Updates

How signed self-update works and how to control it.

Signed and pinned

Agent releases are signed by FluenceSecurity. At install time the agent pins the public key from the bundle. When a new version is offered, the agent verifies its signature against the pinned key, applies it and restarts itself. An update whose signature does not verify is refused and the refusal is logged.

Channels

Fleet policy sets the update channel per fleet group: stable, or an early channel for test hosts. Roll a new version to a test group first, watch the Hosts page for the reported version and health, then move the rest.

Pinning a version

A fleet group can be pinned to a version, which stops offers above it. Use this for change freezes.

Across an update

An update keeps the enrolled identity, the enrolment credential and the containment state. A host that is isolated stays isolated across an update.