Safe OS patching: a checklist approach
What I check before, during and after patching Linux servers.
Short guides, a command cheat sheet and a checklist from my day-to-day infrastructure work. Always test changes in a safe environment first.
What I check before, during and after patching Linux servers.
How they differ, when to use each, and common mistakes.
Everyday habits that reduce risk without a big budget.
Add a new disk to a volume group and grow a logical volume plus its filesystem (ext4 or XFS). Adjust device and VG/LV names.
lsblk sudo pvcreate /dev/sdb sudo vgextend vg_data /dev/sdb sudo lvextend -r -L +10G /dev/vg_data/lv_app df -h
-r resizes the filesystem in the same step. Check vgs first to confirm free space.
Before: confirm a backup or snapshot, note the running kernel (uname -r), and agree a maintenance window.
# Debian / Ubuntu sudo apt update && apt list --upgradable sudo apt upgrade # RHEL family sudo dnf check-update sudo dnf upgrade
After: check whether a reboot is needed (/var/run/reboot-required on Debian/Ubuntu, needs-restarting -r on RHEL), then verify with systemctl --failed and your application.
Keep one session open while testing so you can't lock yourself out. Confirm key login works before disabling passwords.
# /etc/ssh/sshd_config PermitRootLogin no PasswordAuthentication no sudo sshd -t sudo systemctl reload sshd # service is "ssh" on Debian/Ubuntu
Need help applying any of this? Get in touch.