Updates and version compatibility

× Magnified Image

Consult the release notes for supported update paths. For a fresh deployment, use the installation guide. Development builds are not a supported update source.

Screenshots show the Management frontend with simulated example data. Versions, hostnames, timestamps and status observations do not describe a deployed appliance.

Two separate update targets

Target Delivery Effect

Management ISO host and application

Management ISO

A qualified newer ISO boots its embedded Management image against the existing Management state disk. Compatibility depends on the supplied release; the host does not select another container image independently.

Management on an operator-maintained container host

Management image

Follow the target release’s supported image transition, retaining the /var volume, TLS material and fixed identity settings. Host OS and container-runtime maintenance remain the operator’s responsibility.

Installed appliance

Update bundle

An exact source-to-target release transition runs through Appliance > Update. A release bundle for fresh installation cannot serve as an update bundle.

Replacing Management media does not itself update the managed appliance. Likewise, an appliance update does not replace Management’s boot ISO.

Before any future update

Use the target release’s instructions and compatibility information. Retain a complete recovery set outside the appliance, and plan the required maintenance window. Keep Management connected and retain the local bundles required by the operation.

To update the Management ISO, finish current work and shut down Management cleanly. Replace the attached ISO with a qualified newer ISO, then reboot with the same state disk. Within the ISO deployment, there is no ISO rollback or independent container-image selector. Do not switch back to older media as a recovery procedure after a failed forward update.

Before starting, check and renew cluster access. With two hours or less remaining, Management requires explicit acceptance of the expiry risk. Expiry or eviction cancels the update work that depends on the access lease. Reconnect, then use the update’s explicit Retry when offered; reconnection does not resume the update automatically.

The appliance UI separates Prepare update from Apply update. Preparation checks the installed source and captures a verified source backup before update scripts can run. It holds ordinary configuration changes and scheduled backups during the operation. Save the recovery set and acknowledge it in Management before applying the update.

Preparation can be cancelled while the UI offers Cancel preparation. Once update scripts start, the available failure paths are retry or recovery. The update is not complete until the target release has its new full backup. Preserve its source recovery set.

Use these mechanisms only for a source-to-target path documented in the release instructions. The Unsupported source override control does not create a supported path.

If an update needs attention

Keep the exact source and target version, displayed phase, error, and retained recovery set. Use the UI’s reconnection link if access expired. Collect diagnostics and contact support before replacing media or attempting a different update bundle.