I am trying to set up a maintenance_window so that updates can be applied (reboot) over the night. The thing that I ran accross (i do not no if this is by design or no) is that IncusOS will no longer check for updates outside of that maintenance window.
If my understanding is correct, that means that both the update check and the apply should occurs during that configured maintenance window.
I configured it the following way but I just want to make sure this is the appropriate way…
IncusOS doesn’t have separate download and apply stages, so the updates are both pulled and applied during the window.
It’s something that could in theory be changed now that we support having multiple images for applications too, effectively allowing for the OS image to be downloaded and setup for next boot and then application images to be downloaded and not switched to, but that’s adding even more logic to a reasonably complex part of the codebase.
I think the maintenance window logic should be behaving as expected; the config posted above should give the desired result of automatically applying updates only during the overnight window.
The image server holds at most 3 images, so waiting a week to download an image may be problematic as depending on the week, by the time you’ll attempt the download, the image will have expired
Given just about every update these days also has at minimum some high severity Linux kernel fixes, we generally don’t want to hold onto old images for too long.
We’ve got a bunch of work being done around individual component updates and application version locking and such being done as part of some Operations Center work, so that may bring in some extra flexibility and APIs to IncusOS.
Speaking of, if you’re managing a fleet of IncusOS boxes, Operations Center could be useful for that as you can have it pull the latest stable IncusOS images into a “staging” channel within Operations Center, have some servers set to consume that channel while the rest are on an internal “stable” channel.
When managed by Operations Center, servers never look for updates, instead they wait for the user to trigger an update on a specific server or cluster which then pulls the latest image in the channel that the server/cluster uses.
I am running the Operations Center inside a VM on IncusOS. I think it should be able to manage the host on which it is running and being able to update it. If you run a cluster, then a really cool feature of OC is a rolling update, which, in theory, should prevent you from braking the cluster as a result of update since each cluster member is automatically evacuated before applying the update.