cPFence v4 public beta is here.

Explore v4
Enhance CP Tutorials

How to Upgrade from Ubuntu 22.04 to 24.04: A Step-by-Step Guide

Ubuntu Upgrade conceptual feature illustration

Disclaimer

Please note that this guide is provided as-is, and we do not offer support for the upgrade process. Proceed at your own risk.

Upgrading your Ubuntu server from 22.04 to 24.04 brings a newer LTS base to your Enhance servers. This guide keeps the original step-by-step approach, with the stable upgrade command and current cPFence v4+ installation instructions.

Set aside a maintenance window and work on one server at a time. You need root or sudo access and a working hosting-provider console in case SSH drops. Check Enhance’s Ubuntu upgrade instructions and Ubuntu’s release-upgrade guidance before starting; an Ubuntu upgrade and an Enhance major-version migration are separate jobs.

Step 1: Take a Full Backup

Before you start, take a full backup of your system. A provider snapshot is useful for returning the whole server to its previous state, but keep separate website, database, mail and configuration backups outside that server too. Check that the backups are readable and that you know how to restore them through the provider console.

Arrange an application-consistent snapshot, pausing writes where your backup method requires it. Restoring an old snapshot also rolls back data written afterward, so decide how you will handle new orders, mail and database changes before reopening services. Start with a low-risk secondary server and check its services before continuing through the cluster.

Step 2: Check cPFence and Your Package Manager

The original version of this article advised uninstalling cPFence before every OS upgrade. Do not make that an automatic step for cPFence v4+: first save a settings backup, record your protection status, and check any version-specific advice with support. Uninstalling stops protection.

cpfence --status

If you still use v3, plan the cPFence migration as a separate maintenance task. Do not combine an unfinished product migration with an OS upgrade.

Next, ensure your system’s package manager is healthy. If it reports broken dependencies, review the proposed repair before accepting it:

sudo apt --fix-broken install

Resolve errors before proceeding. Check free disk space, including /boot, and leave enough room for the upgrade’s download and installation estimate.

Step 3: Update Your System

Refresh the package list, inspect available updates, then bring Ubuntu 22.04 fully up to date. Review each package summary, especially removals:

sudo apt update
sudo apt list --upgradable
sudo apt upgrade
sudo apt dist-upgrade
sudo reboot

Reconnect and check that the server and its Enhance roles are healthy before moving on. Rebooting loads an updated kernel and exposes problems while you still have a clear recovery point.

Step 4: Prepare for Stability During the Upgrade

Keep the provider console open and retain your current SSH session. The release upgrader may offer a temporary SSH service on TCP 1022. If you use it, temporarily allow that port only from your administrator IP in the existing server firewall and, separately, your hosting-provider firewall. An allow rule does not start an SSH service; test the recovery connection when the upgrader says it is available.

For an already-active UFW firewall, the narrow rule is:

sudo ufw allow from YOUR_ADMIN_IP to any port 1022 proto tcp

Replace YOUR_ADMIN_IP with your own public address. Do not enable UFW or replace another firewall configuration just for this step. Keep a note of each temporary rule so you can remove it afterward.

Step 5: Install the Upgrade Tool

Ensure the release-upgrade tool is installed:

sudo apt install update-manager-core

Check that /etc/update-manager/release-upgrades uses Prompt=lts.

Step 6: Start the Upgrade Process

Begin the stable upgrade:

sudo do-release-upgrade

Confirm that the offered destination is Ubuntu 24.04 LTS. Stay with the interactive prompts and read the changes before accepting them. If no release is offered, resolve pending updates or check Ubuntu’s upgrade availability; do not add -d to force it. That flag is for development releases, as explained in the release-upgrader manual.

Third-party repositories are normally disabled during the upgrade. Leave --allow-third-party out of this general procedure: each additional repository needs its own Ubuntu 24.04 compatibility check. When asked about replacing files under /etc/ufw, Enhance recommends keeping your existing files.

Step 7: Post-Upgrade Cleanup

After the upgrade, you may be prompted to remove old packages. Read the list first. You can postpone removal if you are unsure whether a package is still needed; do not approve removal of a hosting service simply because it appears in the cleanup list.

Step 8: Reboot

Follow the upgrader’s reboot prompt. If you deferred it, reboot after the upgrade has finished:

sudo reboot

Reconnect through SSH or the provider console and confirm the release:

cat /etc/os-release

You should see Ubuntu 24.04. A successful boot is the start of the checks, not confirmation that every hosted service works.

Step 9: Post-Upgrade Adjustments

1. Check and Update Source Lists

Inspect /etc/apt/sources.list.d/. If the upgrader saved the Enhance repository as enhance.list.distUpgrade, compare it with any existing enhance.list before restoring it. When the active file is absent and the saved file contains the expected Enhance repository, restore it:

sudo mv /etc/apt/sources.list.d/enhance.list.distUpgrade /etc/apt/sources.list.d/enhance.list

In the restored Enhance repository, change the Ubuntu suite from jammy to noble:

sudo sed -i 's/jammy/noble/g' /etc/apt/sources.list.d/enhance.list

If your server still uses Docker, review docker.list or its current .sources equivalent against Docker’s Ubuntu repository instructions. Restore only repositories you still need and that support Ubuntu 24.04. The old blanket Docker-file rename is not required on every Enhance installation.

Then refresh the package list. Fix repository errors before installing anything:

sudo apt update
sudo apt upgrade

2. Check PHP Websites

Enhance’s current upgrade procedure includes reinstalling its PHP packages after restoring the correct repository. This replaces builds for the old Ubuntu release. Check the PHP versions installed on your application server:

dpkg-query -W 'ecp-php*'

Reinstall the versions your server uses, following the current Enhance package list. For example, if this server uses PHP 8.2 and 8.3:

sudo apt install --reinstall ecp-php82 ecp-php83

The original command installed a fixed list of PHP versions and reinstalled appcd as well. Do not apply that old repair blindly to a newer Enhance installation. If a PHP site still fails, keep its error logs and ask Enhance support to identify the affected service and package.

Reboot once the package adjustments are complete, then test representative PHP websites, database connections, mail, DNS and backups for the roles on this server. Remove the temporary TCP 1022 rules only after normal SSH works. For the UFW rule above:

sudo ufw delete allow from YOUR_ADMIN_IP to any port 1022 proto tcp

Remove its separate provider-firewall rule too. If services cannot be recovered within your maintenance window, use the agreed snapshot or backup recovery plan, accounting for any writes since that backup.

Step 10: Check or Reinstall cPFence

If cPFence v4+ remained installed, start with cpfence --status. Check the license, intended protection settings and secondary-server connections in the WebUI. An OS upgrade does not itself require a fresh cPFence installation.

If you removed cPFence with support guidance, retrieve your key from the client area and reinstall as root:

bash <(curl -ks https://api.cpfence.app/v4/install.sh) -k YOUR_LICENSE_KEY

A new installation needs the -k key; without it, the installer stops before changing anything. To repair a server that already runs v4, run the installer without a key and choose Back up and reinstall, keeping settings and data:

bash <(curl -ks https://api.cpfence.app/v4/install.sh)

Follow the installation guide, read the installer’s final notices and run cpfence --status again. Confirm an Active license and the expected protection settings on each server; reinstalling can reuse retained settings. For WebUI access, the provider firewall must separately allow TCP 9095 on the main control panel server and TCP 9096 on every secondary server from the main control panel server’s IPs. cPFence manages the required server-local rules.

Conclusion

A careful upgrade is mostly preparation: reliable backups, working console access and time to check the result. Take it one server at a time, keep your recovery point until the hosted services are verified, and leave the next server for later if anything is unclear.

Happy upgrading!

Keep protection in your upgrade plan.

Explore cPFence v4+ for your Enhance servers, with malware scanning, WordPress protection and server monitoring in one WebUI.

Start your free trial →
← Back to all articles
KEEP EXPLORING
All articles