How lazy admins make CentOS 7 server update

scorer(58)
Published in
#centos
Words
672
Reading
3 min
Listen
Play
9y

I was reading some email from developer / admin / programmer mailing list and found an interesting link to CentOS Linux 7 (1708) announce.

I am pleased to announce the general availability of CentOS Linux 7 (1708) for 64 bit x86 compatible machines. Effectively immediately, this is the current release for CentOS Linux 7 and is tagged as 1708, derived from Red Hat Enterprise Linux 7.4

I said to myself - I guess I'll have to check it out and think about updating my boxes.

Server uptime

When I read it, I checked one of my boxes and looked at version it was running.

cat /etc/redhat-release

CentOS Linux release 7.4.1708 (Core)

Hmm. Then I got aha moment of what has happened.

Few days ago I was receiving emails from my servers about huge list of files that were changed.

Time: Thu Sep 14 05:00:21 2017 +0300

The following list of files have FAILED the md5sum comparison test. This means that the file has been changed in some way. This could be a result of an OS update or application upgrade. If the change is unexpected it should be investigated:

/usr/bin/a2p: FAILED
/usr/bin/addr2line: FAILED
/usr/bin/ar: FAILED
/usr/bin/as: FAILED
/usr/bin/aulast: FAILED
/usr/bin/aulastlog: FAILED
/usr/bin/ausyscall: FAILED
/usr/bin/auvirt: FAILED
/usr/bin/bash: FAILED
...
/sbin/zic: FAILED
/etc/init.d/functions: FAILED
/etc/init.d/netconsole: FAILED
/etc/init.d/network: FAILED

And the list goes on. At this moment I thought that it must be a huge update. When you receive such emails, you get used to them and do not care much about it. 😜

I have set up a security check that is running in the background and checking all the files for a changes. I use ConfigServer Security & Firewall (csf) for this purpose. And it is sending me reports about all incidents or suspicious activities going on on my servers.

From csf features I like those ones the most:

  • SSH login notification
  • SU login notification
  • Excessive connection blocking
  • Auto-configures the SSH port if it's non-standard on installation
  • Suspicious process reporting - reports potential exploits running on the server
  • Excessive user processes reporting
  • Excessive user process usage reporting and optional termination
  • Port Scan tracking and blocking
  • Permanent and Temporary (with TTL) IP blocking
  • Exploit checks
  • Distributed Login Failure Attack detection

And maybe something else I can't remember at the moment. Actually I have used to it as a part of system.

And returning for the signs of updates. For one site that has the biggest user load, I had a monitor that informed me about downtime.

It was down for 2 minutes and 25 seconds

So, everything happened without my knowledge and assistance - automagically. It is good because I'm lazy and it is bad - because I am not fully aware of what changes it can bring me. If some software version makes something stop working then I'm in deep trouble.

Actually I have experienced such thing happening in 10 years. But it was only 3 times in my experience. That is another reason why I use CentOS - stable and no tricks. But still I had to downgrade or manually upgrade to specific version that worked fine.

Since those servers do not make me lots of money, are managed mostly for educational purposes and fun, I continue to be lazy living on the edge. 🙌😂

On the latest SystemD based CentOS 7.x servers you can do it in 3 steps.

Install and enable yum-cron service.

yum install -y yum-cron
systemctl enable yum-cron

Edit config file to automatically update.

vim /etc/yum/yum-cron.conf

Make changes you like. But for auto-updates you have to change only this one.

# Whether updates should be applied when they are available.  Note
# that download_updates must also be yes for the update to be applied.
apply_updates = yes

Start service and check its status to be sure that it is running OK.

systemctl start yum-cron
systemctl status yum-cron

And you should see something like this.

Yum-cron status

I did it on my local VirtualBox development server. 😉

That's it. You have a server that is living on its own for years.

However, I'm logging in and restarting web services like MariaDB because it eats memory and does not release it. Since my boxes are running only 2GB of RAM it can eat up everything. So, once in a while you have to check it.

Enjoy and have fun! 🙌

How lazy admins make CentOS 7 server update | Ecency