Saturday, April 21, 2007

Up again, blingier

Moving to the new flat meant lots of downtime for the server, now it's up again and has just come through a automated FC5 -> FC6 upgrade with one minor hickup.

The security support for FC5 is likely to end soon and my original plan was to migrate to CentOS 5, the RHEL5 clone (trademarks and logos replaced) since it has an awesome support period of 7 years. I also had Debian Etch in mind, having using Debian for this server before - Debian releases security updates one year after the next release which means a total support period of a bit less then 3 years (this varies since no-one can predict when Debian releases). Fedora Core (soon to be renamed Fedora) recently decided on releasing updates some month(s) after the second next release which means support for 1 year plus a couple of more months.

I ended up trying the automatic network upgrade the supported way (using the anaconda installer), booting from a FC6 rescuecd. When that finished I booted into my new FC6 system, ran a yum update and got a bunch of updates including the 2.6.20 kernel - rebooted and all set. Thus I'm calming down a bit on my thoughts of migrating the server to a longer-life distribution. Fedora 7 will release in ~one month from now and I plan to do the FC6 -> F7 upgrade shortly after - and won't have to touch the server again for the next 13-14 months until F9 has released.

Here's some help on evaluating lifetime/upgrades for a distribution:



  • How long is the (security) support period for a release?

  • How often does the distribution release since this will equal the average number of days between your upgrades? Most distributions can upgrade only from N -> N+1 in a supported way.

  • How easy is the upgrade to the next release?

  • Is predictable releases important to you?




The lazy admin may also be interested in things like:



  • How soon after disclosure does the security updates come?

  • What's the bug & security update policy? (backported patches only vs major/minor versions upgrades)

  • What's the robustness of the packaging and tools?

  • Is the software you need available in the repositories?

  • Does your bugs get fixed?

  • ...



YMMV

1 comment:

  1. Another few months passed, better do some blogging huh? :-)

    I really think that when it comes to security one should do a treat assessment, and then create a system design that will minimize risk of break in and damage at compromise.

    In other words, if you depend on security fixes to keep your systems secure you are one step behind. Sometimes a security fix is the only way, but most times a security fix is redundant on a secure system setup.

    ReplyDelete

Note: Only a member of this blog may post a comment.