Upgrade the Kubernetes Components
Refresh the chart metadata first, then upgrade each release. Always capture the current values before upgrading:
helm repo update
helm get values <release-name> -n <namespace> > <release-name>-current-values.yamlUpgrading the Secrets Management Agent
Delete the existing agent secret before upgrading. The chart doesn't merge the secret idempotently, and an upgrade performed without this step can leave newly introduced keys missing, causing the Agent to fail at startup.
kubectl delete secret aapm-agent-secrets -n ns-agent
helm upgrade kron-aapm-agent kron-pam/kron-aapm-agent \
--namespace ns-agent \
--set secrets.installToken="<KRON_PAM_AAPM_AGENT_INSTALLATION_TOKEN>" \
--set secrets.address="<KRON_PAM_SERVER_ADDRESS>" \
--set config.singleconnect.agentName="<AGENT_NAME>" \
--set config.singleconnect.sslIgnored=false \
--set config.singleconnect.hostnameIgnored=false \
--set image.pullPolicy=AlwaysRegistration is consumed at first install. If the Agent has to register again after the upgrade, a new installation token may be required. Add --set image.pullPolicy=Always whenever a new build was pushed under the same image tag; otherwise Kubernetes reuses the cached image and the upgrade has no effect.
Upgrading aapm-service
helm upgrade aapm-service kron-pam/aapm-service \
--namespace kron-pam-aapm \
-f service-values.yamlVerify as described in the aapm-service verification section. Note that any active kubectl port-forward is terminated when the pod is recreated and must be restarted.
Upgrading the Injector
helm upgrade kron-aapm-sidecar kron-pam/kron-aapm-sidecar \
--namespace ns-sidecar \
--reuse-values \
--set sidecarImage.tag="<VERIFIED_IMAGE_TAG>"
kubectl rollout restart deployment/kron-aapm-sidecar -n ns-sidecar
kubectl rollout status deployment/kron-aapm-sidecar -n ns-sidecar --timeout=60sThe kubectl rollout restart step is mandatory. Without it, the injector keeps serving the previous ConfigMap and image reference from memory, and even newly created pods are injected with the old configuration. Upgrading the injector does not re-inject pods that are already running. Existing workloads must be recreated to receive the new sidecar configuration, either with kubectl delete pod -n <TARGET_NAMESPACE> or with kubectl rollout restart deployment/ -n <TARGET_NAMESPACE>.

Upgrade Flags | |
|---|---|
Flag | When to use it |
--reuse-values | Keep all previously set values and change only the ones passed explicitly on this command |
--reset-values | Discard previous values and fall back to chart defaults plus what is passed now |
-f <file> | Supply the full desired value set from a file (recommended) |
--set image.pullPolicy=Always | A new build was pushed under an unchanged image tag |
--atomic --timeout 5m | Roll back automatically if the upgrade does not become ready in time |