CERN is changing how it chooses operating systems for the computers that run its accelerators. By the end of 2026, it plans to move more than 2,200 front-end computers to Debian 13, and dozens were already running it at the time of a talk on August 30. That target comes from Debian's official news and the presentation materials from the August 30 talk. However, this is not a change to CERN's entire IT environment. It covers the lower layer that sits next to the electronics, reads signals, and controls the accelerators through electronic boards.

The strongest driver of the move is compatibility with existing hardware. To meet the minimum CPU instruction requirements of newer operating systems, CERN would otherwise have to redesign even control-system boards that still work. It wants to avoid that by separating the OS maintenance deadline from the lifetime of the equipment on site. For facilities that involve shutting down accelerators, rewiring, and recommissioning, swapping a CPU is not a simple fix.

As of 2023, CERN had announced a policy of using RHEL 9 for the upper-level operator consoles and high-availability servers, and Debian for the lower-level control computers closer to embedded systems. The design decided in that paper is now moving into implementation.

AD

Choosing an OS That Doesn't Force Control Computers to Be Replaced

Accelerator control is not monolithic. In CERN's materials, it is divided into three layers: operator consoles used by people, intermediate servers requiring high availability, and front-end computers connected to electronic boards. The control computers at the end of the chain monitor status in real time and pass instructions to the equipment. The PCs there differ from ordinary office terminals: the boards, the wiring, and even the drivers that run them are part of the facility.

CERN also began its move to CentOS 7 in 2014, spent two years on validation, and put it into operation in 2016. According to the paper, that environment ran stably for seven years. However, the five-year lifespan of CentOS Stream is hard to align with accelerator operating schedules. The point at which an OS reaches end of maintenance does not necessarily coincide with the point at which a facility can be safely shut down.

So CERN dropped the assumption that the upper and lower layers must run the same OS. The upper layer continues to use RHEL 9, while the lower layer moves toward Debian. CERN has built its tooling around Ansible for configuration management and LUMENS and systemd for service management, so that it is not tied to any particular distribution. Common management tools like these are the groundwork for running multiple operating systems in parallel.

The scope is also clear. CERN's Linux service states that it supports Debian only for accelerator front-end systems. There is no plan to change the standard OS for desktops, laptops, or data centers to Debian. The explanation of the support scope also serves as a boundary that keeps this decision from being read as a lab-wide OS migration.

CPU Minimum Requirements Change Which Machines Remain Usable

The paper CERN published in 2023 pointed out that changes to RHEL's CPU requirements would require replacing even properly functioning control hardware and the related PCI cards. An OS update triggers a facility update. To stop that chain, CERN chose a different distribution for the control computers alone.

CPU instructions are the basic operations that software has the CPU execute. Red Hat set x86-64-v2 as the minimum baseline for RHEL 9. This level includes SSE4.2 and others, and programs that use newer instructions may not run on older CPUs. For RHEL 10, the minimum requirement for the AMD/Intel 64-bit edition moves up to x86-64-v3, which adds AVX2 and more. This can be confirmed in the RHEL 9 documentation and the RHEL 10 release notes. The issue is not whether the clock speed is sufficient, but whether the CPU can execute the instructions used by the distributed programs.

Distribution Minimum CPU instruction level for AMD/Intel 64-bit edition
RHEL 9 x86-64-v2
RHEL 10 x86-64-v3
Debian 13 amd64 x86-64-v1

This shows the difference in the minimum required CPU instructions; it is not a comparison that guarantees compatibility for entire devices.

Debian's package information lists the amd64 baseline for Debian 13 as x86-64 psABI v1. When actually deploying to control computers, testing that combines the on-site electronics and software will still be needed.

A Q2 2023 estimate in the August 30 slides puts the cost of the updates needed to stay on RHEL at 5.4 million Swiss francs. It would involve redesigning about 11 boards, as well as hiring staff, rewiring, and recommissioning. This is a budget estimate for continuing with RHEL, not a record of savings achieved through the Debian migration. The presentation materials show plainly why CPU instruction requirements cannot be treated as purely an OS matter.

Red Hat also has technical reasons for raising its minimum requirements. According to the company, earlier optimizations were applied to specific libraries and functions, and the remaining code could not make full use of newer CPU features. Raising the assumptions for the entire distributed software stack allows new instructions to be used broadly. CERN's choice does not categorically reject that approach. It reflects a judgment that, in an environment where each facility has its own dedicated electronics, the benefit of continuing to use existing, validated equipment outweighs the benefit of using new CPU features.

AD

How Debian Differs from Linux

Debian and RHEL are both Linux distributions. Linux, however, refers to the kernel at the core of the OS, while Debian combines it with GNU's basic tools, applications, the APT package manager, and more, and distributes the result as a unit for use and maintenance. This distinction, explained in Debian's introduction, is practically relevant to understanding CERN's choice. Even when the kernel is Linux-based in both cases, which CPU instructions are assumed, how long maintenance lasts, and how packages are updated differ by distributor.

Debian is a project started by Ian Murdock in August 1993, and its name derives from the names Debra and Ian. It chose to build and maintain software through open, collaborative work, and it has grown into a distribution that users can keep using over the long term. When Debian says "free," it refers not to price but to the freedom to use, modify, and distribute software. For CERN, what matters is that there is a distribution that supports existing hardware and lets it assemble the parts it needs to suit its facilities.

That said, Debian does not mean every old device can be kept. In Debian 13, i386 is limited to a supporting architecture for running 32-bit software on amd64. The ability to use older 64-bit CPUs should not be mistaken for blanket maintenance of 32-bit-only machines. The Debian 13 release information shows that there are boundaries to both compatibility and maintenance.

Building Distribution and Maintenance Mechanisms Before Switching the OS

The control computers run diskless and boot from the network. According to CERN's presentation materials, the Linux kernel is separated from the distribution, and the configuration incorporates real-time patches and the necessary drivers. It does not end with installing Debian: it is a design in which the kernel and peripheral software needed for the accelerators are maintained separately from the distribution's updates.

That work extends to the package pipeline. CERN uses Koji and RPMCI to build Debian packages in parallel with RPMs. Development teams add Debian package definitions and build settings, so software can be prepared alongside the existing RPM-oriented workflow. The Koji guide also states that, apart from the exception for front-end computers, Debian is not an actively supported target. Precisely because CERN limited the scope rather than broadly replacing standard services, it has to take on the maintenance of the exception.

Beyond these distribution tasks, the maintenance CERN bears also includes keeping its own drivers and the network-boot environment. Simply receiving general-purpose update packages is not enough to maintain the parts specific to the facilities. Even if equipment replacement can be curbed, the operational workload does not disappear.

AD

Aligning OS Lifespans with Accelerator Operating Schedules

What CERN is trying to avoid this time is a situation where a distribution's lifespan runs out first and forces facility renovation schedules to be moved up. Regular maintenance for CentOS 7 has already ended. The 2023 paper pointed out the problem of OS maintenance ending in the middle of a physics experiment's operating period. Beyond hardware compatibility, maintenance schedules must also be aligned.

Debian 13, released on August 9, 2025, has regular support until August 9, 2028, followed by long-term support (LTS) until June 30, 2030. The supported architectures are narrower during the LTS period, however. Migrating at the end of the year does not in itself cover the entire remaining lifetime of the facilities.

CERN's basic plan is to use Debian 13 until 2030 and move to Debian 15 in that year. There is also an alternative of operating through 2033 with extended LTS (ELTS), and CERN says it has begun supporting Freexian. This is not a commitment that fixes the specifications of future versions; it is a plan that prepares both a path of updating and a path of using extended maintenance.

The goal of moving more than 2,200 machines by year-end will be a major milestone for gauging whether this plan works in the field. Beyond that lies the work of supporting running facilities while advancing validation for the 2030 OS update. If CERN can sustain operations in which it can choose among multiple distributions, it can make its accelerator renovation schedules less susceptible to the policies of any particular distributor.