Skip to content
Back to skills

Ubuntu

BSecurity

Ubuntu across all supported LTS versions (20.04, 22.04, 24.04, 26.04): apt/dpkg/snap package management, Netplan declarative networking, cloud-init, UFW firewall, AppArmor, Ubuntu Pro/ESM/Livepatch, Subiquity/autoinstall, ZFS root, LXD/Incus, and MicroK8s. Use when: \"Ubuntu\", \"ubuntu\", \"apt\", \"dpkg\", \"snap\", \"Netplan\", \"cloud-init\", \"UFW\", \"Livepatch\", \"Ubuntu Pro\", \"ESM\", \"Subiquity\", \"autoinstall\", \"LXD\". Do NOT use for AppArmor profile syntax/troubleshooting dep...

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
devopsgoshellbashsqlnodekubernetesazuredebuggingfrontendbackend

Security analysis

B88/100
  • criticalModifies startup scripts or system services for persistence

Pro scans all 20 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill ubuntu --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ubuntu?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ubuntu
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-ubuntu/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-ubuntu)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ubuntu
description: "Ubuntu across all supported LTS versions (20.04, 22.04, 24.04, 26.04): apt/dpkg/snap package management, Netplan declarative networking, cloud-init, UFW firewall, AppArmor, Ubuntu Pro/ESM/Livepatch, Subiquity/autoinstall, ZFS root, LXD/Incus, and MicroK8s. Use when: \"Ubuntu\", \"ubuntu\", \"apt\", \"dpkg\", \"snap\", \"Netplan\", \"cloud-init\", \"UFW\", \"Livepatch\", \"Ubuntu Pro\", \"ESM\", \"Subiquity\", \"autoinstall\", \"LXD\". Do NOT use for AppArmor profile syntax/troubleshooting depth — use the `apparmor` skill. Do NOT use for Debian's release governance and philosophy — use the `debian` skill."
license: MIT
---

# Ubuntu

This skill covers Ubuntu across all supported LTS versions (20.04, 22.04, 24.04, and 26.04), covering both Desktop and Server editions. It provides deep knowledge of:

- apt/dpkg package management, PPAs, deb822 format, and pinning
- snap packaging, confinement, interfaces, refresh scheduling, and Snap Store
- Netplan declarative networking (systemd-networkd and NetworkManager backends)
- cloud-init multi-stage initialization, datasources, and user-data formats
- UFW (Uncomplicated Firewall) with nftables backend
- AppArmor path-based mandatory access control
- Ubuntu Pro, ESM (Extended Security Maintenance), and Livepatch
- Subiquity server installer with autoinstall YAML
- ZFS root filesystem support (pools, datasets, snapshots)
- LXD/Incus system containers and VMs
- MicroK8s lightweight Kubernetes distribution

For generic Linux kernel internals and systemd fundamentals, see the `rhel` skill. This skill focuses on Ubuntu-specific tooling and approaches.

When a question is version-specific, read the relevant file under `references/versions/`. When the version is unknown, provide general guidance and note where behavior differs across versions.

## How to Approach Tasks

Route by request type: **troubleshooting** → `references/diagnostics.md`; **optimization** → `references/best-practices.md`; **architecture** → `references/architecture.md`; **edition selection** → `references/editions.md`; **administration** → the guidance below.

**Identify the Ubuntu LTS version first** — package format, kernel features, and default tooling shift between releases. Apply Ubuntu-specific reasoning, not generic Linux advice. Validate with `systemctl`, `journalctl`, `apt` queries, and `snap` checks.

## Core Expertise

### apt / dpkg Package Management

apt is the high-level package resolver; dpkg is the low-level installer. Ubuntu uses the Debian `.deb` format.

```bash
# Package operations
apt update -q
apt install nginx -y
apt full-upgrade -y                    # upgrade + allow removals for deps
apt autoremove --purge -y              # remove orphans and config files
apt list --upgradable 2>/dev/null      # pending upgrades

# Package queries
dpkg -l 'nginx*'                       # list packages matching pattern
dpkg -L nginx                          # files owned by package
dpkg -S /usr/bin/curl                  # which package owns file
apt-cache policy nginx                 # installed vs available versions
apt-cache rdepends --installed nginx   # reverse dependencies

# Repair
dpkg --configure -a                    # configure partially installed
apt --fix-broken install               # resolve broken dependencies
```

**Repository configuration** evolved across versions:
- Pre-24.04: `/etc/apt/sources.list` one-liner format
- 24.04+: `/etc/apt/sources.list.d/ubuntu.sources` deb822 format (multi-value, `Signed-By` field)

**Archive components:** `main` (Canonical-supported), `restricted` (proprietary drivers), `universe` (community FOSS), `multiverse` (non-free).

**PPAs:** `add-apt-repository ppa:owner/name` adds a Launchpad-hosted repo. Store keys in `/etc/apt/keyrings/` with `Signed-By` in the source definition.

### snap Packaging

snap delivers self-contained, sandboxed applications with automatic updates.

```bash
# Snap lifecycle
snap install firefox                   # install from Snap Store
snap install code --classic            # classic confinement (full access)
snap refresh --hold=48h firefox        # defer updates
snap revert firefox                    # rollback to previous revision
snap remove --purge firefox            # remove with all data

# Inspection
snap list                              # installed snaps
snap info firefox                      # channels, confinement, version
snap connections firefox               # interface plug/slot connections

# Administration
snap set system refresh.timer="mon-fri,02:00-04:00"  # set refresh window
snap list --all | awk '/disabled/{print $1, $3}'      # old revisions
```

**Confinement:** `strict` (AppArmor + seccomp sandbox), `classic` (full system access), `devmode` (violations logged only). Snap data lives in `/var/snap/` and `~/snap/`.

### Netplan Networking

Netplan is Ubuntu's declarative network configuration layer. It generates backend configs for systemd-networkd (server) or NetworkManager (desktop).

```bash
netplan apply                          # apply configuration
netplan try                            # apply with 120s auto-revert
netplan generate                       # write backend config only
netplan status                         # interface status (1.0+)
netplan get                            # current effective config
```

Configuration in `/etc/netplan/*.yaml`:
```yaml
network:
  version: 2
  renderer: networkd
  ethernets:
    eth0:
      addresses: [192.168.1.10/24]
      routes:
        - to: default
          via: 192.168.1.1
      nameservers:
        addresses: [8.8.8.8, 1.1.1.1]
```

### cloud-init

cloud-init initializes instances across five stages: generator, local, network, config, final. Datasources include EC2, Azure, GCE, OpenStack, and NoCloud.

```bash
cloud-init status --wait               # block until complete
cloud-init query -a                    # dump all instance metadata
cloud-init schema --config-file user-data.yaml  # validate syntax
cloud-init clean --logs                # reset for re-run
```

Network config written to `/etc/netplan/50-cloud-init.yaml`. Disable with:
`/etc/cloud/cloud.cfg.d/99-disable-network-config.cfg` containing `network: {config: disabled}`.

### UFW Firewall

UFW is Ubuntu's default firewall frontend (iptables/nftables backend).

```bash
ufw status verbose                     # current rules and defaults
ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 'OpenSSH'
ufw allow from 10.0.0.0/8 to any port 22
ufw limit ssh                          # rate-limit (6 per 30s)
ufw enable
ufw logging medium
```

Application profiles in `/etc/ufw/applications.d/`. Ubuntu does **not** use firewalld by default.

### AppArmor

AppArmor is Ubuntu's default MAC system (path-based profiles, unlike RHEL's SELinux label-based model).

```bash
aa-status                              # all profiles and modes
aa-enforce /etc/apparmor.d/usr.sbin.nginx
aa-complain /etc/apparmor.d/usr.sbin.nginx
journalctl -k | grep -i "apparmor.*denied"  # view denials
aa-genprof /usr/sbin/myapp             # generate profile
aa-logprof                             # update profiles from audit log
```

Modes: **enforce** (block + log), **complain** (log only), **unconfined** (no profile).

### Ubuntu Pro / ESM / Livepatch

Ubuntu Pro extends LTS security maintenance from 5 to 10 years. Free for up to 5 machines.

```bash
pro attach <token>                     # attach subscription
pro status                             # show enabled services
pro enable esm-infra                   # extended main repo patches
pro enable esm-apps                    # extended universe patches
pro enable livepatch                   # kernel live patching
pro enable usg                         # CIS/STIG hardening
pro fix CVE-2024-XXXXX                 # check and fix a CVE
```

**ESM-infra** covers `main` packages; **ESM-apps** covers `universe` (23,000+ packages). **Livepatch** applies critical kernel CVE patches in-memory without reboots via `canonical-livepatch`.

### Subiquity / Autoinstall

Subiquity is Ubuntu's server installer (replaced debian-installer in 20.04). Autoinstall YAML enables unattended provisioning.

```yaml
#cloud-config
autoinstall:
  version: 1
  identity:
    hostname: myserver
    username: ubuntu
    password: $6$...
  storage:
    layout:
      name: lvm
  ssh:
    install-server: true
  packages:
    - nginx
  late-commands:
    - curtin in-target -- systemctl enable nginx
```

Key sections: `identity`, `storage`, `network`, `ssh`, `packages`, `snaps`, `late-commands`.

### ZFS Support

Ubuntu provides first-class ZFS root filesystem support (not available on RHEL):

```bash
zpool status                           # pool health
zpool scrub rpool                      # integrity check
zfs list                               # datasets
zfs list -t snapshot                   # snapshots
zfs snapshot rpool/ROOT/ubuntu@backup  # create snapshot
zfs rollback rpool/ROOT/ubuntu@backup  # restore snapshot
```

Default server install uses LVM (`ubuntu-vg`/`ubuntu-lv`); ZFS is an installer option since 20.04.

### LXD / Incus

System container and VM manager. Canonical's LXD (snap) and community fork Incus (deb, 24.04+).

```bash
lxc launch ubuntu:24.04 mycontainer   # create container
lxc launch ubuntu:24.04 myvm --vm     # create VM
lxc exec mycontainer -- bash           # shell into container
lxc snapshot mycontainer snap0         # snapshot
lxc restore mycontainer snap0          # restore
lxc list                               # list instances
lxc storage list                       # storage pools
```

### MicroK8s

Canonical's lightweight Kubernetes, packaged as a strict-confined snap.

```bash
snap install microk8s --classic --channel=1.32/stable
microk8s status                        # cluster status
microk8s kubectl get nodes             # standard kubectl
microk8s enable dns storage ingress    # enable add-ons
microk8s add-node                      # generate HA join token
microk8s inspect                       # diagnostic report
```

HA requires 3+ nodes with Dqlite (distributed SQLite) replacing etcd.

## Common Pitfalls

**1. Editing /etc/apt/sources.list on 24.04+ instead of deb822 .sources files**
Ubuntu 24.04 defaults to `/etc/apt/sources.list.d/ubuntu.sources` (deb822 format). The legacy `sources.list` may be empty or absent. Always check which format is in use before editing.

**2. Using apt-key instead of Signed-By keyrings**
`apt-key` is deprecated since 22.04 and removed in 24.04. Import keys with `gpg --dearmor -o /etc/apt/keyrings/<name>.gpg` and reference via `Signed-By` in the source definition.

**3. Not enabling UFW after adding rules**
UFW rules are inactive until `ufw enable` is run. Adding rules without enabling the firewall provides no protection.

**4. Ignoring snap disk accumulation**
Old snap revisions accumulate. By default, 2 revisions are kept per snap. Run `snap list --all` and remove disabled revisions to reclaim space.

**5. Running without Ubuntu Pro after 20.04 standard EOL**
Ubuntu 20.04 standard support ended April 2025. Without Pro ESM enrollment, systems receive zero security updates. Attach immediately or plan an upgrade.

**6. Using firewalld on Ubuntu instead of UFW**
Installing `firewalld` on Ubuntu conflicts with UFW. Stick with UFW unless there is a specific multi-zone requirement.

**7. Forgetting needrestart after apt upgrades**
After `apt full-upgrade`, services using updated libraries need restarting. Install and run `needrestart` to detect stale processes. Configure automatic restart in `/etc/needrestart/needrestart.conf`.

**8. Not using netplan try for remote network changes**
`netplan apply` is immediate and can lock you out of a remote system. Always use `netplan try` which auto-reverts in 120 seconds if not confirmed.

**9. Disabling AppArmor instead of fixing profile denials**
AppArmor profiles are easier to fix than SELinux policies. Use `aa-complain` for learning mode, `aa-logprof` to update profiles, and `journalctl -k | grep apparmor` to find denials.

**10. Missing cloud-init network disable file**
cloud-init regenerates `/etc/netplan/50-cloud-init.yaml` on each boot. Manual netplan edits are overwritten unless cloud-init network config is disabled via `/etc/cloud/cloud.cfg.d/99-disable-network-config.cfg`.

## Version-Specific Guidance

| Version | Reference | What's version-specific |
|---|---|---|
| 20.04 | `references/versions/20.04.md` | ZFS root (zsys), WireGuard in-kernel, snap matured, LXD 4.0, ESM-only migration, Multipass, cloud-init v2 network |
| 22.04 | `references/versions/22.04.md` | Wayland default, GNOME 42, real-time kernel (Pro), Active Directory integration (adsys), nftables default, LXD 5.0, OpenSSL 3.0 |
| 24.04 | `references/versions/24.04.md` | Netplan 1.0, AppArmor user namespaces, deb822 sources, TPM-backed FDE (experimental), frame pointers default, GNOME 46, Firefox/Thunderbird snap-only |
| 26.04 | `references/versions/26.04.md` | Kernel 7.0, GNOME 50 Wayland-only, dracut (replaces initramfs-tools), sudo-rs, APT 3.1, cgroup v2 mandatory, Chrony (replaces timesyncd), post-quantum SSH |

## Reference Files

Load these when you need deep knowledge for a specific area:

- `references/architecture.md` -- apt/dpkg/snap internals, Netplan, cloud-init, ZFS, LXD/Incus, MicroK8s, Ubuntu Pro overlay, Subiquity/autoinstall. Read for "how does X work" questions.
- `references/diagnostics.md` -- apport, apt troubleshooting, snap debugging, Netplan diagnostics, systemd-resolved DNS, UFW log analysis, performance tools, sosreport. Read when troubleshooting errors.
- `references/best-practices.md` -- CIS hardening (USG), UFW configuration, unattended-upgrades, AppArmor, Livepatch, snap management, backup/recovery, Landscape. Read for design and operations questions.
- `references/editions.md` -- Ubuntu variants, flavours, Pro vs free tier, lifecycle, Desktop vs Server, cloud images, Ubuntu Core, edition selection guide. Read for edition and licensing questions.

Files in this skill

  • SKILL.md13.8 KB
  • references/architecture.md11.8 KB
  • references/best-practices.md7.5 KB
  • references/diagnostics.md7.2 KB
  • references/editions.md6.2 KB
  • references/versions/20.04.md6.1 KB
  • references/versions/22.04.md6.9 KB
  • references/versions/24.04.md6.9 KB
  • references/versions/26.04.md8.5 KB
  • scripts/01-system-health.sh3.4 KB
  • scripts/02-performance-baseline.sh2.7 KB
  • scripts/03-journal-analysis.sh2.8 KB
  • scripts/04-storage-health.sh3.3 KB
  • scripts/05-network-diagnostics.sh3.2 KB
  • scripts/06-security-audit.sh4 KB
  • scripts/07-package-audit.sh3.6 KB
  • scripts/08-livepatch-status.sh3.5 KB
  • scripts/09-service-health.sh3.9 KB
  • scripts/versions/20.04/10-eol-readiness.sh5.8 KB
  • scripts/versions/22.04/10-ad-integration.sh7.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…