Guspaz wrote:
Even if the primary linode is completely compromised, root and all, they can't mount the ISO as read/write since ultimately the primary linode is not the one putting the read-only restriction on it.
True, but being compromised, the aide system on it will never tell something's amiss, the binary can be compromised regardless where the db resides. So better idea is the other way around, have a dedicated node that periodically scans other nodes, but then again who is to say that that node, which then becomes single point of failure is not compromised?
It's a mess, really. The only way to be sure is having periodic "Crazy Ivans" (shutdown node, mount rescue, scan). Otherwise just have faith aide itself is not compromised (and help it be so with rigorous protection), and if that's not enough, scan it in rescue mode from time to time.
