# How to patch and update a Quake AI VM

Source: https://docs.quake.ai/docs/compute/how-to/patch-and-update-vm
Markdown: https://docs.quake.ai/docs/compute/how-to/patch-and-update-vm.md

---

# How to patch and update a Quake AI VM

Patch the guest operating system manually or on a schedule. Plan reboots for kernel updates, and create a Quake AI snapshot as a rollback point before a major upgrade.



You manage operating system updates inside each instance. Quake AI does not provide managed patching or maintenance windows. Before a major upgrade, create an [instance snapshot](/docs/compute/how-to/create-snapshot) as a rollback point.



Start from a running Linux VM with SSH access. If you still need to lock down a fresh instance, follow [How to harden a Quake AI VM](/docs/compute/how-to/harden-production-vm) first.

<PrerequisiteBlock methods={["cli"]}>

- A running Linux instance with SSH access and a user that can run `sudo`
- Enough disk space for package downloads (check with `df -h` before large upgrades)

</PrerequisiteBlock>

## Manual patching

Review pending updates before you install them. On production VMs, run upgrades during a maintenance window and monitor application health after installation.




Refresh the package index and list upgrades:

```bash
sudo apt update
apt list --upgradable
```

Apply pending upgrades:

```bash
sudo apt full-upgrade
```

For a smaller change set, upgrade individual packages:

```bash
sudo apt install PACKAGE_NAME
```

Remove dependencies that no installed package needs:

```bash
sudo apt autoremove
```




Refresh metadata and list upgrades:

```bash
sudo dnf upgrade --refresh --assumeno
```

Apply upgrades:

```bash
sudo dnf upgrade --refresh
```

Security-only upgrades:

```bash
sudo dnf upgrade --security
```




## Automatic security updates

Configure the guest operating system to install security patches on a schedule. The [hardening how-to](/docs/compute/how-to/harden-production-vm) walks through a baseline unattended-upgrades or `dnf-automatic` setup. This section covers scope, logs, and tuning.




Security-only origins are the default in `/etc/apt/apt.conf.d/50unattended-upgrades`. Confirm the file limits upgrades to security suites:

```bash
grep -E 'origin|label' /etc/apt/apt.conf.d/50unattended-upgrades
```

To include normal updates, add the distribution suite you run (for example, `jammy-updates`) to the `Allowed-Origins` block. On production VMs, keep the security-only scope unless your maintenance policy covers broader automatic changes.

Enable periodic runs in `/etc/apt/apt.conf.d/20auto-upgrades`:

```text
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Unattended-Upgrade "1";
```

Read the log after an unattended run:

```bash
sudo grep -i upgrade /var/log/unattended-upgrades/unattended-upgrades.log | tail -20
```




Confirm `/etc/dnf/automatic.conf` applies security updates only:

```bash
grep -E 'upgrade_type|apply_updates' /etc/dnf/automatic.conf
```

Expected values: `upgrade_type = security` and `apply_updates = yes`.

Check timer status and recent journal output:

```bash
systemctl status dnf-automatic.timer
sudo journalctl -u dnf-automatic -n 30 --no-pager
```

To apply security updates and other package updates, change `upgrade_type` to `default` and account for the broader automatic change set in your maintenance policy.




## Kernel updates and reboots

Kernel packages often require a reboot before the new kernel runs. Plan reboots during a maintenance window.




Check whether a reboot is pending:

```bash
test -f /var/run/reboot-required && cat /var/run/reboot-required
```

List processes still using old libraries:

```bash
sudo apt install -y debian-goodies
checkrestart
```

Reboot when you are ready:

```bash
sudo reboot
```

Canonical offers kernel live patching for supported Ubuntu releases through an Ubuntu Pro subscription. Check its status:

```bash
sudo pro status
```




Check whether the running kernel needs a reboot:

```bash
sudo needs-restarting -r
```

Reboot when you are ready:

```bash
sudo reboot
```

Your subscription and kernel build determine whether you can use `kpatch` or `kmod-livepatch`.




## Snapshot before a major upgrade

Before a distribution upgrade, a large dependency change, or an update with no direct rollback path, capture an instance snapshot. The Image service stores snapshots as Glance images. You can use the image to launch a replacement instance if the upgrade fails.

Follow [How to create an instance snapshot](/docs/compute/how-to/create-snapshot). Name the snapshot with the date and purpose (for example `pre-dist-upgrade-2026-06-19`).

For a file-level backup workflow alongside a snapshot, see [Automated backups with object storage](/docs/quickstart/automated-backups). For platform snapshot recovery and offsite copy patterns, see [How to back up and restore a Quake AI VM](/docs/compute/how-to/backup-and-restore).

To roll back after a failed upgrade:

1. Launch a new instance from the snapshot image.
2. Reattach or restore data volumes if your workload stored state on separate volumes.
3. Update DNS, reverse-proxy targets, or external edge origins to point at the recovered instance.

## Verify after patching

Confirm the VM serves traffic and core services restart cleanly.

**Package versions reflect the upgrade:**




```bash
uname -r
apt list --installed | grep -E 'linux-image|linux-headers' | tail -5
```




```bash
uname -r
rpm -q kernel
```




**Services you care about are active:**

```bash
sudo systemctl is-active SERVICE_NAME
curl -fsS http://localhost/health || true
```

Replace `SERVICE_NAME` and the health URL with your workload checks.

**The VM reports its reboot state:**

```bash
test -f /var/run/reboot-required && echo "reboot still required" || echo "no reboot pending"
```

## Related documentation

- [How to harden a Quake AI VM](/docs/compute/how-to/harden-production-vm): baseline security updates and SSH posture
- [How to create an instance snapshot](/docs/compute/how-to/create-snapshot): rollback point before risky changes
- [How to back up and restore a Quake AI VM](/docs/compute/how-to/backup-and-restore): restore drill from a snapshot image
- [How to maintain a Quake AI VM over its lifetime](/docs/compute/how-to/maintain-vm): resize, disk hygiene, and decommissioning
