Signed and pinned
Agent releases are signed by FluenceSecurity. At install time the agent pins the public key from the bundle. When a new version is offered, the agent verifies its signature against the pinned key, applies it and restarts itself. An update whose signature does not verify is refused and the refusal is logged.
Channels
Fleet policy sets the update channel per fleet group: stable, or an early channel for test hosts. Roll a new version to a test group first, watch the Hosts page for the reported version and health, then move the rest.
Pinning a version
A fleet group can be pinned to a version, which stops offers above it. Use this for change freezes.
Across an update
An update keeps the enrolled identity, the enrolment credential and the containment state. A host that is isolated stays isolated across an update.