Skip to Content
DocsOperationsUpgrade & MigrationPost-Upgrade Checklist

Post-Upgrade Checklist

After the system upgrade is complete and the system has rebooted, follow this checklist item by item to ensure all services and features are working properly.

1. Basic System Verification

Confirm Version Information

# Confirm system version lsb_release -a cat /etc/os-release # Confirm kernel version uname -r # Confirm architecture uname -m dpkg --print-architecture

Check System Boot

# View boot time uptime systemd-analyze # Check for errors during boot systemd-analyze blame journalctl -b -p err # Check dmesg for errors dmesg --level=err,warn | tail -30

2. Package Management Check

Fix Potential Package Issues

# Check for broken packages sudo dpkg --audit # Fix broken dependencies sudo apt --fix-broken install # Complete any interrupted configuration sudo dpkg --configure -a # Check for held-back packages apt list --upgradable

Full Update

# Update package lists and install remaining updates sudo apt update sudo apt upgrade -y sudo apt dist-upgrade -y

Clean Up Old Packages

# Remove packages that are no longer needed sudo apt autoremove --purge -y # Clean package cache sudo apt clean # View installed old kernels dpkg --list | grep linux-image | grep -v $(uname -r) # Old kernels will be handled by autoremove; you can also remove them manually # sudo apt purge linux-image-x.x.x-xx-generic

3. Service Status Check

View Service Running Status

# Check for failed services systemctl --failed # If there are failed services, view details # systemctl status failed-service-name # journalctl -u failed-service-name # View all running services systemctl list-units --type=service --state=running

Compare with Pre-Upgrade Service List

# If you saved the service list before upgrading diff <(cat /backup/services-running-*.txt | awk '{print $1}' | sort) \ <(systemctl list-units --type=service --state=running | awk '{print $1}' | sort)

Common Service Checks

# SSH sudo systemctl status ssh ssh localhost # Web server sudo systemctl status nginx 2>/dev/null || sudo systemctl status apache2 2>/dev/null curl -I http://localhost # Database sudo systemctl status mysql 2>/dev/null || sudo systemctl status postgresql 2>/dev/null # Docker sudo systemctl status docker docker ps # Check all auto-start services systemctl list-unit-files --state=enabled --type=service

4. Network Check

Basic Network Connectivity

# Check network interfaces ip addr # Check routing table ip route # Check DNS resolution resolvectl status 2>/dev/null || cat /etc/resolv.conf dig ubuntu.com +short nslookup ubuntu.com # Test external connectivity ping -c 3 8.8.8.8 ping -c 3 ubuntu.com # Check listening ports ss -tlnp

Compare Network Changes

# Check Netplan configuration cat /etc/netplan/*.yaml # Confirm network management tool systemctl status systemd-networkd 2>/dev/null systemctl status NetworkManager 2>/dev/null

Firewall

# Check UFW status sudo ufw status verbose # Confirm rules are intact sudo ufw status numbered

5. Storage and Filesystem

# Check disk space df -h # Check inode usage df -i # Check for filesystem errors sudo dmesg | grep -i "ext4\|xfs\|btrfs" | grep -i error # Check LVM status (if using LVM) sudo lvs sudo vgs sudo pvs # Check mount points mount | column -t cat /etc/fstab

6. Security Check

SSH Configuration

# Confirm SSH configuration was not overwritten sudo sshd -t grep -E "^(PermitRootLogin|PasswordAuthentication|Port)" /etc/ssh/sshd_config grep -rE "^(PermitRootLogin|PasswordAuthentication|Port)" /etc/ssh/sshd_config.d/ # Confirm custom SSH configuration is still in effect sudo systemctl restart ssh

Users and Permissions

# Check user list cat /etc/passwd | grep -v nologin | grep -v /bin/false # Check sudo permissions sudo cat /etc/sudoers.d/* # Check SSH authorized keys cat ~/.ssh/authorized_keys

Automatic Security Updates

# Check auto-update configuration cat /etc/apt/apt.conf.d/20auto-upgrades cat /etc/apt/apt.conf.d/50unattended-upgrades # Ensure unattended-upgrades is running sudo systemctl status unattended-upgrades

7. Application Check

Web Applications

# Check web server configuration syntax sudo nginx -t 2>/dev/null sudo apache2ctl configtest 2>/dev/null # Check PHP version and modules (if using PHP) php -v php -m # Check SSL certificates sudo certbot certificates 2>/dev/null

Docker Containers

# Check Docker service docker info # Check running containers docker ps # Check stopped containers docker ps -a --filter "status=exited" # Restart Docker Compose projects cd /path/to/project && docker compose up -d docker compose ps

Databases

# MySQL/MariaDB mysql -u root -p -e "SHOW DATABASES;" mysql -u root -p -e "SELECT VERSION();" # PostgreSQL sudo -u postgres psql -c "SELECT version();" sudo -u postgres psql -l

8. Third-Party Sources and PPAs

Check Disabled Sources

# Third-party sources disabled during the upgrade ls /etc/apt/sources.list.d/*.distUpgrade 2>/dev/null # View currently active sources apt-cache policy | head -30 grep -r "^Types:" /etc/apt/sources.list.d/*.sources 2>/dev/null grep -r "^deb " /etc/apt/sources.list.d/*.list 2>/dev/null

Restore Needed Third-Party Sources

# Restore after confirming the source supports 26.04 # For example, restoring the Docker source # sudo mv /etc/apt/sources.list.d/docker.list.distUpgrade /etc/apt/sources.list.d/docker.list # Or re-add # sudo add-apt-repository ppa:example/ppa # Update sources sudo apt update

9. Scheduled Tasks

# Check user cron crontab -l # Check system cron cat /etc/crontab ls /etc/cron.d/ ls /etc/cron.daily/ ls /etc/cron.weekly/ # Check systemd timers systemctl list-timers --all

10. Logs and Monitoring

Check Upgrade Logs

# Upgrade log directory ls -la /var/log/dist-upgrade/ # View main log cat /var/log/dist-upgrade/main.log | grep -E "(ERROR|WARNING)" # View APT log cat /var/log/dist-upgrade/apt.log | tail -50

Clean Up Logs

# Clean old logs to free space sudo journalctl --vacuum-time=7d sudo journalctl --vacuum-size=500M

Checklist Summary

  • System version confirmed as 26.04 LTS
  • No broken or held-back packages
  • All critical services running normally
  • Network connectivity is normal (internal and external)
  • Firewall rules are intact
  • Disk space is sufficient
  • SSH remote access works
  • Web applications responding normally
  • Database services are normal
  • Docker containers running normally
  • Scheduled tasks are working
  • Automatic security updates are enabled
  • Third-party sources restored as needed
  • Old kernels and unnecessary packages cleaned up
  • Upgrade policy set to lts
# Final confirmation grep Prompt /etc/update-manager/release-upgrades # Should output: Prompt=lts
Last updated on