Operate and maintain
Secure, back up, upgrade and uninstall the license server.
Security recommendations
- Replace the initial administrator. After your first sign-in, create a named account for each administrator, then disable the initial account.
- Protect the key pair and secrets. Store them in a vault, never in source control.
- Use HTTPS everywhere. Keep TLS enabled for the license API, the admin console, the database connection and every workstation.
- Keep the network policy enabled so services communicate only with the ingress controller, each other and your database.
- Raise the API rate limit if many workstations share one IP address, for example behind NAT. Set
server.env.API_RATE_LIMITinvalues-secrets.yaml.
Backup and recovery
All data lives in PostgreSQL. A database backup is a complete backup. Also keep a copy of values-secrets.yaml and your signing keys.
Back up the database daily:
pg_dump -h "$PGHOST" -U "$PGUSER" -d "$PGDATABASE" -F c -b -f license_db_$(date +%Y%m%d).dumpStore backups away from the database host and test a restore in staging regularly.
To recover:
pg_restore -h "$PGHOST" -U "$PGUSER" -d "$PGDATABASE" -c license_db_<date>.dump
kubectl rollout restart deployment -n licenseIf the cluster was lost, reinstall with your saved values files first.
Upgrade
Upgrade the license server
Test in staging, back up the database, then run:
helm upgrade soniccloud oci://us-docker.pkg.dev/instant-matter-739/soniccloud-license/soniccloud-license \
--version <new-version> \
-f values-secrets.yaml \
--set 'imagePullSecrets[0].name=registry-pull-secret' \
-n licenseOn OpenShift, add -f values-openshift.yaml after -f values-secrets.yaml.
Upgrade workstations
Run the new installer with the same properties. See Deploy with msiexec.
Roll back
If an upgrade misbehaves, list the release history and return to the previous revision:
helm history soniccloud -n license
helm rollback soniccloud <revision> -n licenseUninstall
Your database is not affected.
helm uninstall soniccloud -n license