OS updates - preferred SOP?

Is there a preferred SOP for updating the OS and underlying software on a Commcare monolith install?
Usually it would be a simple apt update / apt upgrade but I imagine there could conceivably be components required by Commcare HQ or Cloud that may need to be held back for compatibility sake or am I over thinking things?