Install security updates automatically
Use unattended-upgrades on Ubuntu 24.04 or Debian 12 to install security fixes every day, reboot when needed, and check that it runs.
Most servers that get broken into were running something with a known hole that already had a fix. unattended-upgrades installs security updates every day, so the fix lands whether or not you remember to log in that week.
Switch it on
Ubuntu 24.04 has it installed and enabled already. Debian 12 may not. Running this is safe on either:
apt update
apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgradesAnswer Yes when it asks about installing stable updates automatically. That writes /etc/apt/apt.conf.d/20auto-upgrades:
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";Both 1s mean daily: refresh the package lists, then install upgrades.
What it installs
The rules are in /etc/apt/apt.conf.d/50unattended-upgrades, under Allowed-Origins on Ubuntu or Origins-Pattern on Debian. Out of the box:
- Ubuntu installs from
${distro_id}:${distro_codename}-security, plus Ubuntu Pro's ESM archives if you've attached Pro. - Debian installs from the security archive (
label=Debian-Security) and the fixes in Debian's point releases (label=Debian).
That's what most servers want. Leave it unless you have a specific reason.
Rebooting
Kernel and core library updates only take effect after a reboot. You can let unattended-upgrades do that at a quiet hour. Package updates can replace 50unattended-upgrades, so put your own settings in a file of your own, /etc/apt/apt.conf.d/52unattended-upgrades-local:
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:00";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";The time is in the server's time zone. If a surprise restart would hurt (a long job, a game server with people on it), skip the automatic reboot and do it yourself. On Ubuntu, this file exists when a reboot is waiting:
ls /var/run/reboot-required && cat /var/run/reboot-required.pkgsCheck it's actually running
A dry run shows what it would install, and complains loudly about config mistakes:
unattended-upgrade --dry-run --debugThen the timers that kick it off:
systemctl list-timers apt-daily.timer apt-daily-upgrade.timerBoth should be there with a next run time. Give it a day, then read the log:
tail -n 30 /var/log/unattended-upgrades/unattended-upgrades.logIf the log says dpkg was interrupted, run dpkg --configure -a and then apt -f install. If a package keeps getting skipped, it may be held; apt-mark showhold lists those. And if the log stays empty for days, check that 20auto-upgrades has both values at 1 and the timers above are enabled.
Emails when something's installed
Add this to your local file:
Unattended-Upgrade::Mail "[email protected]";
Unattended-Upgrade::MailReport "on-change";You'll need a working local mail command, like mailutils, relaying through a mail service. Outbound port 25 is blocked by default here; Sending email: port 25 explains why and what to use instead.