skip to content

Ubuntu publishes Desktop, Server, minimal and cloud images of the same release. What actually differs between them, and does the kernel differ too?

level: middleimportance: nice to knowfreq 30%

answer

  1. same archive, different seed
  2. cloud image has no installer
  3. cloud-init applies the instance-specific part
  4. GA stays, HWE rolls forward
  5. Desktop HWE, Server GA

basics

~20 s

They are the same distribution with different default package sets and installers, not different operating systems. Server drops the graphical stack, cloud images are prebuilt disks configured on first boot by cloud-init, minimal images strip extras, and Desktop defaults to the hardware-enablement kernel while Server defaults to the GA kernel.

solid answer

~50 s

All of them draw from the same archive, so the difference is which packages are seeded and how the image is installed, not what the system fundamentally is. **Desktop** adds the GNOME session and a graphical installer. **Server** ships the text-mode installer, no desktop, OpenSSH, and unattended security upgrades enabled by default. **Cloud images** are prebuilt disk images with no installer at all: they boot, and `cloud-init` reads the platform's metadata and user-data to set the hostname, create the default `ubuntu` user with your SSH key, and run first-boot configuration — which is why they have no password login. **Minimal** variants trim documentation and non-essential packages for a smaller image and attack surface. The kernel differs by default too: Desktop installs the hardware-enablement (HWE) stack, Server installs the GA kernel. They are the same kernel when an LTS launches and diverge from the first point release, with HWE rolling forward for newer hardware and GA staying put for the full five years.

go deeper

for a junior

Know that Desktop, Server and cloud images are the same Ubuntu with different default packages, and that a cloud image boots straight into a running system rather than an installer.

for a middle

Explain what cloud-init does on first boot, why cloud images are key-only, and the difference between the GA kernel that stays put for five years and the HWE stack that rolls forward.

for a senior

Show fleet judgment — standardise on one image and one kernel line, decide deliberately whether unattended security upgrades belong in your workflow, and know why minimal images reduce more than just size.

for a principal

Own the base-image strategy: whether the organisation builds its own golden images from the cloud image, how kernel-line changes are rolled out, and what standardisation buys against the cost of maintaining the pipeline.

## They are one distribution, seeded differently The first thing to say is that Ubuntu Desktop and Ubuntu Server are not separate products. They install from the same archive, use the same package manager and the same release lifecycle, and a Server install can grow a desktop and vice versa. What the images differ in is the **seed**: which packages are installed by default, and which installer puts them there. - **Desktop** seeds the GNOME session, the graphical stack and desktop applications, and uses a graphical installer. - **Server** seeds no graphical environment, includes OpenSSH, and uses the text-mode live-server installer, which also supports automated installation from a configuration file so a fleet can be provisioned unattended. - **Minimal** variants exist for both the server and cloud lines: documentation, translations and non-essential packages are trimmed, producing a smaller image, a shorter boot and a smaller attack surface. Anything removed is one install away, because it is the same archive. ## Cloud images are a different shape entirely A cloud image is not an installer — it is a **prebuilt root filesystem** shipped as a disk image (or published directly as a cloud provider's machine image). There is no interactive installation step; the image boots as a running system, and everything instance-specific is applied on first boot by **cloud-init**, which reads the platform's metadata service and any user-data you supplied. That is what sets the hostname, expands the root partition to the disk you actually attached, installs your SSH public key, and runs whatever configuration you passed in. This is why the cloud image has no usable password login: the default `ubuntu` user is key-only, and the key comes from metadata. It is also why the same image works identically across providers and local virtualisation — the platform-specific part lives in cloud-init, not in the image. ``` # minimal user-data consumed by cloud-init on first boot #cloud-config packages: - nginx runcmd: - systemctl enable --now nginx ``` One more default worth knowing: Ubuntu server and cloud images enable **unattended-upgrades** for the security pocket out of the box, so a freshly launched instance is applying security updates on its own from the first day. Whether you want that in a golden-image workflow is a real design decision, not an accident to fix blindly. ## GA versus HWE: the kernel choice An Ubuntu LTS offers two kernel lines. The **GA kernel** is the one the LTS launched with. It stays on that kernel version for the whole five-year support window, receiving backported security and bug fixes but never a version bump. Its virtue is that the kernel under your fleet does not change shape for five years. The **HWE (hardware enablement) stack** rolls forward: after the LTS's first point release, HWE machines move onto the kernel from each subsequent interim release. Its virtue is hardware support — a laptop or a server built after the LTS shipped may simply not have working drivers on the launch kernel. The defaults follow the audience: **Desktop installs HWE**, because desktop hardware is new and varied; **Server installs GA**, because a fleet values a stable kernel over new drivers. At LTS launch the two are the same kernel, so the distinction only becomes visible from the first point release onward. Point-release server media give you the option of the HWE stack when you need it, and the packages are named accordingly — `linux-generic` for GA, `linux-generic-hwe-<release>` for the enablement stack. The practical rule: pick GA for a homogeneous fleet on known hardware, pick HWE when the hardware demands it, and — more important than either — pick the *same one everywhere*, because a fleet split across two kernel lines has two sets of driver behaviour, two reboot cadences and two sets of performance characteristics to reason about. ## How this shows up in an interview The question is usually really "which image do I put on this thing, and do I understand what I am choosing?". A good answer establishes that these are seeds of one distribution rather than different systems, names cloud-init as the mechanism that makes a prebuilt image instance-specific, and treats the kernel line as a deliberate fleet-wide choice rather than a default nobody looked at.

  • Why does an Ubuntu cloud image have no password for its default user?
    Because nothing interactive ever configured it. The image is prebuilt and identical for everyone; the instance-specific part is applied on first boot by cloud-init from the platform's metadata and user-data, which is where your SSH public key comes from. Key-only access is the deliberate consequence: a shared image with a known password would be a fleet-wide credential.
  • When would you deliberately choose the HWE kernel on a server?
    When the hardware is newer than the LTS — a NIC, storage controller or accelerator whose driver only exists in a later kernel — or when you need a kernel feature the launch version lacks. The cost is that the kernel version moves roughly every six months, so you accept a rolling kernel in exchange for support. Choose it fleet-wide rather than per machine.
  • Is Ubuntu Server a different operating system from Ubuntu Desktop?
    No. Same archive, same package manager, same release and support lifecycle; only the default package seed, the installer and the default kernel line differ. You can install a desktop environment on a Server install or run a Desktop install headless. Treating them as distinct products leads people to believe a fix or package is unavailable on one of them, which is rarely true.

saying these in an interview costs you the question

  • Thinks Server and Desktop are different operating systems
  • Believes cloud images ship a default password
  • Assumes the HWE kernel is just a newer GA kernel
  • Thinks minimal images come from a separate stripped archive
  • Expects an installer to run when booting a cloud image

context