This guide covers migrating from Ambassador Edge Stack 2.0.5 to Ambassador Edge Stack 2.3.2. If this is not your exact situation, see the migration matrix.
This guide is written for upgrading an installation originally made using Helm. If you did not install with Helm, see the YAML-based upgrade instructions.
Upgrading from Ambassador Edge Stack 2.0.5 to Ambassador Edge Stack 2.3.2 typically requires downtime.In some situations, Ambassador Labs Support may be able to assist with a zero-downtime migration; contact support with questions.
Migrating from Ambassador Edge Stack 2.0.5 to Ambassador Edge Stack 2.3.2 is a four-step process:
Install new CRDs.
Before installing Ambassador Edge Stack 2.3.2 itself, you need to update the CRDs in
your cluster; Helm will not do this for you. This is mandatory during any upgrade of Ambassador Edge Stack.
Ambassador Edge Stack 2.3.2 includes a Deployment in the `emissary-system` namespace called emissary-apiext. This is the APIserver extension that supports converting Ambassador Edge Stack CRDs between getambassador.io/v2and getambassador.io/v3alpha1. This Deployment needs to be running at all times.
If the emissary-apiext Deployment's Pods all stop running, you will not be able to use getambassador.io/v3alpha1 CRDs until restarting the emissary-apiext Deployment.
There is a known issue with the emissary-apiext service that impacts all Ambassador Edge Stack 2.x and 3.x users. Specifically, the TLS certificate used by apiext expires one year after creation and does not auto-renew. All users who are running Ambassador Edge Stack/Emissary-ingress 2.x or 3.x with the apiext service should proactively renew their certificate as soon as practical by running kubectl delete --all secrets --namespace=emissary-system to delete the existing certificate, and then restart the emissary-apiext deployment with kubectl rollout restart deploy/emissary-apiext -n emissary-system. This will create a new certificate with a one year expiration. We will issue a software patch to address this issue well before the one year expiration. Note that certificate renewal will not cause any downtime.
Delete Ambassador Edge Stack 2.0.5 Deployment.
Delete only the Deployment for Ambassador Edge Stack 2.0.5 in order to preserve all of your existing configuration.
Use kubectl to delete the Deployment for Ambassador Edge Stack 2.0.5. Typically, this will be found
in the ambassador namespace.
Install Ambassador Edge Stack 2.3.2.
After installing the new CRDs, use Helm to install Ambassador Edge Stack 2.3.2. Start by
making sure that your datawire Helm repo is set correctly:
Then, install Ambassador Edge Stack in the ambassador namespace. If necessary for
your installation (e.g. if you were running with AMBASSADOR_SINGLE_NAMESPACE set),
you can choose a different namespace.