On an Unmanaged VPS, installing security updates is your job. Most successful attacks use flaws that were fixed weeks or months earlier on servers nobody updated. Automatic security updates close that gap while you get on with running your sites.
This guide enables automatic security updates, which are small and low-risk, and leaves bigger feature upgrades for you to run by hand.
Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.
Ubuntu and Debian: unattended-upgrades
Ubuntu usually has this installed and switched on already; Debian may not. Running these commands is safe either way:
sudo apt update sudo apt install -y unattended-upgrades apt-listchanges sudo dpkg-reconfigure -plow unattended-upgrades
Choose Yes when asked to download and install stable updates automatically. This creates /etc/apt/apt.conf.d/20auto-upgrades, which should contain:
APT::Periodic::Update-Package-Lists "1"; APT::Periodic::Unattended-Upgrade "1";
By default only the security repository is used. The list lives in /etc/apt/apt.conf.d/50unattended-upgrades; leave it as it is unless you know you want more.
Automatic reboots (optional)
Kernel and some library updates only take effect after a reboot. To let the server reboot itself at a quiet time when needed, create a local override file (it survives package upgrades):
sudo nano /etc/apt/apt.conf.d/52unattended-upgrades-local
Add these lines:
Unattended-Upgrade::Automatic-Reboot "true"; Unattended-Upgrade::Automatic-Reboot-Time "04:00"; Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
The time uses the server's time zone. Your sites will be offline for a minute or two during the reboot, so pick your quietest hour.
Test and check
sudo unattended-upgrade --dry-run --debug systemctl list-timers 'apt-daily*' sudo less /var/log/unattended-upgrades/unattended-upgrades.log
AlmaLinux and Rocky Linux: dnf-automatic
sudo dnf install -y dnf-automatic sudo nano /etc/dnf/automatic.conf
In the [commands] section, set:
[commands] upgrade_type = security download_updates = yes apply_updates = yes
Then switch on the timer, which runs once a day:
sudo systemctl enable --now dnf-automatic.timer systemctl list-timers 'dnf-automatic*'
To see whether installed updates are waiting for a reboot, run sudo dnf needs-restarting -r. Recent versions of dnf-automatic also accept a reboot = when-needed option in [commands]; check man dnf-automatic on your server to see if yours supports it. Otherwise, reboot by hand during a quiet time, or schedule it with cron.
Check what was installed with sudo dnf history.
What automatic updates do not cover
- Software installed outside the package manager: WordPress, its plugins and themes, Composer and npm packages, Docker images, and control panels all need their own updates.
- Third-party repositories (for example NodeSource or Docker) are not included in security-only updates. Run
sudo apt upgradeorsudo dnf upgradeyourself every week or two. - Major release upgrades such as Ubuntu 22.04 to 24.04. Plan these separately, with a backup, or move to a freshly installed VPS.
Know your end-of-life dates
Updates only arrive while your release is supported. Roughly: Ubuntu 22.04 standard support ends in 2027, Ubuntu 24.04 in 2029, Debian 12 is covered by long-term support until mid-2028, and AlmaLinux/Rocky 9 until 2032. Plan a move to a newer release well before your date.
Common problems
- “Could not get lock /var/lib/dpkg/lock-frontend”: an automatic update is running. Wait a few minutes and try your command again; don't delete lock files.
- A service stopped working after an update: check
/var/log/apt/history.logorsudo dnf history info lastto see what changed, and restart the service. - The server rebooted unexpectedly: check whether automatic reboot is enabled and look at
last reboot.
Need help?
If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.
Categories
Written by
FimuroHost Team
Technical Writer