Worker updates
How workers update themselves from signed releases — trusted keys, manual and automatic updates, graceful switching and automatic rollback.
The installers set workers up for self-updates: autostart runs a small launcher, and each version lives in its
own folder (app/<version>/, with state.json saying which is current).
Source and trust
- Source: by default the control plane the worker is connected to, which hosts signed releases (see
Publishing worker releases).
updates.manifestUrlsets another source. - Trust: the worker installs only releases signed with a key in
updates.trustedKeys. Add the publisher's public key in the worker UI (Updates → Trusted release keys). The control plane can deliver releases but cannot add keys, so it cannot make a worker run unsigned code. The manifest signature and the package checksum must both verify.
Manual or automatic
- Manual: the local UI's update section (or
POST /api/updates/applyon the local API) downloads, verifies and installs. - Automatic: set
updates.policytoautomatic; the worker checks every six hours.
Switching and rollback
The worker stops taking new tasks, lets running ones finish, and restarts into the new version, which confirms itself once connected (or after 30 seconds without crashing). If it crashes or hangs before confirming, the launcher goes back to the previous version and never retries that version automatically. The current and previous versions are kept.
Without an update source
Re-run the installer: it installs the new version next to the old one and makes it current. Configuration and credentials are kept.
Status
No release has been published and no release key exists yet: each operator generates their own. Until a worker trusts a key, update it by re-running the installer.