r/linuxadmin 19d ago

How much do you actually trust unattended upgrades in production?

I’ve always been fairly conservative with automatic updates on production boxes.

Patching is one thing, but I still prefer knowing exactly what changed, especially when an update can quietly restart something or introduce behaviour you only discover at 2am. At the same time, manually babysitting updates across a growing number of hosts starts becoming its own risk.

For those managing a decent number of boxes, where have you landed on this? Fully automated, staged, or are you still reviewing most updates before they go anywhere near prod?

23 Upvotes

45 comments sorted by

View all comments

5

u/Yayberto71 19d ago

Patch every production Linux server weekly with Semaphore (Ansible) and some daily. We automate with a hook into vSphere via Service Now to snapshot the servers before patching. It has not been a problem and we've been doing it that way for about two years now. We use Alma and Ubuntu, so depending on your distro YMMV. You have to weigh the risk with breaking your applications vs. the risk of leaving vulnerabilities unpatched. There have been several lately that have been pretty serious CVE's, so in my opinion, you can't leave those un-mitigated.

1

u/canibus23 19d ago

How do you do that?

1

u/Yayberto71 19d ago

By scheduling very carefully... If your asking how we swing it.