Chapter 2. Upgrading using Helm charts
You must follow a specific upgrade path for RHACS depending on the release of RHACS that you are running. You must also back up your Central database before updating the Helm chart and performing the upgrade.
In RHACS 4.11, all container image names changed from the -rhel8 suffix to -rhel9 as part of the migration to UBI 9 Minimal base images. For example, rhacs-main-rhel8 is now rhacs-main-rhel9.
If you use image mirrors, allowlists, or firewall rules that reference specific RHACS image names, you must update them to use the new -rhel9 names before upgrading. For the complete list of current image names, see Image versions.
2.1. Helm upgrade overview Copy linkLink copied to clipboard!
If you have installed RHACS by using Helm charts, you must follow specific steps to upgrade to the latest version.
- Back up the Central database.
- Optional: Optimize Central’s database and Persistent Volume Claim (PVC).
-
Optional: Generate a
values-private.yamlconfiguration file containing root certificates for the central-services Helm chart. -
Run the
helm upgradecommand.
- To ensure optimal functionality, use the same version for your secured-cluster-services Helm chart and central-services Helm chart.
- To upgrade to RHACS 4.8, which includes an upgrade to PostgreSQL 15, you must free up disk space. Before beginning the upgrade, ensure that you have free disk space that is at least double the size of your existing database.
2.2. Backing up the Central database Copy linkLink copied to clipboard!
You can back up the Central database and use that backup for rolling back from a failed upgrade or data restoration in the case of an infrastructure disaster.
Prerequisites
-
You must have an API token with
readpermission for all resources of Red Hat Advanced Cluster Security for Kubernetes. The Analyst system role hasreadpermissions for all resources. -
You have installed the
roxctlCLI. -
You have configured the
ROX_API_TOKENand theROX_CENTRAL_ADDRESSenvironment variables.
Procedure
Run the backup command:
$ roxctl -e "$ROX_CENTRAL_ADDRESS" central backup
2.3. Optimizing the Central database and persistent volume claims Copy linkLink copied to clipboard!
When you upgrade to Red Hat Advanced Cluster Security for Kubernetes (RHACS) 4.0, RHACS creates a PostgreSQL instance called central-db. This instance uses a default Persistent Volume Claim (PVC). You can customize the central-db or PVC configuration.
Red Hat recommends the following minimum memory and CPU requests:
central:
db:
resources:
requests:
memory: 16Gi
cpu: 8
limits:
memory: 16Gi
cpu: 8
2.4. Generating root certificates file Copy linkLink copied to clipboard!
If you do not have access to your values-private.yaml configuration file that you have used to install Red Hat Advanced Cluster Security for Kubernetes (RHACS), use the following instruction to generate the values-private.yaml configuration file containing root certificates.
Skip the instruction here, if you have access to your values-private.yaml configuration file.
The generated values-private.yaml file has sensitive configuration options. Ensure that you store this file securely.
Procedure
-
Download the
create_certificate_values_file.shscript. Make the
create_certificate_values_file.shscript executable:$ chmod +x create_certificate_values_file.shRun the
create_certificate_values_file.shscript file:$ create_certificate_values_file.sh values-private.yaml
2.5. Updating the Helm chart repository Copy linkLink copied to clipboard!
You must always update Helm charts before upgrading to a new version of Red Hat Advanced Cluster Security for Kubernetes.
Prerequisites
- You must have already added the Red Hat Advanced Cluster Security for Kubernetes Helm chart repository.
- You must be using Helm version 3.8.3 or newer.
Procedure
Update Red Hat Advanced Cluster Security for Kubernetes charts repository.
$ helm repo update
Verification
Run the following command to verify the added chart repository:
$ helm search repo -l rhacs/
2.7. Preparing the custom resource definition for upgrade Copy linkLink copied to clipboard!
If upgrading from version 4.6 or 4.7, you must prepare the SecurityPolicy custom resource definition (CRD) to avoid upgrade errors.
If you use Kubernetes, enter kubectl instead of oc.
Procedure
Apply Helm-specific labels and annotations to the CRD by running the following commands:
$ oc annotate crd/securitypolicies.config.stackrox.io meta.helm.sh/release-name=stackrox-central-servicesAdjust the value of the
release-nameas needed. The default value isstackrox-central-services.$ oc annotate crd/securitypolicies.config.stackrox.io meta.helm.sh/release-namespace=stackroxAdjust the value of the
release-namespaceas needed. The default value isstackrox.$ oc label crd/securitypolicies.config.stackrox.io app.kubernetes.io/managed-by=Helm
2.8. Running the Helm upgrade command Copy linkLink copied to clipboard!
You can use the helm upgrade command to update Red Hat Advanced Cluster Security for Kubernetes (RHACS).
Prerequisites
-
You must have access to the
values-private.yamlconfiguration file that you have used to install Red Hat Advanced Cluster Security for Kubernetes (RHACS). Otherwise, you must generate thevalues-private.yamlconfiguration file containing root certificates before proceeding with these commands.
Procedure
Run the helm upgrade command and specify the configuration files by using the
-foption:$ helm upgrade -n stackrox stackrox-central-services \ rhacs/central-services --version <current_rhacs_version> \ -f values-private.yaml \ --set central.db.password.generate=true \ --set central.db.serviceTLS.generate=true \ --set central.db.persistence.persistentVolumeClaim.createClaim=true$ helm upgrade -n stackrox stackrox-secured-cluster-services \ rhacs/secured-cluster-services --version <current_rhacs_version> \ -f values-private.yamlNoteYou might use the
--reuse-valuesoption to preserve the Helm values that were configured before the upgrade. If you do that, you must turn offcentral-dbcreation before you upgrade to the next version.See the following command example:
$ helm upgrade -n stackrox stackrox-central-services \ rhacs/central-services --version <current_rhacs_version> --reuse-values \ -f values-private.yaml \ --set central.db.password.generate=false \ --set central.db.serviceTLS.generate=false \ --set central.db.persistence.persistentVolumeClaim.createClaim=false
2.9. Rolling back a Helm upgrade Copy linkLink copied to clipboard!
You can roll back to an earlier version of Central if the upgrade to a new version is unsuccessful.
If you use Kubernetes, enter kubectl instead of oc.
Procedure
Run the following
helm upgradecommand:$ helm upgrade -n stackrox \ stackrox-central-services rhacs/central-services \ --version <previous_rhacs_74_version> \ --set central.db.enabled=falsewhere:
<previous_rhacs_74_version>- Specifies the RHACS version installed before the upgrade.
Delete the
central-dbpersistent volume claim (PVC):$ oc -n stackrox delete pvc central-db