Introduction
Starting with release 2026.1, upgrades are rolling by default. Instead of upgrading every Edge node or every AP at the same time, components upgrade a few at a time, in sequence. This keeps your site serving devices while the upgrade is in progress, instead of taking everything down together.
You start and track upgrades exactly as before, from the same pages. What changes is how the upgrade is paced, and how much per-component progress detail you can see while it runs.
Note: Rolling upgrade behavior applies to components that are already running 2026.1 or later. Components on an earlier release are upgraded using the previous behavior. The Orchestrator handles this automatically and no action is needed from you.
Accessing Upgrade Settings
Log in to the Celona Orchestrator using your Admin credentials.
On the main menu, navigate to Admin Settings → Software Upgrades.
The Software Upgrades page lists all the network components, such as Edges and APs, that can be upgraded.
How Rolling Upgrades Work
Edge nodes: one node at a time
In a multi-node Edge cluster, nodes upgrade one after another rather than all at once:
The first node hands off its active connections to the other node(s) in the cluster so it can be safely taken down.
That node upgrades and confirms it is healthy again.
Only then does the next node start, and so on through the cluster.
If a node fails partway through, the upgrade stops there. Nodes that have not started yet are left untouched on their current version. When you retry the upgrade, nodes that already completed successfully are skipped.
Edge nodes: automatic rollback on failure
If an Edge node's upgrade, or the health check that runs right after it, fails, the node automatically rolls back to its previous software version. The rollback is a fresh reinstall of the previous version. Automatic rollback applies to both on-premises Edge nodes and AerFlex (cloud-hosted) Edges.
Multi-node cluster: The failed node handed off its connections before it started, so your site stays up through the remaining node(s) while the failed node rolls back.
Single-node cluster: There is no other node to take over, so the site is down for the duration of the failed attempt plus the rollback.
If the rollback itself fails, the node reports a rollback failure and the cluster upgrade is marked Failed. In this case, contact Celona Support at support@celona.io.
Access Points: grouped and sequenced
APs are grouped by AP model and target software version. Unreachable APs are placed in their own group so they do not hold up healthy APs.
Within a group, APs upgrade one at a time, so the group is never fully offline.
Different groups (for example, different AP models) can upgrade in parallel.
Before an AP begins its upgrade, connected devices are moved off it first.
To save bandwidth, one AP in each group downloads the software image and shares it with the rest of the group. That AP upgrades itself last, so it stays available to share the image for as long as needed.
All of this happens automatically. You may notice that the AP sharing the image stays in In Queue longer than the other APs in its group, this is expected and does not mean the upgrade is stuck.
Important: Unlike Edge nodes, APs do not automatically roll back if an upgrade fails. A failed AP remains in the Failed state and is not returned to its previous version. To recover the AP, retry the upgrade or contact Celona Support at support@celona.io.

