• brewery@feddit.uk
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 days ago

    I have a mix of Debian and Ubuntu servers. I’ll update manually anyway but for future cases, would unattended-upgrades set to security upgrades run daily be enough to stop this type of issue?

    • vegetaaaaaaa@lemmy.world
      link
      fedilink
      English
      arrow-up
      14
      ·
      edit-2
      2 hours ago

      This is a kernel bug, unattended-upgrades will take care of installing the new kernel once the fix is published, but you still have to reboot to load it. I’ve set up a cron job that runs needrestart nightly and reboots my servers if there is a pending kernel upgrade [1]

        • vegetaaaaaaa@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 hours ago

          True.

          But by default the unattended-upgrades timer has a randomized trigger time (so that not all Debian machines in the world start hammering the mirrors at the same time). If you enable the auto reboot option in unattended-upgrades, your boxes will reboot at an unpredictable time. I prefer doing this at known times (middle of the night when I know nothing important is running/number of users is low).

        • Miaou@jlai.lu
          link
          fedilink
          English
          arrow-up
          2
          ·
          24 hours ago

          Every time I see people boasting about their uptime, I ask myself how old their kernel actually is.

          I’ve set this auto reboot and never had to worry about patching my server.

          Edit: yeah I know live patching is a thing, not worth the hassle for 99% of server workloads.