How Unattended-Upgrades Schedules Reboots
In Debian-based systems, unattended-upgrades does not calculate a dynamic delay based on system load or relative time. Instead, it relies on a fixed wall-clock timestamp defined in the configuration. When a kernel update is installed and a reboot is required, the utility checks the Automatic-Reboot flag; if enabled, it schedules the reboot for the specific time defined in Automatic-Reboot-Time.
Likely Explanation for Timing Uncertainty
The "Reboot scheduled" message in the logs is often generic because the utility is simply handing off the execution to a systemd timer or a scheduled task. If you are experiencing reboots at unexpected times, it is likely due to one of the following:
- Fixed Time Configuration: The system is rebooting at the exact time specified in
Automatic-Reboot-Time (e.g., "02:00"), regardless of when the kernel update actually finished.
- Missing Configuration: If
Automatic-Reboot is true but Automatic-Reboot-Time is unset or invalid, the behavior can become unpredictable or fail to trigger, depending on the distribution version.
- Systemd Execution: Once the trigger fires,
systemd executes a standard reboot. It does not prioritize services differently for unattended updates; it follows the standard dependency graph and honors DefaultTimeoutStopSec for service shutdowns.
Verification and Configuration Steps
To resolve the uncertainty and ensure reboots do not interrupt deployments, verify your configuration in /etc/apt/apt.conf.d/50unattended-upgrades:
- Check the Reboot Settings: Ensure the following keys are explicitly set to your preferred maintenance window:
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "04:00";
- Inspect Active Timers: Run the following command to see if a reboot timer is currently queued by systemd:
systemctl list-timers --all
- Correlate Logs: Use
journalctl to find the exact second the reboot signal was sent to systemd, which provides more granularity than the unattended-upgrades log:
journalctl -u unattended-upgrades | grep -i reboot
Assumptions and Constraints
This analysis assumes a standard Debian/Ubuntu environment. Note that max-reboot-delay is not a standard native configuration key for the unattended-upgrades package; if this is present in your config, it may be a custom script or a distribution-specific modification that is not being honored by the core utility.
Missing Diagnostic Detail: Please provide the specific Linux distribution and version (e.g., Ubuntu 22.04 or Debian 12) to confirm if any vendor-specific patches alter the default reboot scheduling logic.