orca/docs/reference
Yunqian Fan aad34cbb32
docs(headless-server): add upgrade SOP for orca serve on Linux (#9575)
* docs(headless-server): add upgrade SOP for orca serve on Linux

The headless Linux guide covered install/run/systemd but had no upgrade
section, leaving operators to guess how to move to a new AppImage without
losing state.

Add an "Upgrade" section documenting the manual SOP (serve mode never
auto-updates) and one troubleshooting bullet:

- State lives under the service user's ~/.config (orca + Orca dirs),
  independent of /opt/orca, and orca-data.json is forward-migrated on load,
  so a forward upgrade is safe.
- Replace the binary with an atomic same-filesystem rename (download to
  .new, verify, mv) — never curl -o over the FUSE-mounted live binary.
- Back up the whole .config before upgrading, because rollback is NOT
  binary-only safe: an older build strips newer orca-data.json fields it
  doesn't recognize, and the .bak.* ring is corruption-recovery, not a
  pre-upgrade copy.
- Note there is no headless version command; track the release tag instead.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs(headless-server): harden the orca serve upgrade/rollback runbook

Address CodeRabbit review on #9575:

- Fail closed: run the upgrade block under `set -euo pipefail`, remove any stale
  `.new` file before download, and gate the atomic `mv` on an explicit ELF check
  so a failed/partial/non-ELF download can never be promoted.
- Keep /opt/orca/VERSION tied to the installed binary: a single `TAG` variable
  drives both the download URL and the recorded VERSION, saved as VERSION.prev on
  upgrade and restored on rollback so the audit file never drifts.
- Crash-loop troubleshooting now points to Roll back first (restores the
  pre-upgrade orca-data.json) instead of re-running Upgrade.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs(headless): harden server upgrade SOP

---------

Co-authored-by: fanyunqian.1 <fanyunqian.1@bytedance.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: OrcaWin <293788423+OrcaWin@users.noreply.github.com>
2026-07-20 21:38:39 -04:00
..
plans Fix native Windows PTY startup query handling (#9500) 2026-07-19 20:25:52 -07:00
git-compatibility.md fix(worktrees): stop surfacing prunable git worktrees as live workspaces (#8409) 2026-07-15 15:24:15 -07:00
headless-linux-server.md docs(headless-server): add upgrade SOP for orca serve on Linux (#9575) 2026-07-20 21:38:39 -04:00