This process enables you to first upgrade
the CN-MGMT StatefulSet and then upgrade the CN-NGFW pods. The disruption
to application traffic is minimal because the CN-NGFW pods are functioning
during the CN-MGMT StatefulSet upgrade, and the rolling update for
the CN-NGFW pods occurs one instance of the CN-NGFW pod at a time.
If
you have a large Kubernetes cluster with a significant number of
CN-NGFW pods and want a faster upgrade, you can schedule a maintenance
window to delete the CN-NGFW yaml and upgrade all CN-NGFW pods at
once.
During the CN-MGMT upgrade, logging is impacted. Additionally,
both kubectl logs and System log messages are generated for temporary
version mismatch and connection restarts between the CN-NGFW and
the CN-MGMT pods.