ON THIS PAGE
 

In-Place Software Release Updates on Deployed VMs

To support life cycle management of the Apstra VM, we provide a set of utilities designed to simplify and streamline the process. Use os‑ wrappers to run these utilities on a read‑only system.

Wrappers

The wrappers follow the original tools’ behavior. For example, to change your own password you don’t need sudo, and the wrapper behaves the same way. Wrappers don’t escalate privileges—if the original command requires root, the wrapper does too. You can use wrappers to keep local user management on a read‑only system.

Here's a list of wrappers that allow the utilities to function correctly in a read-only environment:

Table 1: Utilities and Wrappers
Original utility Wrapper
/usr/bin/passwd /usr/bin/os-passwd
/usr/bin/adduser /usr/bin/os-adduser
/usr/bin/change /usr/bin/os-change
/usr/bin/chgpasswd /usr/bin/os-chgpasswd
/usr/bin/chpasswd /usr/bin/os-chpasswd
/usr/bin/gpasswd /usr/bin/os-gpasswd
/usr/bin/groupadd /usr/bin/os-groupadd
/usr/bin/groupdel /usr/bin/os-groupdel
/usr/bin/groupmems /usr/bin/os-groupmems
/usr/bin/groupmod /usr/bin/os-groupmod
/usr/bin/grpck /usr/bin/os-grpck
/usr/bin/grpconv /usr/bin/os-grpconv
/usr/bin/grpunconv /usr/bin/os-grpunconv
/usr/bin/newgrp /usr/bin/os-newgrp
/usr/bin/newusers /usr/bin/os-newusers
/usr/bin/prober /usr/bin/os-prober
/usr/bin/pwck /usr/bin/os-pwck
/usr/bin/pwconv /usr/bin/os-pwconv
/usr/bin/pwunconv /usr/bin/os-pwunconv
/usr/bin/update-ca-certificates /usr/bin/os-update-ca-certificates
/usr/bin/useradd /usr/bin/os-useradd
/usr/bin/userdel /usr/bin/os-userdel
/usr/bin/usermod /usr/bin/os-usermod
/usr/bin/vigr /usr/bin/os-vigr
/usr/bin/vipw /usr/bin/os-vipw

Utilities

Use the corresponding os‑ wrapper for each utility:

os-edit

If you need to edit a configuration file on a read-only (RO) file system and can’t use other methods, use the os-edit utility. The utility starts the editor set in the EDITOR environment variable; if EDITOR isn’t set, it falls back to vim.

The utility tracks the files you modify and records them in /etc/changed_files. The os-update utility uses this list of files in /etc/changed_files to collect the modified files and create a tarball.

os-update

os-update is the primary tool for managing update files. Use it to display update details, apply an update, optionally switch the boot partition, and reboot the system.

Here’s a quick walkthrough. Suppose you have an update file named aos.up. First, inspect the file.

The output shows the update file version, a unique update ID, and associated metadata.

You can also validate integrity. ZIP archives include built‑in integrity checks (such as CRC64), but you might also need to validate additional aspects—for example, compliance with a specific JSON schema.

Use this command:

Before you upgrade, review the options:

We’ll cover most options later. For now, remember that:

  • You can skip the os-update validate step.

  • You can skip the reboot after the update (so you can reboot into the new partition when it’s convenient).

  • You can skip switching the boot partition (which also skips the reboot).

  • Advanced options let you set ports, subnets, and DNS settings.

All options are optional. If you run os-update apply without options, it will:

  • Validate the update file.

  • Unpack images into the secondary partition set.

  • Move important changes from one partition to another.

  • Switch the boot partition.

  • Reboot the system.

Let’s see how to perform an upgrade. Then review the options:

The last line is from SSH and indicates that the connection was dropped because of the reboot. You can skip the reboot after the update (so you can reboot into the new partition when it’s convenient).

os-lv-extend

os-lv-extend is a wrapper that simplifies common LVM operations—most notably partition extension. It’s similar to its counterpart in the previous layout, aos_extend_disk.

For example, let’s say you want to extend the log partition.

/dev/vdb and /dev/vdc are eligible for LVM extension.

The utility can distribute space across multiple logical volumes. If you aren’t satisfied with the default allocation, customize it by adjusting these weights.

There are four logical volumes. I’ve set the weights of all volumes to zero except for the logs, which means all available space will be allocated to logs.

Now run the utility:

For /dev/vdc, distribute space as follows: sysdb gets 3 shares; log and user get two shares each; var gets one share, userget two shares each; var gets one share:

Run the utility:

If the proposed changes don’t look right, don’t confirm.

This utility is designed for this use case. It doesn’t support shrinking volumes, creating new logical volumes, or similar operations.

For those tasks, use the standard LVM tool set.