CERN Is Moving 2,200 Accelerator Control Systems to Debian 13, and the Reason Is a CHF 5.4 Million Hardware Bill
CERN will have more than 2,200 industrial computers and embedded systems running Debian 13 “Trixie” across its accelerator control infrastructure by the end of 2026. Engineers Federico Vaga and Nikos Tsipinakis presented the migration at MiniDebConf Winterthur 2026.
The scale is not office IT. The accelerator control infrastructure spans roughly 43 square kilometres, with around 2,200 computers connected to approximately 17,000 devices, and the count is still growing. These machines sit next to accelerator hardware and talk to custom electronics.
The path that led here
CERN’s accelerator systems followed the Red Hat ecosystem for years: Scientific Linux alongside RHEL 5 and 6, then CentOS through the RHEL 7 and 8 generations.
When CentOS Linux was discontinued in favour of CentOS Stream, the controls team began reconsidering how tightly it wanted to be coupled to that ecosystem. The initial plan was still to stay: validate CentOS Stream 9, move to Stream 10 promptly, possibly adopt Stream 11 later.
In parallel, they hedged. They worked to make CERN’s integration layer distribution-agnostic and prepared a fallback operating system. The fallback was Debian.
The number that decided it
A risk analysis in Q2 2023 put a figure on staying the course. Remaining on the Red Hat Enterprise Linux path was estimated at roughly CHF 5.4 million, and the cost was not licensing. It was hardware.
Approximately 11 hardware boards would have required redesign. The work would have needed additional electronics engineers, software engineers, and technicians. Racks would have needed reorganising and rewiring. Most systems would have been affected during commissioning.
Even assuming the replacement boards worked correctly, CERN estimated an optimistic success rate of about 20 percent, against a hard deadline of Q4 2026.
So the team chose what they described as a software solution to a software problem: move the computers to Debian rather than redesign large parts of the hardware to stay compatible with a distribution.
That framing is worth sitting with. The cost of the Red Hat path was not the subscription. It was that hardware compatibility assumptions had been baked into the platform deeply enough that changing distributions within that ecosystem meant changing circuit boards.
You cannot hotpatch a live particle accelerator
The second constraint is one almost no other deployment has. Accelerator operation runs to a planned schedule of operating periods, technical stops, commissioning windows, and long shutdowns. The operating system underneath the control infrastructure has to fit that schedule.
The team’s phrasing was that they needed to pick the right Debian release to avoid having to hotpatch a live particle accelerator. Debian’s predictable freeze-and-release cadence and long support windows line up with multi-year accelerator planning in a way a rolling or fast-moving base does not.
The migration also went well beyond running the installer. CERN redesigned how operating system components are distributed and how front-end computers boot, and reworked how its specialised hardware drivers integrate with Linux rather than depending on distribution-specific assumptions. That last piece is the part that makes the next migration cheaper, whenever it comes.
Why it matters
Institutional migrations off the Red Hat ecosystem have been a steady theme since the CentOS Stream announcement, but most of them are web and application servers where the switching cost is a few Ansible roles.
This one is different: physical infrastructure, custom electronics, tens of thousands of connected devices, and an operational schedule where downtime has consequences measured in beam time rather than uptime percentages. The decision turned on a concrete engineering estimate rather than on licensing sentiment.
By the end of the year, Debian 13 will be running the industrial and embedded computing layer behind CERN’s accelerator complex.
Details are in Debian’s announcement, and the full MiniDebConf talk is archived.