How to update a Debian or Ubuntu VPS, and turn on automatic security updates

A server that is not updated piles up known security holes, and the updates already released are the cheapest defence you have. There are two jobs: the manual routine (updating when it suits you, seeing what changes) and automatic security updates (only the fixes, with no intervention). This guide covers Debian and Ubuntu; at the end, the equivalent for AlmaLinux and Rocky. The commands are yours, on your own server: support does not run them for you (see how far our support goes).

The manual routine

1 Take a copy or a snapshot first. It is what saves you if an update breaks a service. See backing up a VPS: snapshots or files.
2 Refresh the package list: sudo apt update. It installs nothing, it only checks what is new.
3 See what will change: apt list --upgradable.
4 Apply: sudo apt upgrade. Read what it proposes before confirming. sudo apt full-upgrade does the same but also installs or removes packages when needed to resolve dependencies.
5 Clear out what is left over: sudo apt autoremove.
6 Check whether you need to reboot. On Ubuntu, if the file /var/run/reboot-required exists, the updates (the kernel, for example) only take effect after sudo reboot. Reboot at a quiet moment and confirm that the services came back.

Automatic security updates

1 Install: sudo apt install unattended-upgrades. On Ubuntu it usually comes installed.
2 Enable: sudo dpkg-reconfigure --priority=low unattended-upgrades and answer “Yes”.
3 Confirm that the file /etc/apt/apt.conf.d/20auto-upgrades has the lines APT::Periodic::Update-Package-Lists "1"; and APT::Periodic::Unattended-Upgrade "1";.
4 Do a dry run: sudo unattended-upgrade --dry-run --debug shows what it would do, without touching anything. The logs are in /var/log/unattended-upgrades/.

By default only security updates are applied and the server does not reboot by itself. It is worth checking now and then whether a reboot is pending.

On AlmaLinux or Rocky Command
See what is available sudo dnf check-update
Apply sudo dnf upgrade
Check whether a reboot is needed sudo dnf install dnf-utils and then needs-restarting -r
Automatic sudo dnf install dnf-automatic, set apply_updates = yes in /etc/dnf/automatic.conf and sudo systemctl enable --now dnf-automatic.timer
You need not update a production server blindly. An update to something your site depends on (the database, the PHP version) can change behaviour. To pin a package at its current version: sudo apt-mark hold package-name. And if the system has reached end of life, it stops receiving fixes: see keeping your VPS secure: the six that matter.
“Could not get lock /var/lib/dpkg/lock-frontend” means another process (often the automatic updates themselves) is using apt. Wait a few minutes and repeat; do not delete the lock file. Moving to a different release of the system is another matter: see upgrading Ubuntu to the next LTS release without breaking the server.

Did an update break a service and you do not know how to go back? Tell us what ran and the VPS address.

Open a support ticket

SEE ALSO

Keeping your VPS or dedicated server secure: the six that matter

Backing up a VPS: snapshots or files

Upgrading Ubuntu to the next LTS release without breaking the server

Which operating system to choose for your VPS or server

RECOMMENDED PRODUCT

VPS server with root access

Resources of your own, the OS you choose, reinstall whenever you like. from $8.39/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?