Skip to main content

Upgrades

Upgrading a Mesh Node replaces only its executable (and, on Linux, its systemd unit). The node's identity, hardware key, trust files, TLS material, configuration and state are left exactly as they are. Do not create a new enrollment package to upgrade — an enrolled node keeps its identity.

How an in-place upgrade protects you​

Both installers' upgrade modes:

  1. re-authenticate the new release exactly as a fresh install does (Sigstore identity of the repository, workflow and tag, plus signed digests of every artifact);
  2. require an existing enrolled identity (identity.json);
  3. run the new binary with -validate-config against your installed configuration — if the new version cannot accept it, they stop with The installed configuration is incompatible with this release; no system files were changed;
  4. only then replace the executable and restart the existing service, and check that it is running again.

Plan a staged rollout​

  • Promote the same verified release through a canary node, then one failure domain, then the rest of the fleet. Do not rebuild or re-download between stages.
  • Upgrade one node at a time so the customer approval quorum stays available. Check the quorum under ConsoleMesh nodes between nodes.
  • Keep the previous release directory (or image digest) so you can roll back without fetching anything.
  • After each node, confirm health, policy synchronization, integration health and audit continuity before moving on.

Linux​

Download the new release's seven files into a new directory (see Install on Linux), then:

mesh-node-01 (bash)
cd ~/sectigo-edge-v0.1.27
sudo sh ./install-node-linux.sh --verify-only --upgrade . hassard0/sharppki
Sectigo Edge v0.1.27 release identity and selected Linux installer artifacts verified.
sudo sh ./install-node-linux.sh --upgrade . hassard0/sharppki
Sectigo Edge Mesh Node v0.1.27 upgraded in place from a verified release; identity and customer-held configuration were preserved.

v0.1.27 is an example version. --upgrade cannot be combined with --bootstrap-package or --material-directory. Failure messages:

MessageMeaning
A regular enrolled identity is required for an in-place upgradeThe host is not enrolled; perform a normal install.
The installed configuration is incompatible with this release; no system files were changedThe new binary rejected /etc/edgepki/config.json. Run the new binary with -validate-config to see why (see CLI reference).
The upgraded Mesh Node did not become activeThe service failed after restart. Check journalctl -u edgepki-node and roll back.

Windows​

Download the new release's files into a new folder (see Install on Windows), then from an elevated session:

Administrator: Windows PowerShell
.\install-node-windows.ps1 -VerifyOnly -Upgrade -Binary .\edgepki-node-windows-amd64.exe -ReleaseDirectory .
Sectigo Edge v0.1.27 release verified for an in-place Windows upgrade.
.\install-node-windows.ps1 -Upgrade -Binary .\edgepki-node-windows-amd64.exe -ReleaseDirectory .
Sectigo Edge Mesh Node v0.1.27 upgraded in place from a verified release; identity and customer-held configuration were preserved.

The installer stops the SectigoEdgeMeshNode service, replaces edgepki-node.exe, updates the existing service in place (it is never deleted and recreated) and waits up to 30 seconds for it to reach Running. If you run the service under a gMSA, pass the same -ServiceAccount again. -Upgrade cannot be combined with -BootstrapPackage, -Config or -MaterialDirectory.

Kubernetes​

Verify the new image digest from the new release's container-images.json (see Kubernetes / Helm), then upgrade the release with that digest:

workstation (bash)
helm upgrade mesh ./edgepki-node --namespace edgepki --reuse-values \
  --set image.digest=sha256:9e2d4c6a8b0f1e3d5c7a9b2e4f6d8c0a1b3e5d7f9c2a4e6b8d0f1c3a5e7b9d2f
Release "mesh" has been upgraded. Happy Helming!
kubectl -n edgepki rollout status statefulset/mesh-edgepki-node
statefulset rolling update complete 3 pods at revision mesh-edgepki-node-6c9f7d8b5d...

The StatefulSet replaces pods one at a time and the PodDisruptionBudget keeps at least two available. Each replica's identity and state stay on its persistent volume. If you use a new chart version, extract it from the new sectigo-edge-helm-charts.tgz first.

Roll back​

Roll back by installing the previous verified release the same way:

  • Linux: run sudo sh ./install-node-linux.sh --upgrade . hassard0/sharppki from the previous release directory.
  • Windows: run .\install-node-windows.ps1 -Upgrade -Binary .\edgepki-node-windows-amd64.exe -ReleaseDirectory . from the previous release folder.
  • Kubernetes: helm rollback mesh or helm upgrade with the previous image.digest.

The previous binary also validates your configuration first. If you added configuration keys that only the newer version understands, it refuses with the incompatibility message and changes nothing — remove those keys, then retry.

Roll back if, after an upgrade, node health, policy synchronization, dual-slot rotation, signing receipts or audit continuity fail.