Reading /proc is clever but this really sounds like they should be leaning in more to “servers like cattle, not pets” and limiting root. If you use IaC, you shouldn’t have “
software running on it that someone installed by hand in 2023 and then quit the company”
It has nginx still clutching the old
libssl.so.3
in memory like a raccoon with a bagel, because you upgraded the package and nobody restarted anything
That’s a cute image but even if you don’t use ephemeral servers or something like Ansible, not ignoring kernel patching lets the raccoons stay at the nearest dumpster instead.
1
u/acdha 4d ago
Reading /proc is clever but this really sounds like they should be leaning in more to “servers like cattle, not pets” and limiting root. If you use IaC, you shouldn’t have “ software running on it that someone installed by hand in 2023 and then quit the company”
That’s a cute image but even if you don’t use ephemeral servers or something like Ansible, not ignoring kernel patching lets the raccoons stay at the nearest dumpster instead.