Skip to main content

Linux Kernel Update

Use this playbook to roll out a Linux kernel update with minimal risk.

Procedure

  1. Assess impact.

    • Review vendor release notes and known issues for the target kernel version.
    • Identify which Linux distributions and versions in your estate are affected.
    • Coordinate with application owners for systems where kernel changes are high‑risk.
  2. Build a targeted baseline.

    • Create a baseline that includes only the kernel and closely related packages.
    • Exclude non‑essential updates to keep the change focused.
    • Tag the baseline clearly as a kernel‑specific release.
  3. Run canary tests.

    • Choose a small set of non‑critical hosts or environments.
    • Contact Сloudaware to provide parameters for patching.
    • Schedule a patch job for the canary group and verify:
      • Kernel version changes as expected.
      • Applications and services start correctly after reboot.
      • Monitoring shows no abnormal errors or performance issues.

    Example of parameters:

    SettingValue
    Release CycleEvery 10th of every month
    Release DiscretionPer Account
    Default MaintenanceSunday 12 AM - 5 AM EST
    Exemption Tagcloudaware:PatchGroup = Exclude
    Stopped Instance Patch PolicyUpdate to account-level patch release on startup
  4. Roll out in stages.

    • Expand to a wider set of hosts, grouped by environment or role.
    • Contact Сloudaware to perform patching on a new set of hosts.
    • Monitor job results, system metrics, and application health closely on your end.
  5. Roll back and follow up.

    • Be prepared to invoke rollback scripts if significant issues arise.
    • Document any workarounds or additional steps needed for specific hosts.
    • Update operational documentation and baselines for future kernel updates.