question
Kernel updates
To pull this conversation public, I thought I would throw a question out to the senior staff at Cycle in regards to Kernel/OS updates. Lets kick this thread off with a few questions around server security
- How are the kernel and service/library updates performed?
- Do these require downtime? Are we required to run 2N infra or evacuate our nodes to perform kernel upgrades?
- How often are servers patched?
- What root OS variant is used to build the OS from track CVSS scorings and potential vulnerabilities and determine compatibility with various workloads?
I think these type of questions serve as a baseline for determining how folks can address security updates and ensure their servers are kept up to date.