Skip to content
Back to skills

Sles

ASecurity

SUSE Linux Enterprise Server across supported service packs (15 SP5, 15 SP6): module/extension system, YaST, zypper, Btrfs default filesystem, Snapper basics, Wicked networking, transactional updates, RMT mirroring, supportconfig, saptune, AppArmor, and SUSE-specific hardening. Use when: \"SLES\", \"SUSE\", \"SUSE Linux Enterprise\", \"zypper\", \"YaST\", \"Btrfs\", \"Snapper\", \"SUSEConnect\", \"Wicked\", \"SUSE Manager\", \"supportconfig\", \"transactional-update\", \"SLE Micro\". Do NOT u...

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
businesspythongobashapisecurityperformance

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 18 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill sles --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Sles?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Sles
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-sles/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-sles)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: sles
description: "SUSE Linux Enterprise Server across supported service packs (15 SP5, 15 SP6): module/extension system, YaST, zypper, Btrfs default filesystem, Snapper basics, Wicked networking, transactional updates, RMT mirroring, supportconfig, saptune, AppArmor, and SUSE-specific hardening. Use when: \"SLES\", \"SUSE\", \"SUSE Linux Enterprise\", \"zypper\", \"YaST\", \"Btrfs\", \"Snapper\", \"SUSEConnect\", \"Wicked\", \"SUSE Manager\", \"supportconfig\", \"transactional-update\", \"SLE Micro\". Do NOT use for deep Btrfs/Snapper internals (qgroups, send/receive, ENOSPC) — use the `btrfs-snapper` skill. Do NOT use for Pacemaker/Corosync HA clustering — use the `sles-ha-extension` skill."
license: MIT
---

# SUSE Linux Enterprise Server

This skill covers SUSE Linux Enterprise Server across supported service packs (15 SP5 and 15 SP6). It provides deep knowledge of:

- Module and extension system (SUSEConnect, SCC, RMT registration)
- YaST integrated administration framework (ncurses, GUI, AutoYaST)
- zypper package management, patch categories, and distribution upgrades
- Btrfs default root filesystem with CoW, subvolumes, and compression
- Snapper snapshot management, rollback, and GRUB integration
- Wicked networking daemon (ifcfg-based, server-oriented)
- Transactional updates and SLE Micro immutable OS model
- RMT (Repository Mirroring Tool) for air-gapped environments
- supportconfig diagnostic collection
- SAP tuning with saptune (HANA, NetWeaver solutions)
- AppArmor mandatory access control (path-based profiles)
- Crypto policies, FIPS mode, firewalld, and system hardening
- Live Patching (kGraft) for rebootless kernel security fixes

When a question is version-specific, read the relevant file under `references/versions/`. When the version is unknown, provide general guidance and note where behavior differs across service packs.

## How to Approach Tasks

Route by request type: **troubleshooting** → `references/diagnostics.md`; **optimization** → `references/best-practices.md`; **architecture** → `references/architecture.md`; **edition selection** → `references/editions.md`; **administration** → the guidance below.

**Identify the SLES service pack first** — kernel features, OpenSSL version, cgroup mode, and package availability all shift between SP5 and SP6. Apply SLES-specific reasoning, not generic Linux advice. Validate with `zypper`, `SUSEConnect`, `journalctl`, and `supportconfig`.

## Core Expertise

### Module and Extension System

SLES uses a layered modular architecture. The base OS is minimal; functionality is added through **modules** (included in subscription) and **extensions** (separately licensed).

```bash
# Register system with SUSE Customer Center (SCC)
SUSEConnect --regcode <ACTIVATION_KEY>

# Register against a local RMT server
SUSEConnect --url https://rmt.example.com --regcode <KEY>

# List all available modules and extensions
SUSEConnect --list-extensions

# Register a specific module (no regcode needed for free modules)
SUSEConnect --product sle-module-containers/15.5/x86_64

# Register a paid extension (regcode required)
SUSEConnect --product sle-ha/15.5/x86_64 --regcode <HA_KEY>

# Show current registration status
SUSEConnect --status

# Deregister a module
SUSEConnect --deregister --product sle-module-containers/15.5/x86_64
```

Key modules: Basesystem (required foundation), Server Applications, Containers (Podman, Buildah), Development Tools, Python 3, Public Cloud, HPC. Extensions include HA Extension, Live Patching, and Confidential Computing.

### YaST -- Yet another Setup Tool

YaST is SLES's integrated system administration framework running in GUI, ncurses TUI, and command-line modes. Modules are independent packages installed on-demand.

```bash
# Launch YaST interactively
yast2

# Launch specific module directly
yast2 network
yast2 firewall
yast2 users

# Command-line administration (no TUI)
yast2 users list
yast2 firewall zones

# YaST log location
tail -f /var/log/YaST2/y2log
```

AutoYaST provides automated installation using XML control files. Validate with `yast2 autoyast validate filename=/path/to/autoyast.xml`. YaST's installation component is being phased out in favor of Agama for SLE 16.

### Zypper -- Package Management

Zypper is the primary package manager. SLES uses a patch-based model distinct from RHEL's errata system.

```bash
# Repository management
zypper repos --details                    # List all repos with priority and status
zypper refresh                            # Refresh all repo metadata

# Package operations
zypper install <package>                  # Install package
zypper update                             # Update all packages
zypper dup                                # Distribution upgrade (SP migration)

# Patch operations (preferred for security compliance)
zypper patch                              # Apply all applicable patches
zypper patch --category security          # Security patches only
zypper patches --category security        # List pending security patches

# System state
zypper ps -s                              # Services needing restart
zypper needs-rebooting                    # Check if reboot is required
zypper verify                             # Verify package integrity

# Lock management
zypper addlock <package>                  # Prevent package from being modified
zypper locks                              # List all package locks
```

Prefer `zypper patch` for routine security compliance. Use `zypper dup` only for planned SP upgrades. Repository priority is numeric (lower = higher precedence, default 99).

### Btrfs Default Filesystem

SLES uses Btrfs as the default root filesystem, enabling atomic rollbacks via Snapper. The default subvolume layout excludes `/var`, `/home`, `/tmp`, and `/srv` from snapshots to preserve runtime data across rollbacks.

```bash
# Filesystem information
btrfs filesystem show /
btrfs filesystem df /                     # Usage by data/metadata type
btrfs filesystem usage /                  # Detailed space breakdown

# Device health
btrfs device stats /                      # Error counters (check for non-zero)
btrfs scrub start /                       # Start integrity scrub
btrfs scrub status /                      # Check scrub results

# Balance (reclaim space from underused block groups)
btrfs balance start -dusage=50 /          # Balance only chunks <50% used

# Quota groups (per-subvolume space accounting)
btrfs quota enable /
btrfs qgroup show -reF /                  # Show per-subvolume exclusive usage
```

SUSE runs Btrfs maintenance via systemd timers. Verify with `systemctl status btrfsmaintenance-scrub.timer`. Use XFS for SAP HANA data/log volumes and high-IOPS workloads.

### Snapper -- Snapshot Management

Snapper manages Btrfs snapshots with pre/post hooks around every zypper transaction.

```bash
# List snapshots
snapper list

# Create manual snapshot
snapper create --description "Before config change"

# Show diff between snapshots
snapper status 42..43                     # File change summary
snapper diff 42..43                       # Unified diff

# Rollback to snapshot
snapper rollback 42                       # Sets snapshot as new default subvolume
# Then reboot

# Undo specific files from a snapshot
snapper undochange 42..43 /etc/nginx/nginx.conf

# Delete snapshots
snapper delete 40-45                      # Delete range

# Configuration
snapper get-config                        # Show Snapper config
```

Snapshots appear in the GRUB boot menu for boot-time rollback. Key retention settings in `/etc/snapper/configs/root`: `TIMELINE_LIMIT_HOURLY`, `TIMELINE_LIMIT_DAILY`, `NUMBER_LIMIT`.

### Wicked Networking

Wicked is SLES's default network daemon for server deployments. Configuration files live in `/etc/sysconfig/network/`.

```bash
# Interface state
wicked show all                           # Show all interfaces with status
wicked ifup eth0                          # Bring up with config from ifcfg-eth0
wicked ifreload eth0                      # Reload config without full cycle

# Diagnostics
wicked check-config                       # Validate configuration
journalctl -u wickedd.service             # Wicked daemon logs
```

Wicked is being phased out in favor of NetworkManager in future SLE releases. NetworkManager is already the default for SLED (desktop).

### Transactional Updates

Transactional updates provide atomic OS updates using Btrfs snapshots with a read-only root filesystem. This is the update model for SLE Micro and MicroOS.

```bash
transactional-update                      # Apply all pending updates atomically
transactional-update patch                # Apply only security updates
transactional-update pkg install <pkg>    # Install a package (into next snapshot)
transactional-update rollback             # Rollback (reboot into previous snapshot)
```

The live root filesystem is not modified during the update process. On reboot, GRUB boots into the new snapshot.

### RMT -- Repository Mirroring Tool

RMT creates a local mirror of SUSE Customer Center repositories for air-gapped or bandwidth-limited environments.

```bash
# On RMT server
rmt-cli sync                              # Sync metadata from SCC
rmt-cli products enable SLES/15.5/x86_64  # Enable mirroring for SLES 15 SP5
rmt-cli mirror                            # Start mirroring enabled repos

# Client registration to RMT
SUSEConnect --url https://rmt.example.com --regcode <KEY>
```

### Security Overview

**AppArmor** is SLES's default MAC system (path-based profiles, simpler than SELinux):

```bash
aa-status                                 # Full profile list and enforcement mode
aa-enforce /etc/apparmor.d/usr.sbin.nginx # Set profile to enforce mode
aa-complain /etc/apparmor.d/usr.sbin.nginx # Set to complain (log only)
aa-genprof /usr/sbin/myapp                # Generate profile interactively
```

**Crypto policies** apply uniform cryptographic defaults:

```bash
update-crypto-policies --show             # Current policy
update-crypto-policies --set FUTURE       # DEFAULT, FUTURE, LEGACY, FIPS
fips-mode-setup --enable                  # Enable FIPS (requires reboot)
```

**firewalld** manages zone-based firewalling (replaced SuSEfirewall2 in SLES 15):

```bash
firewall-cmd --get-active-zones
firewall-cmd --list-all
firewall-cmd --permanent --add-service=https
firewall-cmd --reload
```

### SAP Tuning with saptune

```bash
saptune solution list                     # Available solutions
saptune solution apply HANA              # Apply SAP HANA tuning
saptune solution verify HANA             # Verify current tuning
saptune status                            # Check saptune status
saptune daemon start                      # Enable saptune at boot
```

saptune configures kernel parameters, I/O schedulers, hugepages, and transparent huge pages for SAP HANA and NetWeaver certification.

## Common Pitfalls

**1. Running zypper update instead of zypper patch for routine patching**
`zypper update` updates individual packages to latest versions, which may introduce unintended changes. Use `zypper patch --category security` for controlled, SUSE-curated security compliance.

**2. Ignoring Btrfs metadata saturation (ENOSPC with free space showing)**
`df` shows data block group space, not metadata. When metadata block groups fill, Btrfs reports "No space left" even with data space available. Monitor with `btrfs filesystem usage /` and balance with `btrfs balance start -musage=50 /`.

**3. Treating Btrfs snapshots as backups**
Snapshots reside on the same physical device. A device failure destroys snapshots and live data simultaneously. Always maintain off-device backups using `btrfs send/receive` or rsync.

**4. Disabling AppArmor instead of troubleshooting denials**
AppArmor Enforce mode is the expected state. Use `aa-complain` for per-profile troubleshooting and `aa-logprof` to update profiles from audit log entries.

**5. Editing Wicked config files without wicked ifreload**
Changes to `/etc/sysconfig/network/ifcfg-*` are not picked up until `wicked ifreload <iface>` or `wicked ifup <iface>` is run. Unlike NetworkManager, Wicked does not auto-detect file changes.

**6. Not registering modules before installing packages**
SLES modules provide separate repository channels. Attempting `zypper install` for a package in an unregistered module fails silently or with "package not found". Use `zypper search-packages` (SP6+) or `SUSEConnect --list-extensions` to find the right module.

**7. Forgetting to take a Snapper snapshot before SP upgrade**
Always run `snapper create --description "Pre-SP-upgrade"` before `zypper dup`. If the upgrade fails, boot from the pre-upgrade GRUB snapshot entry and run `snapper rollback`.

**8. Running zypper dup without registering all modules for the new SP**
SP migration requires re-registering each module for the target SP version. Failing to do so leaves modules pointing at old SP repositories, causing dependency conflicts during `zypper dup`.

**9. Ignoring qgroup overhead on systems with many snapshots**
Btrfs qgroups add 10-30% write overhead. On high-IOPS systems with 50+ snapshots, consider disabling qgroups (`btrfs quota disable /`) if snapshot size reporting is not needed.

**10. No baseline performance data before SAP deployment**
Without a pre-SAP baseline captured by `saptune solution simulate HANA` and `sar`, you cannot determine if saptune changes improved or degraded performance. Enable `sysstat.service` within the first week.

## Version-Specific Guidance

| Version | Reference | What's version-specific |
|---|---|---|
| 15 SP5 | `references/versions/15-sp5.md` | Kernel 5.14, Podman 4.3 with Netavark, NVMe-oF TCP boot, Python 3.11 module, Systems Management module, 4096-bit RPM signing key, TLS 1.0/1.1 deprecated, KVM 768 vCPUs |
| 15 SP6 | `references/versions/15-sp6.md` | Kernel 6.4, OpenSSL 3.1.4, cgroup v2 unified hierarchy, LUKS2 YaST support, OpenSSH 9.6 RSA key policy, NFS over TLS, Confidential Computing module, FRRouting replaces Quagga, zypper search-packages, SP7 deprecation warnings |

## Reference Files

Load these when you need deep knowledge for a specific area:

- `references/architecture.md` -- Module/extension system, YaST, zypper internals, Btrfs filesystem layout, Wicked networking, transactional updates, RMT architecture. Read for "how does X work" questions.
- `references/diagnostics.md` -- supportconfig, YaST logs, zypper diagnostics, system health indicators, Btrfs error analysis. Read when troubleshooting.
- `references/best-practices.md` -- AppArmor hardening, patching workflow, SAP tuning with saptune, Live Patching, SP upgrade procedure, firewalld, crypto policies. Read for design and operations questions.
- `references/editions.md` -- SLES vs SLED vs SLE Micro, modules and extensions, lifecycle and LTSS, SLES for SAP Applications. Read for edition selection and licensing questions.

## Diagnostic Scripts

Run these for rapid SLES assessment:

| Script | Purpose |
|---|---|
| `scripts/01-system-health.sh` | OS version, registration, repos, failed units, reboot status, FIPS |
| `scripts/02-performance-baseline.sh` | CPU, memory, disk I/O, Btrfs usage, saptune status |
| `scripts/03-journal-analysis.sh` | Critical errors, OOM events, AppArmor denials, boot time |
| `scripts/04-btrfs-health.sh` | Btrfs space, device errors, subvolumes, snapshots, scrub status |
| `scripts/05-network-diagnostics.sh` | Wicked/NM status, interface config, routing, DNS, firewall |
| `scripts/06-security-audit.sh` | AppArmor profiles, crypto policy, FIPS, SSH config, open ports |
| `scripts/07-package-audit.sh` | Pending patches, locked packages, orphaned RPMs, repo health |
| `scripts/08-registration-status.sh` | SUSEConnect registration, module status, RMT connectivity |
| `scripts/09-supportconfig.sh` | Automated supportconfig collection with guided analysis |

## Key Paths and Files

| Path | Purpose |
|---|---|
| `/etc/os-release` | OS identification and version |
| `/etc/sysconfig/network/` | Wicked network configuration |
| `/etc/snapper/configs/root` | Snapper retention policy |
| `/etc/sysconfig/btrfsmaintenance` | Btrfs maintenance schedule |
| `/var/log/YaST2/y2log` | YaST operation log |
| `/var/log/zypp/history` | Zypper transaction history |
| `/var/log/scc_*.txz` | supportconfig output archives |
| `/etc/rmt.conf` | RMT server configuration |
| `/etc/apparmor.d/` | AppArmor profile directory |
| `/.snapshots/` | Snapper snapshot storage |

Files in this skill

  • SKILL.md16.2 KB
  • references/architecture.md11.8 KB
  • references/best-practices.md10.3 KB
  • references/diagnostics.md7.8 KB
  • references/editions.md5.7 KB
  • references/versions/15-sp5.md4.2 KB
  • references/versions/15-sp6.md5.8 KB
  • scripts/01-system-health.sh6 KB
  • scripts/02-performance-baseline.sh4.1 KB
  • scripts/03-journal-analysis.sh4.9 KB
  • scripts/04-btrfs-health.sh6.2 KB
  • scripts/05-network-diagnostics.sh4.8 KB
  • scripts/06-security-audit.sh6 KB
  • scripts/07-package-audit.sh4.9 KB
  • scripts/08-registration-status.sh5.3 KB
  • scripts/09-supportconfig.sh5.6 KB
  • scripts/versions/15-sp5/10-sp5-health.sh6.3 KB
  • scripts/versions/15-sp6/10-sp6-migration.sh8.8 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…