How to turn on automatic security updates

Have the server install security patches by itself every day, on Ubuntu with unattended-upgrades and on RHEL-based systems with dnf-automatic.

1–2 minutes
Technician kneeling at a server rack with a laptop

Most break-ins on small servers use flaws that already had a fix available. Installing security updates automatically closes that gap without you having to remember.

Ubuntu and Debian: unattended-upgrades

It is installed by default on most Ubuntu servers. Make sure it is on:

sudo apt install unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgrades

Answer Yes. This applies security updates daily. Check what it has done:

sudo cat /var/log/unattended-upgrades/unattended-upgrades.log

Some updates, especially the kernel, only take effect after a reboot. When one is waiting, the file /var/run/reboot-required exists. To reboot automatically at a quiet time, set these in /etc/apt/apt.conf.d/50unattended-upgrades:

Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:00";

AlmaLinux, Rocky Linux and Fedora: dnf-automatic

sudo dnf install dnf-automatic

Edit /etc/dnf/automatic.conf and set:

[commands]
upgrade_type = security
apply_updates = yes

Then start the timer:

sudo systemctl enable --now dnf-automatic.timer
systemctl list-timers | grep dnf

Check whether a reboot is needed with sudo dnf needs-restarting -r.

What it does not cover

  • Software you installed outside the package manager, such as WordPress, its plugins, or apps from Git. Keep those updated separately.
  • Major version upgrades of the operating system, which you should plan and test.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.