SonicCloud
Skip to content

Operate and maintain

Secure, back up, upgrade and uninstall the license server.

Security recommendations

  • Replace the initial administrator. After your first sign-in, create a named account for each administrator, then disable the initial account.
  • Protect the key pair and secrets. Store them in a vault, never in source control.
  • Use HTTPS everywhere. Keep TLS enabled for the license API, the admin console, the database connection and every workstation.
  • Keep the network policy enabled so services communicate only with the ingress controller, each other and your database.
  • Raise the API rate limit if many workstations share one IP address, for example behind NAT. Set server.env.API_RATE_LIMIT in values-secrets.yaml.

Backup and recovery

All data lives in PostgreSQL. A database backup is a complete backup. Also keep a copy of values-secrets.yaml and your signing keys.

Back up the database daily:

pg_dump -h "$PGHOST" -U "$PGUSER" -d "$PGDATABASE" -F c -b -f license_db_$(date +%Y%m%d).dump

Store backups away from the database host and test a restore in staging regularly.

To recover:

pg_restore -h "$PGHOST" -U "$PGUSER" -d "$PGDATABASE" -c license_db_<date>.dump
kubectl rollout restart deployment -n license

If the cluster was lost, reinstall with your saved values files first.

Upgrade

Upgrade the license server

Test in staging, back up the database, then run:

helm upgrade soniccloud oci://us-docker.pkg.dev/instant-matter-739/soniccloud-license/soniccloud-license \
  --version <new-version> \
  -f values-secrets.yaml \
  --set 'imagePullSecrets[0].name=registry-pull-secret' \
  -n license

On OpenShift, add -f values-openshift.yaml after -f values-secrets.yaml.

Upgrade workstations

Run the new installer with the same properties. See Deploy with msiexec.

Roll back

If an upgrade misbehaves, list the release history and return to the previous revision:

helm history soniccloud -n license
helm rollback soniccloud <revision> -n license

Uninstall

Your database is not affected.

helm uninstall soniccloud -n license

On this page