News: 1612960205

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

All grown up: Raspberry Pis running Ubuntu added to IoT patching service KernelCare

(2021/02/10)


CloudLinux has added the Raspberry Pi to its [1]KernelCare patching service , although only if you're running Ubuntu.

While CloudLinux might have recently been in the headlines regarding its [2]CentOS alternative , its KernelCare service has been ticking over quietly since 2014, patching the running kernel when needed "with zero downtime".

The arrival of the service is a recognition of the diminutive computer's presence in the IoT world, where implementations tend to be more on the appliance side and ongoing security updates are not always applied. The consequences of a failure to patch a connected IoT device can range from inconvenient to catastrophic.

The system works by allocating kernel memory for the new code, pauses all processes, modifies the original functions, jumps to the new code, then resumes processing. No reboot is required.

Oracle's [3]Ksplice will also update critical components, affording Linux fans with pockets deep enough for Oracle Linux Premier Support the ability to dodge downtime when the patch fairy beckons.

KernelCare's take on the Raspberry Pi is free for enthusiasts, but commercial users are expected to pay a fee. The supported chips are the [4]BCM2711 of the Pi 4 and the [5]BCM2837 of the Pi 3 as well as some later Pi 2 models. Operating system-wise, Ubuntu Focal Fossa for the 64-bit ARM platform is supported. Debian and Raspbian are due "soon". ®

[6]

[7]

[8]

Get our [9]Tech Resources



[1] https://lp.kernelcare.com/iot/free-raspberry-pi-patching

[2] https://www.theregister.com/2020/12/15/centos_alternatives/

[3] http://www.ksplice.com/

[4] https://www.raspberrypi.org/documentation/hardware/raspberrypi/bcm2711/README.md

[5] https://www.raspberrypi.org/documentation/hardware/raspberrypi/bcm2837/README.md

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YCQRI30o77gNOxdO7QQXTQAAAEw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YCQRI30o77gNOxdO7QQXTQAAAEw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YCQRI30o77gNOxdO7QQXTQAAAEw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://whitepapers.theregister.com/

Anonymous Coward

We looked at KernelCare a while ago. Didn’t end up using it - patches didn’t seem to be released in a timely fashion & the comms channel was a bit of a bodge (forum or news area on their website, IIRC). Also our security folk weren’t happy with their lack of certification.

Zero-downtime is a bit of an ops own goal too. It’s much better to check your systems & services can withstand the odd restart.

Others’ mileage may vary and this might be a fun thing to play with on a Pi, but I’d never look at it for production systems again.

Redundant service

b0llchit

This is why you design redundancy in your infrastructure and services. If you rely on "always working on one machine" then you will get a surprise when something fails. It may be the hardware, it may be a network- or power-glitch. Something will always go wrong with a single point of failure. That is why you have hot- and cold-standby systems to take over.

But building redundancy is both hard and expensive. That is apparently why the CxO level are such experienced people in applying apologies. And here you can see, the CxO level have redundant operational power where the 'x' in CxO may be any character from the alphabet. No real change in figurehead visible when you change the character. Now, maybe invest some of that CxO money in real technological redundancy?

Lomax

Yeah, and reboots are pretty quick on my Devuan IoT Pis. I always run with automatic security updates, and take into account when designing the system that individual machines will reboot occasionally. Never had a problem. Oh actually, I did have an issue where my OpenVPN connection sometimes wouldn't come back up after a reboot, but I fixed that with a little bashing. I use Mosquitto for messaging, which holds messages until delivered, and Node-Red for flow control, with cold start initialisations. Rebooting is not the drama it used to be.

Wow

Pascal Monett

" The system works by allocating kernel memory for the new code, pauses all processes, modifies the original functions, jumps to the new code, then resumes processing. No reboot is required. "

Elegant, simple and efficient.

In other words, nothing to do with Borkzilla.

The first condition of immortality is death. -Stanislaw Lec