Linux Node Security Patching for RHEL
Is there documentation on the impacts or risks of having your nodes on different security patch versions? For example, If my system had 2 Util, 2 Stream and 4 Web node types and only 2 of 4 web nodes were updated with security patches and the remaining nodes were on the older version of the RedHat security patches - would there be a risk while the other nodes are updated over time?
@ScottR15 Our team patches the k8s cluster servers all at the same times, always patching the DEV/QA clusters before production clusters to make sure nothing breaks. Would not recommend patching half of the servers at all, although most of the time there might not be any impacts.