Linux and Red Hat

Linux patch management

Unpatched Linux servers are how most edge and web compromises start. The fix is boring: a schedule, a staging ring, a reboot policy and reporting that shows what is still behind.

We run patching as a managed service, with security updates applied quickly, feature updates in windows, live kernel patching where reboots are hard and a monthly report.

At a glance

ToolsRed Hat Satellite, Landscape, Ansible, unattended-upgrades, dnf-automatic
Live patchingkpatch (RHEL), Canonical Livepatch, KernelCare
RingsTest, staging, production with defined soak time
ReportingPatch compliance per host, CVE exposure

What RackLedge does

How we work

Linux fleets stay healthy through automation and discipline. We build servers from a standard image with Ansible, patch them on a schedule with a staging ring, keep SELinux or AppArmor on, and log everything to a central collector. The result is a fleet that looks the same everywhere and can be rebuilt from Git.

Migrations, whether CentOS to Rocky, RHEL 8 to 9 or Windows to Linux, are done per workload with a test pass, a cutover window and a rollback. We coordinate with application vendors and keep the paperwork for compliance.

Subscriptions and licences are reviewed as part of the work. Plenty of businesses pay for RHEL where Rocky would do, or run unsupported CentOS where a subscription would satisfy an auditor. We fix both directions.

Related services

More on linux and red hat

Frequently asked questions

How fast should critical patches go out?

Internet-facing systems within days, internal within the next window. A known-exploited vulnerability gets an emergency change.

Need a hand with this?

Tell us what you are running and what is slowing you down. You get a straight assessment and a plan, with no obligation. Support desk is staffed 24/7.

Get in touch