Decide whether a host change is actually running, trusted, and recoverable. A successful command or policy parse is useful evidence, but it is not the final service check.
Review these lessons
- Linux kernel rollouts: prove the running kernel after each reboot cohort
- SSH host-key rotation: change server identity without teaching clients to ignore warnings
- SSH user certificates: bind host login to an expiry and a narrow principal
- sudo policy: authorize an exact maintenance action, not a path to a shell
- nftables rollouts: apply a checked ruleset with an access recovery timer
- LUKS recovery drills: preserve independent unlock and header recovery paths
Other checks
Common Mistakes
- Do not use a broken management path as the only rollback channel.
- Do not confuse encrypted-volume unlock with a verified application restore.
