Infrastructure maintenance¶
You can see your server's infrastructure version on the servers list in the Dashboard. For Infrastructure 7, check for available updates in the server's settings. For other infrastructure changes, contact our support team to schedule an upgrade.
Current Wodby 1 infrastructure lines
Infrastructure 7.0.1 is the default for fresh servers. Infrastructure 6.0.4 is the latest legacy release for existing Infrastructure 6 servers.
No in-place 6 to 7 upgrade
Infrastructure 7 requires a fresh Ubuntu 26.04 or Debian 13 server. Migrate or redeploy applications from Infrastructure 6 instead of running Installer 2.x on the existing host.
You will be notified each time a new version of the infrastructure is released.
Infrastructure 7 maintenance¶
Infrastructure 7 installs exact versions of Docker, Kubernetes, containerd, cri-dockerd, and networking packages and places the apt packages on hold. Do not upgrade these components independently. Contact Wodby support before changing a control-plane component or upgrading the host operating system.
Agent updates are not installed automatically. Apply available infrastructure updates from the Dashboard as described below. Use the Agent update command when instructed by support.
Updating from the Dashboard¶
The Dashboard shows updates available for your server. Review the release summary to see what will change. If you need an update that is not offered, contact Wodby support.
Traffic interruption
Updates that restart Edge briefly interrupt HTTP and HTTPS traffic to applications on the server. Review the update warnings and schedule a suitable maintenance window before proceeding.
You need permission to update the server. The server must be available, and active server and application tasks must finish before you start the update.
- Open the server's settings in the Dashboard and find Infrastructure update.
- Select Check server for update. Checking the server does not apply the update.
- Review the source and target versions, release summary, affected application instances, and warnings. Resolve any reported blockers before proceeding.
- Select the acknowledgement checkbox, then Update infrastructure.
- Select View update task and logs to follow progress. You can leave the page and return later.
- After the update completes, check that your applications are accessible over HTTP and HTTPS and behave as expected.
A preview expires after 15 minutes. Run the checks again if it expires or the server configuration changes. Each user must run their own checks before confirming an update.
During the update, deployments and other changes to the server are blocked. You cannot cancel the update or delete the server while maintenance is in progress. The Dashboard shows the new infrastructure version once the update has been verified.
If an update does not complete¶
If an update fails or your connection is lost, reopen the server's settings and check the task status before retrying.
If the Dashboard shows Update outcome needs verification, the server remains in maintenance. Wait until the displayed recovery time, then select Check update status when it becomes available. This checks whether the update completed; it does not repeat the update.
If the update was not applied, review the task log, resolve any reported problem, and run new checks before retrying. If the server remains in maintenance after checking its status, contact Wodby support and include the update task link.
Infrastructure 6 OS upgrade tips¶
Create snapshot of your VM first
Before performing the upgrade regardless of the method we strongly recommend creating a snapshot of your server if it's a VM.
Test your upgrades with the dev server first
Make sure your prod and dev server are from the same cloud provider and have the same OS distribution/version. After successfully upgrading the dev server and testing all the hosted apps you should continue to upgrading your production server.
These instructions apply only to existing Infrastructure 6 servers. They do not turn an Infrastructure 6 server into Infrastructure 7.
When upgrading an Infrastructure 6 host to a previously supported operating-system version:
- Stop Kubernetes and Docker services first
- Perform the upgrade
- Reboot
- Make sure Docker was not installed from packages (we require a specific version that we manuall install during server connection)
- Check iptables version via
iptables --version. If it's1.8.2or newer switch it to legacy mode:update-alternatives --set iptables /usr/sbin/iptables-legacy - Make sure cgroup v2 is disabled
Infrastructure 6 cgroup2 workaround¶
Some operating systems such as Debian 11 enable cgroup v2, which is not supported by the Docker version used by Infrastructure 6. To retain Infrastructure 6 compatibility:
- Edit /etc/default/grub and add systemd.unified_cgroup_hierarchy=0 to GRUB_CMDLINE_LINUX_DEFAULT (or GRUB_CMDLINE_LINUX if it's not present)
- Run update-grub
- Reboot the server
Changelog¶
7.0.1¶
- Updated Edge to 3.0.9, including NGINX 1.31.3 → 1.31.6.
7.0.0¶
Fresh-server Infrastructure 7 release:
- Added Ubuntu 26.04 and Debian 13 amd64 support
- Kubernetes 1.36.3
- Docker Engine 29.7.2 with containerd 2.3.3 and cri-dockerd 0.4.4
- Canal 3.32.1, combining Calico policy with the Flannel VXLAN data plane
- etcd 3 using the direct v3 API
- Wodby Edge 3.0.0 with support certificates for technical domains
- Wodby Agent 5.5.0
6.0.4¶
Containers' anonymous volumes now clean up by cron
6.0.3¶
large_client_header_buffersset to4 32k- Removed obsolete
http2_max_field_size
6.0.2¶
Edge's nginx updated to 1.24
6.0.1¶
Bugfix: wodby agent couldn't process certain message
6.0.0¶
Upgraded Docker version
5.9.2¶
Wodby agent now supports connection via http proxy
5.9.1¶
Node domain changed from wod.by to wodby.cloud
5.9.0¶
- Added support for Debian 11 and other OSs with cgroup2 enabled by default
- Add a custom seccomp profile for Docker as a workaround for faccessat2 issue in Alpine Linux 3.14+
- ⚠️ This upgrade will cause docker daemon restart, all containers on your server will be restarted
5.8.6¶
Client max body size no longer limited on edge
5.8.5¶
Bugfix: keepalive_requests wasn't increased to 1000
5.8.4¶
- Edge: Nginx 1.19.10
keepalive_requestsincreased to1000https://github.com/wodby/edge-alpine/pull/1
5.8.3¶
Edge: fixed error_log level to avoid significant error log growth in some cases
5.8.2¶
Kubernetes: fixed issue when servers from some cloud providers like Linode failed to start up containers
5.8.1¶
- Edge: Nginx 1.19.8
- Edge: OpenSSL 1.1.1k (major security update)
- Kubernetes: fixed known issue with a sporadic container logs absence
5.8.0¶
Edge: improved security by generating Let's Encrypt SSL certificate for default virtual host
5.7.10¶
Edge: fixed renewing of SSL certificates for domains with a redirect from www to non-www version (and vice versa) enabled
5.7.9¶
Edge: improved security settings of default Nginx virtual host
5.7.8¶
Edge: improved and actualized SSL security settings
5.7.7¶
Docker images clean up added to cron (run every night at 2:30)
5.7.6¶
Edge: fixed renewing Let’s Encrypt SSL certificates via ACME v2
5.7.5¶
Edge: upgraded Let’s Encrypt client
5.7.4¶
Edge: increased value of http2_max_field_size parameter
5.7.3¶
Edge security update for HTTP/2 (CVE-2019-9511, CVE-2019-9513, CVE-2019-9516)
5.7.2¶
Globally disable TLS 1.0, 1.1 for all hosts
5.7.1¶
Bugfix: edge regenerates dh params after restart
5.7.0¶
- Nginx updated to 1.16.0
- TLS 1.0, 1.1 disabled. Added TLS 1.3 support
5.6.1¶
Bugfix: in some cases Diffie-Hellman params failed to generate after the first server connection
5.6.0¶
- Nginx updated to 1.15.10
- Docker log size limited to 100M
- Docker systemd unit max tasks set to unlimited
- Bugfix: low files upload speed with HTTP2
5.5.8¶
Added HTTP2 support
5.5.7¶
Edge: DH key length increased to 2048 and now persistent
5.5.6¶
Security fix: server's metrics could be publicly accessible
5.5.5¶
Bugfix (5.5.4): installer did not report changes to IP address
5.5.4¶
Updates to installer, you don't need to update from the previous version
5.5.3¶
HSTS can now be configured per domain
5.5.2¶
Security vulnerability fix for dnsmasq CVE-2017-14491
5.5.1¶
- Increased kernel param
aio-max-nrfor databases - Updated paths for systemd unit files
- Uninstall fixes
5.5.0¶
- New Docker 17.06.1
- Improved response codes on Edge
5.4.1¶
- Updated Let's Encrypt client
5.4.0¶
- AUFS replaced with Overlay2
- Identified a bug in Debian Kernel 3.16, required upgrade to 4.9
- Fixed a bug with kube-controller service definition that sometime caused deployment failures
5.3.0¶
- New kubernetes version
- Improved agent installer
- Enabled unattended upgrades
- Significantly improved performance (less load on CPU and disk IO)
5.2.0¶
- Decoupled services for system containers
- Improved agent installer
- Bug fixes
5.1.0¶
- Revamped DNS services
- Improved agent installer
- Bug fixes
5.0.0¶
- New kubernetes
- New installer with frozen docker version
- Revamped wodby agent
4.x¶
First version of cluster infrastructure
3.5.0¶
- Updated Nginx (1.10.1) for a system container Edge
- New version of Wodby agent supporting containers upgrade
- New version of orchestration system
Release date: July 1st, 2016
3.4.0¶
includeSubdomainsoption removed from HSTS header- Now
X-Robots-Tagheader added always (not only for 20x, 30x response codes) - New version of Wodby agent. Now with automated infrastructure update (will be announced later)
- Exif extension added to PHP 5.6, 7
- Fixed bug when
X-Wodby-Nodeheader missed sometimes - Added default nginx host for port 443 with self-signed certificates
Release date: June 16th, 2016
3.3.0¶
- $base_url orchestration for Drupal
- Auto generation of trusted host patterns for Drupal 8
- Drupal 7.x, 8.x multi-site support
- Drupal 8 and WordPress now come with PHP7 and Redis
- msmtp + opensmtpd replaced with postfix
- Workaround for Drupal
sites/defaultauto permissions change. This caused problems when settings.php file was changed
3.2.0¶
- WWW redirect actions for domains
- Basic auth configuration
- Maintenance mode
- Dev, staging instances and all instances accessible by technical
*.wod.bydomains not indexed by search engines (header X-Robots-Tag)
3.1.0¶
- Enable HTTPS for domains (SSL certificates via Let's Encrypt)
- Backup mirroring features added.
3.0.0¶
The latest stable version with completely reworked containers structure.
2.0.0¶
In this version we've moved git to the docroot and made major structural changes.
1.0.0¶
Production-ready version with lots of improvements.
0.1.0¶
The first public version of our infrastructure.