Install security updates automatically

Use unattended-upgrades on Ubuntu 24.04 or Debian 12 to install security fixes every day, reboot when needed, and check that it runs.

Most servers that get broken into were running something with a known hole that already had a fix. unattended-upgrades installs security updates every day, so the fix lands whether or not you remember to log in that week.

Switch it on

Ubuntu 24.04 has it installed and enabled already. Debian 12 may not. Running this is safe on either:

bash
apt update
apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades

Answer Yes when it asks about installing stable updates automatically. That writes /etc/apt/apt.conf.d/20auto-upgrades:

text
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";

Both 1s mean daily: refresh the package lists, then install upgrades.

What it installs

The rules are in /etc/apt/apt.conf.d/50unattended-upgrades, under Allowed-Origins on Ubuntu or Origins-Pattern on Debian. Out of the box:

  • Ubuntu installs from ${distro_id}:${distro_codename}-security, plus Ubuntu Pro's ESM archives if you've attached Pro.
  • Debian installs from the security archive (label=Debian-Security) and the fixes in Debian's point releases (label=Debian).

That's what most servers want. Leave it unless you have a specific reason.

Rebooting

Kernel and core library updates only take effect after a reboot. You can let unattended-upgrades do that at a quiet hour. Package updates can replace 50unattended-upgrades, so put your own settings in a file of your own, /etc/apt/apt.conf.d/52unattended-upgrades-local:

text
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:00";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";

The time is in the server's time zone. If a surprise restart would hurt (a long job, a game server with people on it), skip the automatic reboot and do it yourself. On Ubuntu, this file exists when a reboot is waiting:

bash
ls /var/run/reboot-required && cat /var/run/reboot-required.pkgs

Check it's actually running

A dry run shows what it would install, and complains loudly about config mistakes:

bash
unattended-upgrade --dry-run --debug

Then the timers that kick it off:

bash
systemctl list-timers apt-daily.timer apt-daily-upgrade.timer

Both should be there with a next run time. Give it a day, then read the log:

bash
tail -n 30 /var/log/unattended-upgrades/unattended-upgrades.log

If the log says dpkg was interrupted, run dpkg --configure -a and then apt -f install. If a package keeps getting skipped, it may be held; apt-mark showhold lists those. And if the log stays empty for days, check that 20auto-upgrades has both values at 1 and the timers above are enabled.

Emails when something's installed

Add this to your local file:

text
Unattended-Upgrade::Mail "[email protected]";
Unattended-Upgrade::MailReport "on-change";

You'll need a working local mail command, like mailutils, relaying through a mail service. Outbound port 25 is blocked by default here; Sending email: port 25 explains why and what to use instead.

Be first when orders open

Join the waitlist and we'll send you one email when VPSNine launches. Pick a plan if you already know which one you want, and we'll size the first servers around it.