How do I keep a Linux server updated?
Manual update commands
On Debian and Ubuntu, run `sudo apt update` to refresh the package list, then `sudo apt upgrade` to install available updates. For a full distribution upgrade that can add or remove packages, use `sudo apt full-upgrade`. On RHEL-based systems, use `sudo dnf upgrade` (or `sudo yum update` on older releases).
Always reboot after kernel or core library updates. On Ubuntu, `sudo needrestart` shows which services need restarting; on RHEL, `sudo needs-restarting -r` tells you if a reboot is required.
- Debian/Ubuntu: sudo apt update && sudo apt upgrade
- RHEL/CentOS/Rocky: sudo dnf upgrade
- SUSE: sudo zypper update
- Check reboot needed: sudo needrestart (Ubuntu) or sudo needs-restarting -r (RHEL)
Automate security updates
Unattended upgrades reduce the window of exposure. On Debian/Ubuntu install `unattended-upgrades` and enable it with `sudo dpkg-reconfigure -plow unattended-upgrades`. On RHEL-based systems, `dnf-automatic` can apply security updates on a timer.
Automatic updates can occasionally break services, so test on a staging server first. For production, many teams apply security updates automatically but schedule full upgrades during maintenance windows.
- Ubuntu: sudo apt install unattended-upgrades
- RHEL: sudo dnf install dnf-automatic && sudo systemctl enable --now dnf-automatic.timer
- Configure email alerts for update failures
Common mistakes
- Running `apt upgrade` without `apt update` first, so the package list is stale.
- Forgetting to reboot after a kernel update, leaving the old kernel running.
- Assuming automatic updates cover all packages; they often only apply security patches.
