refine docs

This commit is contained in:
Maidul Islam
2025-05-13 22:02:49 -07:00
parent 4e1a5565d8
commit c8a3837432
@@ -1,6 +1,6 @@
--- ---
title: "Upgrading Linux Package" title: "Upgrading"
description: "Learn how to upgrade your Infisical deployment on Linux" description: "How to upgrade Infisical deployment using linux package"
--- ---
This guide explains how to upgrade Infisical Linux package installations to newer versions. This guide explains how to upgrade Infisical Linux package installations to newer versions.
@@ -141,43 +141,50 @@ This approach ensures users/machines do not experience sudden connection errors
#### On the deploy node: #### On the deploy node:
1. **Drain traffic from the node**: <Steps>
<Step title="Drain traffic from the node">
Depending on your load balancer, use one of the following approaches to drain the node: Drain the traffic on this node gracefully. You can do this in a number of ways depending on the load balancer you have configured.
<Tabs> Approaches for some common load balancers are provided below:
<Tab title="NGINX">
If using NGINX as a load balancer, you can remove the server from the upstream pool temporarily:
```bash
# Edit your NGINX configuration to comment out or remove the server
sudo nano /path/to/your/nginx-config.conf
# Reload NGINX to apply changes <Tabs>
sudo nginx -s reload <Tab title="NGINX">
``` If using NGINX as a load balancer, you can remove the server from the upstream pool temporarily:
</Tab> ```bash
<Tab title="HAProxy"> # Edit your NGINX configuration to comment out or remove the server
If using HAProxy, you can put the server in maintenance mode: sudo nano /path/to/your/nginx-config.conf
```bash
# Using the HAProxy socket command
echo "disable server infisical_backend/infisical-node1" | socat stdio /var/lib/haproxy/stats
```
</Tab>
<Tab title="AWS ALB/ELB">
Deregister the instance from the load balancer using the AWS console or CLI
</Tab>
<Tab title="Other load balancers">
Follow your load balancer's documentation for instructions on draining procedure
</Tab>
</Tabs>
2. **Verify no new traffic is arriving ** before proceeding with the upgrade. # Reload NGINX to apply changes
sudo nginx -s reload
```
</Tab>
<Tab title="HAProxy">
If using HAProxy, you can put the server in maintenance mode:
```bash
# Using the HAProxy socket command
echo "disable server infisical_backend/infisical-node1" | socat stdio /var/lib/haproxy/stats
```
</Tab>
<Tab title="AWS ALB/ELB">
Deregister the instance from the load balancer using the AWS console or CLI
</Tab>
<Tab title="Other load balancers">
Follow your load balancer's documentation for instructions on draining procedure
</Tab>
</Tabs>
</Step>
3. **Stop Infisical on this node**: <Step title="Verify no new traffic is arriving">
```bash Verify no new traffic is arriving before proceeding with the upgrade.
infisical-ctl stop </Step>
```
4. **Upgrade the Infisical package**: <Step title="Stop Infisical on this node">
```bash
infisical-ctl stop
```
</Step>
<Step title="Upgrade the Infisical package">
To upgrade to the latest version: To upgrade to the latest version:
@@ -208,39 +215,44 @@ To upgrade to a specific version:
``` ```
</Tab> </Tab>
</Tabs> </Tabs>
</Step>
5. **Apply configuration and start the service**: <Step title="Apply configuration and start the service">
```bash ```bash
infisical-ctl reconfigure infisical-ctl reconfigure
``` ```
</Step>
6. **Verify the upgrade and migration success**: <Step title="Verify the upgrade and migration success">
```bash ```bash
infisical-ctl tail infisical-ctl tail
``` ```
Look for successful migration messages in the logs. Look for successful migration messages in the logs.
</Step>
7. **Return the node to service** once you've verified it's running correctly: <Step title="Return this node to load balancer pool">
Re-enable the server in your load balancer using the same method you used to remove it.
Re-enable the server in your load balancer using the same method you used to remove it. </Step>
</Steps>
#### On all remaining nodes (one at a time): #### On all remaining nodes (one at a time):
1. **Drain traffic from the node** being upgraded: <Steps>
<Step title="Drain traffic from the node">
Follow the same draining procedure as described for the deploy node:
Follow the same draining procedure as described for the deploy node: - Remove the server from your load balancer's active pool
- Wait for existing connections to complete
- Verify the node is no longer receiving traffic
</Step>
- Remove the server from your load balancer's active pool <Step title="Stop Infisical on this node">
- Wait for existing connections to complete ```bash
- Verify the node is no longer receiving traffic infisical-ctl stop
```
2. **Stop Infisical on this node**: </Step>
```bash
infisical-ctl stop
```
3. **Upgrade the Infisical package**:
<Step title="Upgrade the Infisical package">
To upgrade to the latest version: To upgrade to the latest version:
<Tabs> <Tabs>
@@ -270,38 +282,89 @@ To upgrade to a specific version:
``` ```
</Tab> </Tab>
</Tabs> </Tabs>
</Step>
4. **Apply configuration and start the service**: <Step title="Apply configuration and start the service">
```bash ```bash
infisical-ctl reconfigure infisical-ctl reconfigure
``` ```
</Step>
5. **Verify the upgrade success**: <Step title="Verify the upgrade success">
```bash ```bash
infisical-ctl status infisical-ctl status
infisical-ctl tail infisical-ctl tail
``` ```
</Step>
6. **Wait for service to be fully operational**: <Step title="Wait for service to be fully operational">
- Check logs to ensure the service has started successfully - Check logs to ensure the service has started successfully
- Verify it can connect to the database and Redis - Verify it can connect to the database and Redis
</Step>
7. **Return the node to service**: <Step title="Return the node to service">
Re-enable the server in your load balancer using the same method you used to remove it.
</Step>
Re-enable the server in your load balancer using the same method you used to remove it. <Step title="Verify traffic is flowing correctly">
Check logs and monitoring to ensure traffic is flowing correctly.
</Step>
8. **Verify traffic is flowing correctly** by checking logs and monitoring. <Step title="Repeat for each remaining node">
Repeat steps 1-7 for each remaining node, one at a time.
</Step>
8. **Repeat** steps 1-7 for each remaining node, one at a time. <Step title="Verify application functionality">
After all nodes are upgraded, verify that the application is functioning correctly:
- Test core functionality
- Check logs for any errors
</Step>
</Steps>
9. **After all nodes are upgraded**, verify that the application is functioning correctly: ## Rolling Back
- Test core functionality
- Check logs for any errors If you need to roll back to a previous version of Infisical, follow steps below.
<Steps>
<Step title="Stop the Infisical service">
```bash
infisical-ctl stop
```
</Step>
<Step title="Install the previous version">
For Debian/Ubuntu:
```bash
sudo apt-get install -y infisical-core=<previous-version>
```
For RHEL/CentOS/Amazon Linux:
```bash
sudo yum downgrade infisical-core-<previous-version>
```
</Step>
<Step title="Restore your database from backup">
Restore your Postgres/Redis database from backup.
</Step>
<Step title="Start the service">
```bash
infisical-ctl reconfigure
```
</Step>
<Step title="Verify the rollback">
```bash
infisical-ctl status
```
</Step>
</Steps>
## Troubleshooting ## Troubleshooting
### Migration Issues <AccordionGroup>
<Accordion title="Migration Issues">
If you encounter database migration issues: If you encounter database migration issues:
1. Check the logs: 1. Check the logs:
@@ -313,46 +376,15 @@ If you encounter database migration issues:
3. If migrations fail repeatedly, consider restoring from the backup you took prior to upgrading. 3. If migrations fail repeatedly, consider restoring from the backup you took prior to upgrading.
### Service Won't Start After Upgrade </Accordion>
<Accordion title="Service Won't Start After Upgrade">
1. Check for configuration errors: 1. Check for configuration errors:
```bash ```bash
infisical-ctl status
infisical-ctl tail infisical-ctl tail
infisical-ctl status
``` ```
2. Verify all required environment variables are set in your `/etc/infisical/infisical.rb` file. 2. Verify all required environment variables are set in your `/etc/infisical/infisical.rb` file.
</Accordion>
</AccordionGroup>
## Rolling Back
If you need to roll back to a previous version of Infisical, follow steps below.
1. Stop the Infisical service:
```bash
infisical-ctl stop
```
2. Install the previous version:
For Debian/Ubuntu:
```bash
sudo apt-get install -y infisical-core=<previous-version>
```
For RHEL/CentOS/Amazon Linux:
```bash
sudo yum downgrade infisical-core-<previous-version>
```
3. Restore your database from backup.
4. Start the service:
```bash
infisical-ctl reconfigure
```
5. Verify the rollback:
```bash
infisical-ctl status
```