Updates and rollback

Signed updates in three channels, never applied without you asking, with automatic rollback.

Used by
Admin
Plan
Free
Status
Available
Category
Servers and scale

What it is

Channels are estable, candidata and beta, chosen per node. Before applying, the node checks it has no drift; the package signature is verified against a key pinned on the node; a detached process applies it and the node rolls back if the panel does not come up healthy.

What it is for

Keeping nodes current without surprises.

Limits

Nothing updates on its own. A manifest from a different channel is rejected and key rotation only moves forward.