Skip to main content
  1. Blog
  2. Article

Canonical
14 September 2021

Ubuntu Livepatch on-prem reduces downtime and unplanned work on enterprise environments!


London, United Kingdom – Canonical announces Ubuntu Livepatch on-prem, an enhancement to its Ubuntu Livepatch service enabling organisations to take control of their kernel livepatching policy. Designed for complex enterprise environments that follow their own patch rollout policy, Ubuntu Livepatch on-prem provides the basis for an efficient but fine-tuned continuous vulnerability management on private, hybrid, or public clouds. It provides a functional and productive experience to system administrators, or IT operations teams. The announcement represents the next phase in the Ubuntu Livepatch service targeting enterprise environments as organisations around the world adopt cybersecurity frameworks and requirements to tackle a constantly changing threat landscape.

With Ubuntu Livepatch on-prem, we are demonstrating our commitment to improve workflows on enterprise environments,” said Nikos Mavrogiannopoulos, Product Manager at Canonical.  

A new operational paradigm with less downtime

Downtime is one of the major pains of every service provider. That is however unavoidable when deploying vulnerability fixes on the Linux kernel the traditional way. That’s because the updated system needs to be rebooted to apply the changes irrespective of your deployment strategy (Kubernetes, OpenStack or bare-metal). Industry leaders achieve high uptime by applying kernel livepatches without rebooting and scheduled maintenance. With regular server maintenance, Ubuntu Livepatch on-prem can eliminate the need for unscheduled reboots to enterprises while enabling them to closely follow their software updates.

New opportunities for high-security enterprise environments

Complex and high security and availability enterprise environments often follow policies that require a gradual roll-out of updates to reduce risk or have high-security isolated environments that need to be updated. These environments, until now, could not take advantage of the Ubuntu Livepatch service to improve their uptime. Ubuntu Livepatch on-prem brings improved uptime on these environments, by enabling an organisation to access livepatches in isolated environments, as well as define its rollout policy and remain in full control of which machines will get updated and when.

Where can I find more information?

Visit https://ubuntu.com/security/livepatch

About Canonical
Canonical is the company behind Ubuntu, the leading OS for container, cloud, and hyperscale computing. Most public cloud workloads use Ubuntu, as do most new smart gateways, switches, self-driving cars, and advanced robots. Canonical provides enterprise support and services for commercial users of Ubuntu. Established in 2004, Canonical is a privately held company.


Related posts

Mythbusting the scope of Livepatch protection

The purpose of this article is to share the technical realities of security patching for the Linux kernel, and the intended scope of the Linux kernel’s livepatch capability....

라이브패치(Livepatch)에 새로운 13개월 슬라이딩 지원 기간이 있습니다. 여러분에게 어떤 의미가 있을까요?

라이브패치는 시스템을 즉시 재부팅할 필요 없고 런타임에 중요하고 높은 보안 커널 공통 보안 취약성 및 노출(CVE)을 수정하는 유용한 툴입니다. 그러나 정기적인 유지 관리 기간 및 재부팅을 대체하는 용도로 사용해서는 안 됩니다. 좋은 기업 정책에는 시스템이 안정적이고 안전하게 유지되도록 라이브패치와 정기적인...

Canonical announces live kernel patching for Arm64

Canonical Livepatch now officially supports Arm64, further expanding its security patching automation capabilities. For the first time, Ubuntu on an Arm64 machine can apply...

Live Linux kernel patching with progressive timestamped rollouts

In internet connected environments, where Ubuntu instances can reach livepatch.canonical.com, Livepatch Client supports timestamp-based rollout configurations. Organizations...