Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
Try EnsoVPN - Reliable VPN - 1-Day Free Trial
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Try EnsoVPN - Fast & Private VPN - 1-Day Free Trial
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

How often do you reboot because of kernel security patches? (both providers & customers)

minioptminiopt Member

In the past week I've received mails from 3 different providers who had to reboot the node my VPS was on because they had to apply a kernel update and I did the same on my dedis, hence the question.

With the crazy amount of high severity CVEs coming out fueled by AI discovering new classes of vulnerabilities, it seems unlikely that this trend will stop for the foreseeable future.

Comments

  • if necessary i reboot.

  • dedigoddedigod Member

    If a provider needs to reboot your VPS for a patch then they don't have any clustering which means they aren't a legit provider.

  • daviddavid Veteran

    If there's a new kernel, I reboot my machines, vulnerability or not. If there is a vulnerability, I'd hope my providers would install the new kernel and reboot.

    Thanked by 1stable_genius
  • AndruAndru Member

    @dedigod said:
    If a provider needs to reboot your VPS for a patch then they don't have any clustering which means they aren't a legit provider.

    You make me laugh.

  • as fast as i can. faster than provider email.

  • Sometimes I reboot the servers after a kernel update, and sometimes I don’t. To be honest, I occasionally forget to update the kernel, which is why I’ve installed KernelCare on all my servers, especially with the recent increase in kernel-related CVEs.

    It gives me some peace of mind since KernelCare can apply kernel security patches without requiring a reboot, so I don’t have to constantly worry about forgetting a kernel update.

  • DrNutellaDrNutella Member

    I don’t update the kernel and restart. The kernel updates me.

  • @dedigod said:
    If a provider needs to reboot your VPS for a patch then they don't have any clustering which means they aren't a legit provider.

    I disagree, they can still be legit but not excessively competent. They should be able to update the host without rebooting its guest OSs.

  • @dedigod said:
    If a provider needs to reboot your VPS for a patch then they don't have any clustering which means they aren't a legit provider.

    Far from the only solution, and using this to single out a “legit” provider is illogical, lot systems, solutions basic VM clustering is far from the only solution.

    @miniopt said:
    In the past week I've received mails from 3 different providers who had to reboot the node my VPS was on because they had to apply a kernel update and I did the same on my dedis, hence the question.

    With the crazy amount of high severity CVEs coming out fueled by AI discovering new classes of vulnerabilities, it seems unlikely that this trend will stop for the foreseeable future.

    Truthyfully, my main machines are still running ubuntu 18.04 and not updated since 2016, ignorant to a lot of vuln’s as my servers are very locked down, all external traffic is from my own PoP’s that I do maintain heavily personally had 0 issues to this day.

    I think setup, is as important as updating. Learning how to properly secure a linux system will give you an edge, sure some 0day, or vuln’s will be useable regardless but personally never had this happen yet in 10 years, so I don’t personally have the panic.

  • @dedigod said:
    If a provider needs to reboot your VPS for a patch then they don't have any clustering which means they aren't a legit provider.

    This is by far one of the funniest things you have said. Love it.

    OVH, backyard summerhost.

  • HostBilbyHostBilby Member, Patron Provider

    @dedigod said:
    If a provider needs to reboot your VPS for a patch then they don't have any clustering which means they aren't a legit provider.

    Any provider can live migrate VM’s to another host in order to do maintenance. That has nothing to do with whether they’re legit or not.

    As for clustering, I’m assuming you mean shared storage to allow for quicker VM live migrations and support consolidated resources.

    Again, nothing to do with whether a provider is legit or not.

    The rates at which the LE* industry expect hosts to provide services, are often not tenable for us to have a full HA service and or software stack, along with expensive shared storage to keep pace with NVMe speed expectations, again at a low price point. Additionally there aren’t many providers who have enough spare hot capacity sitting around just to justify live migrations for maintenance - sure it would be nice, but at a significantly higher cost.

    We certainly could offer all those things, however the additional hardware, maintenance and support time required would raise prices out of the snack bracket we currently offer within…

    Legit providers, are those that engage their customers, provide a valuable service to those customers and ensure transparent communication when something misses the mark - at least IMO…

    Saying all that, we are actually striving towards shared storage as a way to balance out resources more effectively. Longer term goal, but a fun one nonetheless!

    Thanked by 1skimply153
  • as often as necessary. No need to brag with your uptime.

  • @david said:
    If there's a new kernel, I reboot my machines, vulnerability or not. If there is a vulnerability, I'd hope my providers would install the new kernel and reboot.

    Sadly occasionally you have things like sriov which won't compile for the newest version (although it appears they have fixed that issue now) so I like to lag behind a bit.

Sign In or Register to comment.