-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Brandon Adams wrote: | I woild assume that you would configure / build a new kernel for each | hardware spec in your farm in your test environment, verify there are | no glitches and then distibute the .config file to all servers and | cron a kernel build / installation.
I'd say that depends on your idea of kernel building. We prefer a general kernel with static drivers for crucial hardware/option and module drivers for non-crucial hardware/options Combined with module autoloading this allows for a flexible system with little overhead. I know that there are several people in the security community that advertise disabling module-loading, however consider the problems you're in if someone is actually able to load modules on one of your servers. | The reboot required for the servers would then be done during that | server's maintenance window. We're currently researching if we can reduce the maintenance down-time for kernel reloading by using kexec. On large memory servers and scsi/raid controllers bios re-initialization can easily take up to 10 minutes. (that's pre-bootloader) Ramon -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.7 (GNU/Linux) iD8DBQFHsWqtwiVM6CtDHQ0RAujCAJkB4lBFyxLTfIcGI1Iwfx1k8b5AOgCbBrrk SJIlqHBVcFsfx4VVcFoEdRU= =ZdJY -----END PGP SIGNATURE----- -- [email protected] mailing list
