Skip to main content
Installation

Upgrades, rollback and backups

Upgrading with a new bundle, online updates with automatic rollback, content-pack updates, and backup and restore.

Upgrading with a new bundle

Run the one-command install again, or unpack the new bundle into the same install directory and run sudo ./deploy.sh, keeping the existing .env. The script loads the new images, sets GATEWAY_IMAGE_TAG to the new version and recreates the containers. .env, state/ and the data volumes are kept, the fingerprint does not change, and the license does not need to be activated again. The gateway migrates the database schema on start. This works on offline hosts too.

Upgrading from 0.1.x to 0.2.0

From 0.2.0 the bundle, images and containers are named RST-AI-Copilot-for-Prometheus-* / rst-ai-copilot-for-prometheus-*. A 0.1.x gateway looks for the old file name, so online update cannot reach 0.2.0. Upgrade by hand once; online updates work again after that:

  • Connected host: curl -fsSL https://github.com/Reallysec/RST-AI-Copilot-for-Prometheus/releases/latest/download/install.sh | sudo bash. It finds .env in the old directory /opt/rst-prometheus-ai-copilot and upgrades there.
  • Offline host: unpack the bundle into the existing install directory (default /opt/rst-prometheus-ai-copilot) and re-run deploy.sh, choosing "keep the existing .env".

Do not move the install directory: its name sets the data volume names and it holds the host fingerprint. A new directory starts with empty volumes and the license has to be activated again.

Online updates

Online updates come in two steps. The gateway only downloads and verifies; an operator installs on the host:

  1. The gateway checks for a new version once a day. Settings > Version and updates shows the current and the new version; click Download and stage. The gateway verifies the release signature and the SHA-256 of every file, and stages nothing if any check fails.

  2. In the install directory on the host, run:

    ./deploy/rst-update.sh              # load the staged images, switch versions, health-check
    ./deploy/rst-update.sh --rollback   # go back to the previous version

    The update only counts as successful after /healthz returns 200 three times in a row; otherwise it rolls back automatically. The script also replaces the compose files and the Caddyfile, keeping the old ones as *.bak and restoring them on rollback. .env and ./certs are left alone.

Back up before upgrading, PostgreSQL above all. Database migrations are one-way: rolling back the image does not roll back the schema.

Content packs

The metric dictionary, alert rule pack and runbooks are updated as signed content packs. When the daily update check finds a newer pack, it is verified and enabled automatically by default. To switch manually, set RST_CONTENT_AUTO_APPLY=0 in .env: new packs are only saved, and an admin enables them or switches back to an older one.

Backups

In the install directory, run:

bash scripts/backup.sh [backup directory]   # ./backups by default; keeps 30 days
FileContentsIf you lose it
host-files-<time>.tar.gz.env, state/machine-id, state/server_guidThe host fingerprint changes and the license must be activated again; model and data-source credentials and internal secrets must be re-entered
gateway-state-<time>.tar.gzSettings, model configuration, license activation record, encryption keyConfiguration and activation are lost; notification webhooks and SMTP passwords cannot be decrypted
postgres-<time>.dumpThe whole database: accounts, audit, investigations, report history, delivery log, knowledge baseOnly the first admin account is left; all history is gone
caddy-data-<time>.tar.gzCaddy's internal CA root and site certificatesA new root certificate is generated and browsers must trust it again

Metrics and alerts live in your Prometheus and Alertmanager and are not part of this backup. A daily cron job is recommended:

0 2 * * * cd /opt/rst-ai-copilot-for-prometheus && bash scripts/backup.sh /backup/rst-copilot >> /backup/rst-copilot/backup.out 2>&1

Treat backups as plain-text credentials: .env holds the model key and data-source passwords, and the gateway state holds both the encrypted settings and the key that decrypts them. Keep the backup directory at chmod 700 and encrypt copies you store elsewhere.

Restore

bash scripts/restore.sh host-files-XXXX.tar.gz gateway-state-XXXX.tar.gz postgres-XXXX.dump caddy-data-XXXX.tar.gz
docker compose -f docker-compose.prod.yml up -d --force-recreate gateway caddy

Restore onto an image version no older than the one the backup came from.

Moving to a new host: the fingerprint travels with state/, so the license does not need to be activated again. On the new host, unpack the same bundle version into /opt/rst-ai-copilot-for-prometheus, restore host-files first, run ./deploy.sh keeping the existing .env, then restore the other files and recreate the containers. Do not keep running the same state/ on the old host.

Rehearse a restore on a test machine at least once before going live.

On this page