1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
Brandon Adams wrote: |
5 |
| I woild assume that you would configure / build a new kernel for each |
6 |
| hardware spec in your farm in your test environment, verify there are |
7 |
| no glitches and then distibute the .config file to all servers and |
8 |
| cron a kernel build / installation. |
9 |
|
10 |
I'd say that depends on your idea of kernel building. |
11 |
We prefer a general kernel with static drivers for crucial |
12 |
hardware/option and module drivers for non-crucial hardware/options |
13 |
|
14 |
Combined with module autoloading this allows for a flexible system with |
15 |
little overhead. |
16 |
|
17 |
I know that there are several people in the security community that |
18 |
advertise disabling module-loading, however consider the problems you're |
19 |
in if someone is actually able to load modules on one of your servers. |
20 |
|
21 |
| The reboot required for the servers would then be done during that |
22 |
| server's maintenance window. |
23 |
|
24 |
We're currently researching if we can reduce the maintenance down-time |
25 |
for kernel reloading by using kexec. On large memory servers and |
26 |
scsi/raid controllers bios re-initialization can easily take up to 10 |
27 |
minutes. (that's pre-bootloader) |
28 |
|
29 |
Ramon |
30 |
-----BEGIN PGP SIGNATURE----- |
31 |
Version: GnuPG v2.0.7 (GNU/Linux) |
32 |
|
33 |
iD8DBQFHsWqtwiVM6CtDHQ0RAujCAJkB4lBFyxLTfIcGI1Iwfx1k8b5AOgCbBrrk |
34 |
SJIlqHBVcFsfx4VVcFoEdRU= |
35 |
=ZdJY |
36 |
-----END PGP SIGNATURE----- |
37 |
-- |
38 |
gentoo-server@l.g.o mailing list |