Docs/ Operations/ Updates & Diagnostics

Updates & Diagnostics

Keep sh0 current, go back when a release misbehaves, and check the host before you blame the app.

Updating sh0

Run the update on the server. It looks up the latest final release on GitHub, downloads the archive for your architecture, checks it against the published checksums, and replaces the binary. The version it replaces is kept for a rollback.

Terminal
sudo sh0 update
Output (already up to date)
* sh0 self-update
  Current version: v1.10.3-rc9

  Checking for updates...
  [+] Already running the latest version (v1.10.3-rc9).

In an interactive terminal, sh0 asks before restarting the service. With --yes it restarts without asking. Run from cron, a pipe or a script without --yes, it never restarts and says so first.

Channels

By default the update follows the stable channel: final releases only. --channel beta installs the newest pre-release instead. --force installs the channel’s version even when it is not newer, which is how you go back to an older release.

Rolling Back

--rollback puts back the version that the last update replaced. Use it when a release misbehaves right after an update.

What Keeps Running

Your applications are Docker containers: restarting sh0 does not stop them. The reverse proxy in front of them also stays up, as long as the service unit keeps KillMode=process, which the installer sets (see Installation).

Note
Database migrations of sh0 itself run automatically when the new version starts.

Checking the Host with sh0 doctor

Run sh0 doctor on the server when something looks wrong, before an update, or right after installing. It needs no login and changes nothing.

Terminal
sudo sh0 doctor
Output
sh0 doctor préflight d'hôte
  données : /var/lib/sh0

   OK  docker                     démon joignable -- version 29.8.1, API 1.56, linux/amd64, 2 conteneurs (2 en marche)
   OK  port 80                    tenu par `caddy` -- c'est notre propre pile
   OK  port 443                   tenu par `caddy` -- c'est notre propre pile
   OK  port 9000                  tenu par `sh0` -- c'est notre propre pile
   OK  disque                     /var/lib/docker : 20.5 % occupés, 119.2 Gio libres sur 149.9 Gio
   OK  certificats                1 actif(s) (1 par Caddy, 0 téléversé(s), 35 interne(s) hors seuil), le plus proche expire dans 88 j (demo.sh0.dev)
   OK  panneau (domaine)          demo.sh0.dev servi en HTTPS, certificat valable jusqu'au 2026-12-29
  WARN panneau (exposition)       HTTPS en service, mais le port 9000 répond encore en clair sur 5.78.182.107
   OK  horloge                    synchronisée, décalage mesuré 0 s
   OK  Applications sans projet   toutes les applications sont rattachées à un projet

  des avertissements, rien de bloquant  (code de sortie 0)
Note
In the current version, the report is printed in French.

Each line is one check: Docker, the ports sh0 needs (80, 443 and the panel port), free disk space, certificates close to expiry, the panel domain and whether the panel still answers in plain HTTP, the clock, and apps left outside any project. A WARN line points at something to fix; it does not block.

Exit Codes

  • 0: nothing blocks (warnings may remain).
  • 1: at least one blocking problem.
  • 2: a check could not run. A check that did not run is never reported as passed.

Add --json for machine-readable output, for example in a monitoring script.

Database Checks

Two read-only subcommands inspect the sh0 database for leftovers of older versions:

  • sh0 doctor backup-rows counts restore records that an earlier migration could not reach.
  • sh0 doctor bind-mounts lists host mounts that the current mount rules would refuse.