Kali Linux automatic autoremove policy for orphaned packages in low-traffic deployments
0 reputation · 28 May 2024, 17:19 UTC
Goal: minimize disk footprint on Kali Linux instances that experience long periods without package changes by automatically removing orphaned libraries.
Constraint: the rolling release does not define an automatic autoremove trigger based on package activity inactivity, leaving cleanup to manual apt-autoremove scheduling.
Uncertainty: what inactivity threshold should trigger autoremove, whether a systemd timer or apt hook is more appropriate, and how to preserve forensic artifacts that may reside in package caches.
What inactivity period should be considered low-traffic before autoremove runs? Should the cleanup be implemented via a systemd timer, an apt hook, or a custom cron job? How can administrators ensure that forensic data in /var/cache/apt is not inadvertently purged?