Unattended-Upgrades Patch Coverage Audit Prompt
Audit Debian/Ubuntu unattended-upgrades and dnf-automatic configuration to confirm security patches actually apply and reboots happen safely
- Target user
- security-minded DevOps and Linux platform engineers ensuring fleet patch coverage
- Difficulty
- Beginner
- Tools
- Claude, ChatGPT
The prompt
You are a senior DevSecOps engineer (defensive/blue-team) who audits automated OS patching so security fixes are not silently skipped. I will provide: - My unattended-upgrades config (50unattended-upgrades, 20auto-upgrades) or dnf-automatic.conf - Recent logs (/var/log/unattended-upgrades/) or `apt-get -s upgrade` output - Fleet context: reboot windows, kernel live-patching status, and any held packages Your job: 1. **Origin coverage** — verify the `Allowed-Origins`/`updateinfo` settings actually include the security pocket and aren't limited to a subset that misses CVEs. 2. **Apply-vs-download check** — confirm `Unattended-Upgrade::Automatic-Reboot` and download/install flags are set so patches are installed, not just fetched. 3. **Blocked-package review** — flag `apt-mark hold`, blacklist regexes, and `Package-Blacklist` entries that may be silently freezing vulnerable packages. 4. **Reboot hygiene** — assess reboot windows, `needrestart`/live-patch handling, and the gap between patch install and effective kernel/service restart. 5. **Failure visibility** — check that failures, mail notifications, and exit codes are surfaced to monitoring rather than swallowed. 6. **Remediation config** — provide a corrected configuration snippet with safe defaults. 7. **Coverage check** — recommend a recurring verification (e.g. compare installed versions against the security feed). Output as: a findings table (setting, current, risk, fix), then a corrected config snippet and a patch-coverage verification step. Do not recommend blindly enabling automatic reboots on stateful nodes without a tested drain/window strategy.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
SELinux Targeted Policy Troubleshooting Prompt
Diagnose SELinux denials from audit logs and produce minimal, least-privilege policy fixes — booleans, file contexts, or scoped custom modules — instead of disabling enforcement.
-
Vulnerability & Patch Management Lifecycle Design Prompt
Design a defensible patch and vulnerability-management lifecycle — asset inventory, scanner intake, risk-based SLAs, patch windows, exception handling, and metrics — across servers and containers.
-
auditd Rule-Set Design Prompt
Design a focused, low-noise Linux auditd rule-set that captures the events that actually matter for forensics and compliance without drowning the audit log in irrelevant syscalls.
-
Container Image Vulnerability Scan Triage Prompt
Turn noisy Trivy/Grype container image scan output into a prioritized, actionable remediation plan — separating reachable, fixable CVEs from base-image noise and false positives.
More DevOps Security & Hardening prompts & error guides
Browse every DevOps Security & Hardening prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.