Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Where i should install KernelCare?
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Where i should install KernelCare?

kzedkzed Member

hi LET,
so i have a dedicated server and create only one big KVM inside it, the KVM is under NAT.
if i want to install KernelCare to avoid reboot when there are security update, where i should install it? on the host node or on the KVM itself?

thanks!

Comments

  • Both because KVM is using it's own kernel.

    Thanked by 3kzed alown GCat
  • if i have to choose, which i should choose?
    the node only host one KVM and the KVM is under NAT with some ports exposed to public.

  • WSCallumWSCallum Member
    edited January 2017

    If you're not doing both then you shouldnt bother, as the other will still need manual updates and need to be rebooted upon update. Considering the price of KernelCare you'd might as well install it on both...

    Thanked by 1kzed
  • AnthonySmithAnthonySmith Member, Patron Provider

    In terms of exposed risk, then the physical host node if you only want to pay for 1 license is the obvious choice.

    You have to accept that you need to reboot the NAT guest when you need to update it though, or just buy 2 licenses.

    Thanked by 1kzed
  • Host node, then use ubuntu 16.04 live kernel patching in your vm.

    Thanked by 1kzed
  • thanks for all suggestions :)
    it seem purchasing 2 licenses is the best options, since the VM is storing big mysql databases, im worried to reboot the VM too frequently.

  • AnthonySmithAnthonySmith Member, Patron Provider

    well if you really want to save some money you could just use openvz instead of kvm then you only need to patch 1 kernel, kernelcare supports openvz and openvz is fine for mysql.

    Thanked by 1tmwc
  • joepie91joepie91 Member, Patron Provider

    Hmm. Isn't live patching natively available in the mainline Linux kernel by now?

    Thanked by 2GCat vimalware
  • @AnthonySmith, its dockerized mysql and other images also i do other things that need KVM.
    @joepie91, is live patching only available on ubuntu or its available on general linux kernel too?

  • joepie91joepie91 Member, Patron Provider

    @kzed said:
    @AnthonySmith, its dockerized mysql and other images also i do other things that need KVM.
    @joepie91, is live patching only available on ubuntu or its available on general linux kernel too?

    This post suggests it's in kernel. I'm not sure whether distributions include it as well though, or whether it integrates into any major package management systems yet.

    Thanked by 1GCat
  • Hostnode for sure, VM if you need it.

    Generally VM's restart a lot quicker than the whole server

Sign In or Register to comment.