We have a range of common system services which either get installed by puppet or by the default Ubuntu/Debian installations. All of those are in need of restarts in case of a restart if one of the code system libraries are updated (such as libc, expat, openssl, pcre):
ntpd, atd, salt-minion, systemd-journald, systemd-udevd, system-logind, cron, lldpd, diamond, mcelog, dbus, acpid. exim, nrpe, rsyslog
I think it would be useful to simply restart all of these daily (spread out randomly across the day) at least from Monday to Friday. This simplifies our library rollouts and ensures no restarts are being forgotten (since restarts until now need to be actively made).
(sshd is also installed across the fleet, but should probably be excluded at this point),
These general services are intentionally not restarted automatically: