Upgrades, rollback and backups
Upgrading with a new bundle, online updates with automatic rollback, content-pack updates, and backup and restore.
Upgrading with a new bundle
Run the one-command install again, or unpack the new bundle into the same install directory and run sudo ./deploy.sh, keeping the existing .env. The script loads the new images, sets GATEWAY_IMAGE_TAG to the new version and recreates the containers. .env, state/ and the data volumes are kept, the fingerprint does not change, and the license does not need to be activated again. The gateway migrates the database schema on start. This works on offline hosts too.
Upgrading from 0.1.x to 0.2.0
From 0.2.0 the bundle, images and containers are named RST-AI-Copilot-for-Prometheus-* / rst-ai-copilot-for-prometheus-*. A 0.1.x gateway looks for the old file name, so online update cannot reach 0.2.0. Upgrade by hand once; online updates work again after that:
- Connected host:
curl -fsSL https://github.com/Reallysec/RST-AI-Copilot-for-Prometheus/releases/latest/download/install.sh | sudo bash. It finds.envin the old directory/opt/rst-prometheus-ai-copilotand upgrades there. - Offline host: unpack the bundle into the existing install directory (default
/opt/rst-prometheus-ai-copilot) and re-rundeploy.sh, choosing "keep the existing .env".
Do not move the install directory: its name sets the data volume names and it holds the host fingerprint. A new directory starts with empty volumes and the license has to be activated again.
Online updates
Online updates come in two steps. The gateway only downloads and verifies; an operator installs on the host:
-
The gateway checks for a new version once a day. Settings > Version and updates shows the current and the new version; click Download and stage. The gateway verifies the release signature and the SHA-256 of every file, and stages nothing if any check fails.
-
In the install directory on the host, run:
./deploy/rst-update.sh # load the staged images, switch versions, health-check ./deploy/rst-update.sh --rollback # go back to the previous versionThe update only counts as successful after
/healthzreturns 200 three times in a row; otherwise it rolls back automatically. The script also replaces the compose files and the Caddyfile, keeping the old ones as*.bakand restoring them on rollback..envand./certsare left alone.
Back up before upgrading, PostgreSQL above all. Database migrations are one-way: rolling back the image does not roll back the schema.
Content packs
The metric dictionary, alert rule pack and runbooks are updated as signed content packs. When the daily update check finds a newer pack, it is verified and enabled automatically by default. To switch manually, set RST_CONTENT_AUTO_APPLY=0 in .env: new packs are only saved, and an admin enables them or switches back to an older one.
Backups
In the install directory, run:
bash scripts/backup.sh [backup directory] # ./backups by default; keeps 30 days| File | Contents | If you lose it |
|---|---|---|
host-files-<time>.tar.gz | .env, state/machine-id, state/server_guid | The host fingerprint changes and the license must be activated again; model and data-source credentials and internal secrets must be re-entered |
gateway-state-<time>.tar.gz | Settings, model configuration, license activation record, encryption key | Configuration and activation are lost; notification webhooks and SMTP passwords cannot be decrypted |
postgres-<time>.dump | The whole database: accounts, audit, investigations, report history, delivery log, knowledge base | Only the first admin account is left; all history is gone |
caddy-data-<time>.tar.gz | Caddy's internal CA root and site certificates | A new root certificate is generated and browsers must trust it again |
Metrics and alerts live in your Prometheus and Alertmanager and are not part of this backup. A daily cron job is recommended:
0 2 * * * cd /opt/rst-ai-copilot-for-prometheus && bash scripts/backup.sh /backup/rst-copilot >> /backup/rst-copilot/backup.out 2>&1Treat backups as plain-text credentials: .env holds the model key and data-source passwords, and the gateway state holds both the encrypted settings and the key that decrypts them. Keep the backup directory at chmod 700 and encrypt copies you store elsewhere.
Restore
bash scripts/restore.sh host-files-XXXX.tar.gz gateway-state-XXXX.tar.gz postgres-XXXX.dump caddy-data-XXXX.tar.gz
docker compose -f docker-compose.prod.yml up -d --force-recreate gateway caddyRestore onto an image version no older than the one the backup came from.
Moving to a new host: the fingerprint travels with state/, so the license does not need to be activated again. On the new host, unpack the same bundle version into /opt/rst-ai-copilot-for-prometheus, restore host-files first, run ./deploy.sh keeping the existing .env, then restore the other files and recreate the containers. Do not keep running the same state/ on the old host.
Rehearse a restore on a test machine at least once before going live.