Skip to main content

tare upgrade

Upgrade an existing Agent Router data plane release. By default uses the chart
embedded in this tare binary. Pass --chart-version <v> to fetch a specific
chart version from the OCI registry instead — lets operators upgrade
without downloading a new tare binary.

Reads the live release's Helm values so operator-supplied config
(registry, namespaces, --customer, OTel endpoint) is carried forward
without re-prompting — pass flags to override individually.

Refuses to fresh-install (use 'tare install' for that). Refuses to
upgrade single-replica installs without --allow-downtime, because
rolling a single data-plane Envoy pod RSTs any in-flight LLM streams.

Defaults to helm upgrade --atomic so a failed rollout auto-rolls back
to the previous revision. Pass --no-atomic to leave a stuck release
in place for debugging.

The CRD apply step is run explicitly because Helm's crds/ directory is
install-only — chart upgrades that introduce new CRD fields would
otherwise be silently ignored.

Image sync is NOT performed by this command. Sync new images to your
registry first with 'tare install --image-sync <REG> --sync-only',
then run 'tare upgrade'.

Examples:
# Standard upgrade after replacing the tare binary
tare upgrade identity.json

# Force-upgrade a single-replica install (drops in-flight streams)
tare upgrade identity.json --allow-downtime

# Override the carried-forward image registry
tare upgrade identity.json --image-registry acme.registry.com

Usage:
tare upgrade <identity-file> [flags]

Flags:

Main:
--acknowledge-unsafe-rollback Proceed with an upgrade the release marks not rollback-safe. Auto-rollback (--atomic) is disabled so a failed upgrade is left in place for manual recovery.
--allow-downtime Proceed even if the data-plane is single-replica (drops in-flight requests). Use only on lab installs you intend to migrate later.
--drain-timeout-seconds int EnvoyProxy.spec.shutdown.drainTimeout (seconds). Maximum time Envoy waits for in-flight requests (long LLM streams) to finish before SIGKILL. (default 300)
--enable-semantic-router Override semantic-router enable state (default: carry forward from existing release)
--ha HA-safe defaults for the data-plane Envoy proxy (HPA min 2, PDB min 1). Pass --ha=false to keep single-replica. (default true)
--no-atomic Disable helm --atomic (no auto-rollback on failure). Leaves stuck releases in place for debugging.
--timeout string Helm upgrade --wait timeout. Should exceed drainTimeout × replicas to allow serial drain. (default "10m")


Telemetry:
--enable-otel-collector Override OTel collector enable state (default: carry forward from existing release)
--otel-collector-endpoint string Override OTel OTLP endpoint (default: carry forward from existing release)
--otel-exporter-auth-headers string Override OTel Authorization header value


Networking:
--forward-proxy-address string Override ai-gateway.controller.forwardProxyAddress (envoy's LLM forward-proxy host:port). Default: carry forward from existing release; absent in the release + --http-proxy on is treated as a previous explicit disable and preserved. Pass --forward-proxy-address="" to disable the LLM tunnel while keeping --http-proxy on for the controller.
--forward-proxy-no-proxy strings Override the per-host opt-out list for envoy's LLM forward-proxy egress (default: carry forward). Comma-separated host-name suffixes (e.g. .openai.azure.com); leading dot tolerated.
--http-proxy string Override HTTP_PROXY env on controller/worker/envoy pods, and (by default, host:port-derived) the ai-gateway-controller's EGRESS_FORWARD_PROXY_ADDRESS that drives envoy's HTTP CONNECT egress for LLM upstreams (default: carry forward from existing release; pass --http-proxy="" to clear). Use --forward-proxy-address to override or disable the envoy-side derive without touching the in-pod HTTP_PROXY.
--https-proxy string Override HTTPS_PROXY env on controller/worker/envoy pods (default: carry forward; pass --https-proxy="" to clear)
--no-proxy string Override NO_PROXY env on controller/worker/envoy pods (default: carry forward; pass --no-proxy="" to clear)
--upgrade-manifest-base-url string Override the self-upgrade release-manifest base URL (default: carry forward from existing release)
--upgrade-manifest-certificate-identity-regexp string Override the trusted Sigstore certificate identity regexp (default: carry forward from existing release)
--upgrade-manifest-certificate-oidc-issuer string Override the trusted Sigstore OIDC issuer (default: carry forward from existing release)


Other:
--argocd-namespace string Namespace where ArgoCD Applications live; pre-check uses this to detect mixed-deployment (default: argocd). Set to empty string to disable the check.
--clear-tolerations Drop the data plane's pod tolerations instead of carrying them forward. Omitting --toleration now preserves the release's tolerations, so this is the only way to remove them; the pods it moves may not be schedulable anywhere else. Conflicts with --toleration.
--enable-metrics-server Override metrics-server enable state (default: carry forward from existing release)
--force-gateway-api-crds Apply the Gateway API CRDs bundled with this chart even when the cluster already serves them, overriding the Gateway API version-floor check (also TARE_FORCE_GATEWAY_API_CRDS=1). Use only where tare manages the Gateway API CRDs on this cluster: where a managed addon owns them (GKE, EKS, AKS), the apply takes field ownership that the addon's reconciler will take back. It applies the bundled CRDs only when the cluster is at or below the version this build requires; it will not downgrade a cluster that is ahead.
--ignore-argocd Proceed even when ArgoCD manages the system namespace.
--ignore-flux Proceed even when a Flux HelmRelease manages the system namespace (mixed-deployment override).
--smoke-api-key string Inference API key for the post-apply data plane smoke tests. Prefer TARS_API_KEY — a key passed here lands in shell history and the process list. Mint one from the management-plane dashboard. Without it, only the credential-free auth check runs.
--smoke-mcp-route string MCP route path to establish a post-apply session against (e.g. /mcp/<profile-id>). Omit to skip.
--smoke-model string Model to send a real post-apply request to (e.g. gpt-4o-mini). Requires --smoke-api-key. Spends a few tokens on the named model to prove inference and streaming work end to end. Omit to skip.
--smoke-timeout duration Per-request timeout for the post-apply data plane smoke tests. (default 30s)
--toleration stringArray Pod toleration applied to every data-plane component that schedules on tainted nodes: egress envoy, redis, ratelimit, the label-namespace Job, tareDoctor CronJob, and the configMonitor CronJob (when enabled). Repeatable. Format: key[=value]:effect[:tolerationSeconds]. Examples: --toleration nodepool:NoSchedule (Exists), --toleration nodepool=workload:NoSchedule (Equal). effect ∈ NoSchedule|PreferNoSchedule|NoExecute. Omitting this flag carries the release's existing tolerations forward; pass --clear-tolerations to drop them. Per-component overrides are dashboard-only — use the "Build install values" form to taint a single component differently from the rest.