Patched FreeBSD AMIs
daemonology.net·1d
🌐Iroh
Preview
Report Post

I’ve been maintaining FreeBSD in the EC2 cloud since 2012, and from October 2013 onwards FreeBSD AMIs had code to automatically download and install security and critical errata updates when they first boot. Importantly, this took place before

sshd

started running, to ensure instances could be launched safely even if there were OpenSSH vulnerabilities in the release, and the system rebooted after installing updates to ensure that it would be running an updated kernel.

This was very important for security, but had one downside — and one new issue starting with 15.0:

  1. The process of downloading and installing security updates and rebooting takes time; while I’ve done a lot of work on speeding up the boot process (you can now [launch a FreeBSD/EC2 instance and SSH in less than 10 se…

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help