-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Brandon Adams wrote:
| I woild assume that you would configure / build a new kernel for each
| hardware spec in your farm in your test environment, verify there are
| no glitches and then distibute the .config file to all servers and
| cron a kernel build / installation.

I'd say that depends on your idea of kernel building.
We prefer a general kernel with static drivers for crucial
hardware/option and module drivers for non-crucial hardware/options

Combined with module autoloading this allows for a flexible system with
little overhead.

I know that there are several people in the security community that
advertise disabling module-loading, however consider the problems you're
in if someone is actually able to load modules on one of your servers.

| The reboot required for the servers would then be done during that
| server's maintenance window.

We're currently researching if we can reduce the maintenance down-time
for kernel reloading by using kexec. On large memory servers and
scsi/raid controllers bios re-initialization can easily take up to 10
minutes. (that's pre-bootloader)

Ramon
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.7 (GNU/Linux)

iD8DBQFHsWqtwiVM6CtDHQ0RAujCAJkB4lBFyxLTfIcGI1Iwfx1k8b5AOgCbBrrk
SJIlqHBVcFsfx4VVcFoEdRU=
=ZdJY
-----END PGP SIGNATURE-----
--
[email protected] mailing list

Reply via email to