Maintenance

Routine update/upgrade procedures per deployment type.

Helper-script LXCs

  • Primary: run update in the container console (the helper-script updater).
  • Fallback for some: apt dist-upgrade.

QEMU VMs

  • apt dist-upgrade inside the guest.

Before risky upgrades

Snapshot-first for anything stateful:

  1. Fresh vzdump to the backups storage (Datacenter → Backup → run now).
  2. Run the upgrade.
  3. Verify service-specific extras (e.g. OIDC plugin).

Host (Proxmox VE)

  • PVE updates via apt on the host; check the forum/release notes for major version jumps.
  • Tailscale on the host keeps management access during network changes — but have lockout-recovery handy anyway.

Scheduled jobs

  • Automated backups exist since 2026-09: two Datacenter → Backup jobs (lxc-suspend + vm-snapshot pools, Mon/Thu, backups storage, keep-last=5) — details in storage. Remaining gap is an offsite copy, tracked in TODO.