How to Update a Linux Server Safely (and Automate Security Patches)

The right way to run updates on Ubuntu, Debian and AlmaLinux, what to check before and after, when to reboot, and how to automate security patches only.

Published
Reading time
3 min

An unpatched server is the most common way a site gets hacked — not clever attacks, but a known bug with a fix that was published months ago. Updating is not hard; the fear is that an update breaks something. Here is how to update so that it does not, and how to let security fixes install themselves.

Before you update

  • Have a backup from today. A snapshot from the VPS panel is enough and takes seconds.
  • Know what is running: systemctl list-units --type=service --state=running. After the update, the same list should be running.
  • Read what will change. The dry run below shows the packages; a major PHP or MariaDB version in the list means "read the release notes first".

Ubuntu and Debian

bash
sudo apt update                    # refresh the package index
apt list --upgradable              # see what would change
sudo apt full-upgrade              # apply (handles dependency changes; 'upgrade' does not)
sudo apt autoremove --purge        # remove packages nothing needs any more

If a config file you edited (say /etc/ssh/sshd_config) has a new version in the package, apt asks. Keep your currently installed version is nearly always right; look at the diff (D) if unsure. Never let it silently replace sshd_config — that is how root login comes back.

AlmaLinux and Rocky

bash
sudo dnf check-update              # list available updates
sudo dnf upgrade                   # apply
sudo dnf autoremove

dnf keeps your edited configs and writes the new version alongside as .rpmnew; find them with find /etc -name "*.rpmnew" and merge by hand.

Does it need a reboot?

Libraries that were updated stay in memory in running processes until they restart; a kernel update needs a full reboot.

bash
# Ubuntu / Debian
[ -f /var/run/reboot-required ] && cat /var/run/reboot-required
sudo needrestart            # lists services using old libraries, offers to restart them

# AlmaLinux / Rocky
sudo dnf needs-restarting -r

Reboot in a quiet hour: sudo reboot. A VPS is back in under a minute. After it, check the services list again and open the site.

Automate security patches

Applying security fixes automatically, nightly, and leaving feature updates for you to do by hand is the balance that keeps servers both patched and stable.

Ubuntu / Debian — unattended-upgrades:

bash
sudo apt install unattended-upgrades apt-listchanges -y
sudo dpkg-reconfigure -plow unattended-upgrades    # answer Yes

In /etc/apt/apt.conf.d/50unattended-upgrades, the default origins list includes -security only — that is what you want. Three settings worth adding:

Unattended-Upgrade::Remove-Unused-Dependencies "true";
Unattended-Upgrade::Automatic-Reboot "false";
Unattended-Upgrade::Mail "you@example.com";

Leave automatic reboot off unless the server can be down at 04:00 without anyone caring; if it can, set it and Automatic-Reboot-Time "04:00".

AlmaLinux / Rocky — dnf-automatic:

bash
sudo dnf install dnf-automatic -y
sudo nano /etc/dnf/automatic.conf
ini
[commands]
upgrade_type = security
apply_updates = yes
[emitters]
emit_via = email
[email]
email_to = you@example.com
bash
sudo systemctl enable --now dnf-automatic-install.timer

Kernel updates without rebooting

Ubuntu Pro (free for up to five machines) includes Livepatch, which applies kernel security fixes in memory. AlmaLinux and Rocky have kpatch; KernelCare is the commercial option that supports both. With live patching, the "needs reboot" state becomes a monthly thing rather than a weekly one.

Major version upgrades

Moving from PHP 8.2 to 8.3, MariaDB 10.11 to 11, or Ubuntu 22.04 to 24.04 is not an update; it is a migration. Test on a staging copy, read the changelog, do it in a window. For the OS: sudo do-release-upgrade on Ubuntu; a reinstall or leapp on EL. Which distribution makes this easiest is part of choosing a server Linux.

What breaks, and how to undo it

A package update that breaks a service is rare and usually visible in systemctl status. Downgrade one package on apt with apt install package=version (versions from apt policy package), on dnf with dnf downgrade package. Or restore the snapshot you took first — which is why you took it.

On a VPSPioneer managed VPS this is our job: security patches nightly, kernel live-patched, reboots agreed with you, and major upgrades tested on a copy before they touch the live server.

#linux#updates#security#apt#dnf#unattended-upgrades

Keep reading

More from Linux

All guides

Linux

How to Set Up SSH Keys and Turn Off Password Login

Generate an ed25519 key on Mac, Linux or Windows, install it on the server, test it, and disable password authentication so brute-force attacks cannot succeed.

3 min read →

Linux

How to Create a Sudo User and Disable Root SSH Login

Create a user with sudo rights on Ubuntu, Debian, AlmaLinux or Rocky, test it, then lock root out of SSH without locking yourself out.

3 min read →

Linux

Ubuntu vs Debian vs AlmaLinux vs Rocky: Which Linux for a Server?

The practical differences between the server distributions — release cycles, package freshness, support length, tooling — and which to pick for what.

3 min read →