Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

On bootc and other image-based Linux systems, software and configuration changes are not all handled the same way: install user apps in user space, use the distribution’s supported local layering workflow for a one-off system change, or build a derived OS image when you want repeatable system customization. The right choice depends on the specific distribution and release; “immutable” does not mean that nothing can change.

What “image-based” means in practice

An image-based operating system delivers its base system as a versioned image or deployment rather than treating every system file as an independently maintained package. A change can therefore have different persistence and update behavior depending on where it is made.

For example, Red Hat Enterprise Linux 10 documentation describes image mode as a container-native way to build, deploy, and manage operating systems. In that product, the root filesystem is immutable by default except for /etc and /var. That is a specific RHEL 10 description, not a rule that applies identically to every distribution called atomic or immutable. Red Hat’s RHEL 10 image-mode guide explains that product’s model.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In bootc, the base container image is stored using OSTree. That implementation detail helps explain why bootc-based systems and OSTree-based tooling can intersect, but it does not mean every atomic distribution uses bootc or has identical management commands. bootc’s filesystem documentation describes its OSTree dependency.

Choose a home for each change

Before installing software, identify the exact distribution and release, then check its documentation for the supported method. A useful starting point is to decide whether the change belongs to your account, to the running system temporarily, or to the OS image itself.

Change type Typical fit What to verify
User-space application An application intended to live and update separately from the base operating system Which app formats and installation routes the distribution supports
Local system package change A package needed on one installed system or for a local test The distribution’s current layering or package-management workflow, and whether the change persists through reboot and upgrades
Derived OS image Repeatable system packages or configuration that should travel together as a known OS setup The image build, deployment, and update instructions for the target OS

User applications

If an application is meant to be managed independently of the base OS, a user-space installation can keep it separate from the operating-system deployment. The appropriate format and exact install steps vary by distribution; check its documentation rather than assuming a package command that works on a conventional Linux install will work on an image-based one.

Local package layering

Some systems provide a supported way to add packages to the installed OS deployment. This is useful for a local requirement, but it is distinct from editing the image that defines the base system. Fedora’s Fedora 41 change proposal described client-side package changes through rpm-ostree layering, while distinguishing those from DNF use in container builds and unlocked systems. The proposal was last updated on October 2, 2024, so it is a release-specific record rather than a guarantee for every Fedora variant or later release. See the Fedora change proposal.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Derived images

When a package or OS-owned configuration should be part of a repeatable setup, building a derived image can keep those choices together and make them versionable. bootc’s package-manager guidance presents package installation primarily as a build-time activity for image-based systems and recommends that package managers recognize a read-only /usr and direct users toward supported workflows. This is not a reason to force every app into the OS image: use the image for changes that genuinely belong to the operating system. bootc’s package-manager integration guidance explains the distinction.

bootc and rpm-ostree are related, not interchangeable names

Do not infer a system’s management commands from the words “atomic” or “immutable,” or from the presence of bootc. The bootc project says bootc and rpm-ostree can be used together and that rpm-ostree remains maintained. Fedora’s Fedora 41 proposal likewise described retaining rpm-ostree alongside bootc and DNF5 for image-based variants. Those statements establish coexistence, not one universal workflow. Follow the instructions for the target distribution and release. bootc’s project-relationship documentation covers the relationship.

In short, use bootc-specific deployment guidance where the OS documents a bootc workflow, and use rpm-ostree instructions where the OS documents rpm-ostree. The Fedora proposal’s summary put its direction this way: “This is the start of a process to enable dnf with rpm-ostree features and a re-focus on bootc to manage image mode deployments.” The wording describes that Fedora 41 proposal, not an across-the-board command guarantee.

What updates, tests, and rollback mean

Staged deployments

In the rpm-ostree model, an upgrade can be prepared offline and made the default deployment for the next boot. That means updating is a transition to a deployment you boot into, rather than necessarily changing the active system in place. The rpm-ostree administrator handbook documents staged upgrades and related deployment operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Temporary overlays and recovery

The rpm-ostree handbook also documents usroverlay as a transient workflow: its changes do not persist across reboot. That can suit an experiment, but it is not a substitute for a durable package layer or a rebuilt image.

The rpm-ostree model includes rollback to a previous deployment, which can help recover from an unsuccessful upgrade. Do not assume another bootc-based or third-party system exposes the same command, interface, or recovery path. A rollback also does not replace backups of personal data; keep important files protected separately from the OS deployment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Installation depends on the target

Physical hardware, virtual machines, cloud systems, and edge devices may use different deployment paths. RHEL 10 documents Anaconda and bootc-image-builder options. In the documented bare-metal route, a generated installer ISO is copied to a USB flash drive and used for installation. The guide labels the cited bootable-ISO creation and deployment workflow as Technology Preview, so that status applies to that RHEL 10 path; it should not be generalized to every bootc installation method. Consult the RHEL 10 image-mode guide for its target-specific procedure.

A practical checklist before changing an atomic system

  • Record the distribution, release, and image or deployment workflow in use.
  • Decide whether the software belongs in your user environment, a temporary test, a local system layer, or a derived OS image.
  • Check the release-specific documentation for supported commands and persistence behavior before applying a package-manager instruction from another distribution.
  • For repeatable system customization, consider whether packages and OS-owned configuration should be versioned together in a derived image.
  • Know how that system stages updates and recovers from a failed deployment, and keep separate backups of important personal data.
  • When comparing distributions, evaluate their target hardware and use, image-build and layering workflows, update and rollback behavior, application formats, support model, and migration guidance for the specific releases involved. The cited project documentation does not establish a complete cross-distribution feature matrix or an objective best choice.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.