5 ms·
What I find definitely depressing is the fact we used to roll out progressively even OS upgrades (I guess now that is done through intune?) and was one point in
by chronid 2y ago
What I find definitely depressing is the fact we used to roll out progressively even OS upgrades (I guess now that is done through intune?) and was one point in favor of windows (on Linux you had to do things yourself at the time AFAIK, I don't think the situation has improved much).
Nowadays we get mandated random software upgrading at once on the entire company fleet and no one bats an eye - I counted more than a dozen agents installed for "security" and "monitoring" purposes in my previous company servers, many of those with hooks in the kernel obviously, and many of those installed with random policies to tick yet another compliance box...
- consp 2y ago> (on Linux you had to do things yourself at the time AFAIK, I don't think the situation has improved much) You can schedule the updates any time you want, want to do it staggered then configure that, want to do it all at the same time then do that, want it with a random interval also possible. I don't see the "you need to do everything yourself" option as much as any managed environment.
- chronid 2y agoCentralized management is very useful, just a random delay is not enough. One of the (big) companies I worked with had jury rigged something with chef I believe to show different machines different "repositories" and roll things out progressively (1% of the fleet, 5%...).
- chefandy 2y agoI haven't been a sys admin in a very long time so my systems knowledge might be outdated, but I reckon functionality like intune's built-in monitoring of specific feature install failures would make a huge difference with a few dozen systems, let alone the hundreds of thousands you see in some of today's deployments. It's not like that stuff isn't possible on Linux, but if you're coordinating more than a few systems, that turns into a big, expensive project pretty quickly.
- waterhouse 2y agoStaggering is necessary in some cases. I've heard of scenarios where a company has lots of devices in the field which all simultaneously try to download a big update, and DDOS the servers hosting that update.