1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
Thilo Bangert wrote: |
5 |
| Ramon van Alteren <ramon@××××××××××.nl> said: |
6 |
|> What's wrong with building your stage4 with catalyst and have it |
7 |
|> include a kernel ? |
8 |
| |
9 |
| and what do you do after a weekend like this one: kernel upgrade on 1300 |
10 |
| hosts? |
11 |
|
12 |
What would you do ? |
13 |
But yes if there's a kernel vurnerability that affects our environment |
14 |
we upgrade kernels on all servers starting with the internet-facing ones. |
15 |
|
16 |
Although the question is interesting I fail to see any relevance to |
17 |
installing (or upgrading) kernels in a automated manner. |
18 |
Actually I'd say that if you have a trusted and well-defined automated |
19 |
way to build and install/upgrade kernels you're actually better off. |
20 |
|
21 |
|> We use catalyst to generate all our install images and catalyst uses |
22 |
|> genkernel internally to include it in the image. Just specify which |
23 |
|> kernel you'd like and provide a .config for it. |
24 |
|> |
25 |
|> We've installed 1300 servers that way, I'll personally guarantee you |
26 |
|> that it works :-D |
27 |
| |
28 |
| :) |
29 |
| thats more than good enough for me. |
30 |
|
31 |
Grin, no thanks. |
32 |
It also helps in other ways: You gain repeatable image builds including |
33 |
kernels so after a weekend like this one you can easily rebuild your |
34 |
kernel + image and *just* distribute the updated kernel to your serverpark. |
35 |
|
36 |
Ramon |
37 |
-----BEGIN PGP SIGNATURE----- |
38 |
Version: GnuPG v2.0.7 (GNU/Linux) |
39 |
|
40 |
iD8DBQFHsVaqwiVM6CtDHQ0RAgLmAJwJ9J1mQ2rPkRgndy0RFQ2SQX7IxACfV0oV |
41 |
ntczcCCNwpd2xuqxKUnx1mI= |
42 |
=9kGM |
43 |
-----END PGP SIGNATURE----- |
44 |
-- |
45 |
gentoo-server@l.g.o mailing list |