Update AI/Run CodeMie Core Components
This guide provides comprehensive instructions for updating an AI/Run CodeMie deployment to the latest version. The update process is streamlined and supports all major cloud providers.
Regular updates ensure optimal performance, security patches, and access to the latest features.
Components to Update
This update process will upgrade the following AI/Run CodeMie components:
- CodeMie MCP Connect - Model Context Protocol integration service
- Mermaid Server - Diagram rendering service
- CodeMie NATS Auth Callout - Message bus authentication service
- CodeMie UI - Frontend application
- CodeMie API - Backend services and APIs
Prerequisites
Before beginning the update process, ensure the following are in place:
Required Access and Tools
- Access to the codemie-helm-charts repository
kubectlconfigured with access to the Kubernetes cluster (EKS/AKS/GKE)- Helm 3.16.0 or higher installed
- Local copy of
codemie-helm-chartsrepository with values from initial deployment
Pre-Update Checklist
- Review the latest release notes
- Create backups of critical data and configurations
- Verify cluster resources are sufficient
- Confirm maintenance window with stakeholders
Helm Registry Authentication
Before updating, authenticate with the AI/Run CodeMie Helm registry:
export GOOGLE_APPLICATION_CREDENTIALS=key.json
gcloud auth application-default print-access-token | helm registry login -u oauth2accesstoken --password-stdin europe-west3-docker.pkg.dev
All update operations require valid Helm registry authentication. Ensure credentials are current before proceeding.
Mirroring CodeMie container images to a client-owned private registry isolates the
Kubernetes cluster from GCP Artifact Registry credential issues. The cluster pulls images
from the client registry, so an expired gcp-artifact-registry secret does not cause
ImagePullBackOff errors in pods.
The GCP service account key still requires rotation on the same 90-day cycle. However, the rotation applies to the image mirroring pipeline — the process responsible for pulling images from the CodeMie registry and pushing them to the client registry — rather than to the Kubernetes cluster itself.
A private registry can be provisioned using the Terraform automation included in the deployment repository, or an existing self-hosted registry can be used.
Update Methods
Choose the update method that best suits the operational requirements:
- Automated Update: Recommended for most deployments. Uses a script to update all components in the correct sequence.
- Manual Update: Provides granular control over the update process. Useful for troubleshooting or staged rollouts.
Automated Update (Recommended)
The automated update script ensures all components are updated in the correct order with minimal manual intervention.
Update Command
Replace x.y.z with the target version (e.g., 2.2.5):
- AWS
- Azure
- GCP
bash helm-charts.sh --cloud aws --version x.y.z --mode update
Example:
bash helm-charts.sh --cloud aws --version 2.2.5 --mode update
bash helm-charts.sh --cloud azure --version x.y.z --mode update
Example:
bash helm-charts.sh --cloud azure --version 2.2.5 --mode update
bash helm-charts.sh --cloud gcp --version x.y.z --mode update
Example:
bash helm-charts.sh --cloud gcp --version 2.2.5 --mode update
Update Sequence
The automated script updates components in the following order to ensure compatibility:
- CodeMie MCP Connect - Model Context Protocol integration service
- Mermaid Server - Diagram rendering service
- CodeMie NATS Auth Callout - Message bus authentication service
- CodeMie UI - Frontend application
- CodeMie API - Backend services and APIs
Manual Update
For advanced users requiring granular control over the update process or performing staged rollouts, manual component updates can be performed individually.
Step 1: Update CodeMie MCP Connect Service
Update the Model Context Protocol integration service.
Replace x.y.z with the target version (e.g., 2.2.5):
helm upgrade --install codemie-mcp-connect-service \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie-mcp-connect-service \
--version x.y.z \
--namespace "codemie" \
-f "./codemie-mcp-connect-service/values.yaml" \
--wait --timeout 600s
Step 2: Update Mermaid Server
Update the diagram rendering service.
Replace x.y.z with the target version (e.g., 2.2.5):
helm upgrade --install mermaid-server \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/mermaid-server \
--version x.y.z \
--namespace "codemie" \
-f "./mermaid-server/values.yaml" \
--wait --timeout 600s
Step 3: Update CodeMie NATS Auth Callout
Update the message bus authentication service with cloud-specific configuration.
Replace x.y.z with the target version (e.g., 2.2.5):
- AWS
- Azure
- GCP
helm upgrade --install codemie-nats-auth-callout \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie-nats-auth-callout \
--version x.y.z \
--namespace "codemie" \
-f "./codemie-nats-auth-callout/values-aws.yaml" \
--wait --timeout 600s
helm upgrade --install codemie-nats-auth-callout \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie-nats-auth-callout \
--version x.y.z \
--namespace "codemie" \
-f "./codemie-nats-auth-callout/values-azure.yaml" \
--wait --timeout 600s
helm upgrade --install codemie-nats-auth-callout \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie-nats-auth-callout \
--version x.y.z \
--namespace "codemie" \
-f "./codemie-nats-auth-callout/values-gcp.yaml" \
--wait --timeout 600s
Step 4: Update CodeMie UI
Update the frontend application with cloud-specific configuration.
Replace x.y.z with the target version (e.g., 2.2.5):
- AWS
- Azure
- GCP
helm upgrade --install codemie-ui \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie-ui \
--version x.y.z \
--namespace "codemie" \
-f "./codemie-ui/values-aws.yaml" \
--wait --timeout 180s
helm upgrade --install codemie-ui \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie-ui \
--version x.y.z \
--namespace "codemie" \
-f "./codemie-ui/values-azure.yaml" \
--wait --timeout 180s
helm upgrade --install codemie-ui \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie-ui \
--version x.y.z \
--namespace "codemie" \
-f "./codemie-ui/values-gcp.yaml" \
--wait --timeout 180s
Step 5: Update CodeMie API
Update the backend services and APIs with cloud-specific configuration.
Replace x.y.z with the target version (e.g., 2.2.5):
- AWS
- Azure
- GCP
helm upgrade --install codemie-api \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie \
--version x.y.z \
--namespace "codemie" \
-f "./codemie-api/values-aws.yaml" \
--wait --timeout 600s
helm upgrade --install codemie-api \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie \
--version x.y.z \
--namespace "codemie" \
-f "./codemie-api/values-azure.yaml" \
--wait --timeout 600s
helm upgrade --install codemie-api \
oci://europe-west3-docker.pkg.dev/or2-msq-epmd-edp-anthos-t1iylu/helm-charts/codemie \
--version x.y.z \
--namespace "codemie" \
-f "./codemie-api/values-gcp.yaml" \
--wait --timeout 600s
Step 6: Verify Update Success
After updating all components, verify the deployment status:
kubectl get pods -n codemie
Success Criteria:
- All pods are in
Runningstate - No pods are in
CrashLoopBackOfforErrorstate
Functional Testing
- Access the UI - Verify the web interface loads correctly
- Test Authentication - Confirm user login functionality
- Create Assistant - Validate core functionality
- Review Logs - Check for any error messages or warnings
Troubleshooting
Use these troubleshooting steps if issues arise during or after the update:
Image Pull Errors
Symptoms:
- Pods show
ImagePullBackOfforErrImagePullstatus - Error messages indicate authentication failures
- Container images cannot be downloaded from the registry
Resolution:
Service account keys have a 90-day retention period and expire automatically after this time. If authentication continues to fail after re-authentication attempts, the key.json service account key has likely expired.
To resolve expired keys:
- Request a new service account key from the administrator or support team
- Replace the expired
key.jsonfile with the newly provided key - Re-authenticate using the new credentials
- Update the image pull secret in the Kubernetes cluster
Contact the support team to obtain a new service account key for registry access.
Support
For assistance with the update process:
- Review this documentation thoroughly
- Check the troubleshooting section for common issues
- Consult the FAQ for known issues
- Contact your support team with detailed error messages and logs