You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
= Configuring automatic upgrades for secured clusters
2
+
= Configuring automatic upgrades for manifest-installed secured clusters
3
3
include::modules/common-attributes.adoc[]
4
4
:context: configure-automatic-upgrades
5
5
6
6
toc::[]
7
7
8
8
[role="_abstract"]
9
-
You can automate the upgrade process for each secured cluster and view the upgrade status from the {product-title-short} portal.
9
+
If you installed {product-title} by using the manifest installation method, also known as the _`roxctl` CLI method_ or the _legacy installation method_, you can automate the upgrade process for each secured cluster. You can also view the upgrade status from the {product-title-short} portal.
10
10
11
-
Automatic upgrades make it easier to stay up-to-date by automating the manual task of upgrading each secured cluster.
11
+
[NOTE]
12
+
====
13
+
Automatic upgrades are only available for {product-title-short} systems that were installed by using the manifest installation method. If you installed {product-title-short} by using the Operator, upgrades are controlled by using {olm-first}. If you installed {product-title-short} by using Helm charts, you must use Helm to upgrade.
14
+
====
12
15
13
-
With automatic upgrades, after you upgrade Central; Sensor, Collector, and Compliance services in all secured clusters, automatically upgrade to the latest version.
16
+
Automatic upgrades make it easier to stay up-to-date by automating the manual task of upgrading each secured cluster. If you have automatic upgrades enabled, and the secured cluster is configured for receiving automated upgrades, the upgrader upgrades the entire secured cluster to the same version as Central.
14
17
15
-
{product-title} also enables centralized management of all your secured clusters from within the {product-title-short} portal.
16
18
The new *Clusters* view displays information about all your secured clusters, the Sensor version for every cluster, and upgrade status messages.
17
19
You can also use this view to selectively upgrade your secured clusters or change their configuration.
18
20
@@ -21,8 +23,8 @@ You can also use this view to selectively upgrade your secured clusters or chang
21
23
* The automatic upgrade feature is enabled by default.
22
24
* If you are using a private image registry, you must first push the Sensor and Collector images to your private registry.
23
25
* The Sensor must run with the default RBAC permissions.
24
-
* Automatic upgrades do not preserve any patches that you have made to any {product-title} services running in your cluster.
25
-
However, it preserves all labels and annotations that you have added to any {product-title} object.
26
+
* Automatic upgrades do not preserve any patches that you have made to any {product-title-short} services running in your cluster.
27
+
However, it preserves all labels and annotations that you have added to any {product-title-short} object.
26
28
* By default, {product-title} creates a service account called `sensor-upgrader` in each secured cluster.
27
29
This account is highly privileged but is only used during upgrades.
28
30
If you remove this account, Sensor does not have enough permissions, and you must complete future upgrades manually.
= Automatic upgrade failure for manifest-installed secured clusters
7
7
8
-
Sometimes, {product-title} automatic upgrades might fail to install.
8
+
Sometimes, {product-title-short} automatic upgrades might fail to install.
9
9
When an upgrade fails, the status message for the secured cluster changes to `Upgrade failed. Retry upgrade`.
10
-
To view more information about the failure and understand why the upgrade failed, you can check the secured cluster row in the *Clusters* view.
10
+
To view more information about the failure and understand why the upgrade failed, you can check the secured cluster row in the *Clusters* view. For more information, see "Troubleshooting the cluster upgrader".
11
11
12
12
Some common reasons for the failure are:
13
13
14
14
* The sensor-upgrader deployment might not have run because of a missing or a non-schedulable image.
15
15
* The pre-flight checks may have failed, either because of insufficient RBAC permissions or because the cluster state is not recognizable.
16
16
This can happen if you have edited {product-title} service configurations or the `auto-upgrade.stackrox.io/component` label is missing.
17
17
* There might be errors in executing the upgrade. If this happens, the upgrade installer automatically attempts to roll back the upgrade.
18
-
+
18
+
19
19
[NOTE]
20
20
====
21
-
Sometimes, the rollback can fail as well. For such cases view the cluster logs to identify the issue or contact support.
21
+
Sometimes, the rollback can also fail. For these cases, view the cluster logs to identify the issue or contact support. For more information, see "Troubleshooting the cluster upgrader".
22
22
====
23
23
24
24
After you identify and fix the root cause for the upgrade failure, you can use the *Retry Upgrade* option to upgrade your secured cluster.
Copy file name to clipboardExpand all lines: modules/automatic-upgrade-status.adoc
+4-1Lines changed: 4 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,7 +11,7 @@ The *Clusters* view lists all clusters and their upgrade statuses.
11
11
|===
12
12
|Upgrade status |Description
13
13
14
-
|Up to date with Central version
14
+
|Up to date with Central
15
15
|The secured cluster is running the same version as Central.
16
16
17
17
|Upgrade available
@@ -27,4 +27,7 @@ The *Clusters* view lists all clusters and their upgrade statuses.
27
27
|Pre-flight checks complete
28
28
|The upgrade is in progress. Before performing automatic upgrade, the upgrade installer runs a pre-flight check. During the pre-flight check, the installer verifies if certain conditions are satisfied and then only starts the upgrade process.
29
29
30
+
|Not applicable
31
+
|{product-title-short} cannot communicate with the cluster.
= Enabling automatic upgrades for manifest-installed secured clusters
7
7
8
-
You can enable automatic upgrades for all secured clusters to automatically upgrade Collector and Compliance services in all secured clusters to the latest version.
8
+
You can enable automatic upgrades for all secured clusters that were installed by using the manifest installation method, also known as the `roxctl` CLI method. This feature automatically upgrades Sensor, Admission Controller, Collector, and Compliance in all secured clusters to the same version as Central.
Copy file name to clipboardExpand all lines: modules/manual-upgrade-secured-clusters.adoc
+3-3Lines changed: 3 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,6 +12,6 @@ To manually trigger upgrades for your secured clusters:
12
12
.Procedure
13
13
14
14
. In the {product-title-short} portal, go to *Platform Configuration*->*Clusters*.
15
-
. Select the *Upgrade available* option under the *Upgrade status* column for the cluster you want to upgrade.
16
-
. To upgrade multiple clusters at once, select the checkboxes in the *Cluster* column for the clusters you want to update.
17
-
. Click*Upgrade*.
15
+
. Take one of the following actions:
16
+
* To upgrade a single cluster, select the *Upgrade available* option under the *Sensor Upgrade* column for the cluster you want to upgrade.
17
+
* To upgrade multiple clusters at a time, select the checkboxes next to the *Name* column for the clusters you want to update, and then click*Upgrade*.
0 commit comments