Service 03 / 04
Updates & security
Unpatched systems are the most common way in – and midnight maintenance windows are not a solution. We update your cluster during live operation: node by node, tested, with no interruption for your users.
Approach
Staying current without standing still.
In a high-availability cluster, redundancy is not just insurance against failures – it is also the tool for maintenance: a node is taken out of the pool, updated, tested, and rejoined, then the next one. Your application keeps running on the remaining nodes the whole time.
Security does not stop at patching. Every system is hardened along best practices: minimal attack surface, strict firewall rules, secured access, separated networks. Whatever does not need to be reachable, is not.
And because no protection is absolute, a solid backup strategy with regular restore tests is part of the package. A backup that has never been restored is just a hope – we turn it into certainty.
Scope
What updates & security include.
- Security patches for the operating system, virtualization, and services; critical vulnerabilities take priority.
- Rolling updates node by node during live operation, with no maintenance windows for your users.
- System hardening: minimal services, restrictive firewalls, secured SSH access, network separation.
- Configuration upkeep: traceable, versioned configuration instead of grown hand-crafted state.
- Backup strategy with separate storage and defined retention periods.
- Regular restore tests: recovery is rehearsed, not attempted for the first time in an emergency.
- TLS & certificate management: certificates are renewed automatically and monitored.
- Security incident response: analysis, containment, recovery, and a follow-up report.
Reference
A rolling update, node by node.
FAQ
Common questions about updates & security.
Are there really no maintenance windows?
For routine updates: no – they run node by node without interruption. Only in rare exceptions, such as a major database upgrade, a short cutover may be necessary. We announce those in advance and schedule them in a time window you choose.
How quickly are critical vulnerabilities patched?
Critical vulnerabilities are treated with priority and patched as quickly as possible after they become known, independent of the regular update cycle. Until a patch is available, interim measures such as firewall rules apply where possible.
Where are the backups stored?
Separate from the cluster, in German data centers. Retention periods and scope are agreed together; on request, with an additional copy at a second location.
Do you test updates before they reach the cluster?
Yes. Updates go through the first node, which is verified after patching, before the others follow. If a problem shows up, it stays limited to one node and is rolled back – with no impact on operations.
Contact
When was your last backup actually tested?
If you have to hesitate, we should talk. Initial assessment within one business day, free of charge and without obligation.
Request a project