Upgrade Overview
HCE is continuously updated throughout its lifecycle to fix known vulnerabilities, fix system defects, and improve product experience. This ensures high security, stability, and optimal performance of your system environment. We strongly recommend that all customers establish a regular upgrade mechanism to ensure that the system is upgraded to the latest HCE version at least once a year.
For each HCE kernel iteration version, HCE provides one-year kernel hot patch support. After the support period expires, you need to upgrade the kernel to the latest version to obtain the latest functions, performance optimizations, and security fixes. Note that hot patches are mainly used to fix major and critical CVE vulnerabilities and errors, reducing the need to restart the server due to patch updates. However, they cannot completely eliminate the need for server restarts. Additionally, hot patches are not a universal kernel upgrade solution and are not suitable for fixing all high-risk vulnerabilities or major errors.
You can upgrade HCE using either dnf, yum, or OSMT:
- In Linux, you can use dnf or yum to upgrade or roll back RPM packages.
- OSMT is a software tool from Huawei Cloud that you can use to upgrade or roll back HCE and RPM packages. OSMT allows you to customize the upgrade scope and configure scheduled checks and delayed restarts.
Differences between the two methods are described in the following table.
| Item | dnf or yum | OSMT |
|---|---|---|
| RPM package upgrade |
|
|
| OS version upgrade | Not supported | Supported |
| Version | Upgrade of HCE 1.1 | Upgrade of HCE 2.0 |
| Rollback | Rollback to any historical update | Rollback only to the last update |
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot