OS Security Updates
Over the course of time, multiple software vulnerabilities (a.k.a. CVEs) will be found.
While Dalet is committed to deliver security-fixes to any Flex proprietary services, vulnerabilities found in open-source software which are part of Ubuntu remain out of Dalet's scope.
The deployment framework however allows configuring the operating system to self-upgrade packages from security channel. Ubuntu maintains a dedicated security repository channel which is updated each time a patch for a given security vulnerability is available.
By default, security channel auto-upgrades is enabled.
It can be reconfigured and fine-tuned to specify a given update and, more essentially, upgrade window (defaults to 3am), allowing you to ensure security package upgrades are performed when system is the least used.
Tuning can be applied by editing the ansible/variables/ansible.vars file with the following settings:
dalet_baseos_security_unattended_update_period: 7 # days
dalet_baseos_security_unattended_upgrade_period: 14 # days
dalet_baseos_security_unattended_autoclean_interval: 28 # days
dalet_baseos_security_unattended_upgrade_days_of_the_week: ~ # "Mon,Tue", defaults to everyday.
dalet_baseos_security_unattended_upgrade_hour: 3