apt to dnf command cheat sheet for Linux
Make you no confuse again. See di exact dnf command wey match your apt habits for Rocky, AlmaLinux and Fedora. We cover package install, repo updates and rollback.
Di short answer
To move from apt go dnf na mostly change of vocabulary. apt install nginx go turn to dnf install nginx. apt remove nginx go turn to dnf remove nginx. apt update no get direct replacement, because dnf dey refresh im repository metadata by imself once di cached copy don old. Di easy part of di translation no reach one screen. Di useful part na di four operations wey no get match at all: adding repository, undoing transaction, installing package group, and running unattended updates.
Every command wey dey below, you fit run am for your own server. Read di transaction summary wey dnf print before you answer y, especially when you wan remove something.
Which distros dey use dnf, and which one dey use apt
dnf na di package manager wey Fedora, Red Hat Enterprise Linux (RHEL), and all di RHEL rebuilds like Rocky Linux, AlmaLinux, and CentOS Stream dey use. apt na di package manager for Debian and all di oda operating systems wey come from Debian, wey for VPS matter, almost always mean Ubuntu. No third answer dey. If your provider image list get Rocky Linux or AlmaLinux, na dnf you go use. If e get Ubuntu, na apt you go use. Di reason why one side of this divide get four different names for wetin be mostly di same system na story wey you suppose know before you choose between dem, and how Red Hat Linux become Fedora, RHEL, CentOS, Rocky and AlmaLinux explain where each one come from.
Di package format dey follow di tool. dnf dey install .rpm files and im database na rpm. apt dey install .deb files and im database na dpkg. Na dat one make plenty vendor install pages get separate tab for each family, and na why .deb wey you download from project release page no go work for Rocky Linux.
Any family wey you land, di first login work na di same. Di first ten minutes for new VPS apply to both. Na only di install command dey change.
Every apt command and im dnf equivalent
Install, remove, search and show. These ones get almost the same words for both sides.
# apt
sudo apt install nginx
sudo apt remove nginx
apt search nginx
apt show nginx
# dnf
sudo dnf install nginx
sudo dnf remove nginx
dnf search nginx
dnf info nginxapt show na dnf info. Na only that one dem change name for this group, but one behaviour dey different wey dey confuse pipo. dnf remove dey remove dependencies wey nothing else need, while apt remove dey leave dem make you fit use am for later apt autoremove. So if you remove one small utility for Rocky Linux, e fit suggest say e go carry dozen libraries join am go. Read the list before you confirm.
Refresh metadata, check wetin dey wait, and upgrade.
# apt
sudo apt update
apt list --upgradable
sudo apt install --only-upgrade nginx
sudo apt upgrade
# dnf
sudo dnf makecache
dnf check-update
sudo dnf upgrade nginx
sudo dnf upgradeapt update na must for apt side, because apt dey use any metadata wey dey disk and e go happy install version wey don comot for archive since months ago. dnf dey check im cache age before every transaction and e dey download fresh metadata by imself, so sudo dnf makecache na only to force that download make e happen now instead of when you wan install something next time.
apt dey split the whole system upgrade into two, but dnf no dey do like that. apt upgrade no go gree remove any installed package, so e go stop if update need make one package comot. apt full-upgrade na the version wey dem allow make e remove. dnf no get that kind restriction, wey mean say dnf upgrade na the equivalent of apt full-upgrade, no be apt upgrade. dnf update na old alias for the same command and e still dey work.
One detail dey matter if you dey write script: dnf check-update dey exit with status 100 when updates dey wait and 0 when nothing dey. apt list --upgradable dey exit 0 for both cases, so scripts must check the output.
List wetin you don install, and find out which package get one file.
# apt
dpkg -l
dpkg -S /usr/sbin/nginx
dpkg -L nginx
apt-file search /usr/sbin/nginx
# dnf
dnf list --installed
rpm -qf /usr/sbin/nginx
rpm -ql nginx
dnf provides /usr/sbin/nginxThe last line for each block dey answer different question from the ones wey dey above am. dpkg -S and rpm -qf dey search only packages wey you don already install, so dem dey answer "wetin put this file here". apt-file search and dnf provides dey search the repositories, so dem dey answer "wetin I go install to get this file". apt-file na separate package for Ubuntu and e need sudo apt-file update before you fit run am first time. dnf provides no need anything extra, though the first run fit slow because dnf dey download repository file lists to answer.
To list the files inside one package wey you never install, use dnf repoquery -l nginx. For apt side, that one na apt-file list nginx.
Autoremove, clean the cache, hold a version.
# apt
sudo apt autoremove
sudo apt clean
sudo apt-mark hold nginx
apt-mark showhold
sudo apt-mark unhold nginx
# dnf
sudo dnf autoremove
sudo dnf clean all
sudo dnf versionlock add nginx
dnf versionlock list
sudo dnf versionlock delete nginxversionlock no dey installed by default for Rocky Linux or AlmaLinux, so the first one for those lines go fail with No such command: versionlock for fresh box. Install am first with sudo dnf install python3-dnf-plugin-versionlock. apt no need anything extra for apt-mark hold, because hold na dpkg state, no be plugin.
Where the mapping breaks: adding a repository
Dis na the part wey dey make Ubuntu admins dey find command wey no exist. No add-apt-repository for dnf, and no personal package archives (PPAs) dey. PPA na service wey Launchpad dey run, and Launchpad na Ubuntu infrastructure. Nothing for the RPM world dey host one.
Wetin dnf get instead na one plain text file per repository for inside /etc/yum.repos.d/, wey dey end with .repo.
[docker-ce-stable]
name=Docker CE Stable
baseurl=https://download.docker.com/linux/centos/$releasever/$basearch/stable
enabled=1
gpgcheck=1
gpgkey=https://download.docker.com/linux/centos/gpg$releasever and $basearch na dnf variables. dnf dey put your major release number and your CPU architecture inside when e dey run, so the same file go work for version 9 and version 10, and for x86_64 and aarch64.
Most vendors dey publish that file and tell you make you fetch am. Docker own instructions for RHEL and im rebuilds na two commands:
sudo dnf -y install dnf-plugins-core
sudo dnf config-manager --add-repo https://download.docker.com/linux/rhel/docker-ce.repoThe first line dey there because config-manager na plugin, e no be part of dnf itself. If you skip am, the second line go fail with No such command: config-manager. Nothing stop you from downloading that same .repo file with curl go inside /etc/yum.repos.d/ by yourself, and the result go be the same. Installing Docker on a VPS show how to do the Debian side of the same work, where the equivalent step dey write a source list and a signing key go two different directories.
The difference for layout na wetin dey decide where you go look if repository start to misbehave. apt dey keep definitions for /etc/apt/sources.list and /etc/apt/sources.list.d/, with signing keys wey dem keep separately under /etc/apt/keyrings/. dnf dey keep everything for /etc/yum.repos.d/, and the key na URL inside the .repo file, so na one file you go read and one file you go delete. Newer apt don move go the same shape with the deb822 format, one .sources file per repository. If you don jam the deb822 duplicate sources error on Ubuntu, you don already meet the apt half of this problem.
EPEL na di archive wey most guide dey assume
Extra Packages for Enterprise Linux (EPEL) na Fedora project wey dey build Fedora packages for RHEL and di oda versions wey dem build from am. E be like di closest tin wey we get to universal PPA for dis world, and plenty tutorials dey assume say e don dey enabled already. If dnf install answer No match for argument for package wey you fit see for di project website, EPEL na di first tin wey you suppose check.
For Rocky Linux and AlmaLinux:
sudo dnf config-manager --set-enabled crb
sudo dnf install epel-release
sudo dnf makecacheCRB na CodeReady Builder, one repository of libraries wey dey come with di distribution but dem no dey enable am by default. Most EPEL packages dey depend on one or two tins inside am, so if you enable EPEL without CRB, e no go fail dat moment. E go fail later, wen you wan install, wit unresolved dependencies for package wey you never even hear of before. Enable CRB first and dat kain error go disappear.
For RHEL itself, CRB dey come through your subscription instead of config-manager, so follow Red Hat own EPEL instructions for dat step. Fedora no need all dis one, because im main repository already get wetin EPEL dey backport. EPEL policy be say dem no go ever replace package wey RHEL dey ship, so if you add di repository, e no go change any tin wey you don install for your server already.
dnf history undo, di tin wey apt no fit do
dnf dey record every transaction, and e fit build di opposite of one.
sudo dnf history
sudo dnf history info 42
sudo dnf history undo 42dnf history dey print numbered list of transactions wit di command line wey start each one. undo dey construct di opposite transaction: packages wey dat transaction install go comot, and packages wey e upgrade go go back to di version wey you bin get before. Dis na di feature wey apt users dey miss pass when dem switch.
E get limits, and e good make you know dem before you rely on am. undo fit only reinstall package version wey still dey inside enabled repository, so once dem comot di old build from di mirror, di undo go fail wit not-found error. Rollback sef dey stop for package database. Config file wey upgrade rewrite go still dey rewritten, and database schema wey service migrate for first start go still dey migrated. dnf dey put di files back. E no dey put your data back.
apt no get anytin wey be like dis. /var/log/apt/history.log dey record exactly wetin happen, including di command line, but to read log no mean say you don undo am. Recovery for apt side na manual work: run apt list -a nginx to see which versions di archive still get, den sudo apt install nginx=<exact version string> to pin one, and add sudo apt-mark hold nginx so di next upgrade no go undo your fix.
Apt no get wetin be package groups
dnf fit install set of packages wey get name with one command.
dnf group list
dnf group info "Development Tools"
sudo dnf group install "Development Tools"Old guides dey write dnf groupinstall "Development Tools". Dat alias dey work for dnf 4 but e don commot for dnf 5, so na only the two-word dnf group install be the correct spelling wey go work everywhere. Use am and no worry your head again.
apt no get groups. Wetin Debian get wey near am na metapackage, e be empty package wey just get list of dependencies inside, like build-essential. The main difference be say: if you remove metapackage, the dependencies go still dey installed until you run apt autoremove, but dnf group remove go commot the group packages join am for the same transaction.
unattended-upgrades and dnf-automatic
Both families get way to install updates even if nobody dey login. The tools no share anything except the purpose.
For Ubuntu and Debian, the package na unattended-upgrades, wey you go configure for /etc/apt/apt.conf.d/50unattended-upgrades, where you go list the origins wey e fit pull updates from. Setting up unattended upgrades on Ubuntu explain that config file and the matter of reboot wey dey follow am.
For Rocky Linux, AlmaLinux and Fedora, the package na dnf-automatic, and the systemd timer wey you enable na im go decide how the thing go behave.
sudo dnf install dnf-automatic
sudo systemctl enable --now dnf-automatic-install.timer
systemctl list-timers 'dnf-automatic*'dnf-automatic-install.timer dey download and apply updates. dnf-automatic-download.timer dey download dem come stop, make you be the one to install am. dnf-automatic-notifyonly.timer na only report e dey give. Each of those units dey override the apply_updates setting for /etc/dnf/automatic.conf, so the timer wey you choose important pass wetin the config file talk. To install update no mean say the old code wey dey run go restart automatically, so e good make you check which of those updates need a reboot and which one only need service restart before you assume say the box don patch finish.
To restrict am to security fixes only, set upgrade_type = security for /etc/dnf/automatic.conf. That filter depend on whether your repositories dey publish security errata, so check first with dnf updateinfo list security. If you get empty result for box wey get pending updates, e mean say the metadata no dey, and security no go install anything at all.
For Fedora, dnf 5 change the unit name. E don turn to dnf5-automatic.timer, and e dey read the same /etc/dnf/automatic.conf.
Yum still be real command?
Yes, and e no dey do anything by imsef. For Rocky Linux, AlmaLinux and CentOS Stream, /usr/bin/yum na symbolic link wey point go dnf. Check your own:
ls -l /usr/bin/yum
dnf --versionOld yum syntax still dey show for tutorials sake of say most of am still dey work direct. yum install, yum remove and yum update all dey work. One habit wey you suppose stop: yum-config-manager still dey as im own binary for dnf 4 systems, but dnf config-manager na the spelling wey current documentation dey use, and na that one go still dey work when the box move go dnf 5.
dnf 4 and dnf 5: check before you copy a command
dnf 5 na rewrite, and e change how dem dey spell plenty command. Fedora 41 and versions wey come after am dey use dnf. Enterprise rebuilds dey slow to switch, so no guess based on distribution name. Run dnf --version for your server and check the first line, because that number go tell you which syntax you suppose use from the ones wey dey below.
The best example na Docker, wey get different repository command for each one. For RHEL and im rebuilds, if you dey use dnf 4:
sudo dnf config-manager --add-repo https://download.docker.com/linux/rhel/docker-ce.repoFor Fedora, if you dey use dnf 5:
sudo dnf config-manager addrepo --from-repofile https://download.docker.com/linux/fedora/docker-ce.repoSame vendor, same work, different words. dnf 5 change config-manager make am be tool wey dey use subcommand, so the old --add-repo flag no go work again and you go see usage error instead of repository. Another one wey you go see na how to enable repository: dnf config-manager --set-enabled crb for dnf 4 don turn to dnf config-manager setopt crb.enabled=1 for dnf 5.
The choice wey actually matter
To pick server distribution based on package manager alone na wrong way to reason. dnf and apt dey do the same work, and you fit learn the vocabulary for one afternoon. Wetin go change your year na the release model wey dey behind the repository. Fedora dey move fast and any release go stop to dey get updates roughly thirteen months after e show, wey dey okay for workstation but e dey pain for server wey you no want rebuild. Rocky Linux and AlmaLinux dey follow RHEL, so you go get ten year support window and package versions wey dey stay one place intentionally. Ubuntu get both types, and the difference between Ubuntu LTS and interim releases for server na the same decision wey you go make inside the apt world.
As of August 2026, all these ones na ordinary VPS images. Pick the support window wey you want, then learn the ten commands wey dey up so.
FAQ
Wetin be the dnf equivalent of apt update?
No command dey wey you must run. dnf dey check how old e cached metadata be before every transaction and e go download fresh copy once e don expire, so dnf install for server wey you never touch for one month still go see current packages. sudo dnf makecache dey and e dey force that download, but e real work na to move the delay go time wey you choose instead of make e happen for your next install. The command wey answer "wetin dey wait me" na dnf check-update, wey map go apt list --upgradable and e dey exit with status 100 when updates dey available.
PPA equivalent dey for Rocky Linux or Fedora?
No. Personal package archives na Launchpad service and Launchpad na Ubuntu infrastructure, so add-apt-repository no get anything wey e go translate go. The RPM equivalent na .repo file for inside /etc/yum.repos.d/ wey hold name, baseurl and gpgkey. Vendors dey publish that file for you, and sudo dnf config-manager --add-repo <url> for dnf 4, or sudo dnf config-manager addrepo --from-repofile <url> for dnf 5, go download am put for place. For general extra software, the answer usually na EPEL, wey you go enable with sudo dnf config-manager --set-enabled crb follow by sudo dnf install epel-release.
I fit undo dnf upgrade wey break my server?
Yes, but e get limit. Run sudo dnf history to find the transaction number, sudo dnf history info <id> to see wetin exactly e change, then sudo dnf history undo <id>. The undo go fail if the old package version no dey again for any enabled repository, because dnf no go get anything to reinstall from. E only dey reverse package changes. Configuration file wey upgrade rewrite, or database wey service migrate for first start, go remain as e be. apt no get any equivalent command at all, only the record for /var/log/apt/history.log.
yum still dey work for Rocky Linux and AlmaLinux?
E dey work because /usr/bin/yum na symbolic link to dnf. Confirm am for your own box with ls -l /usr/bin/yum. If you type yum install httpd, e go run dnf, so old tutorials mostly still dey work. Write new scripts and documentation with dnf, because the yum name na just for compatibility, and prefer dnf config-manager pass the older yum-config-manager binary.
Why dnf remove want delete plenty packages?
Because dnf dey remove dependencies wey nothing else need as part of the same transaction, while apt remove dey leave dem installed until you run apt autoremove separately. So removal wey look small for Ubuntu fit print long list for Rocky Linux. The list usually correct, but read am before you confirm. If package wey dey the list na one wey you want keep, install am explicitly first so dnf go record am as something wey you want for yourself.