openSUSE Leap 16.1 now includes an immutable mode, a new security feature that adds a read-only root filesystem to the distribution. This mode is described as a transactionally updated system, similar to Leap Micro, a lightweight, immutable operating system designed for containerized workloads, edge computing, and virtualized environments. Leap 16.1 is the first version of Leap to offer this feature, according to the official openSUSE blog.
In the immutable mode, users can choose between a standard or immutable version of openSUSE Leap during installation. In this mode, directories such as /usr and /etc are mounted read-only, preventing modifications that could be exploited by malicious scripts. This feature is aimed at improving security, particularly for container hosts, virtual machines, edge devices, and users who prefer atomic updates with easy restoration.
openSUSE has long been recognized for its security features, including the use of SELinux starting from version 16.0, which replaces the earlier AppArmor implementation. SELinux assigns labels to files, processes, and ports, applying the principle of least privilege to restrict unauthorized actions. Additionally, openSUSE uses firewalld for dynamic firewall management, similar to Fedora-based distributions, providing robust firewall capabilities.
Other security measures include binary hardening, which involves compiling software with security flags to make executables more resistant to exploits. These measures include position-independent executables, FORTIFY_SOURCE, stack protectors, read-only relocations, and non-executable stacks and heaps. Authorization profiles are also used to centralize permission control, ensuring security during package installations and updates.
openSUSE also utilizes Snapper and Btrfs snapshots to create "point-in-time" backups of the filesystem, allowing users to restore their system to a previous functional state if compromised. The distribution benefits from standard sources, including the RPM source repository and the main free software (OSS) repository, and is compiled directly from the source code of SUSE Enterprise Linux, ensuring enterprise-level stability and security.
The introduction of the immutable mode is expected to further elevate openSUSE Leap's status as one of the most secure Linux distributions. Users can download an ISO image of Leap 16.1, including the immutable mode, from the official openSUSE download server.
openSUSE Leap 16.1 Introduces Immutable Mode for Enhanced Security
AI-rewritten from original reportingHow it works
opensuseimmutable-modesecuritylinuxcontaineredge-computing



