Most servers that get broken into weren't hit by anything clever. They ran software with a known, already-fixed hole, and nobody installed the fix. Automatic security updates close that gap without you remembering to log in. It's one of the highest-value five minutes you can spend on a new server.
Ubuntu and Debian: unattended-upgrades
Ubuntu images usually ship with it; Debian may not. Install and switch it on:
apt update
apt install -y unattended-upgrades apt-listchanges
dpkg-reconfigure -plow unattended-upgrades # answer "Yes"
That creates /etc/apt/apt.conf.d/20auto-upgrades:
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";
Both values 1 mean: refresh package lists and install security updates daily.
Decide about reboots
Kernel patches need a reboot to take effect. To reboot automatically at a quiet hour, edit /etc/apt/apt.conf.d/50unattended-upgrades and set:
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:00";
Unattended-Upgrade::Remove-Unused-Dependencies "true";
The server only reboots when an update actually requires it (when /var/run/reboot-required exists).
Test it
unattended-upgrade --dry-run --debug
Logs live in /var/log/unattended-upgrades/.
Rocky Linux and AlmaLinux: dnf-automatic
dnf install -y dnf-automatic
Edit /etc/dnf/automatic.conf:
[commands]
upgrade_type = security
apply_updates = yes
Enable the timer:
systemctl enable --now dnf-automatic.timer
systemctl list-timers dnf-automatic.timer
To see whether a reboot is needed after updates, install dnf-utils and run needs-restarting -r.
Which reboot policy is right?
- A single app that can blink for a minute at night (a bot, a personal service, a small site): automatic reboots on.
- Something users hit 24/7, or a database you'd rather restart yourself: reboots off, and a reminder to reboot when
/var/run/reboot-requiredshows up.
What this doesn't cover
System packages only. Your Docker images, language dependencies (pip, npm) and self-installed binaries don't update themselves — schedule those separately. And updates within a release are automatic; moving to a new release (Ubuntu 22.04 → 24.04) stays a deliberate, manual job.
If a bad update ever does break boot, the web console in the EQVPS dashboard gets you in without SSH, and Managed Backups give you a restore point from before the change.
Comments
No comments yet. Be the first.