Skip to content
ViaLicense
99.98% UPTIME
EN TR
Sign in Become a reseller
Performance

KernelCare License: Kernel Security Patches Without a Reboot

Close a kernel vulnerability the day the patch lands, without taking the machine down. The license is bound to your server IP and installs with a single command.

KernelCare applies security patches to a running Linux kernel while the machine stays up. The usual alternative is to install the new kernel and schedule a reboot — which, on a box hosting hundreds of sites, means a late-night maintenance window, a notice to customers and, more often than anyone likes to admit, a patch that sits unapplied for weeks. All that time the server keeps running a kernel whose flaw is already public. Live patching removes the trade-off: the fix goes into the running kernel in memory, processes are not interrupted, and uptime is not reset. It is aimed at shared hosting firms with hundreds of accounts on one machine, resellers who share a box with their customers, and sysadmins who never find a convenient moment to restart anything.

The license you buy here is registered against your server's IP address rather than a key file you have to download and keep safe. Installation is a single command on the server; the script resolves the license from the IP and brings the agent online. Payment comes out of your prepaid balance with no approval step in between, so the license is usually live within a minute. When you move the server to another machine or another data centre, you change the IP yourself in the panel — no ticket, no waiting — and the license on the old address stops immediately. If you run a fleet, creating, renewing, suspending and re-pointing licenses is all available over the REST API, which is open on every account tier and can be wired into WHMCS or your own system. Monthly licenses run to the end of the paid period and auto-renewal can be switched off whenever you like; there is no contract and no cancellation fee. Every order, renewal and API call is logged to your account with its result.

Patches are built against stock distribution kernels. If you run a custom-built or modified kernel, check `uname -r` before ordering, because the agent will simply find nothing to apply. With container virtualisation such as OpenVZ or LXC the kernel belongs to the host node, so the license goes on the host rather than on each container; KVM, VMware and bare-metal servers each run their own kernel and each need their own license. Userspace patching — keeping components like OpenSSL and glibc current without restarting services — and extended support for distributions past end of life are separate scopes; the catalogue shows which package covers what, at the current price. Finally, reboots do not disappear altogether: major kernel version jumps, hardware and driver changes and some system updates still call for a planned restart. What you gain is not having to postpone a security patch until that day comes around.

Why buy it here

No-reboot patching

Kernel security patches are applied while the server keeps serving traffic, so there is no maintenance window to schedule.

Unattended updates

The agent checks for new patches on a schedule and applies them without you watching.

Reversible patches

If a patch misbehaves, kcarectl unloads it again without restarting the machine.

IP-based license

No key file to store: the license follows the server's IP, and you re-point it yourself in the panel.

Frequently asked

Once it is installed, do I ever reboot again?

For kernel security patches, no — and that is the whole point. You will still plan a reboot for major kernel version upgrades, hardware or driver changes and certain system updates. What changes is that a published vulnerability no longer has to wait for the next maintenance window.

How many servers does one license cover?

One license, one server, tied to that server's IP. On container platforms such as OpenVZ and LXC the kernel is shared with the host node, so the license belongs on the host and the containers inside it are not licensed separately. KVM, VMware and physical servers each run their own kernel and each need their own license.

I compile my own kernel. Will it work?

Patches are built for the distributions' own kernel builds. A self-compiled or modified kernel will not match, and the agent will not apply anything. Run `uname -r` on the server before you order; if the output is not a stock distribution kernel, or you are not sure, send it to us and ask whether that build is covered.

How soon after payment can I install it?

The cost is deducted from your prepaid balance and the license is created straight away; nothing sits waiting for approval and it is normally usable within a minute. Run the one-line installer on the server — because the script identifies the license by IP, there is no key for you to copy or store anywhere.

Add your server's IP, create the license and get the kernel patched without waiting for the next maintenance window.