10 — Server Maintenance

Per-server patch cadence, OS upgrade status, hardware notes, and scheduled maintenance windows. See README for the full resource inventory.

CRITICAL: bms-1 runs Ubuntu 20.04 (EOL) — no security patches since April 2025. An OS upgrade or server migration is the top infrastructure priority.

Per-Server Status

ServerOSEOLDiskLast patchedAction required
vps-i1AlmaLinux 9.72032NormalRecentNone
vps-h1Ubuntu 24.04 LTS2029NormalRecentNone
bms-1Ubuntu 20.04 LTSApr 2025100% FULLUnknownCRITICAL: upgrade + disk clean
bms-2Ubuntu 24.04 LTS2029~40%RecentNone
bms-3Ubuntu 22.04 LTS2027~44%RecentMonitor MongoDB RAM (~21.7 GB)
bms-4Ubuntu 22.04 LTS2027NormalRecentNone

Server Operations Guides

Patch Management

DocumentDescription
update-management.mdPatch cadence, unattended-upgrades config, Docker image update policy
08-image-cve-scanning.mdDocker image CVE scanning proposal

Modernisation Roadmap

DocumentDescription
02-bms-modernization-plan.mdBMS server consolidation and modernisation plan
04-pinbox24-map-dr-audit.mdPinbox24 DR readiness on bms-1
01-service-distribution.mdCurrent service distribution analysis

Ansible Provisioning

New VPS provisioning is managed via Ansible: ansible/playbooks/provision-new-vps.yml See ansible/roles/ for all provisioning roles.

Cross-references

  • README — security hardening per server
  • README — backup coverage per server
  • README — full server inventory