Ubuntu apt update and upgrade: Full Guide (upgrade, full-upgrade, autoremove, reboots)

apt update upgrade ubuntu - custom-aptup-featured.png

Every Ubuntu admin searches apt update and apt upgrade — often in the same breath. On servers, the goal is predictable maintenance: know what will change, avoid surprise reboots during business hours, and confirm services after a kernel bump.

On AlmaLinux/Rocky the equivalent is dnf update — see distro comparisons in our
Alma vs Ubuntu guide. This tutorial focuses on Debian-family apt.

The apt Workflow

update refreshes package lists from mirrors; upgrade installs newer versions of installed packages. Neither is optional on internet-facing servers for long.

update then upgrade
workflow

apt update

Run this first. Fix mirror or GPG errors before upgrading — a broken sources.list blocks everything downstream.

bashupdate
sudo apt update
refresh indexes
apt update

apt upgrade

Installs newer versions of packages already on the system. Keeps dependency changes conservative compared to full-upgrade.

bashupgrade
sudo apt upgrade -y
safe default
interactive

apt full-upgrade

Allows dependency changes required for new versions — use during release upgrades or when upgrade reports held-back packages.

bashfull upgrade
sudo apt full-upgrade -y
full-upgrade
dist-upgrade

apt autoremove and autoclean

Removes packages installed only as dependencies for something you removed; frees disk on small VPS disks.

bashcleanup
sudo apt autoremove -y
sudo apt autoclean
cleanup
disk space

Hold Packages When Needed

Pin kernels or database engines during incident response with apt-mark hold.

bashhold example
sudo apt-mark hold linux-image-generic
apt-mark showhold
apt-mark hold
pin version

Preview Changes

List upgradable packages before you commit; read changelogs for database or web stack updates.

bashpreview
apt list --upgradable
list --upgradable
plan window

Kernel Updates and Reboot

A new kernel is not active until reboot. Use needrestart or check /var/run/reboot-required on Ubuntu.

bashcheck reboot
[ -f /var/run/reboot-required ] && cat /var/run/reboot-required
uname -r
reboot required
maintenance window

After Updates: Verify Services

Check for failed systemd units and smoke-test web apps and databases before closing the change ticket.

bashhealth
systemctl --failed
sudo nginx -t 2>/dev/null; sudo systemctl is-active mariadb 2>/dev/null
post-check
systemctl

Quick Reference

  • sudo apt update && sudo apt upgrade -y for routine patches
  • full-upgrade when packages are kept back
  • Reboot when a new kernel is installed

Related tutorials

Diagrams are original illustrations by Gnome IT Solutions. Tutorial text © Gnome IT Solutions.