Migrating to Resolute Raccoon: For Platform Engineers¶
Who this is for: operators moving BOSH deployments onto the Ubuntu 26.04 "Resolute Raccoon" stemcell. If you maintain a BOSH release, read the Release Author guide instead.
Note
Coming from Jammy? Work through the Noble migration guide first; everything below assumes those changes are done. The systemd-managed agent, cgroup v2, BOSH DNS via systemd-resolved, and the EFI bootloader all arrived with Noble and are not repeated here.
This page covers what changes for a platform: manifest and runtime config edits, and runtime behaviour you'll see on Resolute VMs. It doesn't require you to change any release source.
Why and When¶
Ubuntu 22.04 (Jammy) leaves Canonical's standard support in May 2027. Resolute is the next LTS, and it brings post-quantum cryptography to OpenSSL and OpenSSH (ML-KEM, ML-DSA, and SLH-DSA), which Noble doesn't have.
Resolute stemcells are published as 0.x versions while the line is in alpha. The line moves to 1.x at GA. See Stemcell Lines & Support for the current status.
Jammy users can go straight to Resolute, but the Noble changes still apply: do the Noble migration guide first, then this page.
BOSH DNS¶
The configure_systemd_resolved runtime config from the Noble guide still applies on Resolute. Its include.stemcell list must contain ubuntu-resolute:
- include:
stemcell:
- os: ubuntu-noble
- os: ubuntu-resolute
jobs:
- name: bosh-dns
properties:
configure_systemd_resolved: true
disable_recursors: true
override_nameserver: false
# ... other properties as in the Noble guide
release: bosh-dns
name: bosh-dns-systemd
The current bosh-deployment runtime-configs/dns.yml already includes ubuntu-resolute. If you use the latest bosh-deployment, you can skip this step.
Warning
If ubuntu-resolute is missing from this list, bosh-dns is silently skipped on Resolute VMs. The deploy then fails later, when links don't resolve.
Check Your Releases First¶
Every release in a deployment has to support Resolute before you can move that deployment. Check each release's notes for Resolute support, and ask its maintainers if they don't mention it.
A release that doesn't support Resolute usually fails in one of two ways:
- Compilation fails. Resolute ships GCC 15 and CMake 4, which reject code that compiled on Noble.
-
A job doesn't start. The Resolute stemcell doesn't include
runit, so thechpstcommand is gone. The job's logs under/var/vcap/sys/log/<job>/show:chpst: command not foundor, from
/bin/shscripts:chpst: not found
The fixes for both belong in the release. Point its maintainers at the Release Author guide.
Addons (Runtime Configurations)¶
If you restrict your addons to certain stemcells, add ubuntu-resolute to every include.stemcell list for addons that should run on Resolute. Addons scoped to an OS that isn't listed are silently skipped.
Before:
addons:
- name: loggregator_agent
include:
stemcell:
- os: ubuntu-jammy
- os: ubuntu-noble
After:
addons:
- name: loggregator_agent
include:
stemcell:
- os: ubuntu-jammy
- os: ubuntu-noble
- os: ubuntu-resolute
Check exclude.stemcell lists too.
BPM¶
BPM is installed in the Resolute stemcell. Jobs can use it without the bpm-release job colocated in the instance group.
Colocating the bpm job still works, but we discourage it on Resolute. When the bpm job is colocated, its version of bpm is used instead of the stemcell's on that instance.
If your platform deploys both older stemcells and Resolute, and you add bpm as an addon, scope that addon to the older stemcells:
addons:
- name: bpm
include:
stemcell:
- os: ubuntu-jammy
- os: ubuntu-noble
jobs:
- name: bpm
release: bpm
IaaS Notes¶
- No instance-type changes. Ubuntu 26.04 cloud images target the
x86-64-v3microarchitecture level, which drops older instance families. The BOSH stemcell is still built for baselinex86-64, so every instance type that runs Noble stemcells also runs Resolute. EFI boot behaves as described in the Noble guide. - Light stemcells. Light stemcells are published for AWS and Google Cloud, as for earlier lines. Use full stemcells on other IaaSes.
Runtime Behaviour Changes¶
SSH¶
Resolute ships OpenSSH 10.2.
- DSA keys don't work. The stemcell generates no DSA host key, and DSA client keys are rejected. Replace any DSA keys with Ed25519, ECDSA, or RSA keys.
- The post-quantum key exchange
mlkem768x25519-sha256is on by default. Thesshclient on a Resolute VM prints a warning when it connects to a server that can't negotiate a post-quantum key exchange. Jobs or scripts that SSH from Resolute VMs to older servers see this warning. sshdno longer reads~/.pam_environment. Set environment variables forbosh sshsessions some other way.
sudo-rs¶
sudo is now sudo-rs, a Rust implementation. Most uses are unchanged. What differs:
sudo-rsdoesn't support some sudoers settings that classic sudo accepted, includingtty_ticketsandlogfile. When a sudoers file uses one, everysudocall prints anunknown settingerror and ignores that line, andvisudo -creports the file as invalid. Remove these settings from any sudoers files that your addons oros-confconfiguration write.sudo -Eis ignored, with the warningsudo: preserving the entire environment is not supported, '-E' is ignored.--preserve-env=VARworks.- sudo activity is logged to syslog (
/var/log/auth.log), not to a dedicated/var/log/sudo.log.
Kernel Modules¶
Ubuntu 26.04 no longer splits kernel modules into a separate "extra" package, so the stock kernel carries nearly 7,000 modules. The Resolute stemcell removes most of them: the ones for hardware that doesn't exist on cloud VMs, and obsolete protocols and filesystems that are a frequent source of CVEs. About 750 remain, covering hypervisor guest drivers, storage, networking, netfilter, container networking, cryptography, and network filesystems.
If a job needs a module that was removed, modprobe fails with:
modprobe: FATAL: Module <name> not found in directory /lib/modules/<kernel-version>
The list of kept and removed modules, with the reason for each, is in linux-generic.csv in the stemcell builder. To get a module back, open an issue or a pull request against bosh-linux-stemcell-builder that changes its row to remove=No, and say what needs it.
This doesn't apply to warden stemcells, which use the host's kernel.
/tmp Is Still Disk-Backed¶
Ubuntu 26.04 makes /tmp a tmpfs by default. The Resolute stemcell masks that unit, and the BOSH agent bind-mounts /tmp from the ephemeral disk as it does on Noble, so nothing changes for BOSH VMs. We call it out because Ubuntu's own release notes say otherwise.
cgroup v2 Only¶
The Resolute kernel has no cgroup v1 support. Noble already used the cgroup v2 unified hierarchy, but on Resolute there's no fallback: anything that expects cgroup v1 paths fails. See systemd and cgroup v2 in the Noble guide.
syslog TLS¶
The stemcell includes rsyslog-gnutls but no longer includes rsyslog-openssl. If you set the syslog-release property syslog.tls_library: ossl, forwarding over TLS fails on Resolute. Use the default, gtls.
Time Sync¶
systemd-timesyncd is no longer installed. chrony, which BOSH stemcells already used for time sync, is the only time daemon.
Audit and Compliance Scanning¶
sudo-rscan't write a log file. sudo events go to/var/log/auth.loginstead.- Audit rules no longer watch the
stimesyscall, which Linux 7.0 removed. auvirtandautraceare no longer shipped withauditd.- On warden stemcells,
audit-rules.serviceis skipped: the kernel rejects audit rule changes from inside a container. Don't expect audit records from warden containers.
bosh-lite on Apple Silicon¶
Resolute warden stemcells don't run under Rosetta 2 emulation on Apple Silicon (bosh-linux-stemcell-builder#577). A -rosetta warden stemcell variant for Apple Silicon bosh-lite is available. It is for local development only, not production.
Getting Help¶
Ask in #bosh on the Cloud Foundry Slack. Report stemcell problems as bosh-linux-stemcell-builder issues.