Upgrades
Preserve data and credentials, and test recovery before changing versions.
Before changing an image
The Dockerfiles pin Elastic images by version and digest. Read Elastic's release notes and upgrade documentation for the source and target versions. Change Elasticsearch, Logstash, and Kibana as a compatible set.
Record the verified source revision, image digests, variable references, volume mounts, and healthchecks. Keep original credentials and Kibana encryption keys in a protected recovery inventory.
Backup and rehearsal
Stop producers for a consistent recovery checkpoint. Configure an owner-controlled snapshot repository using Elastic's supported snapshot and restore process.
Verify the repository, create a snapshot including global state and the security and kibana feature states, and require SUCCESS with no failed shards. Restore into a separate empty stack of the same version and verify saved objects, login, document identities, and an ingest/search canary.
External snapshot restoration has not been tested in the template without owner-provided storage. A volume redeploy is not a backup.
Apply and verify
Follow Elastic's compatible upgrade order. Keep the old stack and verified snapshot until recovery is proven. Verify Elasticsearch authentication and readiness, Logstash intake and indexing, Kibana login, and saved views. Send a unique event and search its original fields.
Rollback or fix-forward
For a configuration-only change with unchanged image versions and data format, redeploy the last verified source with unchanged secrets and volumes. Run the same ingest/search canary.
An older image does not reverse an Elasticsearch data-format upgrade. Do not downgrade against an upgraded data volume. Restore the verified snapshot into a separate stack running the original compatible version, or follow Elastic's supported fix-forward path.
Existing index migrations
Existing fixed elk-logs indices and mappings are preserved on restart. Stop producers, verify a snapshot, and create a distinct alias and policy. Grant the writer access to the new prefix and change Logstash and Kibana together. Keep old data searchable in a separate view. Never delete or rename the original index to force alias creation.
The template's OPERATIONS.md contains the detailed lifecycle, credential rotation, DLQ inspection, and recovery procedures.