Chapter 7. Automating software updates in RHEL 9
DNF Automatic is an alternative command-line interface to DNF that is suited for automatic and regular execution by using systemd timers, cron jobs, and other such tools.
DNF Automatic synchronizes package metadata as needed, checks for updates available, and then performs one of the following actions depending on how you configure the tool:
- Exit
- Download updated packages
- Download and apply the updates
The outcome of the operation is then reported by a selected mechanism, such as the standard output or email.
7.1. Installing DNF Automatic
To check and download package updates automatically and regularly, you can use the DNF Automatic tool that is provided by the dnf-automatic
package.
Procedure
Install the
dnf-automatic
package:# dnf install dnf-automatic
Verification
Verify the successful installation by confirming the presence of the
dnf-automatic
package:# rpm -qi dnf-automatic
7.2. DNF Automatic configuration file
By default, DNF Automatic uses /etc/dnf/automatic.conf
as its configuration file to define its behavior.
The configuration file is separated into the following topical sections:
[commands]
Sets the mode of operation of DNF Automatic.
WarningSettings of the operation mode from the
[commands]
section are overridden by settings used by a systemd timer unit for all timer units exceptdnf-automatic.timer
.[emitters]
Defines how the results of DNF Automatic are reported.
[command]
Defines the command emitter configuration.
[command_email]
Provides the email emitter configuration for an external command used to send email.
[email]
Provides the email emitter configuration.
[base]
Overrides settings from the main configuration file of DNF.
With the default settings of the /etc/dnf/automatic.conf
file, DNF Automatic checks for available updates, downloads them, and reports the results to standard output.
Additional resources
-
dnf-automatic(8)
man page on your system - Overview of the systemd timer units included in the dnf-automatic package
7.3. Enabling DNF Automatic
To run DNF Automatic once, you must start a systemd timer unit. However, if you want to run DNF Automatic periodically, you must enable the timer unit. You can use one of the timer units provided in the dnf-automatic
package, or you can create a drop-in file for the timer unit to adjust the execution time.
Prerequisites
-
You specified the behavior of DNF Automatic by modifying the
/etc/dnf/automatic.conf
configuration file.
Procedure
To enable and execute a systemd timer unit immediately, enter:
# systemctl enable --now <timer_name>
If you want to only enable the timer without executing it immediately, omit the
--now
option.You can use the following timers:
-
dnf-automatic-download.timer
: Downloads available updates. -
dnf-automatic-install.timer
: Downloads and installs available updates. -
dnf-automatic-notifyonly.timer
: Reports available updates. -
dnf-automatic.timer
: Downloads, downloads and installs, or reports available updates.
-
Verification
Verify that the timer is enabled:
# systemctl status <systemd timer unit>
Optional: Check when each of the timers on your system ran the last time:
# systemctl list-timers --all
Additional resources
-
dnf-automatic(8)
man page - Overview of the systemd timer units included in the dnf-automatic package
7.4. Overview of the systemd timer units included in the dnf-automatic package
The systemd timer units take precedence and override the settings in the /etc/dnf/automatic.conf
configuration file when downloading and applying updates.
For example if you set download_updates = yes
in the /etc/dnf/automatic.conf
configuration file, but you have activated the dnf-automatic-notifyonly.timer unit
, the packages will not be downloaded.
Table 7.1. systemd timers included in the dnf-automatic
package
Timer unit | Function | Overrides the apply_updates and download_updates settings in the [commands] section of the /etc/dnf/automatic.conf file? |
---|---|---|
| Downloads packages to cache and makes them available for updating.
This timer unit does not install the updated packages. To perform the installation, you must run the | Yes |
| Downloads and installs updated packages. | Yes |
| Downloads only repository data to keep the repository cache up-to-date and notifies you about available updates. This timer unit does not download or install the updated packages. | Yes |
|
The behavior of this timer when downloading and applying updates is specified by the settings in the This timer downloads packages, but does not install them. | No |