I utilize Ansible to harden Red Hat devices across a multitude of disconnected environments.
CIS Hardened Image Level 2 on Red Hat Enterprise Linux 8
Center for Internet SecurityExternal reviews
External reviews are not included in the AWS star rating for the product.
Helps with centralized development, infrastructure management, and compliance
What is our primary use case?
How has it helped my organization?
One benefit of using Red Hat Enterprise Linux is that a lot of backend applications run natively on Red Hat Enterprise Linux as opposed to a Windows-based option. We are a partner with Red Hat. It essentially allows us to do a lot of our infrastructure stand-up and development.
It has enabled our team to centralize development. We have been able to centralize our automation, playbooks, and different collections we use within Ansible to create a centralized code base. We can use that to configure different types of systems with different requirements from different customers. Having a common platform across the entire enterprise has been very helpful.
We are using Red Hat Enterprise Linux very limitedly for containerization projects. It makes things very seamless. If we get a new developer, we can set up a brand new instance of a container for a dev environment or a test environment. It allows different developers to always have the same starting points with containers.
In terms of security features for risk reduction, there are SELinux and FIPS. Also, when you build a Red Hat Enterprise Linux machine, you can stick it right out of the box. It is very helpful. It is very good, especially for programmers and users who do not know anything about cybersecurity. It takes you 85% to 90% of the way. It has been very helpful and good.
The right commonality across the business or enterprise is always very hard to do, especially when different networks and different customers have different requirements. Being able to at least have continuity between those different environments has been helpful. If you have a system admin at a location and you put him or her at a different location, they at least can expect the same type of infrastructure.
When it comes to compliance, it takes you 85% to 90% of the way there. Different networks require different things. Some cannot implement specific standards for whatever reasons, but being able to utilize and leverage Red Hat Ansible to configure that and make sure those changes are made across the entire network has been very helpful.
Portability depends on the circumstances. Some things are more portable than others, such as containers. We utilize Ansible Core very extensively, but other things, such as AAP, are not necessarily as portable because some of our smaller environments do not have the bandwidth or the actual resources to support a big product like that.
What is most valuable?
In Red Hat Enterprise Linux, I am a big fan of the command line. I like the data manipulation and different commands that we can use. I use Ansible extensively to configure systems.
For how long have I used the solution?
I have been using Red Hat Enterprise Linux for four years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
It is easily scalable with the solutions and the options they have.
How are customer service and support?
Their support is very good. They are very helpful. Some of them are more experienced in handling the niche problems that we have.
I would rate their customer support a nine out of ten because there is always room for improvement, but it has always been very good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have used Ubuntu and other Linux operating systems in the past. However, since I have been with the company, we have used Red Hat Enterprise Linux almost exclusively.
How was the initial setup?
The deployment model depends on the environment. Some are using VMs. Some use containers, and some use bare-metal installations. It depends on what a particular program needs. I support small environments that are on-prem.
It is fairly straightforward to deploy different Red Hat boxes. I was just helping out a sysadmin the other day who had not done it before. It was super straightforward and super easy to deploy.
What about the implementation team?
We deploy it on our own.
What was our ROI?
The return on investment for us and our team is specifically automation. We are able to invest time on the frontend to create different automation playbooks, and we are able to push that out to not only a singular network but also to multiple networks and multiple different configurations. It takes a little bit in the beginning, but there are huge time savings in the end.
What other advice do I have?
If a security colleague is looking at open-source, cloud-based operating systems for Linux instead of Red Hat Enterprise Linux, I would be interested to understand what that colleague's objectives are and why they would consider something other than Red Hat Enterprise Linux. If it is something that fits their particular use case more, they can obviously go with that. Red Hat Enterprise Linux is a standard solution for Linux. If any colleague wants to go for another solution, I have to understand why. I would have to understand what Red Hat Enterprise Linux is not able to provide. However, this has not happened to me.
I would rate Red Hat Enterprise Linux a full ten out of ten.
Helpful for standardization, patch management, and vulnerability management
What is our primary use case?
We are deploying Red Hat Enterprise Linux as our primary Linux OS, and we are using Ansible for some automation initiatives. Our use cases are around centralization.
How has it helped my organization?
We have a supported product. We are at the beginning of building a relationship with Red Hat similar to the one we have with Microsoft, Cisco, and others. It is to standardize the quality, supported version, and company. I am leading this project, and I believe Red Hat is the one.
We have built a hybrid environment. Most of it is on-prem, but we also have Azure, so we have both cloud and on-prem environments. Red Hat Enterprise Linux is helpful for patch and vulnerability management. There have been a lot of security initiatives around Windows and tightening it up, but our Linux environment was not standardized. Red Hat Enterprise Linux standardizes it. With the combination of Insights, it aligns with Windows and other security initiatives.
Red Hat Enterprise Linux has not yet enabled us to centralize development. It is too early for that. I am not very familiar with OpenShift, but with OpenShift, Kubernetes containers, and some of those capabilities, DevOps will become more integrated with Red Hat and its products in the future.
Red Hat Enterprise Linux’s built-in security features seem very good when it comes to risk reduction, business continuity, and maintaining compliance. One thing that helps is the catalog of preexisting playbooks provided by Red Hat around security. It helps you ramp up on security. It aligns it with what an IT person on the Windows side already knows to look for, such as firewalls, setting up permissions, etc. They have playbooks for Active Directory integration, security initiatives, and limiting the firewall. Building out some of the playbooks that Red Hat has in those areas was helpful in getting a good security posture for those systems.
Ansible is going to make the portability of applications and containers happen for us. The OS is important, but our ability to use Ansible and deploy via a cloud or automate via a cloud or on-prem would accomplish that.
What is most valuable?
Red Hat Insights is valuable. There is patch and vulnerability management. It is similar to what you would see with SCCM. I have a single pane of glass interface. I can approve the patches and vulnerabilities, and hopefully, between Satellite and Ansible, we can automate that process.
What needs improvement?
I am looking for training. I am a Windows guy who accidentally became a Linux guy. You volunteer a few times, and you are the guy. Right now, I am looking for training and ramping up to be able to support their products, so professional services are key. There are things like Lightspeed with IBM Watson. I do not know YAML very well, so it is going to be integral for me to create playbooks at the very beginning and be able to use the AI tools. If I say, "How do I open a port on this Cisco router?", the AI tools are going to give me the YAML code. In spite of not being a Linux guy or a great coder, I can use those tools to ramp up very quickly. Making Lightspeed a part of Red Hat deployment initiatives tremendously helps with customers' success. It gives them that extra tool. Right now, it is being sold separately as a subscription. If they could integrate that capability, people would not have to go use ChatGPT and other tools. They could use that as a part of it. It would just align things with Red Hat, so one area they can improve on is the approach to customer success for new deployments.
Red Hat Insights are instrumental in identifying vulnerabilities. I am still learning, but my understanding is that it is not directly connected to your environment to deploy a patch or vulnerability fix. It is going to give a YAML playbook to do that. It does not actually execute it. On the Windows side, I have an approval process on the server where I can say, "Deploy this patch." I thought of Insights along the same lines where I can just approve things, and then based on some backend configuration, it will implement them using Ansible, Satellite, and on-premises Ansible. It seems disconnected right now. It might not be, but to me, there seems to be a gap there. I love Insights, and I want to fully automate that approval process. This could be a point for improvement if it does not already do that.
Another area of improvement is Red Hat expressing a return on investment better. I do not know if they have determined a lot of that. I have always assumed that I could go with an open-source OS in a less expensive manner than Windows or something else. My impression is that there would be less cost, but I do not know that for certain. Red Hat building out some of that ROI on different products would be beneficial to their sales effort.
For how long have I used the solution?
We are a brand new customer.
What do I think about the stability of the solution?
It is more stable than the wild west environment that I have been in. There is standardization. It is stable by standardizing.
What do I think about the scalability of the solution?
So far, its scalability has been good. Once I get a good image built, I will get some workflows built into Ansible. I will have that process all the way down to the help desk. We will be entering variables and kicking out systems all day.
We have been using it minimally. We have about 15% Linux environment with lots of flavors. Red Hat Enterprise Linux is what we are centralizing on from now on, so we are going to do a conversion of all those. We have a new standard going forward. We have about 15% Linux systems, which would amount to about 150 systems throughout North America. It is a small footprint.
How are customer service and support?
I have not had to call them much, so I do not have a good handle on support from Red Hat. Everybody gets at least a C or a five, but I am optimistic. It is going to be good. I would give them at least a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Prior to Red Hat Enterprise Linux, it was CentOS and others. CentOS was free. It was whatever was available or the developers or applications guys were familiar with.
We switched to Red Hat Enterprise Linux for centralization, to be supported, and for patching and vulnerabilities.
How was the initial setup?
Most of the things that I am deploying or replacing are on-prem and on Azure cloud. It is 50/50.
The deployment was very easy. They have a great and user-friendly installation process with 9.x and above. However, just being new to it and having a security hat on, I still struggle with what should and should not be installed on the base image. It is a learning curve for me, but using the interface has been great. I was able to join Active Directory and all those things.
What about the implementation team?
CDW is handling our professional services and our training, which is a separate purchase. Its initial rollout is with CDW.
What was our ROI?
We have not yet seen an ROI.
What's my experience with pricing, setup cost, and licensing?
It is expensive. Everything is. I was happy to get a three-year Red Hat Enterprise Linux contract for our initial rollout.
It is less expensive than other solutions. It is a growing company.
Which other solutions did I evaluate?
It is called Microsoft ARC. It now facilitates patches for Linux, but it did not include certain things. For me, there was much more benefit outside of just patching by going with Red Hat Enterprise Linux and Ansible.
What other advice do I have?
I am not yet certain about Red Hat Insights' vulnerability alerts and targeted guidance. We are at the beginning. We are just adding systems. I have not set those alerts up if they exist. I assume there are some. I am also going to evaluate how accurate the vulnerability and patching information is because we have other security products that are looking at the same things on the Windows side, and they have already identified many of the vulnerabilities. As a new customer, I want to make sure that if our other system says something is a vulnerability, Red Hat Insights also says that it is a vulnerability. I want to feel confident in the vulnerabilities that I am getting from Red Hat Insights. I want to make sure that other products are also scanning for the same thing. I suspect it is.
To a colleague who is looking at open-source, cloud-based operating systems for Linux instead of Red Hat Enterprise Linux, I would recommend going for Red Hat Enterprise Linux. I cannot think of another OS that can match this.
I will start off with an optimistic ten, and I will rate Red Hat Enterprise Linux a ten out of ten.
Provides a reliable base to deploy applications and has a lot of features
What is our primary use case?
We primarily use it for enterprise software, databases, and some custom applications.
How has it helped my organization?
We have a stable base to deploy applications. We need a minimal amount of effort to troubleshoot problems with the applications that are related to the OS.
We are using Red Hat Enterprise Linux in the cloud, in the on-prem data center, and at the edge. We are also using Red Hat Enterprise Linux in a hybrid cloud environment. It has had a positive impact. It is straightforward to deploy. There was no bottleneck.
Red Hat Enterprise Linux has enabled us to centralize development. The stable base that each developer can rely on is great. The consistent ecosystem of the repository makes it easy to rely on.
We use Red Hat Enterprise Linux for containerization projects. Red Hat Enterprise Linux is quick to containerize, so when it started becoming mainstream, it was easier for us to sell to upper management to start doing more containerization.
There has been a positive impact in terms of the portability of applications and containers built on Red Hat Enterprise Linux for keeping our organization agile. It is very portable. I do not have any issues with different ecosystems in relation to how Red Hat Enterprise Linux runs containers.
Our cost of ownership is not high. They are not very expensive. We are never surprised.
What is most valuable?
The repository ecosystem is valuable.
What needs improvement?
I would probably focus more on a rolling release schedule. Instead of a long-term operating support of ten years, I would just have one release and keep rolling it.
In terms of security features, overall, it is lacking cohesion. There are a lot of different options, and it is hard to choose the ones that best fit our business needs without a lot of investigative work.
For how long have I used the solution?
I have been using Red Hat Enterprise Linux for 11 years.
What do I think about the stability of the solution?
It is very stable.
What do I think about the scalability of the solution?
It is scalable.
How are customer service and support?
It takes a little bit to get to the true answer. I know there is a lot of triaging. I am sure we can improve on our end. When we open tickets, we can provide more information. There could be a way to get faster answers from Red Hat support, and we might not be providing the most upfront information needed for the ticket. I would rate their support a ten out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We were not using any other solution previously.
I know of only one other player, and that is Ubuntu. There is also OpenSUSE, but I have not yet seen that personally in my career.
How was the initial setup?
We have cloud and on-prem deployments. We have the AWS cloud.
On AWS, we had an EC2 instance. I clicked, and it was online. For the initial deployment, we just used the Amazon Web UI, and now, we use Ansible for deployment.
What was our ROI?
We have seen an ROI. It is fairly easy to deploy. We do not have too many issues with setting up a new environment in relation to the operating system. The bottlenecks are more related to the hardware or even setting up the cloud.
Which other solutions did I evaluate?
When I came in, Red Hat Enterprise Linux was already being used. It has always been there.
What other advice do I have?
We have not yet fully leveraged Red Hat Insights. We are working on that. It might help with cohesion and security.
I would rate Red Hat Enterprise Linux a ten out of ten. It is reliable for deploying applications. It has a lot of different features. I can find solutions to all my problems, and the industry support is there.
CIS benchmark is more secure than default
Easy to use with good command line capabilities and offers easy access for admins
What is our primary use case?
We have almost thirteen servers. There are SaaS applications installed on this server. We leverage Java and the functionality during installation. We install it on the platform and configure it there. Some are custom applications. Our database is also in the Red Hat Linux environment.
How has it helped my organization?
The solution offers users easy access. It's very simple to have and use, from an admin perspective.
What is most valuable?
The offering provides me with all I need to serve the operation in terms of usage and capabilities.
The general user commands are good. They are helpful for starting and stopping applications and restarting and editing files. The maintenance of user-level processes is easy.
We're not using it in a graphical environment, we're only using command line mode. There may be a lot of features, however, I don't use everything since I don't need to.
There are millions of commands you can use, although we use only five or ten.
Likely the solution has helped our organization save on costs. I'm not sure by how much, as I don't have visibility into that aspect.
It's very easy to use across physical, virtual, and cloud infrastructure. Specifically, on the cloud side, I have noted it's quite easy. Also, on a virtual machine, you can create a cloud version of your infrastructure in a minute.
What needs improvement?
For my work, the solution is not missing any features. We;re only using the command line and that is enough for us.
Maybe they need to make it easier to apply patches from different resources. That said, at my level of usage, I never have to apply patches.
For how long have I used the solution?
I've used the solution for almost ten years.
What do I think about the stability of the solution?
It's a stable product.
What do I think about the scalability of the solution?
While I'm maintaining 30 servers, there are hundreds of servers in use.
The scalability is good. We are able to increase capacity and functionality based on our demands.
I'm not sure if the company has plans to increase usage in the future.
How are customer service and support?
I don't directly deal with technical support. I might send a ticket to my side, and if they have to, they would be the ones to reach out to Red Hat.
Which solution did I use previously and why did I switch?
We used Oracle Linux before we moved over to Red Hat Linux. We likely switched due to costs and licensing. We also use Windows extensively. Since we used the same architecture, we didn't need to use any third-party applications.
How was the initial setup?
As an admin, I was not involved in the setup process.
If there is any maintenance needed, we get support from the Red Hat team. If anything comes up on the operating side, our team will take care of it.
What's my experience with pricing, setup cost, and licensing?
I'm only using this solution as an admin and, therefore, have no visibility on costs.
Which other solutions did I evaluate?
We did not evaluate other options before choosing this solution.
What other advice do I have?
I'm an end-user of the solution. I had admin-level access to the product.
Red Hat Enterprise Linux does not enable us to achieve security standard certification.
I'd rate the solution ten out of ten.
Enables organizations to achieve security standards certification
What is our primary use case?
We are an Azure shop that runs middleware applications like Java and JBoss, running on the Azure back end. We have to redeploy everything via ARM templates. Anytime we do an upgrade of the application itself, it's a redeployment. We have custom images that we set up through Azure pipelines. We use Ansible for code changes and server changes.
What is most valuable?
The solution's stability is great, and patching it with Ansible is very easy.
What needs improvement?
The solution's licensing sometimes could be a little bit confusing for someone who's not a full-blown system admin and doesn't have a lot of experience with Red Hat Enterprise Linux. It took a while for me to understand the licensing.
For how long have I used the solution?
I have been using Red Hat Enterprise Linux for three years.
What other advice do I have?
Red Hat Enterprise Linux’s built-in security features for simplifying risk reduction and maintaining compliance are pretty good. My only exposure is just packet management, but packet management gives me everything that I need.
Red Hat Enterprise Linux has enabled us to achieve security standards certification. We have to stay on top of things because we work with the Ontario District School Board. There's a big emphasis on keeping everything secure, and the solution has helped us to do that.
Right now, our company is migrating to 8.8, and I think we will stay on 8 for a few years. We're doing everything through the images, and we keep everything updated with Ansible. I don't think we have any plans to use any of the automation tools other than Ansible.
Overall, I rate Red Hat Enterprise Linux ten out of ten.
Gives us the confidence that our packages are legitimate and genuine
What is our primary use case?
My primary use case is for web applications and database applications. I've come across quite a few use cases at different companies.
What is most valuable?
The most valuable feature is the package management. It helps a lot. I also like the support.
Red Hat is a Linux-supportive and well-managed offering. It helps a lot in terms of when we're working in production, it gives us the confidence that our packages are legitimate and genuine and we always have support available. It helps a lot. Red Hat Enterprise Linux gives peace of mind compared to other unsupported Linux distributions.
I also like Red Hat Satellite.
I haven't used Insights yet but it seems interesting.
The ability to patch Red Hat Enterprise Linux through Satellite is a huge contributor to mitigating all of the compliance requirements.
Red Hat Enterprise Linux has absolutely affected our security's uptime. None of the other distributions are nearly close to what you can get with Red Hat Enterprise Linux. Red Hat Enterprise Linux is something that helps a lot in ensuring that your secure application is up all the time and that you're not getting hit by vulnerabilities. It is an easier way for you to mitigate vulnerabilities when they're around.
The knowledge base is very useful. The only thing is that you need to have an account to get access. In terms of the content, the relevance, and being able to use the knowledge base to address things I've needed to deal with, it's awesome. For example, I was trying to add proxy configuration to the package manager once and if it wasn't for the knowledge base, I wouldn't have been able to do it.
What needs improvement?
I like it the way it is.
It's getting easier for the community to use it free of charge. If you have an account, you get to use it. It would be better if the community could use it on their own for lab projects.
For how long have I used the solution?
I have been using Red Hat Enterprise Linux since 2011. It's been 12 years.
How are customer service and support?
On the few occasions I needed to reach out to support, I was very satisfied.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have used Linux distributions but when it comes to the work I'm doing at my company, we always use Red Hat Enterprise Linux.
The biggest differences between Red Hat Enterprise Linux and the other OS' are the support, Satellite, Insights, and the fact that Ansible was acquired by Red Hat so you can use all its automation and toolings. The entire ecosystem works very well together.
What other advice do I have?
Red Hat has not personally enabled me to achieve security standard certifications in the projects I've worked on but I could see how it would help.
I would rate Red Hat Enterprise Linux a ten out of ten. I really like it.
We do a lot of patching and upgrading with Ansible and we keep the host up to date all the time.
Secure and feature-rich with a good knowledge base and support
How has it helped my organization?
We are a Linux shop, so a lot of our engineers are familiar with Linux. We try to push Red Hat Enterprise Linux instead of Windows. The reason for it in the beginning was licensing. Some of it was because of the way the contract was set up. It was cheaper, but we do use it now just for the ease of it. I do not know if it is because of Ansible, which we use for a lot of our day-to-day operations, that we tend to lean more toward Red Hat.
Red Hat Enterprise Linux has affected our system's uptime or security. I know Microsoft publishes zero-day vulnerabilities for Windows as fast as Red Hat, but we noticed that in terms of problems or alerts that we get for attacks or viruses, there is not anything on the Red Hat side. That is why we feel that it is more secure. It might be just the nature of Red Hat where all services and ports are off. It is not like Windows where everything is on, and you have to turn it on. I was having a conversation with one of the gentlemen who is also attending the Red Hat conference, and I got to know that there are built-in NIST features with Red Hat that we could turn on, so we do not have to try to figure out how to harden our system.
What is most valuable?
The testing of the updates or the packages of the kernel is valuable because I used to be a part of the Fedora project. I know it is all vetted out before it gets to production, but a majority of it is the support and the relationships I have with the Red Hat employees assigned to our account.
As they move over to newer versions, certain things change, which is expected as the technology matures or new things come out, but what really surprises me are the features that are there in the cloud, such as Red Hat Insights. They are not there on-prem. There are a lot of things on the cloud portal that I did not notice before, and I was surprised because we were unaware of them. Red Hat is doing a lot of investment in that sense.
The knowledge base offered by Red Hat Enterprise Linux is good. It is easy to parse through all of the knowledge base. I do not know if Windows does it because I have not looked at it, but in Red Hat's knowledge base, there are a lot of things. They fast-track a lot of things in their knowledge base, even when they are not yet official. Especially with the tie-in with Bugzilla, even though it is not a true KB, we can see and follow if other people in the world are hitting a certain problem or something similar to what we are experiencing. I like that.
What needs improvement?
It would be great to have an overview of how various Red Hat products work together. They can show how to tie all those pieces together and how to have the products that we work together for our day-to-day processes.
For how long have I used the solution?
I started with the company around 2012, and they have been using it even before then. At that time, it was Red Hat Enterprise Linux 5, and now, we are up to Red Hat Enterprise Linux 9.
How are customer service and support?
In 10 or 11 years of using Red Hat solutions, I have opened only one or two support tickets. It probably was something during a patch and during Satellite 5 to Satellite 6 migration. I would rate them a 10 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
In Linux, there are so many different flavors, but I am partial to Red Hat because I have been a part of the Fedora project. At our place, we have only two operating systems: Microsoft Windows and Red Hat Enterprise Linux. I know CentOS, but that is usually because the appliance from the vendor was set up using that. That is why we had a few instances of CentOS in the past, but nowadays, I do not see any other flavors of Linux.
How was the initial setup?
For the majority of our use cases for Red Hat, we have on-prem deployments. There are some things that they are trying to spin up on AWS. I do not know if they are cloud-native apps or not, but I know our developers are now moving on to it.
I have been involved in the initial setup, upgrades, and migration of Red Hat Enterprise Linux. I did not have any problems while going from major OS versions. I always push new upgrades or homogeneous migrations, such as from version 6 to version 7 to version 8. There is probably an option to upgrade in place. Overall, with Red Hat OS, I have not seen many problems. A long time ago, when they went from Python 2 to Python 3, there were certain things we had to change in the script.
I know that Red Hat is moving to Wayland from X11, but I do not see any problems there. From Satellite 5 to 6, it was a bit hard in the beginning, but now, it is pretty self-explanatory. Overall, everything about which we had questions was very well documented.
In terms of our upgrade and/or migration plans to stay current, first, we look at the EOL and the roadmap of Red Hat because of security. We used to offer every single version before the said EOL happened, but now, we just do an n-minus-one. We try to maintain the newest and one level below version. SAP users are the biggest Red Hat Enterprise Linux users in our environment. They have a particular PAM and upgrade path that they have to do with Red Hat. We also wait to be certified to certain versions, but our main strategy is the newest and one major version down. We try to get everybody off the other versions.
Our provisioning is all done using VMware products. We have a vRealize automation, now called the Aria automation, to spin it up. Patching is done through Satellite. I do not do it, but when I watch them doing it, it seems it is just using remote SSH commands against the list of non-prod and prod servers. It is something simple. We do not seem to be doing anything complicated. I am wondering if there is a better way to do versioning control or patching and whatnot, but currently, it is very simple.
I am satisfied with the management experience not only in terms of patching but also the day zero to day one or day two stuff. We are interested in utilizing Ansible to eliminate human error and whatnot. During provisioning, we have Pearl scripts that we have to manually trigger. I know we can use Ansible for that, but it comes down to the cost of entry which is still very high.
What's my experience with pricing, setup cost, and licensing?
A lot of people are moving into the core count for licensing. We still have a few with one-to-one standard server licensing, but we are utilizing the virtualization host licensing. We license it based on the host, not based on VMs, which is cool. I was very happy that there was certain licensing with SAP to have access to SAP repos. Its cost was the same as the regular one, so I was happy about that.
The only pricing that bugs me right now is the Ansible pricing. We wanted to take a look at Ansible, but the biggest thing a year back with Ansible was that the management did not want to spend half a million on Ansible Tower. They wanted to see first if we would use it and not waste money. I do not know if things have changed now, but Ansible is probably still expensive. That is one of the routes that we want to go to. We will see if we can utilize Ansible Tower, so pricing-wise, that is the only thing that pops up. It is too expensive. The cost of entry seems quite high.
Overall, I do not see any issues with what we have spent on Red Hat. We also have learning subscriptions that we pay to Red Hat for the training, and I do not feel we have wasted any money.
What other advice do I have?
Red Hat Enterprise Linux has built-in features, but we do not use them. It is one of the things about which I need to talk to our account manager. There are so many different ways to skin a cat. My department has so much money, so they bought everything, but a lot of the security features, such as SELinux, are disabled for us. We handle the firewall rules, access lists, and other things at another location rather than on the actual VM itself. It does not hurt to do it at multiple places, but operations-wise, it would be a nightmare, so we try not to do it. I know there are a lot of cool new things built in Red Hat, and that is something we should circle back and take a look at.
I have seen Red Hat Insights. I clicked on it one time when our account manager was showing us something. They have so many features in the cloud that we do not know we can use. Maybe it is wrong to assume, but the reason I do not look at Red Hat Insights is that a part of our patching is already included. We are not that strict about what we patch in terms of the versions. It is useful, but Red Hat emails us anyway. They tell about the severity of an issue. We do not look at Red Hat Insights. We see those emails and we see CVEs. If a package is installed and applicable to our VMs, we just use Satellite and patch that particular vulnerability.
I have also tried the web console once. It looked interesting, but we do not have much use for it because a lot of our customers or application owners are server admins. About 99% of our Red Hat installs are all minimal installs. We do not have a GUI. There is just a terminal screen. Even though they could console in and do whatnot, it is all done via SSH.
Overall, I would rate Red Hat Enterprise Linux a 10 out of 10.
Has secure defaults and nice integrations for security and vulnerability scanning
What is our primary use case?
We have Ansible deployed on our Red Hat Enterprise Linux servers. We use it to manage the security of our fleet of Ubuntu virtual machines.
How has it helped my organization?
Red Hat Enterprise Linux is way ahead of Ubuntu in terms of security and compliance. It is mainly the ecosystem of data science tools that our developers want that pushes us in that direction. As a security engineer, I have a lot more peace at night knowing that my Red Hat servers are doing a good job keeping our Ansible infrastructure safe because that has fingers into everything we do. It is pretty critical.
Red Hat Enterprise Linux has not affected our system's uptime in any particularly noticeable way.
Red Hat Enterprise Linux has not enabled us to achieve security standards certification because we do not have any yet. We will have them hopefully in the future.
What is most valuable?
There are some nice integrations with scanning for vulnerabilities. That is the feature I have enjoyed the most because I am a security person, and that is my bread and butter.
Ansible has certainly been a game-changer. It is a lot easier to keep a whole bunch of virtual machines consistent with each other and make a change consistently across all of them. We use them for data science activities. Our data scientists are constantly trying out new packages and downloading new tools. We have to enable them to have root access on their machines but also need to ensure that they are not doing anything stupid at the same time. There are competitors to Ansible, but we are a big Python shop, so it is a very comfortable environment for us.
What needs improvement?
The only issue we have had with it is around the SELinux configuration because the way Ansible installs, it sticks the platform passwords in a flat file. We want that locked down more strongly than what is there currently with SELinux.
For how long have I used the solution?
I have been using Red Hat Enterprise Linux for two years.
How are customer service and support?
I would rate their support an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Primarily, we have used Ubuntu. We have had some of our use cases on CentOS, and then, of course, our workstations are all Windows, but I wish they were not.
We chose Ansible, and that chose Red Hat Enterprise Linux for us.
How was the initial setup?
We use Red Hat Enterprise Linux in the cloud. We have Azure because it is the corporate standard. We do not have any concerns about using Red Hat Enterprise Linux in the cloud. Obviously, everything in the cloud is more exposed than everything on-prem, but it has got good, sensible, and secure defaults built in, so there are no concerns there.
In terms of Red Hat Enterprise Linux upgrades, when we upgraded Ansible this fall, that pushed us from Red Hat Enterprise Linux 7 to Red Hat Enterprise Linux 8. It should be a little easier from now on. Now that we have made the big jump from the older Ansible to AAP, we will probably be upgrading the systems on a quarterly basis.
What was our ROI?
We probably have not yet seen an ROI. We purchased it a couple of years ago, but we have not had the time to put it to as much use as we wanted to put it to. The cost is low, so it would not take very long to reach a return on investment.
We have not made use of the Committed Spend.
What other advice do I have?
For its use case, I would rate Red Hat Enterprise Linux a ten out of ten.
Enables users to roll out applications easily and provides excellent technical support
What is our primary use case?
We have a lot of Oracle databases, Tomcat, and Java microservices running on Red Hat Enterprise Linux.
How has it helped my organization?
A lot of our applications are like Java microservices. Deploying them on a Unix platform is so much easier. It's open-sourced and provides a lot of compatibility. It makes it easier for us to roll out applications. It is compatible with most Java microservices applications.
What is most valuable?
We like that Red Hat Enterprise Linux is a vendor-supported product. When we have problems, we just call Red Hat Enterprise Linux for support. The product employs a lot of automation tools to manage its OS. We love using Red Hat Satellite. We have close to 5000 servers. Managing individual servers would be a nightmare.
Red Hat Ansible Automation Platform and Red Hat Satellite help us automate our repetitive tasks. Every flavor of Linux distribution has its own specialties. The product offers a lot of integration within the Red Hat products suite. We use Red Hat products mostly, so it works for us.
What needs improvement?
The vendor keeps rolling out many packets, which complicates our job. We keep patching our servers. CVEs come out all the time. However, having a solid and secure OS will make our life much easier.
For how long have I used the solution?
I have been using Red Hat Enterprise Linux since 2004.
How are customer service and support?
I never had any problem with support. I didn't have any issues that I did not get a resolution for. Sometimes, it takes a little bit of time, but eventually, it gets resolved.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I was using AIX, which is also an IBM product. IBM bought Red Hat Enterprise Linux. AIX was more expensive and required IBM System p. Moving to Red Hat Enterprise Linux was much easier because it is a lot more compatible with the regular hardware like HP and Dell that we buy on the market.
What was our ROI?
I have seen an improvement in our deployment. When we have applications running on Windows, it takes longer to get them set up and provisioned, and the security is different compared to Red Hat.
What's my experience with pricing, setup cost, and licensing?
The pricing could be better. The tool is getting expensive. Before, we could license only the hypervisor where Red Hat Enterprise Linux is running. Now, if a customer has a 12-node hypervisor, Red Hat Enterprise Linux forces customers to license all 12, even though they use only six.
Which other solutions did I evaluate?
We evaluated SUSE. At that time, SUSE did not have good support. We needed good support worldwide.
What other advice do I have?
We use AWS and Microsoft Azure as our cloud providers. We don't use the off-the-shelf product that we get from the cloud. We build around it because we have a standard template. When we deploy our solution in the cloud, all the security features we need are already within the OS, as opposed to using the cloud OS and applying all the changes we need. It's easier to get our template to the cloud and use it.
The licensing for the cloud environment is totally different than the on-premise one. We use the Virtual Datacenter license on-premises. I don't see any difference because Red Hat Enterprise Linux still supports it, whether on-premise or on the cloud.
Red Hat Enterprise Linux knows its product. Whenever I have an issue, an engineer gets assigned to me. I can always escalate if needed. We're not using every host that we license. We ensure that we can fail over smoothly on every single hypervisor. It's fair to license them. We're not using it, but we're still paying for it. I do not like it, but it is a business cost.
We migrate workloads to the cloud. I never upgrade an OS. I usually replace the old OS with a new OS and migrate the application. I use the OS versions 7, 8, and 9. The migration is pretty straightforward. AWS and Azure have a tool that we can use to integrate with our environment. It's a lift and shift. We grab the VM from our on-premise hypervisors and move it to the cloud.
We use Red Hat Ansible Automation Platform mostly for patching and upgrading to the next revisions. We don't upgrade from one OS to another. We build on a new OS and get all the applications running there. Once the application is running, we move all the workload from the old OS to the new OS. There's no impact on the existing system.
I don't do the day-to-day patching because we have a managed service. However, it does create interruption. When we do a patch, we have to reboot, especially when there's a kernel update. It causes an outage. I have used Red Hat Insights. It gives us insight into what's happening on every single Red Hat VM that we have. It tells us if it's behind or has some performance bottlenecks. It gives us visibility on the health of the whole OS.
People who are looking into the product must get a good account manager. We must have a good account manager who we can always contact and who gives us all the updates that we need. They keep us in the loop on what is happening in the Red Hat world. We are satisfied with the product.
Overall, I rate the tool a ten out of ten.