Home / Alt manpages / ubuntu-advantage(1)

  • ubuntu-advantage(1)
  • User command
  • linux

Manage Ubuntu Pro Services Safely with pro

One wrong flag in pro can attach, enable or disable an Ubuntu Pro service you did not mean to touch. You will finish with a checked client, a clear view of the services available to this machine, and a repeatable way to change one deliberately. The commands use pro; ua and ubuntu-advantage are installed aliases for the same client.

This guide is based on ubuntu-pro-client version 37.2ubuntu~24.04.1 and the Ubuntu Pro manpage installed here. Allow about fifteen minutes. You need an Ubuntu system with network access, the client package installed, and an Ubuntu Pro token or browser access to your account. Read-only checks do not need sudo; attaching and changing services do.

1. Check the client before changing anything

Confirm the binary, package version and command syntax. These are ordinary read-only checks:

$ command -v pro
/usr/bin/pro
$ dpkg-query -W -f='${Package} ${Version}\n' ubuntu-pro-client
ubuntu-pro-client 37.2ubuntu~24.04.1
$ pro --version
37.2ubuntu~24.04.1

If the package is missing, install it through your normal Ubuntu package-management process before continuing. Do not paste a token into a shell history, ticket or shared terminal recording.

2. Inspect the current subscription state

Run status before deciding what to do:

$ pro status

On an attached machine, the table includes SERVICE, ENTITLED, STATUS and DESCRIPTION. An enabled service is active on this machine. A disabled service may still be available to your subscription, but it is not currently configured here. On an unattached machine, status instead reports whether each service would be available after attaching.

For a script-friendly report, use an explicitly selected format:

$ pro status --format yaml
$ pro security-status --format json

Checkpoint: record the exact service name you intend to change. Use pro status --all if a beta or unavailable service is relevant, then use pro help SERVICE_NAME for its description. Do not guess a name from a marketing label.

3. Attach the machine

Skip this step if status already shows an attached subscription. The safest interactive route keeps the token out of the command line:

$ sudo pro attach

The client prints a Canonical URL and a short code. Open that URL in a browser, sign in, enter the code and choose the subscription. Leave the terminal open until the operation completes. The client may enable services selected by the subscription's defaults.

For a token-based attach, put the real token where the placeholder appears, but treat the token like a password and avoid shell history:

$ sudo pro attach 'TOKEN_FROM_UBUNTU_PRO_DASHBOARD'

Do not run that example unchanged. For automation, the manpage also supports --attach-config FILE; the file contains a token and can list services to enable. Protect it with restrictive permissions, remove it after the operation and ensure it cannot enter image layers or logs.

Checkpoint: verify the result and note that attach returns status 2 when the machine is already attached:

$ pro status
$ printf 'attach exit status: %s\n' "$?"

4. Enable one service deliberately

Enabling changes APT sources or installs service-specific components, so confirm the service and its dependencies first. ESM is a representative example:

$ pro help esm-infra
$ sudo pro enable esm-infra

For application packages, use esm-apps in the same pattern. The manpage also supports --access-only, --auto, --beta, --variant and machine-readable formats, but do not add one without a specific need. Enabling a repository can expose new package updates. Review them before applying changes:

$ pro status
$ apt list --upgradable

When you are ready to apply ordinary package updates, use your normal maintenance procedure. Enabling a service is not the same as upgrading every package.

5. Disable a service, with a recovery path

Disabling removes access to that service's packages or sources. It does not necessarily uninstall packages already installed by the service. Check the current state, then make the change:

$ pro status
$ sudo pro disable esm-infra
$ pro status

If the service was disabled by mistake, enable the same service again:

$ sudo pro enable esm-infra

Warning

sudo pro disable SERVICE --purge requests a more destructive cleanup. Do not use --purge as a routine undo command. First record the package and configuration impact, take the maintenance window you need, and confirm that another service does not depend on it.

6. Refresh or detach only when the scope is clear

refresh updates contract data, reloads configuration or updates Pro-related APT and MOTD messages. You can select one target:

$ sudo pro refresh contract
$ pro status

Use sudo pro refresh with no target when you intentionally want all three refresh actions. This is useful after changing subscription definitions, but it does not replace checking package updates.

Warning

Detaching removes this machine's stored subscription and disables its Pro services. It does not uninstall packages installed by those services:

$ pro status
$ sudo pro detach
$ pro status

Detaching is the recovery action for removing a machine from an account, not a quick way to undo one service. If you need the subscription again, attach it deliberately and verify which services were enabled.

7. Diagnose the common failure modes

  • Already attached: run pro status and confirm the account before attempting another attach.
  • Not entitled: check ENTITLED in status. A spelling change or sudo will not grant a service your subscription does not include.
  • Operation already running: wait for the other Pro operation to finish, then rerun the read-only status check. Do not start several enable or disable commands in parallel.
  • New updates appear: enabling ESM can make additional updates visible. Review apt list --upgradable and follow your normal change process.
  • Need evidence for support: use sudo pro collect-logs -o /path/to/pro-logs.tar.gz. Inspect the destination and protect the archive because it contains system information.

Done means

  • The installed client version and binary path are known.
  • pro status confirms the attachment and each service state.
  • Any attach token was handled as a secret.
  • Service changes were made with an explicit name and followed by verification.
  • Any newly available package updates were reviewed separately.
  • You know whether the next recovery action is enable, refresh or a carefully planned detach.