Debian 11 end of life: upgrade your server
Debian 11 bullseye lost LTS security support on 31 August 2026. Confirm your version, then upgrade in two careful hops to Debian 13 before apt stops working.
Is Debian 11 end of life?
Yes. Debian 11 "bullseye" reached the end of its Debian Long Term Support (LTS) period on 2026-08-31, as the Debian LTS wiki page lists. The Debian LTS team no longer publishes security fixes for it. A server still on Debian 11 should move to Debian 13 "trixie" in two upgrade hops, or be rebuilt on a fresh Debian 13 image. Freexian's paid Extended LTS can cover the gap while you plan.
Debian 11 end of life matters most for servers that face the internet. A new flaw in OpenSSL or OpenSSH now gets a fix for Debian 12 and 13, and no fix for 11. Nothing stopped working on 2026-09-01. The packages still run. The risk grows each week, because the list of unfixed issues only gets longer. To see that list for your own box, scan your server for known CVEs before and after the upgrade.
How to confirm the server runs Debian 11
Two files answer the question. Both exist on every Debian install.
cat /etc/debian_version
grep -E '^(VERSION_ID|VERSION_CODENAME)=' /etc/os-releaseOn Debian 11, the first command prints a number that starts with 11.. The part after the dot counts point releases. A point release is a bundled update of a stable release, with security fixes and important bug fixes. The second command should print VERSION_ID="11" and VERSION_CODENAME=bullseye. Each Debian release has a codename, and apt uses the codename in its sources, so bullseye is the word to look for next.
Now find every package source that names the old release:
grep -rn bullseye /etc/apt/sources.list /etc/apt/sources.list.d/Each line it prints is a source that apt reads. Most point at Debian. Some may point at a third party, such as Docker, PostgreSQL, Nginx or Node.js. Write those down. They are not part of Debian, so the Debian upgrade does not move them, and you will handle them one by one.
Why apt stops working on an end-of-life release
The main Debian mirrors, such as deb.debian.org, carry the releases Debian still supports. Some time after a release ends, its suites are removed from the main mirrors and kept on archive.debian.org instead. A suite is the name apt uses for one set of packages, such as bullseye, bullseye-updates or bullseye-security.
Once a suite is gone from the mirror, apt update fails for that suite, because the mirror no longer has its index files. After that, you cannot install any package from it, not even a small tool you need for the upgrade itself. Pointing apt at the archive makes installs work again. The archive is frozen, though. It receives no new security fixes.
The timing is not settled. As of late September 2026, when the bullseye-security suite would move to the archive was still an open question, and Debian's archive page did not yet list bullseye. Do not plan around a date from a forum post. Upgrade while apt update still works, because the first hop is easiest when you can still pull the last bullseye packages before you leave. If apt update already fails for you, take the sources lines from Debian's archive page, not from memory or from an old blog post.
Upgrade, rebuild, or buy time with ELTS
Upgrade in place. You keep the same server, the same IP address and the same data. This suits a box that was configured by hand over years, where moving everything would take longer than the upgrade. The cost is risk: an old server carries old leftovers, and the upgrade has to deal with all of them.
Rebuild on a fresh Debian 13 image. You start clean and copy data and configuration across. This suits a server whose setup lives in a script or in Ansible, or a box that has drifted so far that nobody knows what is on it. The same reasoning applies as for Ubuntu, and deciding whether to upgrade or reinstall a server walks through it. If you rebuild, this is also a good moment to ask whether Debian is still the right base, and choosing an OS for your VPS compares the options.
Buy time with Freexian ELTS. Extended Long Term Support (ELTS) is a commercial service from Freexian. It continues security updates for Debian 11 until 2031-06-30, from a separate package repository with its own signing key and sources lines. Coverage and price are Freexian's to define, so read their ELTS page and the ELTS documentation for the exact setup. ELTS moves the deadline. The server still has to reach a newer release in the end.
Why the upgrade is two hops, and 12 is not the finish line
Debian supports upgrades from one release to the next release only. The Debian 12 release notes describe upgrading from 11. The Debian 13 release notes describe upgrading from 12. Nobody tests a jump from 11 straight to 13, which means package install scripts may meet a state they were never written for.
Stopping at Debian 12 is a short stop. Debian 12 "bookworm" moved from regular security support into LTS on 2026-06-11, and the LTS wiki page lists its end as 2028-06-30. Stop at 12 and you repeat this job in under two years. Do both hops in one maintenance window, or in two windows a few days apart. For the background on how packages flow between Debian's branches, see which Debian branch a server should track.
Before each hop: snapshot, read, check
Take a provider snapshot. A snapshot is a point-in-time copy of the whole disk, taken by your VPS provider from outside the server. If the upgrade breaks the boot, you can restore it in minutes. A snapshot usually lives on the same platform as the server, so it does not replace a backup kept somewhere else. The difference between VPS snapshots and backups explains when each one saves you. Take a fresh snapshot before hop two as well, so a failure there does not send you back to Debian 11.
Read the release notes for the release you are moving to: upgrading from Debian 11 to 12 and upgrading from Debian 12 to 13. Each set of notes also has a chapter of known issues for that release. This guide does not copy those lists. They are long, and the notes are the source.
Test the console. Most providers offer a web console (VNC or serial) in their control panel. Open it once and log in before you start, so you know your password works there. If networking does not come back after a reboot, that console is the only way in.
Check the package system. These checks come from the release notes:
sudo dpkg --audit
sudo apt-mark showhold
apt list '?narrow(?installed, ?not(?origin(Debian)))'
df -h / /boot /vardpkg --audit should print nothing. Any output means a package is half-installed or half-configured. Run sudo dpkg --configure -a and check again. apt-mark showhold lists packages pinned at their current version. A held package blocks the upgrade of everything that depends on it, so release any hold you no longer need with sudo apt-mark unhold <package>. The apt list pattern prints installed packages that did not come from Debian, either from a third-party repository or from a .deb file installed by hand. df shows free space. The upgrade downloads and unpacks many packages into /var, and a new kernel lands in /boot, so both need room.
Hop one: upgrade Debian 11 to Debian 12
First, bring bullseye up to its latest point release while its mirrors still answer:
sudo apt update
sudo apt full-upgradeReboot if that installed a new kernel. Then start a terminal session that survives a dropped SSH connection, open a root shell, and record everything, as the release notes suggest:
sudo apt install -y tmux
tmux new -s upgrade
sudo -i
script -t 2>/root/upgrade-bookworm.time -a /root/upgrade-bookworm.scriptIf SSH drops, log back in and run tmux attach -t upgrade. The upgrade keeps running inside tmux while you are away. script writes the whole session to /root/upgrade-bookworm.script, which is what you read later if something went wrong.
Edit the sources. A Debian 11 server normally keeps them in one-line format in /etc/apt/sources.list. Keep a copy, change the codename, then look for anything left:
cp /etc/apt/sources.list /root/sources.list.bullseye
sed -i 's/bullseye/bookworm/g' /etc/apt/sources.list
grep -rn bullseye /etc/apt/sources.list /etc/apt/sources.list.d/The sed line rewrites bullseye, bullseye-updates and bullseye-security in one pass. If the last grep still shows a Debian source in sources.list.d, edit that file the same way. For each third-party source, check the vendor's own documentation for a bookworm repository. If there is none yet, rename the file so it no longer ends in .list, because apt reads only .list and .sources files in that directory. Then compare your Debian lines with the example lines in the release notes. Debian 12 added a separate non-free-firmware component, and the notes say to add it if the system has non-free firmware installed. A KVM VPS seldom does.
Now run the two-step upgrade from the release notes:
apt update
apt upgrade --without-new-pkgs
apt full-upgradeThe order matters. apt upgrade --without-new-pkgs upgrades what it can without installing new packages or removing any, so the base system moves first, with the smallest changes. apt full-upgrade then does the rest. It may install new dependencies and remove packages that conflict. Read its list of removals before you answer yes. If it wants to remove something you need, such as your web server or database, stop and find out why. The cause is usually a held package or a third-party repository.
The upgrade asks questions. A configuration file prompt appears when you changed a file, such as /etc/ssh/sshd_config, and the new package ships a different version of it. Keeping your version is the safe default. The prompt has an option to show the difference, so you can see what the new default changed. Note each file name, and review it after the upgrade. A question about restarting services during library upgrades is also common. Answering yes saves you a long series of separate prompts.
Reboot, then check the result:
systemctl rebootcat /etc/debian_version
uname -r
systemctl --failed/etc/debian_version should now start with 12.. uname -r should show a 6.1 series kernel, which is the bookworm kernel. systemctl --failed should list zero units. A failed unit after an upgrade usually means the new version rejects an old configuration file, and journalctl -u <unit> -b shows the reason.
Clean up the leftovers, again from the release notes:
sudo apt purge '~c'
apt list '~o'The ~c pattern matches packages that were removed but left their configuration files behind. The ~o pattern lists obsolete packages: installed packages that no configured source carries any more. Review that list before you purge anything from it, because a package you installed by hand from a .deb file also appears there. Then test the things the server is for: websites, databases, cron jobs, backups. Take a new snapshot once they work.
Hop two: upgrade Debian 12 to Debian 13
The second hop is the same procedure with new names. The trixie release notes ask you to start from the latest bookworm point release, so begin with sudo apt update and sudo apt full-upgrade, and reboot if a kernel arrived.
Start a new tmux session and record it to /root/upgrade-trixie.script. Then find the bookworm sources and change them:
grep -rn bookworm /etc/apt/sources.list /etc/apt/sources.list.d/
cp /etc/apt/sources.list /root/sources.list.bookworm
sed -i 's/bookworm/trixie/g' /etc/apt/sources.listIf your Debian sources live in a .sources file instead, the codenames sit on its Suites: line. Edit that file the same way. Check every third-party source for a trixie repository, exactly as in hop one.
Then run the same three commands: apt update, apt upgrade --without-new-pkgs, apt full-upgrade. Answer the prompts with the same care, reboot, and confirm that /etc/debian_version starts with 13. and that /etc/os-release shows VERSION_CODENAME=trixie.
The Debian 13 release notes describe sources in the deb822 format, which uses .sources files in /etc/apt/sources.list.d/ in place of one-line entries. They also describe an optional apt modernize-sources command that converts the old format after the upgrade. Read that section before you run it. If you convert by hand, make sure the same repository does not end up in both formats, because apt then warns about duplicate sources. Fixing apt duplicate source warnings after a deb822 conversion explains why that happens and how to clean it up.
Keep security updates arriving after the upgrade
Debian 13 helps only if its security updates actually install. Many servers rely on unattended-upgrades for that. Check that it ran after the upgrade, and read its log in /var/log/unattended-upgrades/. If it has gone quiet, why Debian unattended upgrades stop running covers the usual causes. Also run apt list --upgradable now and then, to see what is waiting.
What to do when the upgrade goes wrong
apt update fails for one source. This is almost always a third-party repository that has no suite for the new release yet. Rename its file in sources.list.d so apt skips it, and add it back when the vendor publishes the new suite.
The upgrade stopped halfway. A dropped connection outside tmux, or a full disk, can interrupt dpkg. Free space if needed, then run dpkg --configure -a followed by apt full-upgrade again. Both commands pick up where the last run stopped.
The server does not come back on the network. Log in through the provider console. Run ip a to see whether the interface is up and has its address, and journalctl -b -p err to see errors from this boot. If you cannot find the cause quickly, restore the snapshot you took before the hop. You lose only the time spent, and you can try again with what you learned.
FAQ
Is Debian 11 still getting security updates?
Not from Debian. Debian 11 "bullseye" left Debian LTS on 2026-08-31, according to the Debian LTS wiki page. Freexian's commercial Extended LTS continues security updates for it until 2031-06-30, from a separate repository you have to configure. Without ELTS, any new flaw found after that date stays unfixed on Debian 11.
Can I upgrade directly from Debian 11 to Debian 13?
No. Debian supports upgrades from one release to the next only. Upgrade from 11 to 12 first, reboot and check the system, then upgrade from 12 to 13. Take a provider snapshot before each hop, and follow each release's own release notes, because each set of notes covers only the upgrade from the release before it.
How do I check which Debian version my server is running?
Run cat /etc/debian_version, which prints a version number such as one starting with 11. or 12.. Then run grep VERSION_CODENAME /etc/os-release, which prints the codename that apt uses, such as bullseye, bookworm or trixie. Both files exist on every Debian system.
Is it enough to upgrade to Debian 12 and stop there?
It buys little time. Debian 12 "bookworm" moved into LTS on 2026-06-11, and its LTS period is listed to end on 2028-06-30. If you stop at 12, you repeat the whole job in under two years. Most servers should continue to Debian 13 in the same maintenance window, or a few days later.
Why does apt update fail on my Debian 11 server?
Old releases are removed from the main Debian mirrors some time after support ends and kept on archive.debian.org. Once a suite is gone from the mirror, apt update can no longer fetch its index files. The archive works for installs but receives no new security fixes. Use the sources lines from Debian's archive page, then upgrade to a supported release.