MAQPNADocs

maqpna upgrade

Upgrade MAQPNA; 'upgrade check' says whether it is safe

Operateplugin: maqpna-install-o json | yaml

Synopsis#

maqpna upgrade [--to V] [--chart oci://...|DIR] [--profile P] [-f values.yaml] [--set K=V] [--reset-values]
               [--dry-run] [--skip-crds] [--wait] [--atomic] [--timeout 10m] [--release maqpna] [-n NS]
maqpna upgrade check [--to V] [--chart ...] [-f values.yaml] [--set K=V] [-o table|json|yaml]   (exit 3 when blocked)

Description#

The deployed release's values are reused under the new chart's defaults (helm --reset-then-reuse-values); -f/--set/--profile apply on top. --dry-run renders the upgrade on the API server and prints the CRD diff and the per-resource manifest diff (Secret values redacted) without changing anything. CRDs are never rolled back: see docs/install/upgrading.md.

Subcommands#

Flags#

FlagTypeDescriptionDefault
--atomicswitchroll back the release when the upgrade fails (implies --wait)none
--chartstringchart: oci:// reference, directory, .tgz, or a chart name with --repooci://<release-registry>/charts/maqpna
--debugswitchprint Helm's debug log to stderrnone
--dry-runswitchprint the CRD and manifest diff; change nothingnone
-f, --valuesstringvalues file (repeatable)none
--kube-contextstringkubeconfig context (default: the maqpna context's)none
-n, --namespacestringnamespace of the MAQPNA control plane (the Helm release)maqpna-system
--passwordstringregistry/repository password (env MAQPNA_CHART_PASSWORD)none
--plain-httpswitchpull the chart over plain HTTP (in-cluster test registries)none
--profilestringvalues profile shipped with the chart: dev|prod|sovereign-eu (lowest priority)none
--releasestringHelm release namemaqpna
--repostringchart repository URL (with --chart NAME)none
--reset-valuesswitchdrop the deployed values (default: reuse them under the new chart defaults)none
--setstringset a value, KEY=VAL (repeatable)none
--set-filestringset a value from a file, KEY=PATH (repeatable)none
--set-jsonstringset a JSON value, KEY=JSON (repeatable)none
--set-stringstringset a string value, KEY=VAL (repeatable)none
--skip-crdsswitchdo not apply the chart's CRDsnone
--timeoutdurationtimeout of Kubernetes operations (CRDs Established, --wait)10m0s
--to, --versionstringchart version (default: this CLI's version)none
--usernamestringregistry/repository username (env MAQPNA_CHART_USERNAME)none
--waitswitchwait until every workload is readynone

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna upgrade check --to 1.5.0
maqpna upgrade --to 1.5.0 --dry-run
maqpna upgrade --to 1.5.0 --wait --atomic

What happens when you run it#

  • Runs the lifecycle plugin maqpna-install (next to maqpna or on PATH), which drives the Helm v3 SDK against the cluster of your kubeconfig (--kubeconfig, --kube-context).
  • --dry-run: print the CRD and manifest diff; change nothing.
  • --wait: wait until every workload is ready.
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)

Terminal demo#

maqpna upgrade --help.cast

This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.