Managing Snap Packages on Ubuntu LTS: Installation, Interface Connections, and Update Control
Guide to installing Snaps, managing interfaces, controlling update timing, and rolling back updates on Ubuntu LTS.
25 Jun 2026, 19:40 UTC

Desired outcome
You want to install a Snap package, grant it only the interfaces it needs, control when automatic updates occur, and be able to roll back a problematic update.
Prerequisites
- Ubuntu 20.04 LTS or later (any LTS release).
- A user account with sudo privileges.
- Internet access for downloading snaps from the Snap Store.
- The snapd service installed and running (it is present by default on Ubuntu LTS).
Procedure
1. Verify snapd is active
Run the following command in a terminal:
systemctl status snapd.service
You should see active (running). If the service is not running, start it with sudo systemctl start snapd.service and enable it for boot with sudo systemctl enable snapd.service.
2. Install a Snap package
Choose a package, for example htop (a system monitor). Install it with:
sudo snap install htop
The command performs an atomic transaction; if anything fails, the system remains unchanged.
3. List installed snaps and their versions
After installation, verify with:
snap list
Look for the entry htop and note its version and confinement type (usually strict).
4. Examine required interfaces
Each snap declares the interfaces it needs. To see what htop requests and what is currently connected:
snap connections htop
The output shows slots (provided by the system) and plugs (requested by the snap). For htop you will typically see process-control and system-observe plugs.
5. Connect or disconnect interfaces manually
If a needed plug is not connected, connect it with:
sudo snap connect htop:process-control
To disconnect a plug you no longer need:
sudo snap disconnect htop:system-observe
Only disconnect interfaces you are certain are not required; otherwise the snap may lose functionality.
6. Control automatic refresh timing
Snap updates are managed by a systemd timer snapd.refresh.timer. To view the current schedule:
systemctl list-timers --all | grep snapd.refresh
The timer runs up to four times a day by default. To change the interval, create an override:
sudo systemctl edit snapd.refresh.timer
In the editor, add:
[Timer]
OnUnitActiveSec=12h
This example sets updates to occur at most every 12 hours. Save and exit; the override takes effect immediately. To revert to the default, remove the override file:
sudo rm /etc/systemd/system/snapd.refresh.timer.d/override.conf
sudo systemctl daemon-reload
7. Perform a manual refresh and verify
To trigger an immediate refresh:
sudo snap refresh
After the command finishes, run snap list again and confirm the version numbers have changed (or stayed the same if no newer version exists).
8. Roll back a problematic update
If a refresh introduces an issue, you can revert to the previous version:
sudo snap revert htop
The command switches the snap back to the revision that was active before the last refresh. Verify with snap list that the version number matches the earlier one.
9. Check logs for confinement denials or update errors
When a snap is denied access by its sandbox, the denial is logged by the kernel audit system and forwarded to journald. Inspect with:
journalctl -u snapd.service --since "1 hour ago"
Look for lines containing avc: denied or snapd error messages. If you see a denial for an interface you expect to be needed, connect the missing plug as described in step 5.
Expected checks
snap listshows the package with the expected version and confinement (strictorclassic).snap connections <package>lists all required plugs as connected.- The refresh timer shows the interval you set (e.g., 12 h) when you run
systemctl list-timers. - After a manual refresh, the version reported by
snap listmatches the latest available in the channel you are tracking. - After a rollback, the version reverts to the previous revision.
- Journal queries return no new
avc: deniedentries for the snap after you have connected all needed interfaces.
Recovery options
- If the snapd service fails to start, reinstall it:
sudo apt install --reinstall snapd. - If manual timer edits cause the timer to not trigger, remove the override and reload systemd as shown in step 6.
- If a snap refuses to start after a refresh, first try
snap revert; if the problem persists, consider removing and reinstalling the snap:sudo snap remove <package> && sudo snap install <package>.
Limitations
Strict confinement prevents a snap from accessing arbitrary files or hardware unless the corresponding interface is connected. Some legacy applications may require classic confinement to work; using classic mode disables the sandbox and should be limited to trusted sources. The refresh timer can only be adjusted in increments supported by systemd; values shorter than 1 hour may be ignored by the snapd service to avoid excessive load.
Practical verification
To confirm that your refresh‑timer change is active, run:
systemctl show snapd.refresh.timer --property=ActiveSec
The output should reflect the value you set (e.g., ActiveSec=43200 for 12 hours).
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.