March 16, 2021 20:03
sudo apt install unattended-upgrades apt-listchanges
…to allow a regulary report about the updates.
You also may modify the
Unattended-Upgrade::Allowed-Origins array to only include a…
…this will allow automatic updates for basically all packages - make sure to have backups!
Auto cleanups & more
Well, just uncomment & modify these in the config (I just recommend this settings):
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true"; Unattended-Upgrade::Remove-New-Unused-Dependencies "true"; Unattended-Upgrade::Remove-Unused-Dependencies "false"; Unattended-Upgrade::AutoFixInterruptedDpkg "true"; Unattended-Upgrade::MinimalSteps "true";
Also when you are configuring this on an e.g. containerized environment or webserver (basically everything except of root-/gameservers), you may also want to enable automatic reboots (uncomment & modify these):
Unattended-Upgrade::Automatic-Reboot "true"; Unattended-Upgrade::Automatic-Reboot-WithUsers "false"; Unattended-Upgrade::Automatic-Reboot-Time "02:00";
Test with (check for the matching string messages!!!):
sudo unattended-upgrade --debug --dry-run