3 min read Sep 26, 2026

How to Enable Automatic Security Updates on Your VPS

Keep your Linux VPS patched without logging in every day: set up unattended-upgrades on Ubuntu and Debian or dnf-automatic on AlmaLinux and Rocky, and handle reboots safely.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

On an Unmanaged VPS, installing security updates is your job. Most successful attacks use flaws that were fixed weeks or months earlier on servers nobody updated. Automatic security updates close that gap while you get on with running your sites.

This guide enables automatic security updates, which are small and low-risk, and leaves bigger feature upgrades for you to run by hand.

Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.

Ubuntu and Debian: unattended-upgrades

Ubuntu usually has this installed and switched on already; Debian may not. Running these commands is safe either way:

sudo apt update
sudo apt install -y unattended-upgrades apt-listchanges
sudo dpkg-reconfigure -plow unattended-upgrades

Choose Yes when asked to download and install stable updates automatically. This creates /etc/apt/apt.conf.d/20auto-upgrades, which should contain:

APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";

By default only the security repository is used. The list lives in /etc/apt/apt.conf.d/50unattended-upgrades; leave it as it is unless you know you want more.

Automatic reboots (optional)

Kernel and some library updates only take effect after a reboot. To let the server reboot itself at a quiet time when needed, create a local override file (it survives package upgrades):

sudo nano /etc/apt/apt.conf.d/52unattended-upgrades-local

Add these lines:

Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:00";
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";

The time uses the server's time zone. Your sites will be offline for a minute or two during the reboot, so pick your quietest hour.

Test and check

sudo unattended-upgrade --dry-run --debug
systemctl list-timers 'apt-daily*'
sudo less /var/log/unattended-upgrades/unattended-upgrades.log

AlmaLinux and Rocky Linux: dnf-automatic

sudo dnf install -y dnf-automatic
sudo nano /etc/dnf/automatic.conf

In the [commands] section, set:

[commands]
upgrade_type = security
download_updates = yes
apply_updates = yes

Then switch on the timer, which runs once a day:

sudo systemctl enable --now dnf-automatic.timer
systemctl list-timers 'dnf-automatic*'

To see whether installed updates are waiting for a reboot, run sudo dnf needs-restarting -r. Recent versions of dnf-automatic also accept a reboot = when-needed option in [commands]; check man dnf-automatic on your server to see if yours supports it. Otherwise, reboot by hand during a quiet time, or schedule it with cron.

Check what was installed with sudo dnf history.

What automatic updates do not cover

  • Software installed outside the package manager: WordPress, its plugins and themes, Composer and npm packages, Docker images, and control panels all need their own updates.
  • Third-party repositories (for example NodeSource or Docker) are not included in security-only updates. Run sudo apt upgrade or sudo dnf upgrade yourself every week or two.
  • Major release upgrades such as Ubuntu 22.04 to 24.04. Plan these separately, with a backup, or move to a freshly installed VPS.

Know your end-of-life dates

Updates only arrive while your release is supported. Roughly: Ubuntu 22.04 standard support ends in 2027, Ubuntu 24.04 in 2029, Debian 12 is covered by long-term support until mid-2028, and AlmaLinux/Rocky 9 until 2032. Plan a move to a newer release well before your date.

Common problems

  • “Could not get lock /var/lib/dpkg/lock-frontend”: an automatic update is running. Wait a few minutes and try your command again; don't delete lock files.
  • A service stopped working after an update: check /var/log/apt/history.log or sudo dnf history info last to see what changed, and restart the service.
  • The server rebooted unexpectedly: check whether automatic reboot is enabled and look at last reboot.

Need help?

If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.

Categories

FimuroHost Team

Written by

FimuroHost Team

Technical Writer