Operate Snaps Safely with snap: Install, Refresh, Inspect and Recover
By the end of this guide you will be able to inspect installed snaps, install one with its confinement understood, check what refreshes will do, and recover from a problematic revision. The examples use the snap client from snapd 2.76.3+ubuntu24.04, installed on Ubuntu 24.04 in the reference environment. Allow about 10 minutes, plus download time.
The route
Jump straight to the step you need, or tick off Done means at the end.
Before you change anything
You need a shell on a machine running snapd. Reading information normally needs no elevated privileges. Installing, refreshing, removing, changing configuration, and changing interfaces normally need sudo. If the command says that snapd is not running, check the service with your distribution's service manager before retrying.
A snap tracks a channel, normally stable, and is installed with strict confinement unless you explicitly select another mode. Do not copy --classic, --devmode, or --dangerous just to make an installation succeed: each changes the security boundary. A classic snap has wider access, devmode relaxes confinement, and a dangerous local snap has not been verified through the normal assertion path.
1. Establish the current state
Start with the client and server versions, then list installed snaps. This avoids guessing which commands or revisions are present on the host.
snap version
snap list
On the reference machine the first command reports client and server version 2.76.3+ubuntu24.04, series 16, Ubuntu 24.04, and kernel 6.8.0-139-generic. Your versions may differ. In the list, Tracking is the channel, Rev is the installed revision, and Notes can identify a base snap.
Checkpoint
You have recorded the snap name and revision you care about. Use that exact name in later commands; do not confuse a snap's version string with its revision number.
2. Inspect a snap before installing it
Use snap find to search the store, then snap info to inspect a candidate. The info output includes available channels and confinement details.
snap find hello-world
snap info hello-world
Read the publisher, channels, revision, and confinement in the output. Store search results are not a substitute for checking that the name and publisher are the ones you intended. If you only need to inspect an installed snap, snap info NAME also accepts its name without installing anything.
3. Install one snap deliberately
Warning
Installation changes the system and may add services, commands, interfaces, and automatic refresh behaviour. Substitute a snap name you have checked in the previous step.
sudo snap install hello-world
snap list hello-world
snap run hello-world
With no channel option, installation follows stable. The final command runs the snap through its confinement and environment rather than bypassing the snap launcher. Some snaps expose a different application command from their snap name; use the apps section of snap info NAME to find it.
To undo this particular example, remove the named snap after confirming it is not needed:
sudo snap remove hello-world
snap list hello-world
Removal normally saves a snapshot of the snap's data. The second command should report that the snap is not installed. Do not add --purge unless you intentionally want removal without that automatic snapshot.
4. Preview and perform refreshes
Refreshes update named snaps, or every installed snap when no name is supplied. Preview the next changes before applying them.
snap refresh --list
sudo snap refresh
If the preview says all snaps are up to date, the refresh is unlikely to have work to do. To refresh one snap only, provide its name: sudo snap refresh NAME. A revision selected with --revision is typically temporary because a later refresh returns the snap to the current revision of its tracked channel.
A hold affects automatic refreshes when no snap names are supplied. It does not block a general snap refresh request in that form. When names are supplied, the hold also affects general refresh requests for those snaps, but a specifically named refresh can still proceed. Keep holds short and visible:
sudo snap refresh --hold=24h
snap refresh --time
sudo snap refresh --unhold
The last command removes the refresh hold. If an operation is asynchronous or you used --no-wait, note its change ID and inspect it with snap watch CHANGE_ID.
5. Diagnose services and connections
Snaps can provide background services. List their current and startup state before restarting or disabling anything.
snap services
snap services SNAP_NAME
As root, the service status columns have special rules for user services: use --user to see the invoking root user's status, or --global when you need global enablement. Starting, stopping, enabling, disabling, or restarting a service changes live system behaviour, so identify the exact service first. For example, the reversible form is sudo snap stop SNAP_NAME.SERVICE_NAME; start it again with sudo snap start SNAP_NAME.SERVICE_NAME.
Interfaces control connections between a snap's plugs and slots. Inspect them before granting access:
snap connections SNAP_NAME
snap connections SNAP_NAME --all
Connecting an interface can grant access to hardware, files, the network, or system services. Treat sudo snap connect SNAP:PLUG SLOT as a security-sensitive change. If you made a manual connection by mistake, disconnect the same plug and slot with sudo snap disconnect SNAP:PLUG SLOT. The --forget option also clears remembered state, which can allow an automatic connection to return after a refresh.
6. Recover from a failed refresh
First inspect recent changes rather than repeating the failed command.
snap changes
snap tasks CHANGE_ID
snap watch CHANGE_ID
Use the change ID from snap changes. tasks shows which part failed; watch waits for a change that is still running. If a pending change is safe to abandon, abort the last matching change only after checking its identity:
sudo snap abort --last=refresh?
The question mark means do nothing if no matching change exists; quote it if your shell treats it as a wildcard. For a snap that worked before its latest refresh, revert it:
sudo snap revert SNAP_NAME
snap list SNAP_NAME
Revert reactivates the previous revision and discards data changes belonging only to the latest revision. Data deliberately shared across revisions is not changed. Check the application's own recovery procedure before reverting a stateful service, and plan a later refresh once the cause is understood.
7. Protect configuration with snapshots
For a planned change, save snap data first. With no snap name, save includes all snaps and all users, so name the snap when a narrow backup is enough.
sudo snap save SNAP_NAME
snap saved
Record the snapshot ID from snap saved. A restore replaces the included user, system, and configuration data with the saved data; it is not a harmless preview.
sudo snap restore SNAPSHOT_ID
snap saved --id SNAPSHOT_ID
Use snap check-snapshot SNAPSHOT_ID to verify integrity before relying on a snapshot. Delete a snapshot only when you accept that the operation cannot be undone: sudo snap forget SNAPSHOT_ID.
Done means
- You confirmed the snapd client and server versions.
- You checked the publisher, channel, revision, and confinement before installation.
- You previewed refreshes and know how to remove a hold.
- You inspected service status and interface connections before changing access.
- You can trace a change ID, abort a pending operation, revert a refresh, and restore a verified snapshot.
For command-specific options on this installed version, use snap help COMMAND. The local snap(8) manual is the authority for what this machine's client accepts.