# Updating a Palaver server

Prerequisite: server installed per [INSTALL.md](INSTALL.md)

Placeholders in the commands:

| Placeholder | Replace with |
|---|---|
| `0.3.1` | new Palaver release |
| `https://<release host>/lasse-tech/palaver/releases/download` | release download location, as in [INSTALL.md](INSTALL.md) |
| `chat.example.org` | your domain name (INSTALL.md blocks) |
| `<cert-name>` | certificate name, if it differs from the domain |
| `vi` | editor of your choice |

## Contents

1. [Release notes](#1-release-notes)
2. [Backup](#2-backup)
3. [Download Palaver](#3-download-palaver)
4. [palaverd](#4-palaverd)
5. [Web client](#5-web-client)
6. [Restart](#6-restart)
7. [LiveKit](#7-livekit)
8. [Check](#8-check)
- [Once: servers installed with install.sh](#once-servers-installed-with-installsh)
- [Back to the previous version](#back-to-the-previous-version)

## 1. Release notes

- read: release notes of every version after the installed one
- apply: changes listed there (configuration files, units, nginx, LiveKit version)

Show the installed version.

```sh
/opt/palaver/bin/palaverd version
```

## 2. Backup

Dump the database.

```sh
sudo -u palaver pg_dump -Fc palaver > "palaver-$(date +%F).dump"
```

Save the configuration.

```sh
sudo tar -czf "palaver-etc-$(date +%F).tar.gz" -C /opt/palaver etc
```

Keep the current palaverd for the way back.

```sh
sudo cp /opt/palaver/bin/palaverd /opt/palaver/bin/palaverd.old
```

## 3. Download Palaver

Download the server, the web client and the checksums.

```sh
curl -fLO "https://<release host>/lasse-tech/palaver/releases/download/v0.3.1/palaverd-0.3.1-linux-amd64"
curl -fLO "https://<release host>/lasse-tech/palaver/releases/download/v0.3.1/palaver-web-0.3.1.tar.gz"
curl -fLO "https://<release host>/lasse-tech/palaver/releases/download/v0.3.1/SHA256SUMS"
```

Verify both files; each line must end in `OK`.

```sh
sha256sum -c --ignore-missing SHA256SUMS
```

## 4. palaverd

Install the new palaverd.

```sh
sudo install -m 755 palaverd-0.3.1-linux-amd64 /opt/palaver/bin/palaverd
```

## 5. Web client

Unpack the new web client next to the old one.

```sh
sudo install -d -m 755 /opt/palaver/web.new
sudo tar -xzf palaver-web-0.3.1.tar.gz --no-same-owner -C /opt/palaver/web.new
sudo chmod -R u=rwX,go=rX /opt/palaver/web.new
```

Swap them.

```sh
sudo mv /opt/palaver/web /opt/palaver/web.old
sudo mv /opt/palaver/web.new /opt/palaver/web
```

## 6. Restart

Restart palaverd.

```sh
sudo systemctl restart palaverd
```

## 7. LiveKit

Only for a newer LiveKit in the release notes. Show the installed version.

```sh
/opt/palaver/bin/livekit-server --version
```

Download and install: [INSTALL.md, step 7](INSTALL.md#7-livekit), without the configuration.

Restart LiveKit; calls in progress drop.

```sh
sudo systemctl restart livekit
```

## 8. Check

Run doctor; expected: no findings.

```sh
sudo -u palaver /opt/palaver/bin/palaverd -env /opt/palaver/etc/palaverd.env doctor
```

Open the web client and log in.

**Destructive:** remove the previous web client (`/opt/palaver/web.old`, release files only).

```sh
sudo rm -r /opt/palaver/web.old
```

**Destructive:** remove the previous palaverd (`/opt/palaver/bin/palaverd.old`).

```sh
sudo rm /opt/palaver/bin/palaverd.old
```

## Once: servers installed with install.sh

- for: servers set up with `install.sh` (Palaver 0.2.x)
- once, after [step 8](#8-check)
- leftovers: helper script, install log, nginx site without the web snippet

Show the certificate name.

```sh
sudo ls /etc/letsencrypt/live/
```

Keep the old nginx site outside nginx's directories.

```sh
sudo cp /etc/nginx/sites-available/palaver "/root/nginx-palaver-$(date +%F).conf"
```

Web snippet `/etc/nginx/snippets/palaver-web.conf`: as in [INSTALL.md, step 9](INSTALL.md#9-web-client).

Site `/etc/nginx/sites-available/palaver`: full site as in [INSTALL.md, step 10](INSTALL.md#10-nginx-and-certificate).

Certificate name differs from the domain: open `/etc/nginx/sites-available/palaver` in an editor.

```sh
sudo vi /etc/nginx/sites-available/palaver
```

Change:

- `ssl_certificate`, `ssl_certificate_key`: `/etc/letsencrypt/live/chat.example.org/` → `/etc/letsencrypt/live/<cert-name>/`

Check and load it.

```sh
sudo nginx -t && sudo systemctl reload nginx
```

**Destructive:** remove the helper script (`/usr/local/sbin/palaverctl`).

```sh
sudo rm /usr/local/sbin/palaverctl
```

**Destructive:** remove the install log (`/var/log/palaver-install.log`).

```sh
sudo rm /var/log/palaver-install.log
```

**Destructive:** remove install.sh's certificate name file (`/opt/palaver/etc/cert`), if present.

```sh
sudo rm /opt/palaver/etc/cert
```

## Back to the previous version

- for: new version does not work
- database changes are not undone; if needed: dump from [step 2](#2-backup), as in [INSTALL.md, Restore](INSTALL.md#restore)

Put the previous palaverd back.

```sh
sudo cp /opt/palaver/bin/palaverd.old /opt/palaver/bin/palaverd
```

Put the previous web client back.

```sh
sudo mv /opt/palaver/web /opt/palaver/web.failed
sudo mv /opt/palaver/web.old /opt/palaver/web
```

Restart palaverd.

```sh
sudo systemctl restart palaverd
```
