升级后检查清单
系统升级完成并重启后,按照以下清单逐项检查,确保所有服务和功能正常运行。
1. 基本系统验证
确认版本信息
# 确认系统版本
lsb_release -a
cat /etc/os-release
# 确认内核版本
uname -r
# 确认架构
uname -m
dpkg --print-architecture检查系统启动
# 查看启动时间
uptime
systemd-analyze
# 查看启动过程是否有错误
systemd-analyze blame
journalctl -b -p err
# 检查 dmesg 中的错误
dmesg --level=err,warn | tail -302. 包管理检查
修复可能的包问题
# 检查损坏的包
sudo dpkg --audit
# 修复损坏的依赖
sudo apt --fix-broken install
# 完成可能中断的配置
sudo dpkg --configure -a
# 检查是否有保留未升级的包
apt list --upgradable完整更新
# 更新包列表并安装剩余更新
sudo apt update
sudo apt upgrade -y
sudo apt dist-upgrade -y清理旧包
# 删除不再需要的包
sudo apt autoremove --purge -y
# 清理包缓存
sudo apt clean
# 查看已安装的旧内核
dpkg --list | grep linux-image | grep -v $(uname -r)
# 如有旧内核,autoremove 会处理,也可手动删除
# sudo apt purge linux-image-x.x.x-xx-generic3. 服务状态检查
查看服务运行状态
# 检查失败的服务
systemctl --failed
# 如有失败的服务,查看详细信息
# systemctl status failed-service-name
# journalctl -u failed-service-name
# 查看所有运行中的服务
systemctl list-units --type=service --state=running对比升级前的服务列表
# 如果升级前保存了服务列表
diff <(cat /backup/services-running-*.txt | awk '{print $1}' | sort) \
<(systemctl list-units --type=service --state=running | awk '{print $1}' | sort)常见服务检查
# SSH
sudo systemctl status ssh
ssh localhost
# Web 服务器
sudo systemctl status nginx 2>/dev/null || sudo systemctl status apache2 2>/dev/null
curl -I http://localhost
# 数据库
sudo systemctl status mysql 2>/dev/null || sudo systemctl status postgresql 2>/dev/null
# Docker
sudo systemctl status docker
docker ps
# 检查所有自启动服务
systemctl list-unit-files --state=enabled --type=service4. 网络检查
基本网络连通性
# 检查网络接口
ip addr
# 检查路由表
ip route
# 检查 DNS 解析
resolvectl status 2>/dev/null || cat /etc/resolv.conf
dig ubuntu.com +short
nslookup ubuntu.com
# 测试外网连通性
ping -c 3 8.8.8.8
ping -c 3 ubuntu.com
# 检查监听端口
ss -tlnp对比网络变化
# 检查 Netplan 配置
cat /etc/netplan/*.yaml
# 确认网络管理工具
systemctl status systemd-networkd 2>/dev/null
systemctl status NetworkManager 2>/dev/null防火墙
# 检查 UFW 状态
sudo ufw status verbose
# 确认规则完整
sudo ufw status numbered5. 存储和文件系统
# 检查磁盘空间
df -h
# 检查 inode 使用
df -i
# 检查文件系统错误
sudo dmesg | grep -i "ext4\|xfs\|btrfs" | grep -i error
# 检查 LVM 状态(如使用 LVM)
sudo lvs
sudo vgs
sudo pvs
# 检查挂载点
mount | column -t
cat /etc/fstab6. 安全检查
SSH 配置
# 确认 SSH 配置未被覆盖
sudo sshd -t
grep -E "^(PermitRootLogin|PasswordAuthentication|Port)" /etc/ssh/sshd_config
grep -rE "^(PermitRootLogin|PasswordAuthentication|Port)" /etc/ssh/sshd_config.d/
# 确认自定义的 SSH 配置仍然生效
sudo systemctl restart ssh用户和权限
# 检查用户列表
cat /etc/passwd | grep -v nologin | grep -v /bin/false
# 检查 sudo 权限
sudo cat /etc/sudoers.d/*
# 检查 SSH 授权密钥
cat ~/.ssh/authorized_keys自动安全更新
# 检查自动更新配置
cat /etc/apt/apt.conf.d/20auto-upgrades
cat /etc/apt/apt.conf.d/50unattended-upgrades
# 确保 unattended-upgrades 正在运行
sudo systemctl status unattended-upgrades7. 应用程序检查
Web 应用
# 检查 Web 服务器配置语法
sudo nginx -t 2>/dev/null
sudo apache2ctl configtest 2>/dev/null
# 检查 PHP 版本和模块(如使用 PHP)
php -v
php -m
# 检查 SSL 证书
sudo certbot certificates 2>/dev/nullDocker 容器
# 检查 Docker 服务
docker info
# 检查运行中的容器
docker ps
# 检查停止的容器
docker ps -a --filter "status=exited"
# 重启 Docker Compose 项目
cd /path/to/project && docker compose up -d
docker compose ps数据库
# MySQL/MariaDB
mysql -u root -p -e "SHOW DATABASES;"
mysql -u root -p -e "SELECT VERSION();"
# PostgreSQL
sudo -u postgres psql -c "SELECT version();"
sudo -u postgres psql -l8. 第三方源和 PPA
检查被禁用的源
# 升级过程中被禁用的第三方源
ls /etc/apt/sources.list.d/*.distUpgrade 2>/dev/null
# 查看当前激活的源
apt-cache policy | head -30
grep -r "^Types:" /etc/apt/sources.list.d/*.sources 2>/dev/null
grep -r "^deb " /etc/apt/sources.list.d/*.list 2>/dev/null恢复需要的第三方源
# 确认源支持 26.04 后恢复
# 例如恢复 Docker 源
# sudo mv /etc/apt/sources.list.d/docker.list.distUpgrade /etc/apt/sources.list.d/docker.list
# 或重新添加
# sudo add-apt-repository ppa:example/ppa
# 更新源
sudo apt update9. 定时任务
# 检查用户 cron
crontab -l
# 检查系统 cron
cat /etc/crontab
ls /etc/cron.d/
ls /etc/cron.daily/
ls /etc/cron.weekly/
# 检查 systemd timer
systemctl list-timers --all10. 日志和监控
检查升级日志
# 升级日志目录
ls -la /var/log/dist-upgrade/
# 查看主日志
cat /var/log/dist-upgrade/main.log | grep -E "(ERROR|WARNING)"
# 查看 APT 日志
cat /var/log/dist-upgrade/apt.log | tail -50清理日志
# 清理旧日志释放空间
sudo journalctl --vacuum-time=7d
sudo journalctl --vacuum-size=500M检查清单总结
- 系统版本确认为 26.04 LTS
- 无损坏或保留未升级的包
- 所有关键服务正常运行
- 网络连接正常(内网和外网)
- 防火墙规则完整
- 磁盘空间充足
- SSH 可正常远程访问
- Web 应用正常响应
- 数据库服务正常
- Docker 容器正常运行
- 定时任务正常
- 自动安全更新已启用
- 第三方源已按需恢复
- 旧内核和无用包已清理
- 升级策略设置为
lts
# 最终确认
grep Prompt /etc/update-manager/release-upgrades
# 输出应为: Prompt=ltsLast updated on