Automatic Linux Updates: unattended-upgrades & dnf-automatic | INTROSERV
EUR
european

EUR

usa

USD

English En
Ex. VAT Ex. VAT 0%

Automatic Linux updates: Configuring unattended-upgrades and dnf-automatic for Linux server updates

Level: Expert
Estimated time: ~30 minutes
Goal: Configure zero-downtime, scalable automatic Linux updates using unattended-upgrades and dnf-automatic following Infrastructure as Code principles.

Introduction

Manual patching of servers - is a critical bottleneck in managing any production environment: without automation, reliably keeping hundreds of nodes secure and up to date would be very difficult. A vulnerable application can be compromised in minutes, and most exploits target well-known unpatched vulnerabilities. We need to apply Security Updates (critical patches released to fix known vulnerabilities in software) in a timely manner to avoid security breaches. In this tutorial, we will configure automatic Linux updates on a Linux server using unattended-upgrades and dnf-automatic. This approach standardizes Linux server updates.

What are unattended-upgrades and dnf-automatic?

unattended-upgrades is a Debian/Ubuntu utility that automates the installation of security and other package updates.

dnf-automatic is a component that provides automated updates for RHEL/CentOS/Fedora systems.

These utilities allow Automatic Updates (the process of fetching and installing updates without human intervention) to run seamlessly in the background. They are typically run daily via a Systemd Timer (a systemd unit that controls the scheduling of tasks, replacing traditional cron jobs).

Prerequisites

Before you begin, make sure the following conditions are met:

  • Operating system: Ubuntu 20.04/22.04/24.04 LTS, Debian 12/13, or RHEL/AlmaLinux 9/10
  • Access: sudo or root access to the server
  • Network requirements: Outbound HTTPS access to package repositories (archive.ubuntu.com, security.debian.org, repo.almalinux.org)
  • Required knowledge: Expert understanding of system administration, systemd, and basic Patch Management (the process of distributing and applying updates to software) along with Linux patch management.

Step 1: Configuring automatic Linux updates with unattended-upgrades

For systems using APT (Advanced Package Tool) (the core package management system used by Debian-based distributions), we use unattended-upgrades. This tool integrates seamlessly into your Linux patch management strategy.

1.1 Install the package

First, verify and install the required package from the Package Repository (a centralized storage location from which software packages are retrieved and installed).

Run the following command:

sudo apt update && sudo apt install unattended-upgrades -y

You should see output confirming the installation. This ensures the system is ready for apt automatic updates.

1.2 Configure allowed origins

The main config is located at /etc/apt/apt.conf.d/50unattended-upgrades. We will modify the configuration to only install Security Updates. This minimizes the risk of breaking changes during automatic package updates.

Before making changes, it is best practice to create a backup of the original configuration file:

sudo cp /etc/apt/apt.conf.d/50unattended-upgrades /etc/apt/apt.conf.d/50unattended-upgrades.bak

Open the configuration file:

sudo nano /etc/apt/apt.conf.d/50unattended-upgrades

Replace the contents of the Allowed-Origins block entirely, and append the listed names to the Package-Blacklist block:

For Ubuntu:

Unattended-Upgrade::Allowed-Origins { "${distro_id}:${distro_codename}-security"; };

For Debian:

Unattended-Upgrade::Origins-Pattern { "origin=Debian,codename=${distro_codename},label=Debian-Security"; "origin=Debian,codename=${distro_codename}-security,label=Debian-Security"; };

Then, configure the package blacklist and reboot behavior:

Unattended-Upgrade::Package-Blacklist { "^nginx$"; "^mysql-server$"; "^mariadb-server$"; "postgresql*"; "docker*"; }; Unattended-Upgrade::Automatic-Reboot "false";

Info

The Package-Blacklist uses regular expressions. An entry like "nginx" matches nginx-common, nginx-extras, etc. To target only the specific package, use regex anchors like "^nginx$".

This restricts apt automatic updates to security patches only and excludes critical packages from automatic updates, reducing the risk of service disruption while maintaining security patch automation.

Warning

Kernel, libc, and low-level package updates may still require a reboot. In production environments, keep automatic reboots disabled unless maintenance windows are enforced through orchestration.

1.3 Enable automatic updates

Create the auto-upgrades file to activate the Systemd Timer for APT.

Open the file:

sudo nano /etc/apt/apt.conf.d/20auto-upgrades

Paste the following inside:

APT::Periodic::Update-Package-Lists "1"; APT::Periodic::Unattended-Upgrade "1"; APT::Periodic::AutocleanInterval "7";

This config instructs the system to:

  • Update-Package-Lists "1" - run daily package list updates.
  • Unattended-Upgrade "1" - execute apt automatic updates automatically.
  • AutocleanInterval "7" - keep the package cache clean every 7 days.

Step 2: Configuring dnf-automatic for Linux server updates

For systems utilizing DNF (Dandified YUM) (the next-generation package manager for RHEL-based distributions), dnf-automatic provides robust dnf update automation.

2.1 Install the package

Install the automation tool from the Package Repository.

Run the following command:

sudo dnf install dnf-automatic -y

You should see output confirming the successful installation of the dnf update automation package.

2.2 Configure update policies

The main config is located at /etc/dnf/automatic.conf. Configure the tool to download and apply only Security Updates.

Before making changes, back up the configuration file and verify if security advisories are available for your distribution:

sudo cp /etc/dnf/automatic.conf /etc/dnf/automatic.conf.bak sudo dnf updateinfo summary sudo dnf updateinfo list security

Open the configuration file:

sudo nano /etc/dnf/automatic.conf

Adjust the following parameters:

[commands] upgrade_type = security random_sleep = 3600 download_updates = yes apply_updates = yes [emitters] emit_via = stdio

This config instructs the system to:

  • upgrade_type = security - target security patches exclusively.
  • random_sleep = 3600 - randomize execution by up to 1 hour, spreading the load across large-scale Infrastructure as Code deployments to prevent repository spikes and simultaneous cascading failures.
  • download_updates and apply_updates - download and install security updates automatically.

Info

upgrade_type = security depends on repository security metadata. If security advisories are missing (which is typical for a fresh AlmaLinux 10 installation), dnf-automatic with this setting may not apply anything at all. Verify repository support before relying on security-only updates in production. Alternatively, for production systems, consider using upgrade_type = security-severity:Critical or default-security.

2.3 Enable the systemd timer

Activate the timer to schedule the dnf update automation.

Run the following command:

sudo systemctl enable --now dnf-automatic.timer

You should see output indicating the timer is enabled and started. This activates scheduled automatic package updates for the system.

Step 3: Verifying the configuration

After writing the configuration, it should be verified.

3.1 Verification on Debian/Ubuntu

Execute a dry run to validate the configuration. The -d (or --dry-run) flag runs unattended-upgrades in debug mode - nothing is actually changed:

sudo unattended-upgrades --dry-run --debug

Info

The --dry-run flag outputs diagnostic information but does not modify any files. Ensure no blacklisted packages are queued.

In production, logs matter more than dry-runs. Verify the timer and service are active:

systemctl list-timers | grep apt systemctl status apt-daily-upgrade.service --no-pager

Then check the recent log output to confirm update activity. On a freshly configured system, the log may be empty. For an immediate check, run: sudo unattended-upgrade -v.

sudo tail -n 50 /var/log/unattended-upgrades/unattended-upgrades.log

3.2 Verify timer on RHEL/AlmaLinux

Check the status of the timer:

systemctl list-timers | grep dnf-automatic

Expected output:

Wed 2026-05-27 06:23:13 EEST 16h left - - dnf-automatic.timer dnf-automatic.service

If the timer is listed, your updates are scheduled correctly.

3.3 Checking the need for a reboot

Kernel and libc updates are included in the security queue (for example, on Debian linux-image-amd64 is part of security updates). Since Automatic-Reboot=false is set, you need to check if a manual reboot is required.

For Debian/Ubuntu:

test -f /var/run/reboot-required && cat /var/run/reboot-required.pkgs

For AlmaLinux/RHEL:

sudo dnf needs-restarting -r

3.4 Force-run for verification

You may not see the result until the timer triggers. To manually execute the update process for verification:

For Debian/Ubuntu:

sudo unattended-upgrade -v

For AlmaLinux/RHEL:

sudo dnf-automatic

Step 4: Advanced configuration (Expert level)

To match expert-level requirements, you can extend the setup with notifications and fine-grained scheduling.

4.1 Email notifications

To receive reports about the updates:

For Debian/Ubuntu:

In /etc/apt/apt.conf.d/50unattended-upgrades, uncomment and adjust:

Unattended-Upgrade::Mail "<YOUR_EMAIL>"; Unattended-Upgrade::MailReport "on-change";

For AlmaLinux/RHEL:

In /etc/dnf/automatic.conf, configure the [email] section and change the emitter:

[emitters] emit_via = email [email] email_from = [email protected] email_to = <YOUR_EMAIL> email_host = localhost

4.2 Advanced dnf-automatic timers

dnf-automatic offers multiple timers to split the download and install phases, allowing for greater control in production:

  • `dnf-automatic.timer`: The default timer (downloads, and optionally installs if configured).
  • `dnf-automatic-notifyonly.timer`: Only checks for updates and sends a notification.
  • `dnf-automatic-download.timer`: Downloads the updates but does not install them.
  • `dnf-automatic-install.timer`: Downloads and installs updates automatically (overrides the apply_updates setting in the config).

Use the specific timer that matches your cluster's maintenance policy.

Rollback

To undo everything done, simply remove the tools and configurations.

Debian/Ubuntu:

sudo apt purge unattended-upgrades -y sudo rm -rf /etc/apt/apt.conf.d/20auto-upgrades /var/log/unattended-upgrades/ /var/run/reboot-required* sudo mv /etc/apt/apt.conf.d/50unattended-upgrades.bak /etc/apt/apt.conf.d/50unattended-upgrades

RHEL/AlmaLinux:

sudo systemctl disable --now dnf-automatic.timer sudo mv /etc/dnf/automatic.conf.bak /etc/dnf/automatic.conf sudo dnf remove dnf-automatic -y

Warning

Removing these tools will disable automatic updates for the entire system, leaving your servers vulnerable unless patched manually.

Conclusion

That is all. One properly configured system with unattended-upgrades or dnf-automatic, verified with a dry run, - and it's done. Through this security patch automation, automatic Linux updates are applied seamlessly, maintenance overhead stays low, and Linux server updates become predictable instead of reactive. For larger environments, combine this setup with Infrastructure as Code and staggered rollouts to avoid updating every node at the same time.

Document Version: 1.0
Last Updated: May 2026
Owner: Technical Documentation Team

VAT

  • Other

    Ex. VAT

    0%
  • austria

    Austria

    20%
  • Belgium

    Belgium

    21%
  • Bulgaria

    Bulgaria

    20%
  • Croatia

    Croatia

    25%
  • Cyprus

    Cyprus

    19%
  • Czech Republic

    Czech Republic

    21%
  • Denmark

    Denmark

    25%
  • Estonia

    Estonia

    22%
  • France

    France

    20%
  • Finland

    Finland

    24%
  • Germany

    Germany

    19%
  • Greece

    Greece

    24%
  • Hungary

    Hungary

    27%
  • Ireland

    Ireland

    23%
  • Italy

    Italy

    22%
  • Latvia

    Latvia

    21%
  • Lithuania

    Lithuania

    21%
  • Luxembourg

    Luxembourg

    17%
  • Malta

    Malta

    18%
  • Netherlands

    Netherlands

    21%
  • Poland

    Poland

    23%
  • Portugal

    Portugal

    23%
  • Romania

    Romania

    19%
  • Slovakia

    Slovakia

    20%
  • Slovenia

    Slovenia

    22%
  • Spain

    Spain

    21%
  • Sweden

    Sweden

    25%
  • USA

    USA

    0%
european
states
  • germany
  • Español
  • Italiano
  • Poland
  • Русский
  • Slovenski
  • Türkçe
  • ukraine
  • kingdom
  • French
  • Hrvatska
  • Other
  • Austria
  • Belgium
  • Bulgaria
  • Croatia
  • Cyprus
  • Czech Republic
  • Denmark
  • Estonia
  • Finland
  • France
  • Germany
  • Greece
  • Hungary
  • Ireland
  • Italy
  • Latvia
  • Lithuania
  • Luxembourg
  • Malta
  • Netherlands
  • Poland
  • Portugal
  • Romania
  • Slovakia
  • Slovenia
  • Spain
  • Sweden
  • USA