Automatic Security Updates
Timely installation of security updates is a fundamental measure for maintaining server security. dnf-automatic is the official tool for automating updates in the RHEL/CentOS/Rocky Linux/AlmaLinux family, supporting automatic downloading, automatic installation, and email notifications.
Install dnf-automatic
Section titled “Install dnf-automatic”sudo dnf install dnf-automatic -yVerify the installation:
rpm -qi dnf-automaticConfiguration File Explained
Section titled “Configuration File Explained”The main configuration file for dnf-automatic is located at /etc/dnf/automatic.conf.
sudo vi /etc/dnf/automatic.confComplete Configuration File Breakdown
Section titled “Complete Configuration File Breakdown”[commands]# Update type:# default - all available updates# security - security updates onlyupgrade_type = security
# Random delay in seconds before execution (0 means no delay)random_sleep = 0
# Whether to automatically install after downloading# yes = automatically download and install# no = download only, do not installapply_updates = yes
# When apply_updates=no, whether to only download updatesdownload_updates = yes
# Reboot policy after updates (dnf-automatic 3.0+)# never - never reboot# when-changed - reboot when kernel or similar updates require it# when-needed - reboot after installing updates that require itreboot = never
# Wait time before reboot (seconds)reboot_command = "shutdown -r +5 'Rebooting after applying updates'"
[emitters]# Notification method:# stdio - output to stdout (logged)# email - send email# motd - update /etc/motd# command_email - use an external command to send emailemit_via = email
[email]# Sender addressemail_from = dnf-automatic@hostname# Recipient addressemail_to = [email protected]# SMTP serveremail_host = localhost
[command_email]# External mail command (when emit_via = command_email)command_format = "cat"email_from = dnf-automatic@hostnameemail_to = [email protected]stdin_encoding = utf-8
[base]# Debug level (0-10)debuglevel = 1# Excluded packages (not automatically updated)# exclude = kernel* php*Configuration Policies Explained
Section titled “Configuration Policies Explained”download_updates vs apply_updates
Section titled “download_updates vs apply_updates”These two options determine the behavior of dnf-automatic:
| Combination | Behavior | Use Case |
|---|---|---|
download_updates=yes + apply_updates=no | Download updates only, do not install | Manual confirmation required before installation |
download_updates=yes + apply_updates=yes | Automatically download and install | Fully automated security update handling |
Install Security Updates Only (Recommended)
Section titled “Install Security Updates Only (Recommended)”[commands]upgrade_type = securityapply_updates = yesDownload All Updates Without Installing
Section titled “Download All Updates Without Installing”[commands]upgrade_type = defaultdownload_updates = yesapply_updates = noExclude Specific Packages
Section titled “Exclude Specific Packages”Add exclusions in the [base] section to prevent automatic updates of critical software that might affect services:
[base]# Exclude kernel and specific applicationsexclude = kernel* mysql* nginx*Activate Timers
Section titled “Activate Timers”dnf-automatic uses systemd timers for periodic execution. Several predefined timers are provided.
Available Timer Units
Section titled “Available Timer Units”| Timer | Description |
|---|---|
dnf-automatic.timer | Download and install updates |
dnf-automatic-download.timer | Download updates only |
dnf-automatic-install.timer | Download and install updates |
dnf-automatic-notifyonly.timer | Check and notify only, no download or install |
Enable the Auto-Install Timer
Section titled “Enable the Auto-Install Timer”sudo systemctl enable --now dnf-automatic-install.timerEnable the Download-Only Timer
Section titled “Enable the Download-Only Timer”sudo systemctl enable --now dnf-automatic-download.timerEnable the Notify-Only Timer
Section titled “Enable the Notify-Only Timer”sudo systemctl enable --now dnf-automatic-notifyonly.timerCheck Timer Status
Section titled “Check Timer Status”sudo systemctl status dnf-automatic-install.timersudo systemctl list-timers --all | grep dnfCustomize Execution Time
Section titled “Customize Execution Time”The default timer typically runs daily in the early morning with a random delay. To customize the time:
sudo systemctl edit dnf-automatic-install.timerAdd the override configuration:
[Timer]# Clear default settingsOnCalendar=RandomizedDelaySec=0# Set to run daily at 3:00 AMOnCalendar=*-*-* 03:00:00Verify the timer configuration:
sudo systemctl daemon-reloadsudo systemctl list-timers | grep dnfConfigure Email Notifications
Section titled “Configure Email Notifications”Using a Local Mail Service
Section titled “Using a Local Mail Service”Ensure the system has a mail transfer agent (MTA) installed and configured:
sudo dnf install postfix mailx -ysudo systemctl enable --now postfixConfigure in automatic.conf:
[emitters]emit_via = email
[email]email_from = dnf-automatic@$(hostname)email_to = [email protected]email_host = localhostUsing an External SMTP Server
Section titled “Using an External SMTP Server”If you need to send email through an external SMTP server:
[emitters]emit_via = email
[email]email_from = [email protected]email_to = [email protected]email_host = smtp.example.com:587Using MOTD Notification
Section titled “Using MOTD Notification”Write update information to /etc/motd so users see it upon login:
[emitters]emit_via = motdCombining Multiple Notification Methods
Section titled “Combining Multiple Notification Methods”You can use multiple notification methods simultaneously:
[emitters]emit_via = email,motdManual Testing
Section titled “Manual Testing”Dry Run
Section titled “Dry Run”Check what would be done without actually performing updates:
sudo dnf-automatic --timerManually Trigger the Timer
Section titled “Manually Trigger the Timer”sudo systemctl start dnf-automatic-install.serviceView Execution Logs
Section titled “View Execution Logs”sudo journalctl -u dnf-automatic-install.service --no-pager -lsudo journalctl -u dnf-automatic-install.timer --no-pager -lView dnf History
Section titled “View dnf History”# View recent update historysudo dnf history
# View details of the most recent updatesudo dnf history info lastHands-On: Deploying Automatic Security Updates
Section titled “Hands-On: Deploying Automatic Security Updates”-
Install dnf-automatic:
Terminal window sudo dnf install dnf-automatic -y -
Configure the automatic security update policy:
Terminal window sudo cp /etc/dnf/automatic.conf /etc/dnf/automatic.conf.baksudo tee /etc/dnf/automatic.conf <<'EOF'[commands]upgrade_type = securityapply_updates = yesrandom_sleep = 300reboot = never[emitters]emit_via = email,motd[email]email_from = [email protected]email_to = [email protected]email_host = localhost[command_email]command_format = "cat"email_from = [email protected]email_to = [email protected]stdin_encoding = utf-8[base]debuglevel = 1# Exclude kernel updates for manual handlingexclude = kernel*EOF -
Install and start the mail service (if email notifications are needed):
Terminal window sudo dnf install postfix mailx -ysudo systemctl enable --now postfix -
Enable the auto-install timer:
Terminal window sudo systemctl enable --now dnf-automatic-install.timer -
Customize the execution time to 2:00 AM daily:
Terminal window sudo mkdir -p /etc/systemd/system/dnf-automatic-install.timer.dsudo tee /etc/systemd/system/dnf-automatic-install.timer.d/override.conf <<'EOF'[Timer]OnCalendar=RandomizedDelaySec=0OnCalendar=*-*-* 02:00:00EOFsudo systemctl daemon-reload -
Verify the configuration:
Terminal window # Check timer statussudo systemctl status dnf-automatic-install.timersudo systemctl list-timers | grep dnf# Manual test runsudo systemctl start dnf-automatic-install.servicesudo journalctl -u dnf-automatic-install.service --no-pager -l -
Periodically check update history:
Terminal window sudo dnf historysudo dnf history info last
By properly configuring dnf-automatic, you can maintain server security while reducing operational burden. Automatic installation is recommended for security updates, while kernel and critical business software should be excluded for manual handling.