.

Why It Matters

If you're running Amazon Linux 2023, your apps may break with the new enforcing SELinux mode in AL2027. Validate your file contexts, ports, and access patterns now to avoid issues. The preview's most useful purpose is identifying and fixing these mismatches before the official release.

Amazon LinuxSELinuxAL2027previewcloud

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,482 builders reading daily.

Also get