−25%

on annual Windows plans, until 31 Oct. See plans

EQVPS

How to enable automatic security updates on a VPS

Turn on unattended-upgrades on Ubuntu/Debian or dnf-automatic on Rocky/AlmaLinux so security patches install themselves — and decide about auto-reboots.

Most servers that get broken into weren't hit by anything clever. They ran software with a known, already-fixed hole, and nobody installed the fix. Automatic security updates close that gap without you remembering to log in. It's one of the highest-value five minutes you can spend on a new server.

Ubuntu and Debian: unattended-upgrades

Ubuntu images usually ship with it; Debian may not. Install and switch it on:

apt update
apt install -y unattended-upgrades apt-listchanges
dpkg-reconfigure -plow unattended-upgrades    # answer "Yes"

That creates /etc/apt/apt.conf.d/20auto-upgrades:

APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";

Both values 1 mean: refresh package lists and install security updates daily.

Decide about reboots

Kernel patches need a reboot to take effect. To reboot automatically at a quiet hour, edit /etc/apt/apt.conf.d/50unattended-upgrades and set:

Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:00";
Unattended-Upgrade::Remove-Unused-Dependencies "true";

The server only reboots when an update actually requires it (when /var/run/reboot-required exists).

Test it

unattended-upgrade --dry-run --debug

Logs live in /var/log/unattended-upgrades/.

Rocky Linux and AlmaLinux: dnf-automatic

dnf install -y dnf-automatic

Edit /etc/dnf/automatic.conf:

[commands]
upgrade_type = security
apply_updates = yes

Enable the timer:

systemctl enable --now dnf-automatic.timer
systemctl list-timers dnf-automatic.timer

To see whether a reboot is needed after updates, install dnf-utils and run needs-restarting -r.

Which reboot policy is right?

What this doesn't cover

System packages only. Your Docker images, language dependencies (pip, npm) and self-installed binaries don't update themselves — schedule those separately. And updates within a release are automatic; moving to a new release (Ubuntu 22.04 → 24.04) stays a deliberate, manual job.

If a bad update ever does break boot, the web console in the EQVPS dashboard gets you in without SSH, and Managed Backups give you a restore point from before the change.

FAQ

Is it safe to install updates automatically?

For security updates, yes — that's what unattended-upgrades installs by default. They're small, targeted fixes. The risk of an unpatched, known vulnerability is far higher than the risk of a security patch breaking something.

Should the server reboot automatically?

Kernel and core-library patches only take effect after a reboot. If your service can survive a minute of downtime at 4 a.m., turn automatic reboots on. If it can't, leave them off and reboot by hand when /var/run/reboot-required appears.

How do I know updates actually ran?

Check /var/log/unattended-upgrades/unattended-upgrades.log on Debian/Ubuntu, or 'journalctl -u dnf-automatic' on Rocky/Alma. A dry run with 'unattended-upgrade --dry-run --debug' shows what would be installed right now.

Will this upgrade my distribution to a new major version?

No. unattended-upgrades and dnf-automatic only install updates within your current release. Moving from Ubuntu 22.04 to 24.04, for example, is always a manual step.

Does it update Docker containers too?

No — only system packages. Container images are updated by pulling new versions and recreating the containers, on your schedule.

Comments

No comments yet. Be the first.

Leave a comment

Comments are moderated before they appear.