Securing the enterprise software fabric: A blueprint for open source

พิมพ์เขียวความปลอดภัยซอฟต์แวร์องค์กร: ใช้โอเพ่นซอร์สอย่างมั่นใจ

Securing the enterprise software fabric: A blueprint for open source

Lately, headlines dominated by AI-driven zero-day vulnerabilities have raised a question: Is open source software becoming too risky for the enterprise? With open source comprising more than three-quarters of the average enterprise codebase, the question matters. But the answer is clear: open source software remains inherently safe, structurally resilient, and fundamentally secure.

Open source effectively serves as the foundation for all of modern technology, not just enterprise IT, and this is about much more than just Linux. Application servers, databases, network routing, developer environments, and all of the other invisible components that make up our technological fabric are fueled by open source projects in some way, shape, or form. 

The alternative to open source, in short, is that there isn’t one. Proprietary software comes closest, which is owned and controlled by a single company, but it lacks the sheer scale, variety, and ubiquity of open source. With proprietary software, the source code is a black box. Only the vendor decides what gets fixed and when. When a vulnerability is found, it may stay secret, known only to the attackers who discovered it. That model might feel secure, but the risk has only moved out of sight and become an unknown. Proprietary software allows vulnerabilities to breed in darkness.

Open source changes this by making the code available to everyone, highlighted by the mantra of “Given enough eyeballs, all bugs are shallow.” When anyone can read the code, anyone can find and report problems, and this now includes AI massively amplifying the inspection of the code. And because so many groups depend on open source software, there is a great collective motivation to resolve vulnerabilities. 

No software development method guarantees perfectly secure software, but the transparent, crowd-sourced nature of open source has distinct advantages over proprietary models when combating modern threats. Enterprises have always been, and will continue to be, vigilant to vulnerabilities as they are discovered. What has changed is the velocity. The number of published CVEs has grown by more than 520% since 2016. AI-powered scanning tools now discover critical zero-day vulnerabilities in hours, not months, and fewer than one percent of AI-discovered vulnerabilities have been patched. The challenge is now the enterprise’s operational ability to consume and deploy fixes fast enough. 

This problem is compounded by a coordination failure. Every major institution depends on the same core open source packages — Spring Framework, Jackson, Log4j, Pandas, OpenSSL — yet without coordination, each institution independently discovers the same vulnerabilities, develops patches in isolation, and maintains private forks that no one else benefits from. The result is redundant effort at enormous cost and uneven quality, while the broader ecosystem remains exposed. To stay secure, organizations must contribute to upstream communities, accelerate their operational baselines, and they must do it together.

What enterprises can do to get started today

Open source remains the safest foundation for innovation, but closing the threat window requires immediate action. Here are simple, actionable steps enterprises can take to protect their supply chains today:

  • Choose platforms backed by responsible vendors: Your infrastructure is the foundation everything else runs on. Make sure the vendors that support it are active contributors to the open source projects they ship. A vendor with a long track record of upstream contributions, security backports, and responsible disclosure is invested in keeping the community healthy, not just keeping your business.
  • Build a complete dependency inventory: Begin by auditing your application portfolios to map your baseline. Identify every open source library, transitive dependency, and pinned version currently running in production.
  • Define your patch-to-production cycle time: Measure your current reality. How long does it actually take for an upstream patch to navigate your internal security scans, testing, change advisory boards, and deployment pipelines? Once defined, set aggressive targets to shrink this window.
  • Automate rebuild and redeploy pipelines: As the threat window shrinks from months to hours, manual updates fail. Prepare your environment for frequent, deterministic, and automated application rebuilds so you can safely consume secure packages at velocity.
  • Use active security offerings: Adopt active supply chain solutions that provide zero-CVE baselines and runtime protection, such as Red Hat Hardened Images, Red Hat Trusted Libraries, and OpenShift Advanced Cluster Security, to move more quickly.

Accelerating change with Project Lightwell

As you automate your pipelines to consume fixes faster, IBM and Red Hat are building a remediation engine designed specifically to supply them. We recently introduced Project Lightwell, a joint $5 billion commitment backed by a global force of more than 20,000 engineers to redefine software supply chain security for the AI era.

Project Lightwell scales Red Hat’s proven, two-decade-long methodology of backporting enterprise-grade security patches. We are extending this rigorous engineering discipline above the operating system layer to the broader application framework and dependency landscape starting with Maven/Java and expanding to PyPI, npm, and beyond. By combining AI for high-volume threat ingestion with expert human engineering, we execute surgical fixes on the exact stable versions enterprises run in production, eliminating the need to blindly upgrade and break systems.

Without a mechanism to get fixes accepted upstream, every backport an enterprise develops on its own creates a permanent private fork, one that must be carried forward through every subsequent vulnerability, update, and dependency change. This increases an organization’s costs and risks. Project Lightwell breaks this cycle: Red Hat develops the fix, delivers it to the enterprise, and contributes it to the originating open source project. The fix becomes part of the public codebase.

Working together to protect your enterprise and all of open source

Securing the software supply chain is a collective industry challenge, one that no single enterprise can solve alone. Through Project Lightwell, we are collaborating with a premier cohort of financial and critical infrastructure leaders to establish a secure enterprise clearinghouse.

This collaborative intelligence network provides three capabilities that no enterprise can build independently. First, members share novel vulnerability findings and receive coordinated patches before public disclosure — turning isolated discovery into shared defense. Second, every patch is delivered production-ready: cryptographically signed, with machine-readable SBOM and security advisories to address compliance requirements. Third, and crucially, Project Lightwell operates on an upstream-always mandate. Every fix we develop is submitted back to the originating open source projects. By working together in this clearinghouse, we are not just protecting individual enterprises; we are systematically returning security advancements to the community, keeping open source safe for everyone.

Open source built the modern enterprise. Coordinated vigilance and Project Lightwell help this code remain secure by fixing it faster, as one community, in the open.

Article by Chris Wright, Chief Technology Officer and Senior Vice President, Global Engineering, Red Hat

พิมพ์เขียวความปลอดภัยซอฟต์แวร์องค์กร: ใช้โอเพ่นซอร์สอย่างมั่นใจ

พิมพ์เขียวความปลอดภัยซอฟต์แวร์องค์กร: ใช้โอเพ่นซอร์สอย่างมั่นใจ

พิมพ์เขียวความปลอดภัยซอฟต์แวร์องค์กร: ใช้โอเพ่นซอร์สอย่างมั่นใจ

ช่วงหลังมานี้ พาดหัวข่าวส่วนใหญ่เป็นเรื่องเกี่ยวกับช่องโหว่ zero day ที่เกิดจาก AI ซึ่งทำให้เกิดคำถามว่า องค์กรจะเสี่ยงเกินไปในการใช้ซอฟต์แวร์โอเพ่นซอร์สหรือไม่ ประเด็นนี้เป็นเรื่องที่ไม่ควรมองข้าม เนื่องจากโอเพ่นซอร์สครองสัดส่วนเฉลี่ยมากกว่าสามในสี่ของคลังซอร์สโค้ดทั้งหมดที่องค์กรหนึ่ง ๆ ใช้ในการพัฒนาซอฟต์แวร์หรือระบบไอทีภายในองค์กร (codebase) แต่คำตอบนั้นชัดเจนว่า ซอฟต์แวร์โอเพ่นซอร์สยังคงมีความปลอดภัยโดยเนื้อแท้ มีโครงสร้างที่แข็งแกร่ง และมีความปลอดภัยฝังตัวอยู่ตั้งแต่ระดับรากฐานเริ่มแรก

โอเพ่นซอร์สมีบทบาทเป็นฐานที่ทรงประสิทธิภาพให้กับเทคโนโลยีสมัยใหม่ทั้งหมดโดยไม่จำกัดเฉพาะไอทีขององค์กรเท่านั้น แต่มีบทบาทกว้างกว่าเฉพาะเรื่องของ Linux อย่างมาก แอปพลิเคชันเซิร์ฟเวอร์ต่าง ๆ ฐานข้อมูล เส้นทางเครือข่าย สภาพแวดล้อมในการพัฒนาซอฟต์แวร์ และส่วนประกอบอื่น ๆ ที่มองไม่เห็นทั้งหมดซึ่งถักทอขึ้นเป็นโครงสร้างพื้นฐานทางเทคโนโลยี ล้วนขับเคลื่อนด้วยโปรเจกต์โอเพ่นซอร์สไม่ทางใดก็ทางหนึ่ง

กล่าวโดยสรุปคือ ไม่มีทางเลือกอื่นใดที่จะมาทดแทนโอเพ่นซอร์ส ซอฟต์แวร์กรรมสิทธิ์อาจเป็นทางเลือกที่ใกล้เคียงที่สุด เพราะบริษัทเป็นเจ้าของและควบคุมด้วยตนเองเพียงผู้เดียว แต่ก็ยังขาดทั้งในเรื่องของขนาดที่กว้างขวาง ความหลากหลาย และความแพร่หลาย เมื่อเทียบกับโอเพ่นซอร์ส ซอร์สโค้ดของซอฟต์แวร์กรรมสิทธิ์นั้นเป็นเหมือนกล่องดำ ที่มีเพียงเวนเดอร์ผู้ขายซอฟต์แวร์นั้นเท่านั้นที่เป็นผู้ตัดสินใจว่าจะแก้ไขอะไรเมื่อไร และเมื่อมีการตรวจพบช่องโหว่ ช่องโหว่นั้นอาจถูกปิดเป็นความลับ โดยมีเพียงผู้โจมตีที่ค้นพบช่องโหว่นั้นเท่านั้นที่รับรู้ โมเดลรูปแบบนี้อาจจะให้ความรู้สึกที่ปลอดภัย แต่ในความเป็นจริงแล้ว ความเสี่ยงเพียงแค่ถูกย้ายไปอยู่ในจุดที่มองไม่เห็นและกลายเป็นสิ่งที่ไม่สามารถคาดเดาได้ ซอฟต์แวร์กรรมสิทธิ์จึงเปิดโอกาสให้ช่องโหว่ต่าง ๆ แพร่กระจายในมุมมืด

โอเพ่นซอร์สเปลี่ยนข้อจำกัดนี้ด้วยการเปิดให้ทุกคนสามารถเข้าถึงซอร์สโค้ดได้ ซึ่งสะท้อนให้เห็นเด่นชัดจากแนวคิดที่ว่า “เมื่อมีคนช่วยกันตรวจโค้ดมากพอ บั๊กย่อมไม่มีที่ให้ซ่อน” และเมื่อทุกคนสามารถอ่านโค้ดได้ ทุกคนจึงสามารถค้นหาและรายงานปัญหาได้ ซึ่งในปัจจุบันยังรวมถึงการนำ AI เข้ามาช่วยเพิ่มประสิทธิภาพในการตรวจสอบโค้ดได้อย่างมหาศาล และเนื่องจากมีกลุ่มผู้ใช้งานจำนวนมากที่ต้องพึ่งพาซอฟต์แวร์โอเพ่นซอร์ส จึงเกิดเป็นแรงขับเคลื่อนร่วมกันครั้งใหญ่ในการแก้ไขช่องโหว่ต่าง ๆ ให้หมดไป

แม้จะไม่มีวิธีการพัฒนาซอฟต์แวร์ใดที่สามารถรับประกันความปลอดภัยได้อย่างสมบูรณ์แบบ แต่ความโปร่งใสและการระดมสมองจากกลุ่มคนจำนวนมากในชุมชนโอเพ่นซอร์ส ถือเป็นข้อได้เปรียบที่เด่นชัดเหนือโมเดลซอฟต์แวร์กรรมสิทธิ์เมื่อต้องรับมือกับภัยคุกคามยุคใหม่ แน่นอนว่าองค์กรธุรกิจต่างเฝ้าระวังช่องโหว่ทันทีที่ถูกตรวจพบมาโดยตลอดและจะยังคงทำเช่นนั้นต่อไป แต่สิ่งที่เปลี่ยนแปลงไปคือความเร็ว เห็นได้จากจำนวนช่องโหว่ความปลอดภัยที่ถูกเปิดเผยต่อสาธารณะ (CVEs) ที่พุ่งสูงมากกว่า 520% ตั้งแต่ปี 2016 เป็นต้นมา อีกทั้งเครื่องมือสแกนที่ขับเคลื่อนด้วย AI ในปัจจุบัน สามารถตรวจพบช่องโหว่ร้ายแรงประเภท zero-day ได้ภายในเวลาไม่กี่ชั่วโมง แทนที่จะเป็นหลายเดือนเหมือนในอดีต แต่ช่องโหว่ที่ถูกค้นพบโดย AI กลับได้รับการแก้ไขหรือทำการแพตช์ไม่ถึง 1% ความท้าทายในปัจจุบันจึงตกไปอยู่ที่ขีดความสามารถในการดำเนินงานขององค์กร ว่าจะสามารถนำตัวแก้ไขหรือฟิกส์ (fixes) เหล่านั้นมาทดสอบและใช้งานได้ทันท่วงทีหรือไม่ 

ปัญหานี้ทวีความรุนแรงยิ่งขึ้นจากความล้มเหลวในการผสานการทำงานร่วมกัน องค์กรใหญ่ ๆ ทุกแห่งต่างต้องพึ่งพาแพ็กเกจโอเพ่นซอร์สหลัก ๆ ชุดเดียวกัน เช่น Spring Framework, Jackson, Log4j, Pandas และ OpenSSL แต่หากขาดการประสานงาน ต่างคนต่างตรวจหาช่องโหว่แบบเดียวกัน พัฒนาแพตช์แยกกันในพื้นที่ปิด และรักษาเวอร์ชันย่อยส่วนตัวเอาไว้ โดยที่ไม่มีใครได้ประโยชน์ร่วมด้วย จะส่งผลให้เกิดการทำงานที่ซ้ำซ้อนด้วยต้นทุนที่สูงลิ่วและได้คุณภาพที่ไม่แน่นอน ในขณะที่ระบบนิเวศในภาพรวมยังคงเผชิญกับความเสี่ยง การจะคงความปลอดภัยไว้ได้นั้น องค์กรต่าง ๆ ต้องเข้าไปมีส่วนร่วมกับชุมชนผู้พัฒนาหลัก (upstream communities) เร่งยกระดับมาตรฐานการดำเนินงาน และที่สำคัญคือต้องลงมือทำสิ่งเหล่านี้ไปด้วยกัน

สิ่งที่องค์กรธุรกิจสามารถลงมือทำได้ทันที

แม้โอเพ่นซอร์สจะยังคงเป็นฐานที่ปลอดภัยที่สุดสำหรับการสร้างสรรค์สิ่งใหม่ แต่การจะปิดช่องทางที่ภัยคุกคามจะเข้ามาได้นั้นจำเป็นต้องดำเนินการทันที ขั้นตอนง่าย ๆ ที่องค์กรสามารถนำไปปฏิบัติได้จริงทันทีเพื่อปกป้องซัพพลายเชนของทุกอย่างที่ประกอบขึ้นมาจนกลายเป็นซอฟต์แวร์หรือระบบที่องค์กรใช้ มีดังต่อไปนี้

  • เลือกใช้แพลตฟอร์มที่มีเวนเดอร์หรือผู้จำหน่ายที่มีความรับผิดชอบสนับสนุนอยู่เบื้องหลัง: โครงสร้างพื้นฐานขององค์กรคือฐานที่รองรับการทำงานของระบบทั้งหมด ดังนั้น ควรตรวจสอบให้แน่ใจว่าเวนเดอร์ที่ดูแลระบบเหล่านั้น เป็นผู้ที่มีส่วนร่วมอย่างจริงจังในโครงการโอเพ่นซอร์สที่พวกเขาหยิบยกมาให้บริการ เวนเดอร์ที่ให้การสนับสนุนชุมชนนักพัฒนาต้นน้ำมาอย่างยาวนาน มีการนำแพตช์จากเวอร์ชันล่าสุดย้อนไปติดตั้งให้เวอร์ชันเก่า (security backports) และมีกระบวนการแจ้งเตือนช่องโหว่อย่างรับผิดชอบ นับเป็นเวนเดอร์ที่มุ่งมั่นในการดูแลรักษาชุมชนโอเพ่นซอร์สให้แข็งแกร่ง ไม่ใช่เพียงแค่ต้องการรักษาผลประโยชน์ทางธุรกิจกับองค์กรที่เป็นลูกค้าเท่านั้น
  • จัดทำรายการส่วนประกอบที่ต้องพึ่งพากันทั้งหมด: เริ่มจากการตรวจสอบพอร์ตโฟลิโอของแอปพลิเคชันขององค์กรเพื่อสร้างฐานข้อมูลอ้างอิง (baseline) จากนั้นระบุไลบรารีโอเพ่นซอร์สทั้งหมด ระบุส่วนประกอบที่เกี่ยวเนื่องกัน (transitive dependency) และเวอร์ชันที่ถูกล็อกไว้ (pinned version) ที่กำลังถูกใช้งานจริงในปัจจุบัน
  • วัดรอบระยะเวลาการแพตช์จนถึงการนำไปใช้จริง: ประเมินจากเวลาที่เกิดขึ้นจริง ว่าแพตช์จากต้นทางต้องใช้เวลานานเท่าใดในการผ่านระบบสแกนความปลอดภัยภายใน การทดสอบ คณะกรรมการพิจารณาความเปลี่ยนแปลง จนถึงการเปิดใช้งานจริงบนระบบ เมื่อได้ตัวเลขระยะเวลาแล้ว ให้ตั้งเป้าหมายที่ท้าทายเพื่อลดระยะเวลานี้ลง
  • ทำไปป์ไลน์ของการประกอบซอฟต์แวร์ใหม่ (rebuild) และติดตั้งใหม่ (redeploy) ให้เป็นอัตโนมัติ: ช่วงเวลาที่เสี่ยงต่อการถูกโจมตีหดสั้นลงจากหลักเดือนเป็นเพียงไม่กี่ชั่วโมงทำให้การอัปเดทระบบแบบแมนนวลไม่ตอบโจทย์อีกต่อไป องค์กรควรเตรียมสภาพแวดล้อมให้พร้อมสำหรับการ rebuild แอปพลิเคชันแบบอัตโนมัติได้อย่างแม่นยำและบ่อยครั้ง เพื่อให้องค์กรสามารถใช้แพ็คเกจที่ปลอดภัยได้อย่างรวดเร็ว
  • ใช้โซลูชันด้านความปลอดภัยแบบเชิงรุก: เลือกใช้โซลูชันซัพพลายเชนเชิงรุกที่มาพร้อม zero-CVE baselines และการปกป้องระบบขณะทำงาน (runtime protection) เช่น Red Hat Hardened Images, Red Hat Trusted Libraries และ OpenShift Advanced Cluster Security เพื่อให้องค์กรขับเคลื่อนงานได้อย่างรวดเร็วยิ่งขึ้น

เร่งการเปลี่ยนแปลง ด้วย Project Lightwell

ในขณะที่องค์กรกำลังทำให้ไปป์ไลน์ต่าง ๆ เป็นอัตโนมัติเพื่อให้สามารถนำตัวแก้ไขหรือฟิกซ์ (fixes) เหล่านี้เข้ามาปรับใช้ในระบบให้ได้เร็วขึ้น ด้านไอบีเอ็มและเร้ดแฮทก็กำลังสร้างกลไกแก้ไขช่องโหว่ (remediation engine) ที่ออกแบบมาเพื่อให้บริการตัวแก้ไขหรือฟิกซ์เหล่านั้นเป็นการเฉพาะ ล่าสุดได้เปิดตัว Project Lightwell ซึ่งเป็นความร่วมมือร่วมทุนมูลค่า 5 พันล้านเหรียญสหรัฐฯ โดยมีกองกำลังวิศวกรกว่า 20,000 คนทั่วโลกคอยสนับสนุน เพื่อพลิกโฉมความปลอดภัยของซัพพลายเชนของซอฟต์แวร์ในยุค AI

Project Lightwell ขยายขอบเขตความสามารถของเร้ดแฮทที่ผ่านการพิสูจน์มาแล้วนานกว่าสองทศวรรษ ในการนำแพตช์ความปลอดภัยจากเวอร์ชันใหม่ล่าสุดส่งย้อนกลับไปแก้ไขให้กับซอฟต์แวร์เวอร์ชันเก่าที่องค์กรยังใช้อยู่(backporting) เป็นการขยายวินัยทางวิศวกรรมอันเข้มงวดนี้จากระดับระบบปฏิบัติการ ขึ้นไปสู่ระดับแอปพลิเคชันเฟรมเวิร์กและกลุ่ม dependency ที่กว้างขึ้น โดยเริ่มจาก Maven/Java และขยายไปยัง PyPI, npm รวมถึงแพลตฟอร์มอื่น ๆ ต่อไป ด้วยการผสานพลังของ AI ในการประมวลผลภัยคุกคามปริมาณมาก ร่วมกับความเชี่ยวชาญของวิศวกรที่เป็นมนุษย์ ทำให้สามารถเจาะลึกเข้าไปแก้ไข (surgical fixes) บนเวอร์ชันที่มีเสถียรภาพซึ่งองค์กรใช้งานจริงได้อย่างแม่นยำ ช่วยตัดความจำเป็นในการสุ่มอัปเดตเวอร์ชันใหม่แบบสุ่มเสี่ยง ซึ่งอาจทำให้ระบบเสียหายได้ 

หากไม่มีกลไกในการส่งฟิกซ์ (fixes) กลับคืนสู่โครงการต้นทาง (upstream) ทุก ๆ แบ็กพอร์ต (backport) ที่องค์กรพัฒนาขึ้นเองจะกลายเป็นการแยกโค้ดมาทำเองเป็นการภายในอย่างถาวร ซึ่งเป็นโค้ดที่องค์กรต้องคอยดูแลต่อไปในทุกครั้งที่มีช่องโหว่ มีการอัปเดต หรือเกิดความเปลี่ยนแปลงของ dependency ในอนาคต สิ่งนี้จะเพิ่มทั้งต้นทุนและความเสี่ยงให้กับองค์กร แต่ Project Lightwell จะเข้ามาทำลายวงจรนี้ โดยเร้ดแฮทจะเป็นผู้พัฒนาฟิกซ์ส่งมอบให้กับองค์กร และส่งกลับคืนให้กับโครงการโอเพ่นซอร์สต้นน้ำนั้น ๆ ทำให้ฟิกซ์ดังกล่าวกลายเป็นส่วนหนึ่งของซอร์สโค้ดสาธารณะ (public codebase)

ผสานพลังเพื่อปกป้ององค์กรและโลกโอเพ่นซอร์ส 

การรักษาความปลอดภัยซัพพลายเชนของซอฟต์แวร์ถือเป็นความท้าทายร่วมกันของทั้งอุตสาหกรรม ซึ่งไม่มีองค์กรใดสามารถแก้ไขได้เพียงลำพัง Project Lightwell เป็นโซลูชันที่เป็นการร่วมมือกับกลุ่มผู้นำชั้นนำด้านการเงินและโครงสร้างพื้นฐานที่สำคัญ เพื่อจัดตั้งศูนย์กลางการแลกเปลี่ยนข้อมูลระดับองค์กรที่ปลอดภัย

เครือข่ายอัจฉริยะในรูปแบบความร่วมมือนี้ มอบความสามารถสามประการที่ไม่มีองค์กรใดสามารถสร้างขึ้นเองได้โดยลำพัง 

  • ประการแรก สมาชิกจะสามารถแชร์การค้นพบช่องโหว่ใหม่ ๆ และได้รับแพตช์ที่ผ่านการประสานงานร่วมกันก่อนที่จะมีการเปิดเผยสู่สาธารณะ ซึ่งจะเปลี่ยนการค้นพบแบบต่างคนต่างทำเป็นการร่วมกันป้องกัน 
  • ประการที่สอง ทุกแพตช์จะถูกส่งมอบแบบ production-ready ที่มีการทำ cryptographic signature มาคู่กับ machine-readable SBOM และรายงานเตือนภัยด้านความปลอดภัย (security advisories) เพื่อตอบโจทย์ด้านการปฏิบัติตามกฎระเบียบ 
  • ประการที่สามซึ่งสำคัญมากคือ Project Lightwell ดำเนินงานภายใต้หลักการที่ต้องส่งตัวแก้ไขหรือฟิกซ์ (fixes) ที่พัฒนาขึ้น คืนกลับไปยังโครงการโอเพ่นซอร์สต้นทางเสมอ (upstream-always mandate) การทำงานร่วมกันในศูนย์กลางข้อมูลแห่งนี้ จึงไม่ใช่แค่การปกป้องเป็นรายองค์กร แต่เป็นการส่งคืนความก้าวหน้าด้านความปลอดภัยกลับสู่ชุมชนอย่างเป็นระบบ เพื่อช่วยให้โอเพ่นซอร์สปลอดภัยสำหรับทุกคน

โอเพ่นซอร์สเป็นรากฐานของการสร้างองค์กรยุคใหม่ การเฝ้าระวังร่วมกันและ Project Lightwell ช่วยให้โค้ดเหล่านี้ปลอดภัยเสมอด้วยการแก้ไขที่รวดเร็วมากขึ้นภายในชุมชนเดียวกันและเป็นแนวคิดระบบเปิด

บทความโดย นายคริส ไรท์ประธานเจ้าหน้าที่ฝ่ายเทคโนโลยี และรองประธานอาวุโสฝ่ายวิศวกรรมระดับโลกเร้ดแฮท

Red Hat Unites Builders and Operators on the Agentic Future with Major Advancements to Red Hat AI

Red Hat Launches Red Hat AI Enterprise to Deliver a Unified AI Platform that Spans from Metal to Agents

Red Hat Unites Builders and Operators on the Agentic Future with Major Advancements to Red Hat AI

New metal-to-agent capabilities in Red Hat AI provide a foundation for scaling models and autonomous agents across the hybrid cloud

Red Hat, the world’s leading provider of open source solutions, today announced significant advancements across the Red Hat AI portfolio to help bridge the gap between AI experimentation and production-grade operational control. By delivering a unified, metal-to-agent platform, Red Hat AI 3.4 simplifies the development and deployment of agentic workflows, allowing organizations to move beyond pilots to scalable AI across their entire infrastructure.

By providing a consistent framework for both builders and operators, Red Hat provides a foundation for organizations to scale autonomous systems while maintaining the control, security capabilities and hardware efficiency required by the modern enterprise.

What is Red Hat AI 3.4? 

Red Hat AI 3.4 is a comprehensive platform that delivers the architectural foundation and operational tools necessary to scale models and agentic workflows across the hybrid cloud. Central to this release is the delivery of Model-as-a-Service (MaaS), which provides a single, governed interface for developers to access curated models while enabling administrators to track consumption and enforce policies. This builds on a foundation of high-performance distributed inference, powered by vLLM and llm-d, to maintain optimized and efficient model serving across a wide range of environments.

While AI agents drive exponential demand for inference, Red Hat AI provides the capabilities for organizations to deploy and manage agents at scale, regardless of agent framework. Newly introduced AgentOps tools manage agents from development to production with integrated tracing, observability, cryptographic identity and lifecycle management. 

To integrate enterprise data with models and agents, Red Hat AI 3.4 introduces prompt management – treating prompts as first-class data assets – and evaluation hub for assessing model and agent accuracy, quality and safety. These capabilities are powered by MLflow, which provides integrated experiment tracking and artifact management for both generative and predictive AI use cases. The platform empowers users to validate model and agent safety with automated safety testing and red-teaming for models and agents, using technology from Chatterbox Labs and the Garak project to provide a security-forward path from experimental pilots to production-ready enterprise utility.

Why does Red Hat AI 3.4 matter? 

The transition from experimental chatbots to production-grade autonomous systems requires a fundamental shift in how IT teams collaborate. Many organizations now recognize the need to move from being merely “token consumers” to “token providers” to better manage costs and power private, sovereign AI use cases. However, the friction between builders and infrastructure administrators remains a primary hurdle to adoption. Without a unified approach that aligns these two roles, infrastructure access barriers slow innovation while “shadow AI” shortcuts introduce ungoverned risks and unpredictable costs.

Red Hat AI 3.4 helps resolve this tension by providing an enterprise foundation for scalable inference and autonomous agent deployments, delivering the transparency and control required to meet rigorous risk and governance standards. Because agents operate with a level of independence, the lack of visibility into their decision-making creates a critical security risk. Red Hat AI addresses this by providing the infrastructure to trace actions, reasoning steps, and tool calls, making it possible to audit how an agent arrived at an outcome. By integrating cryptographic identity management, the platform ties actions to a verified identity, helping identify which entity performed the task. Together, these capabilities move organizations beyond disconnected pilots to treat AI as a scalable, predictable, and, most importantly, accountable enterprise utility.

What Red Hat and partners are saying

“The agentic era represents an evolution of our platform from running traditional applications to powering intelligent, autonomous systems,” said Joe Fernandes, vice president and general manager, AI Business Unit, Red Hat. “We are defining the open standard for how the enterprise executes AI. By providing a hardened, metal-to-agent foundation for AI inference, MaaS and AgentOps, Red Hat provides the operational assurance organizations need to innovate at scale while maintaining rigorous control.”

“CoreWeave’s collaboration with Red Hat is grounded in a shared commitment to openness and delivering a high-performance inference foundation that allows enterprises to scale their most complex AI workloads,” said Urvashi Chowdhary, Vice President of Product Management – AI Services at CoreWeave. “Together, we’ve delivered a deployment blueprint for Red Hat AI Inference on CoreWeave Kubernetes Service to run the same inference stack on-prem and in the cloud, with Kubernetes-native control and production-grade performance. This enables enterprise AI teams in regulated industries to focus on the important work: building and scaling AI, not retooling their stack for every new environment.”

“Autonomous, long running agents in the enterprise demand a new level of infrastructure control and security to ensure trustworthy operations at scale,” said John Fanelli, Vice President, Enterprise Software, NVIDIA. “Red Hat AI Factory with NVIDIA provides a unified, open source-driven foundation that gives developers and operators the governance and confidence necessary for the agentic future.”

Key takeaways

  • Scalable, high-performance inference meets governed model access: High-efficiency model inference remains the core of production-ready AI. By combining the vLLM inference server and llm-d distributed inference engine with MaaS, Red Hat AI 3.4 provides a reliable and performant foundation for model inference while simplifying governed model access for users and agents.
  • Streamlined AgentOps for the autonomous application lifecycle: Red Hat AI 3.4 introduces comprehensive AgentOps capabilities to help operationalize agents at scale. This includes integrated tracing, observability and evaluations, alongside agent identity and lifecycle management to move agents from development to production.
  • Connecting data to models and agents:  Enterprise data is the fuel that powers models and agents. Red Hat AI 3.4 adds prompt management, treating prompts as first-class data assets, and an evaluation hub for managing evaluations across quality, accuracy, safety, and risk. These capabilities are powered by MLFlow, which also provides integrated experiment tracking and artifact management for both gen AI and predictive AI/ML use cases.
  • Integrated safety and security for models and agents: To help protect the entire AI stack, Red Hat AI delivers a layered security posture that extends from the operating system to the agentic logic. By providing automated safety testing and red-teaming, organizations can take a data-driven approach to model and guardrail selection and configuration, helping to better protect AI workloads against evolving threats.

Deeper details

  • Advanced inference and model optimization: Red Hat AI Inference adds request prioritization to its distributed inference capabilities, allowing interactive and background traffic to share the same endpoint while latency-sensitive requests are processed first under load. Red Hat AI Inference also extends beyond Red Hat OpenShift to additional Kubernetes services, including CoreWeave and Azure, providing organizations a consistent inference stack across environments. Speculative decoding support, now generally available, improves response speeds by 2x–3x with minimal quality impact while lowering the cost per interaction.
  • Governed Model-as-a-Service (MaaS): This feature enables platform engineers to deliver curated, validated models through security-enhanced API endpoints using standard OpenAI-compatible interfaces. This allows for unified governance of both internal models and external APIs, integrated with identity provider (IDP)-based authentication.
  • Integrated prompt management: The platform provides unified tools for building and managing prompts as first-class data assets. Storing the inputs driving models and agents in a central registry provides a single source of truth for both developers and administrators.
  • Automated evaluations for models and agents: Red Hat AI 3.4 introduces evaluation hub, a framework-agnostic unified AI evaluation control plane for evaluating large language models (LLMs), AI applications and agents. This replaces fragmented testing methods with a unified approach to benchmarking quality, accuracy and risk.
  • Multi-layered safety: Automated adversarial scanning is now integrated directly into the development lifecycle. Leveraging technology from Chatterbox Labs, the Red Hat AI platform uses Garak to screen models and agentic systems for risks such as jailbreaks, prompt injections and bias, paired with NVIDIA NeMo Guardrails for run-time safety.
  • Production-ready observability: The integration of MLflow provides visibility into agent execution, enabling end-to-end tracing of LLM calls, reasoning steps, tool execution, model responses, and token usage via OpenTelemetry. This creates a transparent audit trail for the entire lifecycle of prompts, embeddings and RAG configurations to support debugging and auditing. MLFlow also provides integrated experiment tracking and artifact management for gen AI and predictive AI use cases.
  • Identity-based governance: Using cryptographic identity management (SPIFFE/SPIRE), Red Hat AI enables organizations to replace static hardcoded keys with short-lived tokens. This supports least-privilege operations for autonomous agents across the stack and helps confirm that agentic actions are tied to a verified identity.
  • Automated experiences: Tools like AutoRAG and AutoML automate complex AI tasks, ranging from selecting the most effective retrieval strategies for specific datasets to building and optimizing traditional predictive models.
  • Hardware flexibility and managed clouds: Red Hat AI 3.4 delivers day-zero support for NVIDIA Blackwell GPUs and AMD MI325X architectures. By extending this unified platform architecture to run natively on third-party managed clouds – including through the new Red Hat AI Inference on IBM Cloud – Red Hat provides operational consistency across a wide range of hardware and cloud providers.

Availability

Red Hat AI 3.4 is expected to be available later this month.

Red Hat AI เพิ่มศักยภาพครั้งสำคัญ เพื่อผนึกพลังนักพัฒนาและผู้ปฏิบัติงาน สู่โลกอนาคตของ Agentic

Red Hat Launches Red Hat AI Enterprise to Deliver a Unified AI Platform that Spans from Metal to Agents

Red Hat AI เพิ่มศักยภาพครั้งสำคัญ เพื่อผนึกพลังนักพัฒนาและผู้ปฏิบัติงาน สู่โลกอนาคตของ Agentic

metal-to-agent ขีดความสามารถใหม่ใน Red Hat AI มอบรากฐานสำหรับการขยายขอบเขตการทำงานของโมเดลและเอเจนต์อัตโนมัติ ครอบคลุมทั่วทั้งไฮบริดคลาวด์

เร้ดแฮทผู้นำระดับโลกด้านโซลูชันโอเพ่นซอร์ส ประกาศเพิ่มประสิทธิภาพครั้งสำคัญในกลุ่มผลิตภัณฑ์ Red Hat AI เพื่อช่วยปิดช่องว่างระหว่างการทดลองใช้ AI และ การควบคุมการปฏิบัติงานในระดับใช้งานจริงในภาคการผลิต Red Hat AI 3.4 เป็นแพลตฟอร์มรวมศูนย์ที่ครอบคลุมตั้งแต่โครงสร้างพื้นฐานล่างสุดไปจนถึงซอฟต์แวร์อัจฉริยะระดับบนสุดที่ตัดสินใจและทำงานแทนมนุษย์ได้ (metal-to-agent) แพลตฟอร์มนี้ช่วยลดความซับซ้อนในการพัฒนาและติดตั้งใช้งาน agentic workflows ช่วยให้องค์กรเดินหน้าขยายการใช้งาน AI จากโครงการนำร่องไปสู่การใช้งานจริงครอบคลุมทั่วโครงสร้างพื้นฐานขององค์กร

เร้ดแฮทมอบกรอบการทำงานที่เป็นมาตรฐานเดียวกันให้กับผู้พัฒนา (builders) และผู้ปฏิบัติการ (operators) เพื่อเป็นรากฐานให้องค์กรต่าง ๆ ขยายระบบอัตโนมัติ ควบคู่กับการคงความสามารถในการควบคุมและความปลอดภัย รวมถึงประสิทธิภาพของฮาร์ดแวร์ที่องค์กรสมัยใหม่ต้องการ

Red Hat AI 3.4 เป็นแพลตฟอร์มครบวงจรที่มอบโครงสร้างสถาปัตยกรรมและเครื่องมือสำหรับการทำงานที่จำเป็นในการขยายการใช้งานโมเดล และสำหรับเวิร์กโฟลว์ของเอเจนต์ต่าง ๆ บนไฮบริดคลาวด์ โดยมีหัวใจสำคัญคือการให้บริการ Model-as-a-Service (MaaS) ซึ่งเป็นอินเทอร์เฟซการกำกับดูแลหนึ่งเดียวที่ช่วยให้นักพัฒนาซอฟต์แวร์สามารถเข้าถึงโมเดลที่คัดสรรมาแล้ว ในขณะเดียวกันก็ช่วยให้ผู้ดูแลด้านไอทีสามารถติดตามการใช้ทรัพยากรและการบังคับใช้นโยบายต่าง ๆ ได้ แพลตฟอร์มนี้สร้างบนรากฐานของการอนุมานแบบกระจาย (distributed inference) สมรรถนะสูงที่ใช้พลังจาก vLLM และ llm-d เพื่อคงประสิทธิภาพและความเสถียรในการให้บริการโมเดลให้เหมาะสมกับทุกสภาพแวดล้อม

แม้ความต้องการด้านการอนุมานผลจะพุ่งสูงขึ้นมากจากการใช้ AI agents แต่ Red Hat AI มอบขีดความสามารถให้องค์กรสามารถปรับใช้และบริหารจัดการเอเจนต์ได้ตามต้องการ โดยไม่ขึ้นอยู่กับกรอบการทำงานของเอเจนต์ นอกจากนี้เครื่องมือ AgentOps ที่เปิดตัวเมื่อเร็ว ๆ นี้ ยังช่วยบริหารจัดการเอเจนต์ต่าง ๆ ตั้งแต่ขั้นตอนการพัฒนาไปจนถึงการใช้งานจริง ผ่านระบบที่รวมทั้งการติดตาม (tracing) การตรวจสอบสถานะ (observability) การระบุตัวตนด้วยเทคโนโลยีการเข้ารหัส  (cryptographic identity) และการบริหารจัดการไลฟ์ไซเคิลไว้อย่างครบวงจร 

Red Hat AI 3.4 นำเสนอความสามารถในการบริหารจัดการคำสั่ง (พรอมต์: prompt) เพื่อบูรณาการข้อมูลขององค์กรเข้ากับโมเดลและเอเจนต์ต่าง ๆ โดยถือว่าพรอมต์เป็นสินทรัพย์ข้อมูลหลัก และเป็นศูนย์กลางของการประเมินความแม่นยำ คุณภาพ และความปลอดภัยของโมเดลและเอเจนต์ ความสามารถเหล่านี้ขับเคลื่อนด้วย MLflow ซึ่งรองรับการติดตามการทดลองแบบบูรณาการ และการบริหารจัดการชิ้นงานที่ได้จากการพัฒนา (artifact management) ให้ทั้งกับการใช้ generative และ predictive AI แพลตฟอร์มนี้ยังช่วยให้ผู้ใช้สามารถตรวจสอบความปลอดภัยของโมเดลและเอเจนต์ ด้วยการทดสอบความปลอดภัยอัตโนมัติและการทดสอบเจาะระบบ (red-teaming) โดยใช้เทคโนโลยีจาก Chatterbox Labs และโปรเจกต์ Garak เพื่อมอบเส้นทางที่ปลอดภัยในการเปลี่ยนจากโครงการนำร่องไปสู่การใช้งานจริงในระดับองค์กร 

การเปลี่ยนผ่านจากแชตบอตที่อยู่ในขั้นทดลองไปสู่ระบบอัตโนมัติระดับใช้งานจริง จำเป็นต้องปรับเปลี่ยนรูปแบบการทำงานร่วมกันของทีมไอทีอย่างสิ้นเชิง องค์กรหลายแห่งในปัจจุบันตระหนักถึงความจำเป็นในการเปลี่ยนจากการเป็นเพียง “ผู้ใช้โทเคน” (token consumers) ไปสู่การเป็น “ผู้ให้บริการโทเคน” (token providers) เพื่อให้สามารถบริหารจัดการต้นทุนได้ดีขึ้น และรองรับการใช้งาน AI ทั้งที่เป็น private AI และ sovereign AI อย่างไรก็ตาม ช่องว่างในการทำงานระหว่างผู้พัฒนา และผู้ดูแลโครงสร้างพื้นฐาน ยังคงเป็นอุปสรรคสำคัญต่อการนำไปใช้งาน หากขาดแนวทางที่เป็นหนึ่งเดียวในการเชื่อมประสานบทบาทของทั้งสองฝ่ายนี้ อุปสรรคในการเข้าถึงโครงสร้างพื้นฐานจะทำให้การพัฒนานวัตกรรมล่าช้า ในขณะที่การหันไปใช้ทางลัด “shadow AI” จะนำมาซึ่งความเสี่ยงที่ควบคุมไม่ได้ และต้นทุนที่คาดการณ์ไม่ได้ 

Red Hat AI 3.4 ช่วยขจัดช่องว่างดังกล่าวด้วยการวางรากฐานให้องค์กรเพื่อการอนุมานที่ปรับขยายการทำงานได้ และการปรับใช้เอเยนต์อัตโนมัติ พร้อมมอบคุณสมบัติด้านความโปร่งใสและการควบคุมที่จำเป็นเพื่อให้สอดคล้องกับมาตรฐานการกำกับดูแลและมาตรฐานด้านความเสี่ยงที่เข้มงวด เนื่องจากเอเจนต์ทำงานด้วยความเป็นอิสระในระดับหนึ่ง การขาดความสามารถในการมองเห็นความเป็นไปของกระบวนการตัดสินใจจะทำให้เกิดความเสี่ยงด้านความปลอดภัยที่ร้ายแรง Red Hat AI แก้ปัญหานี้ด้วยการมอบโครงสร้างพื้นฐานที่สามารถติดตามการกระทำ ขั้นตอนการให้เหตุผล และการเรียกใช้เครื่องมือต่าง ๆ ทำให้สามารถตรวจสอบได้ว่าเอเจนต์บรรลุผลลัพธ์แต่ละอย่างได้อย่างไร แพลตฟอร์มนี้บูรณาการการระบุตัวตนด้วยการเข้ารหัส ซึ่งจะเชื่อมโยงการกระทำต่าง ๆ เข้ากับข้อมูลประจำตัวที่ผ่านการตรวจสอบแล้ว ช่วยให้ระบุได้ชัดเจนว่าหน่วยงานใดเป็นผู้ปฏิบัติงานนั้น ๆ ขีดความสามารถทั้งหมดที่กล่าวมานี้ช่วยพาองค์กรก้าวหน้าไกลกว่าการเป็นเพียงโปรเจกต์นำร่องที่กระจัดกระจาย แต่ก้าวไปสู่การใช้ AI เหมือนเป็นหนึ่งในระบบสาธารณูปโภคขององค์กรที่ขยายการทำงานได้ คาดการณ์ได้ และที่สำคัญที่สุดคือมีความสามารถในการตรวจสอบย้อนกลับเพื่อให้มีผู้รับผิดชอบต่อการตัดสินใจของ AI

คุณโจ เฟอร์นันเดส รองประธานและผู้จัดการทั่วไปหน่วยธุรกิจ AI ของเร้ดแฮท กล่าวว่า “ยุคแห่งเอเจนติก เป็นยุคที่แพลตฟอร์มของเราวิวัฒนาจากการรันแอปพลิเคชันแบบดั้งเดิม ไปสู่การขับเคลื่อนระบบอัจฉริยะที่ทำงานได้ด้วยตนเอง เรากำลังกำหนดมาตรฐานเปิดให้กับวิธีการที่องค์กรจะนำ AI ไปใช้งานจริง เร้ดแฮทวางรากฐานที่แข็งแกร่งตั้งแต่ระดับฮาร์ดแวร์ไปจนถึงเอเจนต์ (metal-to-agent) ให้กับระบบ AI Inference, MaaS และ AgentOps มอบความมั่นใจในเชิงปฏิบัติการที่องค์กรต้องการ เพื่อสร้างสรรค์นวัตกรรมในวงกว้างควบคู่กับการรักษาอำนาจในการควบคุมที่เข้มงวด 

คุณเออร์วาชิ เชาธารี รองประธานฝ่ายบริหารจัดการผลิตภัณฑ์ – บริการด้าน AI ของ CoreWeave กล่าวว่า “ความร่วมมือระหว่าง CoreWeave และ Red Hat มีพื้นฐานมาจากความมุ่งมั่นร่วมกันในด้านระบบเปิดและการส่งมอบรากฐานการอนุมานผลประสิทธิภาพสูง เพื่อช่วยให้องค์กรสามารถขยายการใช้เวิร์กโหลด AI ที่ซับซ้อนที่สุดได้ เราได้ร่วมกันส่งมอบพิมพ์เขียวการปรับใช้ Red Hat AI Inference บน CoreWeave Kubernetes Service เพื่อรันชุดคำสั่งในการอนุมานผลเดียวกันได้ทั้งในระบบที่อยู่ในองค์กร (on-premise) และบนคลาวด์ ด้วยระบบควบคุมแบบ Kubernetes-native และประสิทธิภาพระดับใช้งานจริง (production-grade) ซึ่งช่วยให้ทีม AI ขององค์กรที่อยู่ในอุตสาหกรรมที่มีการกำกับดูแลเข้มงวดสามารถมุ่งเน้นไปที่งานสำคัญ เช่น การสร้างและขยายการใช้ AI โดยไม่ต้องเสียเวลาปรับเครื่องมือใหม่ทุกครั้งที่เปลี่ยนสภาพแวดล้อมการใช้งาน”

คุณจอห์น ฟาเนลลี รองประธานฝ่ายซอฟต์แวร์องค์กรของ NVIDIA กล่าวว่า “ในยุคที่เอเจนต์ที่ทำงานอัตโนมัติต่อเนื่องยาวนานเข้ามามีบทบาทในองค์กร องค์กรจำเป็นต้องมีระบบควบคุมโครงสร้างพื้นฐานและความปลอดภัยระดับใหม่ เพื่อให้มั่นใจได้ว่าการดำเนินงานในวงกว้างนั้นมีความน่าเชื่อถือ Red Hat AI Factory with NVIDIA มอบรากฐานหนึ่งเดียวที่ขับเคลื่อนด้วยโอเพ่นซอร์สที่ช่วยให้นักพัฒนาและฝ่ายปฏิบัติการมีระบบการกำกับดูแลและมีความมั่นใจที่จำเป็นต้องใช้ในอนาคตในยุคแห่งเอเจนติก” 

ประเด็นสำคัญ

  • การอนุมานผลที่ทรงพลังและขยายได้ และการเข้าถึงโมเดลที่มีการกำกับดูแล: การอนุมานผลโมเดลที่มีประสิทธิภาพสูงยังคงเป็นหัวใจสำคัญของ AI ในระดับใช้งานจริง ซึ่งการรวมเอา vLLM inference server และ llm-d distributed inference engine เข้ากับบริการ MaaS ทำให้ Red Hat AI 3.4 มอบรากฐานการอนุมานผลโมเดลที่เสถียรและมีประสิทธิภาพ ในขณะเดียวกันก็ช่วยให้ผู้ใช้งานและเอเจนต์ต่าง ๆ เข้าถึงโมเดลที่มีการกำกับดูแลได้อย่างไม่ยุ่งยาก
  • AgentOps ที่คล่องตัวเพื่อไลฟ์ไซเคิลของแอปพลิเคชันอัตโนมัติ: Red Hat AI 3.4 นำเสนอขีดความสามารถด้าน AgentOps ที่ครอบคลุม เพื่อช่วยให้นำเอเจนต์ไปใช้งานจริงในวงกว้างได้อย่างมีประสิทธิภาพ ซึ่งรวมถึงระบบการติดตามการทำงาน (tracing) การเฝ้าสังเกต (observability) และการประเมินผล (evaluations) ที่ผสานรวมมาให้ในตัว ควบคู่ไปกับการจัดการตัวตนและการบริหารไลฟ์ไซเคิลของเอเจนต์ เพื่อขับเคลื่อนการเปลี่ยนผ่านเอเจนต์จากขั้นตอนการพัฒนาไปสู่การใช้งานจริง
  • การเชื่อมโยงข้อมูลเข้ากับโมเดลและเอเจนต์: ข้อมูลขององค์กรคือเชื้อเพลิงที่ขับเคลื่อนโมเดลและเอเจนต์ Red Hat AI 3.4 ได้เพิ่มระบบการจัดการพรอมต์ เพื่อยกระดับให้พรอมต์เป็นสินทรัพย์ข้อมูลที่มีความสำคัญลำดับต้น ๆ พร้อมด้วยศูนย์กลางการประเมินผลสำหรับบริหารจัดการการทดสอบทั้งในด้านคุณภาพ ความแม่นยำ ความปลอดภัย และความเสี่ยง ขีดความสามารถเหล่านี้ขับเคลื่อนโดย MLFlow ซึ่งรองรับทั้งการติดตามการทดลอง และการบริหารจัดการชิ้นงานที่ได้จากการพัฒนา (artifact management) ที่ครอบคลุมทั้งการใช้งานในรูปแบบ generative AI และ predictive AI/ML 
  • ความปลอดภัยและความมั่นคงแบบครบวงจรสำหรับโมเดลและเอเจนต์: เพื่อช่วยปกป้องโครงสร้างพื้นฐาน AI ทั้งระบบ Red Hat AI นำเสนอการรักษาความปลอดภัยแบบเป็นลำดับชั้น (layered security posture) ที่ครอบคลุมตั้งแต่ระดับระบบปฏิบัติการไปจนถึงตรรกะการทำงานของเอเจนต์ การจัดให้มีการทดสอบความปลอดภัยแบบอัตโนมัติและการจำลองการโจมตี (red-teaming) ช่วยให้องค์กรสามารถใช้แนวทางที่ขับเคลื่อนด้วยข้อมูลในการคัดเลือกและตั้งค่าโมเดลรวมถึงระบบป้องกัน (guardrail) ซึ่งช่วยให้ปกป้องเวิร์กโหลด AI จากภัยคุกคามที่เปลี่ยนแปลงตลอดเวลาได้ดีขึ้น 

การวางตลาด

คาดว่าจะวางตลาด Red Hat AI 3.4 ในช่วงปลายเดือนพฤษภาคม

Red Hat Delivers Post-Quantum Readiness and AI-Powered Automation with Latest Versions of Red Hat Enterprise Linux

Red Hat Launches Red Hat AI Enterprise to Deliver a Unified AI Platform that Spans from Metal to Agents

Red Hat Delivers Post-Quantum Readiness and AI-Powered Automation with Latest Versions of Red Hat Enterprise Linux

Red Hat Enterprise Linux 10.2 and 9.8 provide a unified foundation for the hybrid cloud designed to address emerging security challenges, featuring advanced AI assistance, quantum-resistant cryptography and streamlined upgrade paths.

Red Hat, the world’s leading provider of open source solutions, today announced the upcoming general availability of Red Hat Enterprise Linux 10.2 and 9.8. Building on the innovation of Red Hat Enterprise Linux 10, the latest versions help address modern security threats, speed AI innovation and minimize operational drift.

What Red Hat announced

Red Hat Enterprise Linux 10.2 and 9.8 provide a strategic and durable operating system (OS) platform that unifies IT operations across the hybrid cloud with security in mind. By enhancing confidential computing capabilities in the OS foundation, Red Hat provides a trusted environment for AI workloads, helping to protect sensitive data while it’s being processed in memory and CPU. Other security features like post-quantum cryptography and sealed images, a new technology preview capability enabled by image mode, further support this trusted foundation for critical production workloads. Additionally, AI-guided automation smooths complex upgrades and image mode enhancements boost workflow innovation.

Why it matters

The gap between traditional system reliability and IT breakthroughs like AI and quantum computing continues to widen as infrastructure evolves toward autonomous systems and faster, container-based image workflows. Red Hat Enterprise Linux 10.2 and 9.8 provide the operational guardrails and precision management to address these needs, helping to deliver innovation without compromising security or sovereignty. The latest versions of the world’s leading enterprise Linux platform strengthen system security in the face of quantum threats and automate the time-consuming and stressful upgrade process, reducing manual maintenance and enabling IT teams to focus on supporting strategic high-value architecture. Customers can also gain greater choice and control over hardware-rooted security with sealed images, enabling customers to sign container images at build-time so that systems only start verified, trusted images chosen by the customer.

What Red Hat is saying

“Red Hat Enterprise Linux 10.2 and 9.8 directly address the balancing act between the speed of AI innovation and the rigors of enterprise security, turning complex operational hurdles into automated, repeatable processes,” said Gunnar Hellekson, vice president and general manager, Red Hat Enterprise Linux, Red Hat. “By integrating post-quantum cryptography and AI-driven upgrade tools, we’re helping our customers confidently push into computing’s future with defenses against emerging threats and the ability to consistently and reliably scale AI workloads across the hybrid cloud.”

Key takeaways

  • A new era of foundational security: Red Hat helps prepare systems against emerging threats in quantum computing with post-quantum cryptography, integrating National Institute of Standards and Technology (NIST) standards. Confidential computing protects sensitive workloads, shielding data and configuring AI to support organizations in using sensitive data in the cloud while addressing privacy requirements.
  • AI-assisted automation and upgrades: Red Hat bridges admin skills gaps with Red Hat Ansible Certified Content and the Red Hat Enterprise Linux upgrade system role, automating complex in-place upgrades by packaging accumulated best practices into a “fail fast then iterate” approach to reduce downtime and limit human error.
  • Accelerated delivery with image-based workflows: Image mode enhancements drive consistency in building, deploying and managing Red Hat Enterprise Linux using container technologies, helping to contain system drift and maintain control over maintenance schedules.

Deeper details: Building the intelligent foundation

Red Hat Enterprise Linux 10.2 and 9.8 are engineered to reduce the friction between modern development and mission-critical operations:

  • Future-ready security: Red Hat Certificate System 11.0, available alongside Red Hat Enterprise Linux, introduces quantum-resistant signatures to help organizations meet emerging NIST standards and resist “harvest now, decrypt later”.
  • Boost visibility against threats: Red Hat and CrowdStrike customers have access to over 2,300 new malware signatures, enhancing malware detection and enabling a more proactive security posture.
  • Solve issues faster: Model Context Protocol (MCP) servers for Red Hat Satellite (technology preview), Red Hat Enterprise Linux (developer preview) and Red Hat Lightspeed (developer preview), offer an AI-ready approach to Linux management. AI agents can securely tap into real-time Linux data, so administrators can manage Red Hat Enterprise Linux systems using natural language and automated, multi-step workflows backed by safety guardrails.
  • Address IT skills gaps: goose, an open source agent, is now available in the extensions repository to connect multiple MCP servers into a single command-line assistant, helping IT teams transition from manual troubleshooting to high-velocity, automated infrastructure management with confidence and precision.
  • Accelerate innovation, govern integrity: Red Hat Satellite 6.19 strengthens sovereign control with general availability of local vulnerability triage for air-gapped environments and introduces AI-assisted troubleshooting via the MCP server for Satellite, which is all supported by an optional extra 12 months of Extended Update Support (EUS) for long-term operational security.
  • AI-assisted automated upgrades: Deploying Red Hat Enterprise Linux best practices for in-place OS upgrades is simplified with the introduction of a new Red Hat Enterprise Linux upgrade system role, available as a Red Hat Ansible Certified Content Collection, and secure self-service upgrades using Ansible Automation Platform for a smoother and more reliable experience.
  • Pre-download updates with image mode: To enhance control over large-scale Red Hat Enterprise Linux estates, administrators can download platform updates without immediate application, allowing them to determine when and how to apply these patches to better manage system uptime.

Availability

Red Hat Enterprise Linux 10.2 and 9.8 is planned to be available in the near future. Red Hat Satellite 6.19 is now generally available.

Connect with Red Hat