Stop fighting drift on your immutable fleet with bootc
By Saket Jain Published Linux/Unix
Stop fighting drift on your immutable fleet with bootc
Technical Briefing | 9/25/2026
You probably spent years managing golden images or fighting configuration drift with massive Ansible playbooks. It feels like you’re constantly patching holes in a sinking ship. Moving to an immutable OS approach using bootc feels like a breath of fresh air until you realize that your old habits of patching in-place are gone, and you need to rethink how your host OS actually updates.
Why image-based updates aren’t just for containers
Bootc treats your entire host operating system like a container image. This means you stop running package managers on your production hosts and start shipping atomic updates. The risk here is that if your build pipeline isn’t tight, you can end up with a bricked node that won’t boot because a library version mismatch was baked into the latest hash. You’ve got to treat your host image lifecycle with the same scrutiny as your microservices.
bootc switch --mutate-in-place quay.io/my-org/my-os-image:latest
- Avoid running dnf or rpm directly on the host to prevent configuration drift
- Test your new host image in a ephemeral VM before rolling it out to your primary fleet
- Ensure your container registry has lifecycle policies to keep your storage footprint sane
The transition to bootc forces you to stop being a sysadmin who tweaks configs on the fly and starts you acting more like an infrastructure engineer. It forces the state into the image. If you find yourself sshing in to fix a config file, stop, go back to your Containerfile, and rebuild. Your future self dealing with a broken cluster update will thank you.
