maqpna upgrade
Upgrade MAQPNA; 'upgrade check' says whether it is safe
Synopsis#
maqpna upgrade [--to V] [--chart oci://...|DIR] [--profile P] [-f values.yaml] [--set K=V] [--reset-values]
[--dry-run] [--skip-crds] [--wait] [--atomic] [--timeout 10m] [--release maqpna] [-n NS]
maqpna upgrade check [--to V] [--chart ...] [-f values.yaml] [--set K=V] [-o table|json|yaml] (exit 3 when blocked)Description#
The deployed release's values are reused under the new chart's defaults (helm --reset-then-reuse-values); -f/--set/--profile apply on top. --dry-run renders the upgrade on the API server and prints the CRD diff and the per-resource manifest diff (Secret values redacted) without changing anything. CRDs are never rolled back: see docs/install/upgrading.md.
Subcommands#
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--atomic | switch | roll back the release when the upgrade fails (implies --wait) | none |
--chart | string | chart: oci:// reference, directory, .tgz, or a chart name with --repo | oci://<release-registry>/charts/maqpna |
--debug | switch | print Helm's debug log to stderr | none |
--dry-run | switch | print the CRD and manifest diff; change nothing | none |
-f, --values | string | values file (repeatable) | none |
--kube-context | string | kubeconfig context (default: the maqpna context's) | none |
-n, --namespace | string | namespace of the MAQPNA control plane (the Helm release) | maqpna-system |
--password | string | registry/repository password (env MAQPNA_CHART_PASSWORD) | none |
--plain-http | switch | pull the chart over plain HTTP (in-cluster test registries) | none |
--profile | string | values profile shipped with the chart: dev|prod|sovereign-eu (lowest priority) | none |
--release | string | Helm release name | maqpna |
--repo | string | chart repository URL (with --chart NAME) | none |
--reset-values | switch | drop the deployed values (default: reuse them under the new chart defaults) | none |
--set | string | set a value, KEY=VAL (repeatable) | none |
--set-file | string | set a value from a file, KEY=PATH (repeatable) | none |
--set-json | string | set a JSON value, KEY=JSON (repeatable) | none |
--set-string | string | set a string value, KEY=VAL (repeatable) | none |
--skip-crds | switch | do not apply the chart's CRDs | none |
--timeout | duration | timeout of Kubernetes operations (CRDs Established, --wait) | 10m0s |
--to, --version | string | chart version (default: this CLI's version) | none |
--username | string | registry/repository username (env MAQPNA_CHART_USERNAME) | none |
--wait | switch | wait until every workload is ready | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna upgrade check --to 1.5.0
maqpna upgrade --to 1.5.0 --dry-run
maqpna upgrade --to 1.5.0 --wait --atomicWhat happens when you run it#
- Runs the lifecycle plugin
maqpna-install(next tomaqpnaor onPATH), which drives the Helm v3 SDK against the cluster of your kubeconfig (--kubeconfig,--kube-context). --dry-run: print the CRD and manifest diff; change nothing.--wait: wait until every workload is ready.- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |
Related commands#
Terminal demo#
This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.