Ubiquiti releases something almost every week: UniFi OS, the Network application, Protect, Access, Talk, and firmware for each switch, access point and camera. "Update everything the moment it appears" and "never update anything" are both wrong. This is the policy we use on UniFi Care sites, and it works just as well for a house you look after yourself.
The three tiers
Security fixes: apply within days. If a release note mentions a security fix, a CVE, or "hardening", it goes on in the next maintenance window, which on managed sites is within the week. Firewalls, gateways and anything exposed to the internet first.
Official releases: apply within a month. Ordinary feature releases on the official (non-early-access) channel wait until the first point release after them, or two to three weeks, whichever is sooner. Most regressions in UniFi releases show up in the community forums within that window, and the follow-up point release fixes them. Letting other people find the bugs is a legitimate strategy.
Early access: never, on a client network. EA builds are for Ubiquiti's testers and our lab. They are not for a business that needs the phones to work on Monday.
The routine
Every update on a managed site follows the same five steps, and they are the reason updates are boring instead of stressful.
- Back up first. Settings → System → Backups → download a config backup. On a Cloud Key or Dream Machine, also confirm the automatic cloud backup ran. Thirty seconds, and it is the difference between "revert" and "rebuild".
- Read the notes. Skim the release notes for anything that touches features you use: VLANs, VPN, specific switch models, camera models. If there is a "known issues" section, read it twice.
- Gateway and application first, then devices. Update UniFi OS and the Network application on the gateway, let it settle, then update switches, then access points, then cameras. Updating devices before the controller is the classic way to get a mismatch.
- Check the things that matter. Internet up, Wi-Fi up, VPN connects, cameras recording, phones register. Five minutes with a checklist beats waiting for someone to notice.
- Note what was done. A line in the site log with version numbers. When something odd happens a week later, you will want to know whether it was the update.
Timing
Residential: a weekday morning after everyone has left, or late evening. Business: outside opening hours, never on a Friday afternoon, never the day before a holiday. Updates take five to twenty minutes of disruption depending on how many devices reboot; access points are the longest.
Automatic updates: yes or no?
UniFi can auto-update devices overnight. We enable it for device firmware on most sites (switches, access points, cameras) because those updates are low-risk and frequent, and we leave it off for the gateway and applications, which we do by hand with a backup. If you manage your own house and would rather not think about it, turning on full auto-update is a reasonable choice; you are trading a small chance of a surprise for never being behind on security fixes.
When something goes wrong
Test & Confirm (in Network 10.5 and later) will revert a change that cuts you off. For an update that misbehaves more subtly, the fix is usually the point release that follows within days. If it is worse than that, restore the backup from step one onto the previous version. That is the whole reason the backup exists.
Further reading
- UniFi release notes, all applications (Ubiquiti Community)
- Ubiquiti Help Center for backup and restore guides per device
- Our write-up of Network 10.5 and 10.6, including Test & Confirm