Patching

Patching #

Day 2 maintenance and security updates for substrate hosts.


Status: Planned #

This section will document:

  • Online patching (hosts with internet access)
  • Offline patching (air-gapped site)
  • Local dnf mirror setup for full air-gap

Decision Required #

Post-install updates currently require internet access. Options:

OptionProsCons
Accept internet requiredSimple, no extra storageNot true air-gap
Full local dnf mirrorTrue air-gap~200GB per Fedora release
Hybrid (security only)BalancedComplex to maintain

Current State #

Install-time packages come from ISO/cdrom (air-gap ready).

Post-install dnf update reaches public Fedora mirrors unless a local mirror is configured.


Future Work #

When this decision is made, document:

  1. Mirror setup (if local)
  2. Update frequency and process
  3. Rollback procedures
  4. Security advisory monitoring
Page last modified: March 9, 2026