Automatic updates must be always disabled in production. Here’s why:
While keeping your servers patched up-to-date might seem like a valid idea, here’s few reasons why to avoid automatic installation.
- 
    It means that your servers are NOT immutable. Read more on this here. 
- 
    It can cause un-planned downtime. Consider this scenario - you have to reboot your server quickly to fix some urgent error/failure, you log-in to your server, send it to reboot and systems begins installing updates for some hour or two. 
- 
    Your servers become unique after some period of time unless you have proper procedure for installing updates. 
https://i.redditmedia.com/EhT64WxhlxPgV9MjFXBSH5rj_uC8idsDy_u1F7sHZZg.jpg?w=1024&s=948374c836947dea0153c5f3878cb894
