Upgrading
The routine
Section titled “The routine”- Back up first: the database and the key store. Migrations run forward only, so this backup is your rollback. See Backup, restore and key custody.
- Upgrade a staging node first: check out the new release tag in its clone, set
ODAL_VERSIONto match (the release number without its leadingv), then runodal update, which rebuilds the node from that source and restarts it. - Check it:
odal status, the trust posture on/vault/api/v1/node/state, and publish, resolve and verify a test passport. - Upgrade production the same way, and record the version and date.
Migrations apply automatically at start-up when DATABASE_MIGRATE_URL is set. A published passport is never rewritten by an upgrade: passports issued under an older schema version keep resolving exactly as they were issued.
Changes that need action
Section titled “Changes that need action”Next release
Section titled “Next release”These are not in a release yet and ship with the next one. The rest of this documentation already describes them.
- Retire replaces archive.
POST /dpp/{dppId}/archiveis nowPOST /dpp/{dppId}/retire, the status it sets is"retired"and the event isdpp.passport.retired.odal passport archiveis nowodal passport retire, andtrustMode.archiveon/vault/api/v1/node/stateistrustMode.backup."archived"is refused, not aliased: update clients, and resubscribe webhooks and NATS consumers that filter ondpp.passport.archived. A migration rewrites stored statuses on upgrade. - Rename
ARCHIVE_S3_*toBACKUP_S3_*. The variables are otherwise unchanged; see Configuration reference. - Product group data carries a
productIdentifier, not agtin."gtin": "09506000134352"becomes"productIdentifier": { "scheme": "gs1", "gtin": "09506000134352" }, and an identification link or a DID is accepted where a GTIN was required.GET /vault/api/v1/dpp/by-identitytakesidentifierinstead ofgtin. Stored passports are not rewritten. - The printed carrier follows the passport’s stated level. A model-level passport prints
/01/{gtin}, a batch-level one/01/{gtin}/10/{batch}, and an item-level one, or one that states no level,/01/{gtin}/21/{serial}. Anything that parsesqrCodeUrlshould expect all three. - A production or sandbox node refuses
ALLOW_UNSIGNED_PLUGINS=true. Remove the variable and setPLUGIN_SIGNING_KEYto the plugin publisher’s Ed25519 public key.
v0.14.0
Section titled “v0.14.0”RESOLVER_BASE_URLis required by the node and the resolver, with no default. Set it to your resolver’s public address before starting the new version.- Second-life lineage is
derivedFrom, an array of{ reference, operation }. Clients that sentparentPassportRefmust sendderivedFrominstead. - A component reference is an object, not a bare passport reference. Clients building
componentRefsmust send the new shape. SEAL_CONFORMANCE_LEVELdefaults toLTA, the sealer’s own level. Nothing to do unless you pinned a lower level on purpose.- The release’s container images now carry a software bill of materials and build provenance.
Every change, with its reasoning, is in the engine’s changelog.
Read next
Section titled “Read next”- Production deployment: the go-live checks this routine reuses.
- Configuration reference: every setting a release may add.
Information on this site is not legal advice. Legal noticePrivacy policy