NiceOS
NICE.OS is a locally developed next-generation cloud operating system. It is not a rebuilt distribution but an OS built from scratch with minimalism, security, and performance in mind.
It is designed specifically for container infrastructure and virtualized environments, where everything runs in Docker, Podman, and Kubernetes.
The system is totally headless: no X11, Wayland, or excessive services for a lightweight, fast, and secure build.
Two control modes
NICE.OS offers equal convenience both for classic servers and Kubernetes/DevOps infrastructure.
- Classic RPM: Familiar package-based workflow and compatibility with corporate applications.
- OSTree: Atomic updates of the whole system and instant rollbacks.
NICE.OS key benefits
- Lightning-fast boot: Minimal set of components and optimized init.
- Container-centric design: Built-in support for Kubernetes, Docker, Podman, and OCI containers.
- Security by default: SELinux, minimum attack surface, and regular updates.
- Cloud optimization: Efficient utilization of Yandex Cloud resources.
- Reliability: Atomic updates and reproducible builds.
- Locally developed solution: Independence, quality control, and GOST-compliant cryptography (GnuPG, OpenSSL, libksba, kernel).
For whom
- DevOps and SRE teams building Kubernetes clusters and CI/CD.
- Startups and businesses with microservice architecture.
- State-owned and corporate organizations looking for security and GOST compliance.
- IoT and edge projects where compact design and fault tolerance are critical.
Philosophy
NICE.OS = Minimum extras → Maximum performance, security, and ease of use.
This is not a fork or a clone but an independent domestic product engineered for clouds, containers, and virtualized environments.
NICE.OS vs. CentOS and Ubuntu
- NICE.OS is a state-of-the-art cloud OS with atomic updates (OSTree), built-in container support, GOST compliance, and domestic origin. Great choice for DevOps, Kubernetes, CI/CD pipelines, government agencies, and cloud environments.
- CentOS is a stable but increasingly outdated classic. Well-suited for legacy systems and conservative server applications but no longer relevant for clouds.
- Ubuntu is a flexible and popular general-purpose distribution. Perfect for development and fast-growing startups but less predictable in enterprise and not GOST compliant.
| Characteristic | NICE.OS | CentOS 7 / Stream | Ubuntu Server (LTS) |
|---|---|---|---|
| Main purpose | Clouds, containers, virtualization, DevOps | Classic servers, corporate environments | Versatile server, development, clouds |
| Architecture | Headless, minimalistic, container-centric | Traditional server distribution | Versatile distribution (features GUI and server mode) |
| Package management | RPM + OSTree (atomic updates) | RPM (via yum/dnf) | DEB (via apt) |
| Updates | Atomic, predictable, can be rolled back | Conservative (CentOS 7), rolling (Stream) | Frequently updated, LTS every two years |
| Containers | Built-in Docker, Podman, Kubernetes | Limited docker support | Docker, LXD, Kubernetes (via Snap) |
| Performance | Lightweight, no GUI, fast init | Heavier and older stack | Versatile, more superfluous services |
| Security | SELinux, minimal attack surface, GOST | SELinux but with an old package stack | AppArmor, SELinux (partially), non-GOST |
| Domestic support | Fully Russian-made | No | No |
| Cloud optimization | Optimized for Yandex Cloud, vSphere, AWS, Azure | More for baremetal and on-prem | Actively used in AWS, Azure, and GCP |
| GOST compliance | Built-in | No | No |
| Lifecycle | Modern, independent | CentOS 7: EOL 2024, Stream: unstable | LTS: 5-years, Extended: up to 10 years |
| For whom | DevOps, government agencies, clouds, IoT | Admins, legacy systems, “classic” | Developers, startups, cloud services |
Security by default
NICE.OS Cloud for Yandex Cloud is delivered as a hardened image by default: Linux Audit (audit=1, active auditd) is on for security event logging and compatibility with container policies. If Podman is installed, the SELinux environment (policies, utilities) gets engaged, and the system operates in SELinux permissive mode, where contexts and rules are ready, violations are logged, and roles/profiles transition to enforcing mode deliberately without the risk of “ruining” the initial deployments or CI/CD.
The network perimeter follows the “closed until opened” principle: the firewall is configured to allow inbound connections only via SSH (port 22), blocking all other traffic, whereas the services open up manifestly on a per-task basis. At the same time, the system does not function as a router: IPv4/IPv6 forwarding is off to prevent the VM from becoming a transit node and to ensure predictable network behavior in a public cloud.
A number of hardening parameters are used in the kernel and network stack: maximum ASLR (kernel.randomize_va_space=2), kernel address hiding (kernel.kptr_restrict=2), ban on reading dmesg for non-root users, disabled sysrq, restricted ptrace (Yama), disabled core dumps for setuid/setgid, enabled protection against symlink/hardlink attacks, anti-spoofing (rp_filter), disabled ICMP redirects and source routing, and anti-SYN-flood measures (syncookies and backlog settings). The result is a secure, headless cloud OS with a minimal attack surface and container-ready architecture.
Certification
Registry entry No. 30128 dated October 22, 2025 based on the order of the Ministry of Digital Development, Communications and Mass Media of the Russian Federation dated October 22, 2025, under Minutes of the Expert Council meeting No. 872pr dated October 09, 2025.
-
Create a cloud network and a subnet to host the virtual machine (VM).
-
In the new cloud network, create a security group and configure the rules for VM connections over SSH:
Traffic direction Description Port range Protocol Source / Destination CIDR blocks IngressSSH22TCPCIDR0.0.0.0/0EgressAny Egress0-65535AnyCIDR0.0.0.0/0 -
Get an SSH key pair for connection to the VM.
-
Create a VM from a public image:
-
Under Boot disk image on the Marketplace tab, select the NICE.OS image.
-
Under Network settings, select the network, subnet, and security group you created earlier.
-
Under Access:
- Enter the username in the Login field.
- In the SSH key field, select from the list the SSH key you got earlier.
-
-
Connect to the VM over SSH. Use the username you set when creating the VM and the private SSH key you created earlier.
- Running Kubernetes clusters and CI/CD systems.
- Lightweight and secure VM images for microservices.
- Power-efficient edge platforms (IoT gateways and industrial solutions).
- Critical systems that require predictability and security compliance.
- Cloud and data center infrastructures relying on sparing use of resources and reproducible environments.
NICE SOFT LLC
Free community support in the official Telegram channel:
- NICE.OS community’s official Telegram channel.
- Help from developers and users: environment setup, best practices, and tips.
- Opportunity to share your experience and contribute to the project.
When requesting support, please specify your image version, environment (cloud or bare metal), and describe the issue.
The OS vendor provides paid technical support for the NICE.OS operating system itself.
This includes system setup, maintenance, and administration on your servers or in the cloud (including Yandex Cloud).
Write to support@niceos.ru and tell us what you need. We will propose the optimal maintenance format — from a one-time consultation to full administration.
Yandex Cloud
Yandex Cloud does not provide support for this product. If you have any issues, please refer to the vendor’s information resources.