Most break-ins on small servers use flaws that already had a fix available. Installing security updates automatically closes that gap without you having to remember.
On Ubuntu and Debian, turn on unattended-upgrades; on AlmaLinux, Rocky Linux and Fedora, turn on dnf-automatic. Both install security updates daily without you logging in. Then decide how reboots happen, because kernel updates need one.
Why automatic updates are worth it
Most compromised servers are not broken into with clever new attacks. They are running software with a known, already-fixed hole, found by bots that scan the whole internet within hours of a fix being published. Security updates for the operating system and its packages are tested and conservative, so installing them automatically is far safer than leaving them for when you remember.
Ubuntu and Debian: unattended-upgrades
It is installed by default on most Ubuntu servers. Make sure it is on:
sudo apt install unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgrades
Answer Yes. This applies security updates daily. Check what it has done:
sudo cat /var/log/unattended-upgrades/unattended-upgrades.log
Some updates, especially the kernel, only take effect after a reboot. When one is waiting, the file /var/run/reboot-required exists. To reboot automatically at a quiet time, set these in /etc/apt/apt.conf.d/50unattended-upgrades:
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:00";
AlmaLinux, Rocky Linux and Fedora: dnf-automatic
sudo dnf install dnf-automatic
Edit /etc/dnf/automatic.conf and set:
[commands]
upgrade_type = security
apply_updates = yes
Then start the timer:
sudo systemctl enable --now dnf-automatic.timer
systemctl list-timers | grep dnf
Check whether a reboot is needed with sudo dnf needs-restarting -r.
Get told what happened
Both tools can email a summary. For unattended-upgrades, set in /etc/apt/apt.conf.d/50unattended-upgrades:
Unattended-Upgrade::Mail "you@example.com";
Unattended-Upgrade::MailReport "only-on-error";
For dnf-automatic, set emit_via = email and email_to in /etc/dnf/automatic.conf. Both need the server to be able to send mail, which many cloud servers cannot do without a relay. If yours cannot, check the logs instead:
grep -h "Packages that will be upgraded" /var/log/unattended-upgrades/*.log | tail
sudo journalctl -u dnf-automatic-install --since "1 week ago"
Services that need a restart
Updating a library such as OpenSSL does not change programs already running with the old copy. Debian and Ubuntu’s needrestart tool, installed by default on recent Ubuntu, lists and can restart affected services:
sudo needrestart -r l
On RHEL-based systems, sudo dnf needs-restarting -s lists services to restart.
Kernel updates without rebooting
A rebooted kernel is the only way to run a kernel fix on most setups. Live patching services, such as Ubuntu Pro’s Livepatch (free for a few personal machines) or KernelCare, apply critical kernel fixes in memory, so reboots can wait for a planned window. For most single servers, an automatic reboot at 4 a.m. once a week is simpler and good enough.
What it does not cover
- Software you installed outside the package manager, such as WordPress, its plugins, or apps from Git. Keep those updated separately.
- Major version upgrades of the operating system, which you should plan and test.
Check it is working
A month after turning it on, confirm updates are really being applied:
grep -i "upgrade" /var/log/apt/history.log | tail
sudo dnf history | head
The first is Debian and Ubuntu, the second RHEL-based systems. You should see recent dates.
Related
Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.

