New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
How often do you reboot because of kernel security patches? (both providers & customers)
In the past week I've received mails from 3 different providers who had to reboot the node my VPS was on because they had to apply a kernel update and I did the same on my dedis, hence the question.
With the crazy amount of high severity CVEs coming out fueled by AI discovering new classes of vulnerabilities, it seems unlikely that this trend will stop for the foreseeable future.

Comments
if necessary i reboot.
If a provider needs to reboot your VPS for a patch then they don't have any clustering which means they aren't a legit provider.
If there's a new kernel, I reboot my machines, vulnerability or not. If there is a vulnerability, I'd hope my providers would install the new kernel and reboot.
You make me laugh.
as fast as i can. faster than provider email.
Sometimes I reboot the servers after a kernel update, and sometimes I don’t. To be honest, I occasionally forget to update the kernel, which is why I’ve installed KernelCare on all my servers, especially with the recent increase in kernel-related CVEs.
It gives me some peace of mind since KernelCare can apply kernel security patches without requiring a reboot, so I don’t have to constantly worry about forgetting a kernel update.
I don’t update the kernel and restart. The kernel updates me.
I disagree, they can still be legit but not excessively competent. They should be able to update the host without rebooting its guest OSs.
Far from the only solution, and using this to single out a “legit” provider is illogical, lot systems, solutions basic VM clustering is far from the only solution.
Truthyfully, my main machines are still running ubuntu 18.04 and not updated since 2016, ignorant to a lot of vuln’s as my servers are very locked down, all external traffic is from my own PoP’s that I do maintain heavily personally had 0 issues to this day.
I think setup, is as important as updating. Learning how to properly secure a linux system will give you an edge, sure some 0day, or vuln’s will be useable regardless but personally never had this happen yet in 10 years, so I don’t personally have the panic.
This is by far one of the funniest things you have said. Love it.
OVH, backyard summerhost.
Any provider can live migrate VM’s to another host in order to do maintenance. That has nothing to do with whether they’re legit or not.
As for clustering, I’m assuming you mean shared storage to allow for quicker VM live migrations and support consolidated resources.
Again, nothing to do with whether a provider is legit or not.
The rates at which the LE* industry expect hosts to provide services, are often not tenable for us to have a full HA service and or software stack, along with expensive shared storage to keep pace with NVMe speed expectations, again at a low price point. Additionally there aren’t many providers who have enough spare hot capacity sitting around just to justify live migrations for maintenance - sure it would be nice, but at a significantly higher cost.
We certainly could offer all those things, however the additional hardware, maintenance and support time required would raise prices out of the snack bracket we currently offer within…
Legit providers, are those that engage their customers, provide a valuable service to those customers and ensure transparent communication when something misses the mark - at least IMO…
Saying all that, we are actually striving towards shared storage as a way to balance out resources more effectively. Longer term goal, but a fun one nonetheless!
as often as necessary. No need to brag with your uptime.
Sadly occasionally you have things like sriov which won't compile for the newest version (although it appears they have fixed that issue now) so I like to lag behind a bit.