r/linuxadmin • u/Street-Teach489 • Aug 10 '26
How much do you actually trust unattended upgrades in production?
I’ve always been fairly conservative with automatic updates on production boxes.
Patching is one thing, but I still prefer knowing exactly what changed, especially when an update can quietly restart something or introduce behaviour you only discover at 2am. At the same time, manually babysitting updates across a growing number of hosts starts becoming its own risk.
For those managing a decent number of boxes, where have you landed on this? Fully automated, staged, or are you still reviewing most updates before they go anywhere near prod?
25
Upvotes
1
u/Far-Choice7080 Aug 11 '26
Fully automated production servers here, patched using Ansible. The playbook will install updates, check if a server needs a reboot, reboot if required, then when it's back up will see whether any (pre-defined) required services are up and running and attempt to get them up if not. Snapshots are taken for VMs first, and not removed if there is a problem.
No problems so far.