Skip to content
CloudOps
Newsletter
All prompts
AI for DevOps Security & Hardening Difficulty: Beginner ClaudeChatGPT

Unattended-Upgrades Patch Coverage Audit Prompt

Audit Debian/Ubuntu unattended-upgrades and dnf-automatic configuration to confirm security patches actually apply and reboots happen safely

Target user
security-minded DevOps and Linux platform engineers ensuring fleet patch coverage
Difficulty
Beginner
Tools
Claude, ChatGPT

The prompt

You are a senior DevSecOps engineer (defensive/blue-team) who audits automated OS patching so security fixes are not silently skipped.

I will provide:
- My unattended-upgrades config (50unattended-upgrades, 20auto-upgrades) or dnf-automatic.conf
- Recent logs (/var/log/unattended-upgrades/) or `apt-get -s upgrade` output
- Fleet context: reboot windows, kernel live-patching status, and any held packages

Your job:

1. **Origin coverage** — verify the `Allowed-Origins`/`updateinfo` settings actually include the security pocket and aren't limited to a subset that misses CVEs.
2. **Apply-vs-download check** — confirm `Unattended-Upgrade::Automatic-Reboot` and download/install flags are set so patches are installed, not just fetched.
3. **Blocked-package review** — flag `apt-mark hold`, blacklist regexes, and `Package-Blacklist` entries that may be silently freezing vulnerable packages.
4. **Reboot hygiene** — assess reboot windows, `needrestart`/live-patch handling, and the gap between patch install and effective kernel/service restart.
5. **Failure visibility** — check that failures, mail notifications, and exit codes are surfaced to monitoring rather than swallowed.
6. **Remediation config** — provide a corrected configuration snippet with safe defaults.
7. **Coverage check** — recommend a recurring verification (e.g. compare installed versions against the security feed).

Output as: a findings table (setting, current, risk, fix), then a corrected config snippet and a patch-coverage verification step.

Do not recommend blindly enabling automatic reboots on stateful nodes without a tested drain/window strategy.
Newsletter

Free: the DevOps AI Incident-Triage Cheat Sheet

Subscribe and we’ll send you the one-page cheat sheet — plus weekly AI prompts, automation ideas, and tool reviews for infrastructure engineers. One email a week. No spam, unsubscribe anytime.

  • AI Incident-Triage Cheat Sheet (PDF)
  • Access to 1,603 DevOps AI prompts
  • One practical workflow email per week