How to patch and update a Quake AI VM
Coming from another cloud?
▸AWS·SSM Patch Manager
This Quake AI feature maps to AWS’s SSM Patch Manager.
▸Azure·Update Management
This Quake AI feature maps to Azure’s Update Management.
▸DigitalOcean·Droplet Updates
This Quake AI feature maps to DigitalOcean’s Droplet Updates.
▸Google Cloud·OS Patch Management
This Quake AI feature maps to Google Cloud’s OS Patch Management.
How to patch and update a Quake AI VM
Patch the guest operating system manually or on a schedule. Plan reboots for kernel updates, and create a Quake AI snapshot as a rollback point before a major upgrade.
Start from a running Linux VM with SSH access. If you still need to lock down a fresh instance, follow How to harden a Quake AI VM first.
Prerequisites
- CLIOpenStack CLI installed and authenticated (
clouds.yamloropenrcsourced)
Windows: CLI examples use bash. Set up a Linux CLI environment on Windows before proceeding.
- A running Linux instance with SSH access and a user that can run
sudo - Enough disk space for package downloads (check with
df -hbefore large upgrades)
Manual patching#
Review pending updates before you install them. On production VMs, run upgrades during a maintenance window and monitor application health after installation.
Refresh the package index and list upgrades:
sudo apt update
apt list --upgradableApply pending upgrades:
sudo apt full-upgradeFor a smaller change set, upgrade individual packages:
sudo apt install PACKAGE_NAMERemove dependencies that no installed package needs:
sudo apt autoremoveAutomatic security updates#
Configure the guest operating system to install security patches on a schedule. The hardening how-to walks through a baseline unattended-upgrades or dnf-automatic setup. This section covers scope, logs, and tuning.
Security-only origins are the default in /etc/apt/apt.conf.d/50unattended-upgrades. Confirm the file limits upgrades to security suites:
grep -E 'origin|label' /etc/apt/apt.conf.d/50unattended-upgradesTo include normal updates, add the distribution suite you run (for example, jammy-updates) to the Allowed-Origins block. On production VMs, keep the security-only scope unless your maintenance policy covers broader automatic changes.
Enable periodic runs in /etc/apt/apt.conf.d/20auto-upgrades:
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";Read the log after an unattended run:
sudo grep -i upgrade /var/log/unattended-upgrades/unattended-upgrades.log | tail -20Kernel updates and reboots#
Kernel packages often require a reboot before the new kernel runs. Plan reboots during a maintenance window.
Check whether a reboot is pending:
test -f /var/run/reboot-required && cat /var/run/reboot-requiredList processes still using old libraries:
sudo apt install -y debian-goodies
checkrestartReboot when you are ready:
sudo rebootCanonical offers kernel live patching for supported Ubuntu releases through an Ubuntu Pro subscription. Check its status:
sudo pro statusSnapshot before a major upgrade#
Before a distribution upgrade, a large dependency change, or an update with no direct rollback path, capture an instance snapshot. The Image service stores snapshots as Glance images. You can use the image to launch a replacement instance if the upgrade fails.
Follow How to create an instance snapshot. Name the snapshot with the date and purpose (for example pre-dist-upgrade-2026-06-19).
For a file-level backup workflow alongside a snapshot, see Automated backups with object storage. For platform snapshot recovery and offsite copy patterns, see How to back up and restore a Quake AI VM.
To roll back after a failed upgrade:
- Launch a new instance from the snapshot image.
- Reattach or restore data volumes if your workload stored state on separate volumes.
- Update DNS, reverse-proxy targets, or external edge origins to point at the recovered instance.
Verify after patching#
Confirm the VM serves traffic and core services restart cleanly.
Package versions reflect the upgrade:
uname -r
apt list --installed | grep -E 'linux-image|linux-headers' | tail -5Services you care about are active:
sudo systemctl is-active SERVICE_NAME
curl -fsS http://localhost/health || trueReplace SERVICE_NAME and the health URL with your workload checks.
The VM reports its reboot state:
test -f /var/run/reboot-required && echo "reboot still required" || echo "no reboot pending"Related documentation#
- How to harden a Quake AI VM: baseline security updates and SSH posture
- How to create an instance snapshot: rollback point before risky changes
- How to back up and restore a Quake AI VM: restore drill from a snapshot image
- How to maintain a Quake AI VM over its lifetime: resize, disk hygiene, and decommissioning
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
Last validated: 01.09.2026
Quick answers
- Why does `openstack image save` write a 0-byte file for my boot-from-volume instance?CLI
- Why does `openstack server create` fail with "Only volume-backed servers are allowed for flavors with zero disk"?CLIAPITerraform
- Why does my project still have a 10 GiB Cinder volume after I deleted my instance?CLIAPI