Skip to content
The 31 guidesFREN中文
Guides
Part 5 · guide 5 of 5 Level: Intermediate Reading time: 12 min Platforms: Linux

Maintain and update

A machine that's always on stays clean over time. The OS, the dependencies, the tools, the agents: what you automate, what you update by hand, and how to avoid breaking anything.

In this guide
  1. 01The OS: the base system
  2. 02Dependencies: what your projects rest on
  3. 03Tools and agents
  4. 04Disk space: the silent trap
  5. 05Knowing when it breaks
  6. 06Let the agent help you
  7. 07Frequently asked questions

In short

A machine that is always on stays healthy with two habits: security fixes apply themselves (unattended-upgrades), and once a month you back up, run sudo apt update && sudo apt upgrade, update Ollama, the agents and the dependencies one at a time, then clean up the disk. Moving from Ubuntu 24.04 to 26.04 is done with sudo do-release-upgrade, after a backup, keeping an eye on the new Rust base tools (rust-coreutils, sudo-rs) and the switch to Python 3.14. To know when something breaks, propagate exit codes, hook OnFailure onto your services and actually test the alert.

Do this first: Essential system settingsGit, GitHub & backups

A machine that runs 24/7 and is reachable from the outside is never “done.” It’s alive, and like everything that’s alive, it needs a bit of upkeep. The good news: 90% of it comes down to two habits, one automatic, the other monthly. Let’s look at which ones, and above all how to update without breaking anything.

The OS: the base system

Your Ubuntu is the foundation. Two levels of upkeep:

# The routine move: refresh the package list, then install updates
sudo apt update && sudo apt upgrade -y
# Clean out packages that have become useless
sudo apt autoremove --purge

For security, you’ve already automated everything in System settings with unattended-upgrades: the machine applies critical patches on its own. That’s the automatic habit we mentioned.

Once every two years, a new LTS version of Ubuntu comes out. The latest, Ubuntu 26.04, was released in April 2026, and the upgrade path from 24.04 has been open since its first point release, 26.04.1, published at the end of August: Canonical always waits for that “.1” before offering LTS-to-LTS upgrades. Nothing urgent, 24.04 gets security fixes until 2029. The day you go for it, back up first (see Git, GitHub & backups) and skim the release notes.

# First finish pending updates, reboot if asked
sudo apt update && sudo apt full-upgrade -y
# Then start the upgrade to the next LTS (inside tmux if you're over SSH)
sudo do-release-upgrade

Dependencies: what your projects rest on

This is where the surprises hide, because a dependency that jumps a major version can break a project.

  • Node (via nvm): nvm install --lts installs the latest LTS (Node 24 as of October 1, 2026, with Node 26 due to become LTS on October 28), nvm alias default sets it as the default. Keep the old one around long enough to confirm your projects still run.
  • A project’s packages: npm outdated shows what’s behind, npm update updates within the bounds of your package.json. For major versions, read the changelog first: that’s where the breaking changes live.
  • The habit that saves you: lockfiles. Version your package-lock.json / requirements.txt. They guarantee your project reinstalls exactly the same versions, everywhere, and that nothing shifts behind your back.

Tools and agents

The rest of your stack updates cleanly, each in its own way:

  • Docker: follows the system’s apt updates. Remember to clean up what piles up (see below).
  • Ollama: rerun the install script to move to the latest version (curl -fsSL https://ollama.com/install.sh | sh). And for models, you grab a new vintage with ollama pull <model>: the local version is replaced. To spot the ones worth updating to, the Quelle IA ranking of local models (in French) is refreshed every week.
  • Your coding agents: Claude Code, installed through its script, updates itself in the background, and claude update forces the latest version. OpenCode moves to the latest with opencode upgrade. If you had installed Claude Code with npm, switch to the native installer (curl -fsSL https://claude.ai/install.sh | bash), then remove the old copy with npm uninstall -g @anthropic-ai/claude-code. An up-to-date agent means new capabilities for free.
  • Tailscale and cloudflared: installed via their own repos, they update with the system. Nothing special to do.

Disk space: the silent trap

Models, Docker images, and old packages fill a disk without warning, and a full machine starts crashing in mysterious ways. The cleanup comes down to three commands:

df -h                      # how much room is left
docker system prune -a     # drop unused images and containers
ollama rm <model>          # remove a model you no longer use
sudo apt autoremove --purge # orphaned packages

Knowing when it breaks

A machine working alone overnight only warns you if you programmed it to. The risk is not the outage, it is how long it takes to reach you. Everything below comes from real incidents on this machine.

1. A script calling another must propagate its exit code

The classic trap, and a very common one:

#!/bin/bash
set -uo pipefail
python3 import.py >> import.log 2>&1        # the exit code goes in the bin
systemctl --user restart my-site || true    # last command: always returns 0

This script always returns 0. The import can crash, systemd reports success, and your weekly report tells you everything is fine. It happened here: a database sat empty for a day while the monitor showed green.

The fix is two lines:

python3 import.py >> import.log 2>&1
rc=$?
systemctl --user restart my-site || true
exit $rc

2. OnFailure: get told the second it falls over

systemd can trigger one unit when another fails. You write a small service that messages you, and wire it onto everything that matters.

# ~/.config/systemd/user/my-service.service.d/onfailure.conf
[Unit]
OnFailure=alert@%n.service

Use an override file in a .d/ directory rather than editing the unit: it works even on a unit symlinked from a repository, and removing it means deleting a folder.

3. A system probe, because no unit alert sees the machine drowning

When RAM fills up, no unit is “failed”. The machine itself is going under, and OnFailure cannot see a thing. You need a separate probe, on a timer, watching available memory, processes killed by the kernel, swap and load, then messaging you on state change so it does not repeat the same alert every five minutes.

Let the agent help you

This is exactly the kind of chore your agent loves. “Check what’s due for an update on this machine, summarize the important changes for me, and propose a plan”: it lists the packages that are behind, reads the changelogs for you, and offers to act step by step. You keep your finger on the button, it does the investigative work.

Frequently asked questions

Should you upgrade from Ubuntu 24.04 to 26.04 right away?

There is no rush: 24.04 receives security fixes until 2029. The upgrade has been offered since 26.04.1, released at the end of August 2026, because Canonical always waits for that first point release before opening the path from one LTS to the next. When you do go ahead, back up first and read through the release notes.

Why do some Ubuntu updates need a reboot?

Some updates, the Linux kernel above all, only take effect after a reboot. Ubuntu tells you when one is needed through the /var/run/reboot-required file. Schedule it for a quiet moment: if the site, the tunnel and your agents are installed as systemd services, they restart on their own.

How do you update Claude Code and OpenCode?

Claude Code, installed with its script, updates itself in the background, and claude update forces the latest version. OpenCode moves to the latest version with opencode upgrade. If you had installed Claude Code with npm, switch to the native installer, then remove the old copy with npm uninstall -g @anthropic-ai/claude-code.

How do you free up disk space on a machine that runs local models?

Models, Docker images and old packages fill a disk without warning, and a full machine starts crashing in mysterious ways. Check the space left with df -h, then clean up: docker system prune -a for unused images and containers, ollama rm for a model you no longer use, and sudo apt autoremove --purge for orphaned packages.

Why isn't systemctl --failed enough to monitor your scheduled jobs?

That command only shows the present moment. A daily job that breaks on Monday and goes green again on Tuesday has vanished from the list long before your Sunday report, which will say 'nothing failed'. Combine both mechanisms: OnFailure catches the switch to red, the periodic report catches failures that have settled in.

Terms in this guide: UbuntuDockerOllamaClaude CodeOpenCodeAgentTailscaleCloudflare TunnelRepository (repo)RAM

Spotted a mistake?

A command stopped working, a price changed?

Tools change every month. Tell me what is wrong in this chapter and I will fix it and update its date.

Only the page, your message and the optional contact are kept. Nothing else.

Guide 31 of 31 · part 5 no guides read yet Open the list of guides