Operations
Upgrades, health and high availability
Upgrade safely, roll back, monitor health, and run more than one node.
on the server
./setup.sh --upgrade # pull, keep the old image as npm-repo:previous, rebuild, restart, wait for health
curl -s https://packages.example.com/_health # {"ok":true}, or a 503 if the database is unreachable
# roll back, if the database was not upgraded to a newer MariaDB
docker tag npm-repo:previous npm-repo:latest && docker compose up -d
--upgraderefuses to run over local edits and never touches.envor the data directory. Database changes run automatically at start.- Plain
docker compose up -ddoes not rebuild. Use--buildor the upgrade script. - Hard refresh the portal after an upgrade. The page is cached for five minutes.
More than one node
- Point every node at one MariaDB with
DB_HOST. Rules, users, sessions, tokens, settings, allow lists and findings are shared. - Cached files are not shared unless you use S3 or Azure storage. Otherwise sync the cache directory and run Check for drift after a failover.
- Settings reach other nodes within 30 seconds, rules within 5. Background jobs run on every node, so active and passive is recommended.
Reverse proxy
Put nginx or another proxy with TLS in front, using the example in nginx/npm-repo.conf.example. The proxy must set X-Forwarded-For to the client address, and the container port should only listen on 127.0.0.1.