Apply Exadata Live Update for VM Operating System Updates

Introduction

Exadata Live Update lets you apply eligible VM operating system fixes while the virtual machines remain online. This helps you address security requirements without temporarily reducing VM cluster capacity for a rolling reboot.

The feature is available for eligible Exadata VM clusters in Oracle Exadata Database Service on Dedicated Infrastructure and Oracle Exadata Database Service on Cloud@Customer that use a supported Exadata Image release.

When an image contains updates that cannot be installed online, it applies the eligible online fixes first and records the remaining changes as pending updates. You can apply those pending changes later through the standard rolling-reboot process.

For VM operating system updates, there are two update paths to choose from:

Option What it does
Full update Applies the target image using rolling reboots. Databases remain available, but each VM is restarted in turn.
Online update Applies eligible updates while the VMs remain online. Any fixes that require a reboot remain pending.

For Online update path, you have options to select update scope:

CVSS (Common Vulnerability Scoring System) is an industry standard for describing the severity of a security vulnerability. Its Base Score ranges from 0.0 to 10.0, with higher scores indicating greater severity. Oracle uses CVSS Base Metrics in security advisory risk matrices; these metrics reflect characteristics intrinsic to a vulnerability, while temporal and environmental factors can change over time or depend on your environment.

Use the CVSS score to help prioritize the eligible security fixes included in an online update. For Oracle’s scoring interpretation, including CVSS version 3.1 details and metric definitions, see Use of Common Vulnerability Scoring System (CVSS) by Oracle.

Objectives

In this tutorial, you will:

  1. Apply VM operating system online update with High CVSS only scope.
  2. Apply VM operating system online update with All CVSS scope.
  3. Apply VM operating system online update with All online updates scope.
  4. Review and apply pending updates, if required.

Note: You do not need to complete these tasks sequentially. Choose and perform the update-scope (High CVSS/All CVSS/All Online) that meets your requirements; review and apply pending updates only when applicable.

Prerequisites

Before you begin, make sure you have:

Important: A precheck is strongly recommended before every update. Review the precheck results and resolve any reported issues before you apply the update.

Task 1: Apply VM operating system online update with High CVSS only scope

  1. Open the navigation menu and select Oracle AI Database.

  2. Select Oracle Exadata Database Service on Dedicated Infrastructure or Oracle Exadata Database Service on Cloud@Customer.

    OCI Console screenshot: live update console service navigation

    Description of the illustration live-update-console-service-navigation.png

  3. Open Exadata VM Clusters, choose the correct compartment, and select the VM cluster.

    OCI Console screenshot: live update vm clusters list

    Description of the illustration live-update-vm-clusters-list.png

  4. On the VM cluster details page, review the current Exadata image version. A New versions available indicator identifies an image that can be evaluated for update.

    OCI Console screenshot: live update vm cluster version details

    Description of the illustration live-update-vm-cluster-version-details.png

  5. Select the Updates (OS) tab. For the target image, select Actions, then Apply Exadata OS Image Update.

    OCI Console Actions menu for an available OS image update

    Description of the illustration live-update-os-update-actions-available.png

  6. Select Online update, then select High CVSS only. Review the target image and pending-update message, then click Run Precheck. Confirm the precheck if prompted.

    Online update dialog with High CVSS only scope selected for precheck

    Description of the illustration live-update-select-high-cvss-scope-precheck.png

  7. Wait for the precheck work request to succeed. Reopen Apply Exadata OS Image Update, select Online update and High CVSS only, then click Apply.

    Online update dialog with High CVSS only scope selected before applying the update

    Description of the illustration live-update-select-high-cvss-scope.png

  8. Monitor Work requests, Updates (OS), and Update History until the update succeeds. Verify that Update History records the High CVSS only scope.

    OCI Console screenshot: live update history online update result

    Description of the illustration live-update-history-online-update-result.png

Task 2: Apply VM operating system online update with All CVSS scope

  1. Return to Updates (OS) and select the next approved available OS image. From its Actions menu, select Apply Exadata OS Image Update.

  2. Select Online update, then select All CVSS. Review the target image and pending-update message, then run and confirm the precheck.

    Online update dialog with All CVSS scope selected for precheck

    Description of the illustration live-update-select-all-cvss-updates-precheck.png

  3. After the precheck succeeds, reopen Apply Exadata OS Image Update, select Online update and All CVSS, then click Apply.

    Online update dialog with All CVSS scope selected before applying the update

    Description of the illustration live-update-select-all-cvss-updates.png

  4. Monitor Work requests and Update History until the update succeeds. Verify that Update History records the All CVSS scope.

    OCI Console screenshot: live update history all cvss applied

    Description of the illustration live-update-history-all-cvss-applied.png

Task 3: Apply VM operating system online update with All online updates scope

  1. Return to Updates (OS) and select the next approved available OS image. From its Actions menu, select Apply Exadata OS Image Update.

  2. Select Online update, then select All online updates. Review the target image and pending-update message, then run and confirm the precheck.

    Online update dialog with All online updates scope selected for precheck

    Description of the illustration live-update-select-all-online-updates-precheck.png

  3. After the precheck succeeds, reopen Apply Exadata OS Image Update, select Online update and All online updates, then click Apply.

    Online update dialog with All online updates scope selected before applying the update

    Description of the illustration live-update-select-all-online-updates.png

  4. Monitor Work requests, Updates (OS), and Update History until the update succeeds. Verify that Update History records the All online updates scope.

    Update History showing completed online update operations

    Description of the illustration live-update-history-overview.png

Task 4: Review and apply pending updates, if required

An online update can leave reboot-required fixes as pending updates. The VM cluster details page identifies this condition and provides the Apply pending updates action.

  1. On the VM cluster details page, review the version section and identify any pending updates.

    VM cluster version section showing the Apply pending updates action

    Description of the illustration live-update-pending-updates-available.png

  2. Click Apply pending updates when you are ready to complete the outstanding changes in an approved rolling-reboot window.

    Apply pending updates button on the VM cluster version section

    Description of the illustration live-update-pending-updates-button.png

  3. Run the precheck from the pending-update dialog by clicking Run Precheck.

    Apply pending Exadata OS Image update dialog with Run Precheck highlighted

    Description of the illustration live-update-pending-updates-precheck.png

  4. After the precheck succeeds, reopen Apply pending updates and click Apply.

    Apply button in the pending Exadata OS Image update dialog

    Description of the illustration live-update-pending-updates-apply.png

  5. Monitor the pending-update work request and Update History entry until the operation succeeds.

    Update History showing the completed pending-update operation

    Description of the illustration live-update-history-pending-updates-completed.png

  6. On the VM cluster details page, verify that the version section no longer shows pending updates or the Apply pending updates action.

    VM cluster version section after pending updates are applied

    Description of the illustration live-update-pending-updates-applied.png

Acknowledgments

More Learning Resources

Explore other labs on docs.oracle.com/learn or access more free learning content on the Oracle Learning YouTube channel. Additionally, visit education.oracle.com/learning-explorer to become an Oracle Learning Explorer.

For product documentation, visit Oracle Help Center.