Ubuntu 24.04 LTS Minimal | Support by cloudimg
by cloudimg
Ubuntu 24.04 on Canonical's Minimal seed: 342 fewer packages, hardened, fully patched.
Ubuntu 24.04 LTS on Canonical's Minimal package seed
Ubuntu Server 24.04 LTS (Noble Numbat) is a long-term-support release with security maintenance through 2029. This image differs from the standard 'Ubuntu Server 24.04 LTS' image in one deliberate way: the package profile. The installed set is trimmed to Canonical's own published Ubuntu Minimal cloud-image seed — the package set Canonical themselves define as Minimal — plus the Azure provisioning stack. Measured at capture on this exact image: 664 packages on the standard image, 322 on this one (342 fewer), a dpkg payload 902 MiB smaller, and a root filesystem over a gigabyte leaner.
A measured trim, not a marketing claim
The trim is one guarded, simulated-first package transaction, and the provisioning path is on the guard's protected list: cloud-init, the Azure Linux agent, OpenSSH, netplan, the Azure kernel flavour and its initramfs boot chain cannot be removed by construction. The image ships its own evidence at /usr/share/cloudimg/ubuntu-24-04-minimal.manifest — a manifest derived from the package database at capture, stating exactly what is installed, what was removed, and what that means (no man command, no full-screen editor, no classic cron, no NFS client — each restorable with a single apt install, spelled out in the file).
Why a minimal base
Fewer installed packages means a smaller attack surface, fewer packages to patch, scan and audit, faster update runs and faster boots. The root layout stays the standard flat partition, so cloud-init auto-grows the root filesystem at first boot on larger OS disks — deploy on 64 GiB and the root is 61G before you first log in, no manual steps.
Hardened and current at capture
Every available security update is applied at build time and an automated gate blocks capture if any update remains outstanding. unattended-upgrades is part of Canonical's Minimal seed, so automatic security updates survive the trim by design — armed, with the security origin enabled and the apt-daily timers active.
Secure by default
No credential is baked into the image: the root password is locked, password authentication is disabled and root password login is prohibited, so access is only ever by the SSH key you supply when you create the VM. The machine identity and SSH host keys are regenerated uniquely on every instance. AppArmor is enforcing, the only advertised inbound port is SSH on 22, and no swap is baked into the OS disk.
What you get from cloudimg
- Canonical's Minimal package seed on cloudimg's hardened Azure lineage: 664 -> 322 packages, measured and ledgered
- An on-image manifest derived from the package database — the image cannot describe itself wrongly
- A fully patched, secure-by-default Ubuntu 24.04 LTS base with unattended security updates armed
- A deployment guide tested block-by-block against this exact image
- 24/7 expert support from cloudimg
Licensing
Ubuntu is free and open source. It is not a single licence but a collection of independently licensed open-source packages (GPL, LGPL, MIT, BSD, Apache-2.0, MPL and more). No subscription, no licence key and no Canonical entitlement is required. Ubuntu is produced by Canonical Ltd.; Ubuntu Pro is an optional Canonical subscription that is neither included nor required by this image. The cloudimg charge ($0.04 per vCPU/hour) covers packaging, security patching, image maintenance and 24/7 support.