Major outage listed against several of Canonical's websites

Ubuntu’s websites are currently experiencing a “sustained distributed denial of service attack”.

Canonical says some of its online sites will be ‘intermittently unavailable’ as its teams work to resolve the incident. There’s no ETA on them coming back online, but that’s understand since ‘automated volumetric onslaught’ rarely keeps to a schedule.

This is the second major attack the company has experience this year.

Back in May, swathes of Canonical infrastructure forced offline by what it referred to as a “sustained cross-border attack”. That incident caused outages of the main websites and blogs, plus Launchpad PPAs, Ubuntu Single Sign-on, mailing lists, signing keys and the Snap Store.

Ubuntu’s APT repos (which are mirrored and distributed) were unaffected then, and the OS build infrastructure and ISO downloads were compromised.

Canonical hasn’t (publicly, to my knowledge) said who was behind the May attack, nor why it was the target. It did undertake a post-incident ‘autopsy’ to learn from and harden its infrastructure against a repeat.

Did those “lessons” pay off?

This time, only the main Ubuntu and Canonical domains are experiencing outages, including canonical.com, ubuntu.com, blog.ubuntu.com, developer.ubuntu.com and the Ubuntu Security API and notices pages.

Ubuntu PPAs, CD image server, Launchpad, Snap Store, Ubuntu SSO etc are all, as of writing, operational.

You can monitor the situation in real-time via the Canonical and Ubuntu Status page.