Kingsfordweg 151, 1043GR Amsterdam, The Netherlands ● 24/7 support — support@novogara.com
Knowledge base

Upgrading the kernel safely

A kernel upgrade is the most common reason a remote machine does not come back. It is also easy to make safe.

Before you reboot

  • Keep the previous kernel installed. Never let a cleanup remove every older version; that is your way back.
  • Check that the boot menu actually appears and is reachable over remote KVM. A timeout of five seconds is enough to catch it, zero is not.
  • Make sure you can get in without the network: the console is your lifeline if the new kernel loses a driver.
  • Out-of-tree modules — ZFS, proprietary drivers, anything DKMS builds — rebuild against the new kernel before the reboot, not after.

Reboot at a sane moment

Not at the end of your working day. If something goes wrong you want an hour of daylight and a clear head, not a dark evening and a deadline.

If it does not come back

Open the console, power-cycle from the portal, and watch from the first frame. Pick the previous kernel from the boot menu and you are running again in a minute. Then work out what broke, with the machine up instead of down.

No boot menu at all? Boot into single user mode or a rescue environment from the console. Nothing here needs a ticket — but if you want a second pair of eyes while you do it, open one anyway.

Live patching

Useful on machines that genuinely cannot reboot, but it does not replace reboots forever: eventually you need the new kernel. Plan a maintenance window every few months rather than postponing one for years.


Still stuck? Mail support@novogara.com — an engineer answers, at any hour. Back to the knowledge base