Server Management (Unmanaged)

Updating the OS and software packages

By the Domain India teamPublished 8 min read
Knowledge base article
Contents (9 sections)

Keeping a Linux server's operating system and packages up to date is the single most effective thing you can do for its security: most break-ins exploit flaws that already have a fix. This guide shows how to update Debian and Ubuntu servers with apt, and AlmaLinux, Rocky Linux and other RHEL-family servers with dnf, how to automate security updates, and how to fix the problems that updates sometimes cause.

This guide is for your own server

These commands need root or sudo access, so they apply to a VPS or dedicated server that you manage. On Domain India shared hosting, the servers are updated for you and you can't install or update system packages; there is nothing to do on your side.

Key takeaways

On Debian or Ubuntu, run sudo apt update and then sudo apt upgrade; on AlmaLinux, Rocky Linux or Fedora, run sudo dnf upgrade. Take a backup first, reboot when a new kernel or core library is installed, and turn on automatic security updates with unattended-upgrades or dnf-automatic. Never fix a stuck update by deleting lock files. CentOS 7 and CentOS 8 are end-of-life and get no updates, so move to a supported release.

1. Why regular updates matter

  • Security: updates close known vulnerabilities in the kernel, OpenSSH, OpenSSL, the web server, PHP and everything else on the machine.
  • Stability: bug fixes stop crashes and memory leaks.
  • Compatibility: newer applications often need newer libraries.

The risk of updating is small and manageable; the risk of not updating grows every week.

2. Before you update

  1. Back up.
    Copy your databases and important files off the server, or take a snapshot if your provider offers one. A backup on the same disk is not enough.
  2. Check disk space.
    Run df -h. Updates need free space in /, /var and /boot.
  3. Know what runs on the server.
    Note the services your sites depend on (web server, PHP-FPM, database, mail) so you can check them afterwards.
  4. Use a supported release.
    Run cat /etc/os-release. If the version is end-of-life, updating only installs the last packages ever published; plan a move to a supported release instead.
  5. Pick a quiet time.
    Service restarts and reboots cause short interruptions.

3. Updating Debian and Ubuntu (apt)

bash
sudo apt update            # refresh the package lists
apt list --upgradable      # see what will change
sudo apt upgrade           # install updates, never removes packages
sudo apt full-upgrade      # also allows removals and new dependencies
sudo apt autoremove        # remove packages nothing needs any more

apt upgrade is the safe everyday command. apt full-upgrade (the old dist-upgrade) can remove packages to resolve dependencies, so read its summary before you answer yes. apt-get still works with the same subcommands and is better in scripts.

To see whether a reboot is needed:

bash
[ -f /var/run/reboot-required ] && cat /var/run/reboot-required

4. Updating AlmaLinux, Rocky Linux, RHEL and Fedora (dnf)

On release 8 and later, dnf replaced yum; the yum command still works as an alias.

bash
sudo dnf check-update       # list available updates
sudo dnf upgrade            # install them
sudo dnf upgrade --security # security updates only, where the repositories publish advisories
sudo dnf autoremove         # remove unneeded dependencies

To check whether a reboot is needed, install the utilities package (dnf-utils or yum-utils) and run:

bash
sudo dnf needs-restarting -r

If an update broke something, dnf history lists every transaction and sudo dnf history undo 42 reverts transaction 42. To stop a package from being upgraded, use a version lock; see Managing DNF and YUM version locks.

CentOS 7 and 8 no longer get updates

CentOS Linux 8 reached end-of-life in December 2021 and CentOS 7 in June 2024. Their repositories are archived, so yum update either fails or installs nothing new. Build new servers on AlmaLinux or Rocky Linux, which use the same dnf commands, and migrate existing ones.

5. Reboots and service restarts

A new kernel is used only after a reboot. Updated libraries such as OpenSSL or glibc are used only by processes started after the update.

  • Reboot with sudo reboot when the checks above say so, and confirm afterwards that your sites, database and mail are running (systemctl --failed lists anything that didn't start).
  • For libraries, restarting the affected services is often enough. On Debian and Ubuntu, the needrestart tool lists them after each upgrade; on RHEL-family systems, sudo dnf needs-restarting -s lists services to restart.
  • After a kernel update, keep an eye on /boot: old kernels are removed automatically once the configured number is exceeded, but a small /boot partition can still fill up.

6. Automating security updates

Security fixes are worth installing automatically; feature updates are better done by hand.

Debian and Ubuntu:

bash
sudo apt install unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades

By default it installs security updates only. Its log is in /var/log/unattended-upgrades/.

AlmaLinux and Rocky Linux 8 and 9:

bash
sudo dnf install dnf-automatic
# in /etc/dnf/automatic.conf set:  upgrade_type = security  and  apply_updates = yes
sudo systemctl enable --now dnf-automatic.timer

Automatic updates don't reboot the server unless you configure them to, so still check for pending reboots regularly.

7. Major version upgrades

Moving from one major release to the next (for example Ubuntu 22.04 to 24.04, or AlmaLinux 8 to 9) is a bigger job than routine updates. On Ubuntu, sudo do-release-upgrade handles it. For AlmaLinux and Rocky Linux, the ELevate project provides an in-place path. For a production server, building a fresh server on the new release and moving your sites across is often safer, because you can test before you switch and keep the old server as a fallback.

8. Troubleshooting common update problems

ProblemWhat to do
Could not get lock /var/lib/dpkg/lock-frontendAnother apt process, often unattended-upgrades, is running. Wait, or find it with sudo lsof /var/lib/dpkg/lock-frontend. Never delete the lock file.
dpkg was interruptedRun sudo dpkg --configure -a, then sudo apt --fix-broken install
Broken or unmet dependencies (apt)Run sudo apt --fix-broken install and read which package conflicts
Conflicts or missing packages (dnf)Run sudo dnf upgrade --refresh, and check third-party repositories are enabled for your release
No space left on deviceRun sudo apt clean or sudo dnf clean all, remove old logs and backups, then retry
Service fails after updateRead journalctl -u servicename, compare config files with any .dpkg-dist or .rpmnew copies left by the update

Deleting lock files while a package manager is still running can corrupt the package database. It is a common way for a routine update to turn into a broken server.

9. Updates on Domain India

Shared hosting (cPanel, DirectAdmin, Webuzo): the operating system and server software are managed for every account on the server. You can't run system updates, but you should keep your own applications current: WordPress core, plugins and themes, and the PHP version you select in your panel. See what software versions Domain India hosting runs.

VPS: Domain India VPS plans are self-managed, with full root access, so operating system updates are your responsibility and everything in this guide applies. If you install a control panel on your VPS, update the panel with its own updater as well as the operating system. Prices on the card are live and exclude 18% GST.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details
What is the difference between apt upgrade and apt full-upgrade?

apt upgrade installs newer versions of installed packages but never removes a package. apt full-upgrade can also remove packages or install new dependencies when that is needed to complete the upgrade, so read its summary before confirming.

How do I update AlmaLinux or Rocky Linux?

Run sudo dnf check-update to see what is available, then sudo dnf upgrade to install it. Use sudo dnf upgrade --security to install security updates only, and sudo dnf needs-restarting -r to check whether a reboot is needed.

Do I need to reboot after updating?

Only when a new kernel or a core library such as glibc was installed. On Debian and Ubuntu, the file /var/run/reboot-required exists when a reboot is needed. On RHEL-family systems, run dnf needs-restarting -r.

Is it safe to delete the apt or dnf lock file?

No. The lock means another package manager process is running. Wait for it to finish or find it with lsof. Deleting the lock while it runs can corrupt the package database.

Can I still update a CentOS 7 server?

No. CentOS 7 reached end-of-life in June 2024 and gets no further updates. Move to AlmaLinux or Rocky Linux, which use the same dnf commands.

Do I need to update the operating system on Domain India shared hosting?

No. The shared servers are managed for every account, and customers can't install or update system packages. Keep your own applications, plugins and PHP version up to date instead.

Are operating system updates included on a Domain India VPS?

Domain India VPS plans are self-managed with full root access, so you run operating system updates yourself using the commands in this guide.

Ready to run your own server? Compare VPS plans, secure access with SSH key authentication, or open a support ticket if you have a question about your service.

Your server, your updates

Self-managed KVM VPS plans with full root access, so you choose the operating system and when it updates.

See VPS plans

Ready when you are

Get VPS from ₹552.65/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Update Linux OS and Packages with apt and dnf | Domain India