Automatic updates must be always disabled in production. Here’s why:

While keeping your servers patched up-to-date might seem like a valid idea, here’s few reasons why to avoid automatic installation.

  1. It means that your servers are NOT immutable. Read more on this here.

  2. It can cause un-planned downtime. Consider this scenario - you have to reboot your server quickly to fix some urgent error/failure, you log-in to your server, send it to reboot and systems begins installing updates for some hour or two.

  3. Your servers become unique after some period of time unless you have proper procedure for installing updates.

https://i.redditmedia.com/EhT64WxhlxPgV9MjFXBSH5rj_uC8idsDy_u1F7sHZZg.jpg?w=1024&s=948374c836947dea0153c5f3878cb894