---
title: "Features | Ubuntu Core\n    | Ubuntu"
description: Explore Ubuntu Core's IoT features like strict confinement, 15 year updates,
  real-time, low-touch recovery, FDE, secure boot, fleet management and more.
url: https://ubuntu.com/core/features?format=md
keywords: index, follow
---

# Ubuntu Core features

A minimal and secure OS for IoT, devices, and embedded systems.

---

[Try Ubuntu Core](https://ubuntu.com/core/docs/getting-started)
[Read the Ubuntu Core datasheet](https://pages.ubuntu.com/rs/066-EOV-335/images/Ubuntu_Core_4_pager_DS_revised_may_2024.pdf?version=0)

---

## Security

### [Strict confinement ›](https://snapcraft.io/docs/snap-confinement)

Build on top of a whole new armory of Linux security capabilities to ensure strict confinement. Leverage a clean separation between the kernel, OS image and the developers’ applications, providing a secure and immutable OS.

### [Full disk encryption ›](https://ubuntu.com/core/features/full-disk-encryption)

Disks are locked with private key-based cryptography. Private keys for hardware, TPM and other layers are securely stored. Symmetric key encryption is enabled by the use of specialized software-enabled stores.

### [Secure boot ›](https://ubuntu.com/core/features/secure-boot)

Each component in the boot sequence cryptographically validates the authenticity of the subsequent component. Every component is measured before it’s loaded in the runtime memory space.

---

## Updates

### [OTA update control ›](https://ubuntu.com/core/features/ota-updates)

Over-the-air (OTA) updates guarantee secure and stable software in any location. You decide which updates are signed, certified, and delivered to your devices. Plus, Ubuntu Core keeps the last working boot so you always have a safety net.

### [Device management ›](https://ubuntu.com/internet-of-things/management)

Landscape delivers comprehensive management capabilities across the full scope of your device fleets. Stay in control with features including canary releases, remote device remodelling, and system monitoring.

### [Validations sets ›](https://snapcraft.io/docs/validation-sets)

Validation sets guarantee the installation of required applications with fine-grained permissions. What’s more, you can update applications consistently and simultaneously, improving out-of-the-box experience for end-users.

---

## Operations

### [Low-touch recovery ›](https://ubuntu.com/core/features/recovery)

Ubuntu Core offers a recovery mode that can be activated manually when booting, or remotely via an API call. It additionally offers a graphical user interface to manage recovery options. Configuration settings are backed up in the recovery system.

### [Real-time systems ›](https://ubuntu.com/real-time)

The real-time kernel integrates the PREEMPT\_RT patchset to reduce kernel latencies as required by the most demanding workloads, guaranteeing a time-predictable task execution.

### [Device remodelling ›](https://ubuntu.com/core/docs/remodelling)

Ubuntu Core’s remodelling feature enables you to change any of the elements of your device’s model assertion. Brand, model, IoT App Store ID, or version can be changed to simplify device rebranding for resellers.

---

## What's under the hood

Ubuntu Core is ideal for embedded devices because it manages itself. Snaps, Snapd, and Snapcraft bring security and robustness. Applications are easy to install, easy to maintain, and easy to upgrade.

---

* Snaps
* Snapd
* Snapcraft
* Ubuntu-image

Snaps
Snapd
Snapcraft
Snapcraft

Ubuntu Core is built from snaps, a secure, confined, dependency-free, cross-platform Linux packaging
format. Snaps are entirely self-contained, even to the point of encapsulating their own file system. This
means they include everything they need to run in any environment. They're used by Ubuntu Core to both
compose the image that's run on a device, and to deliver consistent and reliable software updates, even to
low-powered, inaccessible, and remotely administered embedded and IoT systems.

---

[Learn more about Snaps ›](https://ubuntu.com/core/docs/snaps-in-ubuntu-core)

Snapd is the background service that manages and maintains installed snaps. Alongside its various service and
management functions, snapd:

* Provides an API used to install and remove snaps and interact with snaps
* Implements confinement policies that isolate snaps from the base system and
  from other snaps
* Governs the interfaces that allow snaps to access specific system resources
  outside of their container
* Integrates with [Landscape](https://ubuntu.com/landscape) for advanced fleet management

---

[Learn more about Snapd ›](https://github.com/snapcore/snapd)

Snapcraft is a powerful and easy to use tool for building and publishing snaps. It helps you:

* Build and then publish your snaps to your IoT app store
* Fine version control of updates and releases
* Build and debug snaps within a confined environment
* Update and iterate over new builds without rebuilding the environment
* Test and share your snaps locally

---

[Learn more about Snapcraft ›](https://snapcraft.io/docs/snapcraft-overview)

Ubuntu-image is your tool to generate bootable Ubuntu Core images for your application and targeted hardware.
With Ubuntu-image, you can:

* Build production-ready images from a model assertion
* Specify sets of snaps, including fixed revisions, that must be installed
* Dynamically customize and modify snap selection at build time
* Optimize image boot speed by pre-installing and initializing specific snaps

---

Ubuntu-image can be installed on a snap-supporting Linux system as follows:

[Learn how to create your image ›](https://ubuntu.com/core/docs/image-building)

---

## Tamper-resistant and hardened

Ubuntu Core simplifies your security compliance

You need to know your software is pristine; not just for installation, but for the lifetime of the device. Immutable packages and persistent digital signatures mean that Ubuntu Core can verify any software component at any time, to guard against corruption and attack.

Comply with cybersecurity requirements and build a reliable business.

---

[Read our Ubuntu Core security deep dive whitepaper ›](https://assets.ubuntu.com/v1/2566b90c-ubuntu_core_security_whitepaper_2.pdf)

---

## Learn more about Ubuntu Core

* ### Docs

  [Start your Core journey today](https://ubuntu.com/core/docs/getting-started)
* ### Video

  [Introduction to Ubuntu Core](https://www.youtube.com/watch?v=zf9bapbzb8o)
* ### Whitepaper

  [Embedded Linux: make or buy?](https://ubuntu.com/engage/embedded-linux-make-or-buy/)

---

## Ready to innovate?

Whether you are a startup bringing your concept to market or already have large fleets of devices deployed in the field, we have the expertise and infrastructure to launch and support you.

---

[Get in touch](https://ubuntu.com/core/contact-us)
