Meet the cousins: Alma, Amazon Linux & more
This course uses Rocky and Ubuntu, the heads of the two big families. At work, and in the cloud, you'll also meet their cousins. The good news: once you know which family a distro belongs to, you already know 95% of it. This lesson covers the differences that trip people up.
You will learn
- The family tree: who is built from whom
- AlmaLinux (Rocky's twin) and Amazon Linux 2023 (Red Hat family, with surprises)
- Debian, Fedora and Alpine, and which images you'll see in containers
- How a script can tell which family it's running on
The family tree
AlmaLinux: Rocky's twin
When CentOS Linux was discontinued, two free RHEL rebuilds took its place: Rocky Linux (started by one of CentOS's original founders) and AlmaLinux (backed by the company CloudLinux). For everything in this course they're identical: same dnf, same package names, same /etc/sysconfig, same firewalld and SELinux. Wherever a lesson says “Rocky”, it means Alma too.
/etc/os-releasesaysID="almalinux", and/etc/almalinux-releasereplaces/etc/rocky-release.- Rocky aims to match RHEL “bug-for-bug”. Since 2023, Alma aims to be “binary compatible” (programs built for RHEL run on it), which occasionally lets Alma ship a fix before RHEL does. You'll almost never notice.
- Alma is a popular container base image:
almalinux:9, plus a tinyalmalinux:9-minimalthat usesmicrodnf, a small dnf without the extras. Rocky publishes images too:rockylinux/rockylinux:9.
Amazon Linux 2023: Red Hat family, with surprises
A common mix-up: Amazon Linux is not Debian-based. Amazon Linux 2023 (AL2023) is built from Fedora, so it uses dnf and .rpm, and its /etc/os-release says ID="amzn" and ID_LIKE="fedora". The older Amazon Linux 2 was based on CentOS 7 and reached end of life in June 2026, so migrate anything still running it. Things that surprise Rocky users on AL2023:
| Rocky / Alma | Amazon Linux 2023 | |
|---|---|---|
| Log in over SSH as | rocky / ec2-user (on AWS) | ec2-user |
| EPEL extra packages | Yes: dnf install epel-release | Not supported. Use Amazon's repos, or install the software another way |
| Firewall | firewalld, on | None installed. AWS security groups do the job |
| SELinux | enforcing | permissive (logs, but doesn't block) |
| cron | installed | Not installed. Use systemd timers, or dnf install cronie |
| Network settings | NetworkManager (nmcli) | systemd-networkd |
| New major version | every ~3 years (with RHEL) | every 2 years, each supported for 5 |
The AWS learning path (coming soon) will go deeper. The takeaway: dnf commands transfer, but check the “out of the box” assumptions.
Everyone else, side by side
| Distro | Family | Packages | AWS login | Security module | Container image |
|---|---|---|---|---|---|
| Rocky Linux | Red Hat | dnf | rocky | SELinux | rockylinux/rockylinux:9 |
| AlmaLinux | Red Hat | dnf | ec2-user | SELinux | almalinux:9 |
| Amazon Linux 2023 | Red Hat (via Fedora) | dnf | ec2-user | SELinux (permissive) | amazonlinux:2023 |
| Fedora | Red Hat | dnf | fedora | SELinux | fedora |
| Ubuntu | Debian | apt | ubuntu | AppArmor | ubuntu:24.04 |
| Debian | Debian | apt | admin | AppArmor | debian:13 |
| Alpine | its own | apk add | alpine | none | alpine |
Alpine is the container favorite because it's tiny, but it has no bash (only BusyBox sh, see lesson 14) and uses a different C library (musl), which occasionally breaks programs built for other distros. It gets a whole lesson of its own next: lesson 16.
Which one am I on?
Every one of them has /etc/os-release (Linux Basics, lesson 1). Scripts should look at ID_LIKE, not just ID. Then a script written for “rhel” also works on Rocky, Alma, Oracle and Amazon Linux without knowing their names:
#!/bin/sh
# which Linux family is this? (give an os-release file, or it reads this machine)
. "${1:-/etc/os-release}"
case "$ID $ID_LIKE" in
*rhel*|*fedora*|*centos*) echo "$PRETTY_NAME: Red Hat family (dnf, .rpm)" ;;
*debian*|*ubuntu*) echo "$PRETTY_NAME: Debian family (apt, .deb)" ;;
*alpine*) echo "$PRETTY_NAME: Alpine (apk)" ;;
*) echo "$PRETTY_NAME: unknown family" ;;
esac
It's written in plain POSIX sh, so it runs even on Alpine.
Try it: the family detector 🧬
Your home folder has os-release/, real /etc/os-release files copied from AlmaLinux, Amazon Linux 2023, Debian and Alpine. Build a tool that sorts them into families.
Quick check
1. Which family is Amazon Linux 2023 in?
✓ Its os-release even says ID_LIKE="fedora".
2. A Rocky tutorial says sudo dnf install epel-release. It fails on Amazon Linux 2023. Why?
✓ Same family doesn't mean identical. Check the out-of-the-box differences.
3. Your install script checks if [ "$ID" = "rocky" ]. A colleague runs it on AlmaLinux and it says “unsupported”. The better fix?
✓ Think in families, not names.