3 ms·
I agree with pretty much everything here. I don’t think there’s a no-maintenance solution out there that will just keep running hands-off (maybe 25 years ago in
by janstice 5y ago
I agree with pretty much everything here. I don’t think there’s a no-maintenance solution out there that will just keep running hands-off (maybe 25 years ago in a uni environment, but certainly not for the last 10 years).
You could probably automate a simple(?) cloud stack using a declarative & open-ended template that can be rerun every couple of years (or months) to pick up security changes, but someone’s going to have to set up & pay for sufficiently secure networking from the cloud provider to your internal network - this is a surprisingly large amount of work when you include security, user access, backups of systems & data, etc.
I work in academic IT and this is the sort of thing that we deal with frequently, so I’d hope that your internal IT would be similar - when you request things, tell them the whole story, rather than say request 2 Linux servers, so you can leverage their enterprise security & backup, and they can set up things so that the internal IT can effectively support the system (We see a bunch of issues in systems where we provided bare boxes, the research/academic team set something up, then disbanded or moved on to something else, leaving cruft and security vulnerabilities all over the place).
- midasuni 5y agoI have many systems that have been running for 10 years with few or indeed no changes, the same deb applies now on Ubuntu 2004 as it did on 804 I don’t use the latest fancy technology and frameworks that work today but have breaking changes every few minutes. I care about the output of the code, not the feelings of the person writing it. LAMP worked 20 years ago, and there’s been little update. Use Perl instead and there’s been even less. I’d be surprised if rhey didn’t work in 10 years. Meanwhile I accidentally upgraded some version of nodejs and it broke some “fancy” code that somebody had written. We ended up rewriting the entire code in php rather than try to unpick the mess that had been left.
- xupybd 5y agoYou're not wrong about Perl. I hate working with it but if you're looking for longevity it's near the top of the list for good choices. There are some things that run you into trouble. When SSL versions change you might have to update that part of your stack. When things like the log4j vulnerability hit you have to update that sort of thing. If you are working with external systems sometimes they change interfaces and you're forced to update. If you're working with government compliance you no doubt have to change every 3 years for no good reason.
- midasuni 5y agoI don’t use cpan modules directly, just OS bundled modules. Apt dist upgrade handles the required security issues (and besides these are internal apps, the threat surface is much reduced as you have to be an authenticated user/machine to access it in the first place)