New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
How often do you reboot because of kernel security patches? (both providers & customers)
In the past week I've received mails from 3 different providers who had to reboot the node my VPS was on because they had to apply a kernel update and I did the same on my dedis, hence the question.
With the crazy amount of high severity CVEs coming out fueled by AI discovering new classes of vulnerabilities, it seems unlikely that this trend will stop for the foreseeable future.

Comments
if necessary i reboot.
If a provider needs to reboot your VPS for a patch then they don't have any clustering which means they aren't a legit provider.
If there's a new kernel, I reboot my machines, vulnerability or not. If there is a vulnerability, I'd hope my providers would install the new kernel and reboot.
You make me laugh.
as fast as i can. faster than provider email.
Sometimes I reboot the servers after a kernel update, and sometimes I don’t. To be honest, I occasionally forget to update the kernel, which is why I’ve installed KernelCare on all my servers, especially with the recent increase in kernel-related CVEs.
It gives me some peace of mind since KernelCare can apply kernel security patches without requiring a reboot, so I don’t have to constantly worry about forgetting a kernel update.
I don’t update the kernel and restart. The kernel updates me.
I disagree, they can still be legit but not excessively competent. They should be able to update the host without rebooting its guest OSs.
Far from the only solution, and using this to single out a “legit” provider is illogical, lot systems, solutions basic VM clustering is far from the only solution.
Truthyfully, my main machines are still running ubuntu 18.04 and not updated since 2016, ignorant to a lot of vuln’s as my servers are very locked down, all external traffic is from my own PoP’s that I do maintain heavily personally had 0 issues to this day.
I think setup, is as important as updating. Learning how to properly secure a linux system will give you an edge, sure some 0day, or vuln’s will be useable regardless but personally never had this happen yet in 10 years, so I don’t personally have the panic.
This is by far one of the funniest things you have said. Love it.
OVH, backyard summerhost.
Any provider can live migrate VM’s to another host in order to do maintenance. That has nothing to do with whether they’re legit or not.
As for clustering, I’m assuming you mean shared storage to allow for quicker VM live migrations and support consolidated resources.
Again, nothing to do with whether a provider is legit or not.
The rates at which the LE* industry expect hosts to provide services, are often not tenable for us to have a full HA service and or software stack, along with expensive shared storage to keep pace with NVMe speed expectations, again at a low price point. Additionally there aren’t many providers who have enough spare hot capacity sitting around just to justify live migrations for maintenance - sure it would be nice, but at a significantly higher cost.
We certainly could offer all those things, however the additional hardware, maintenance and support time required would raise prices out of the snack bracket we currently offer within…
Legit providers, are those that engage their customers, provide a valuable service to those customers and ensure transparent communication when something misses the mark - at least IMO…
Saying all that, we are actually striving towards shared storage as a way to balance out resources more effectively. Longer term goal, but a fun one nonetheless!
as often as necessary. No need to brag with your uptime.
Sadly occasionally you have things like sriov which won't compile for the newest version (although it appears they have fixed that issue now) so I like to lag behind a bit.
I approve HostBilby as a legit provider!
So you take clients offline for all patches? How often are you bringing clients VMs offline?
If you don't have enough capacity to migrate for patches what do you do when there's a hardware failure like main board on a server?
Did you ask these questions to your current providers BEFORE actually buying from them? Or did you rather assume or guess or just expect?
No. Routine maintenance and updates don’t generally require a reboot. So they happen seamlessly to the client.
We have cold spares ready to swap in. Like most providers.
Like I said, there aren’t many providers with true HOT capacity ready to migrate an entire node of clients just for maintenance. Even the large cloud providers are the same.
If you need that level of uptime, you’re in a different snack bracket cost wise, or with a provider large enough to justify the resource sharing - shoutout @crunchbits (Synteq HPC’s new cloud, it’s awesome!)
I’m rich. I use kernelcare.
I wish... cries in daily reboot
I don't like live migrations. Unless it shuts down the database before moving the files, there's a risk of database corruption. I'd rather backup/restore myself if needed.
why cant you turn on a cold spare, patch it then live migrate to them then keep doing the other servers and make the last one a spare? all enterprise systems do this and auto turn on based on capacity
Because we keep spare parts, not entire replications of all of our configurations - simply not feasible at our target customer price point today.
Also, the amount of support and coordination time this would require is again, not tenable at our current snack bracket.
No, not all enterprise systems do this - if you think they do, then you might want to ask for proof from your provider...
He just asks Andrew from legal instead.
The expectancies for a $7/yr service is crazy 😂.
Expectations are just premeditated resentments.
Who also has no idea lol
Because the time to "live migrate" 10-30 VMs, hope you didn't blow a VM/data up, and then reboot is insanely complicated versus a 1-3m reboot. It's also very high risk. If you need something better, as a customer, pay for it. Otherwise deal with a host rebooting a machine for critical CVE's.
Prior to AI-assists, CVEs like this that affect such a wide breadth of deployments were incredibly rare. I can think of maybe 1-2 in ~6 years?
you dont need every configuration, you need just 1 for every hardware generation, and most work for 1-2 generations previously.
what hypervisor are you running? do you have shared storage?
Hi eric
n-no this is richard
Thanks for the back up Dad, love you 😘
How dare you 2, that you 2 would hypothetically inconvenience me for 3 minutes?! OUTRAGEOUS