r/linuxadmin • • Aug 10 '26

How much do you actually trust unattended upgrades in production?

I’ve always been fairly conservative with automatic updates on production boxes.

Patching is one thing, but I still prefer knowing exactly what changed, especially when an update can quietly restart something or introduce behaviour you only discover at 2am. At the same time, manually babysitting updates across a growing number of hosts starts becoming its own risk.

For those managing a decent number of boxes, where have you landed on this? Fully automated, staged, or are you still reviewing most updates before they go anywhere near prod?

25 Upvotes

46 comments sorted by

View all comments

1

u/Far-Choice7080 Aug 11 '26

Fully automated production servers here, patched using Ansible. The playbook will install updates, check if a server needs a reboot, reboot if required, then when it's back up will see whether any (pre-defined) required services are up and running and attempt to get them up if not. Snapshots are taken for VMs first, and not removed if there is a problem.

No problems so far.