关于阻止unattended-upgrades重启服务及解决生产环境关键systemd服务重启问题的技术问询
Hey there, let’s tackle this head-on because unexpected service restarts from unattended upgrades in production are a total nightmare—especially when they lead to data loss. Here’s how you can safely prevent your critical systemd service from being restarted during upgrades:
1. Tell dpkg to skip restarting your critical service
dpkg is the tool that handles most service restart triggers when packages are upgraded, so we can explicitly whitelist your service to avoid restarts:
- Create a custom dpkg config file (this keeps your changes separate from default system configs):
sudo nano /etc/dpkg/dpkg.cfg.d/99-no-restart-critical-service - Add this single line, making sure to replace
my-critical-servicewith the actual name of your systemd service:No-Services: my-critical-service - Save and exit. This config tells dpkg to never restart this specific service, no matter which packages are being upgraded (including those pushed through unattended-upgrades).
2. Exclude the service from needrestart (if it’s installed)
A lot of Debian/Ubuntu-based systems use needrestart to detect services that need a refresh after library or dependency upgrades. If you have this tool installed, you’ll need to blacklist your service here too:
- Create a custom needrestart config file (again, avoiding changes to the default main config):
sudo nano /etc/needrestart/conf.d/99-blacklist-critical-service.conf - Add these lines to block the service:
# Prevent our critical systemd service from being auto-restarted by needrestart $nrconf{'blacklist'}{'my-critical-service'} = 1; - If you want to take it a step further and disable all automatic service restarts via needrestart (forcing it to just alert you instead), edit the main config at
/etc/needrestart/needrestart.confand set:$nrconf{'restart'} = 'i'; # 'i' triggers an interactive prompt; use 'n' to never restart anything
3. Harden your unattended-upgrades config (optional but recommended)
While the first two steps cover the core triggers, you can tweak unattended-upgrades to be more cautious with your production system:
- Open the main config file:
sudo nano /etc/apt/apt.conf.d/50unattended-upgrades - Look for and adjust these settings to match your needs:
# Disable automatic system reboots entirely (if you don't want them) Unattended-Upgrade::Automatic-Reboot "false"; # If you keep reboots enabled, skip them when users are logged in (avoids disruptions) Unattended-Upgrade::Automatic-Reboot-WithUsers "true"; - Note: Unattended-upgrades follows the rules set by dpkg and needrestart, so the first two steps are the most critical for blocking specific service restarts.
4. Test your changes before relying on them
Always verify your setup with a dry run to make sure nothing is broken:
sudo unattended-upgrade --dry-run --debug
Scan the output to confirm your critical service isn’t listed as needing a restart.
A quick heads-up: Make sure you have a full backup of your service’s data and configs before making these changes. If possible, test this in a staging environment first—production systems don’t have room for trial and error!
备注:内容来源于stack exchange,提问作者Sevenzzz

