Upgrade from 2026.07 to 2026.09
Follow this page from top to bottom to upgrade a Self-Managed Kindo install from 2026.07 to 2026.09. Plan a maintenance window with each organization’s IdP administrator available: SSO sign-in fails until you restore SSO for each organization after the upgrade.
Prepare
Section titled “Prepare”Complete these steps before the maintenance window.
-
Back up the configuration with the 2026.07 CLI. You need current copies of
install-contract.yamlandenvironment-bindings.yamlfor this install. If you don’t have them, write them from the cluster, and replace any placeholder admin database credentials in the generatedenvironment-bindings.yamlwith real ones:Terminal window kindo config reconstruct --context <kube-context>From the directory holding both files, run the backup against this install’s cluster:
Terminal window kindo config backup --context <kube-context>The command requires
openssland prompts for a passphrase. Store the bundle and passphrase away from the cluster, and keep the 2026.07 CLI artifact. Rolling back requires both. -
Provision what 2026.09 needs.
Requirement What to do Superadmin host Point DNS for superadmin.<domain>at your ingress load balancer, and cover it with a TLS certificate. A wildcard record and certificate for*.<domain>already cover it.External Secrets Operator The upgrade installs the External Secrets Operator, so run it as an identity that can create CRDs and admission webhooks. If the cluster already runs the External Secrets Operator, upgrade it to 0.17 or later first. Pod security If you enforce Pod Security Admission baselineorrestricted, allow two workloads. The per-node log collector inkindo-monitoringruns as root, mounts/var/log/podsand/var/lib/otelcol/logsfrom the host, and uses thesystem-node-criticalpriority class. Sandbox pods insandboxrun an init container as root that adds theNET_ADMIN,NET_RAW,CHOWN, andFOWNERcapabilities.SMTP relay Have an authenticated SMTP relay ready. Kindo sends sign-in codes by email. -
Confirm you can snapshot and restore every PostgreSQL instance Kindo uses. Don’t take them yet: you take them at the start of the maintenance window, immediately before the upgrade.
-
Move model proxy clients to the API. 2026.09 no longer publishes
litellm.<domain>. Point anything that calls it athttps://api.<domain>/v1with a Kindo API key, created under Settings → API in Kindo. -
Arrange the SSO migration. List the organizations that use SSO, and book each one’s IdP administrator into the maintenance window.
Update the configuration
Section titled “Update the configuration”-
Install the 2026.09 CLI and its tools. The CLI requires kubectl 1.32 or later, Helm 4.0 or later, helmfile 1.2 or later, and yq 4 or later. The commands on this page use 2026.09.0. If a later 2026.09 release is out, use it instead. Pull, verify, and install the CLI, then check its version:
Terminal window helm registry login registry.kindo.ai --username '<registry-username>'helm pull oci://registry.kindo.ai/kindo-cli/kindo-cli --version 2026.09.0 --untar(cd kindo-cli && sha256sum -c SHA256SUMS)uv tool install --force ./kindo-cli/kindo_cli-*.whlkindo --version -
Check SMTP. Make sure
smtp.host,smtp.user,smtp.password, andsmtp.fromEmailare set ininstall-contract.yaml.smtp.portdefaults to 587.kindo upgradestops with an error until they’re set. -
Migrate the install contract. Preview the changes, then apply them:
Terminal window kindo config migrate --dry-runkindo config migrateCheck
operatorEmailin the migrated contract. The upgrade makes that address the install’s first superadmin.kindo config migratefills it in fromadminUser.email; if it’s empty or should be someone else, set it.
Upgrade
Section titled “Upgrade”Run these steps in the maintenance window, from the directory holding install-contract.yaml and environment-bindings.yaml.
-
Snapshot every PostgreSQL instance Kindo uses. Use your managed snapshot mechanism or a consistent
pg_dump. A rollback loses anything written after the snapshot, so take it immediately before the upgrade. -
Check cluster health. Resolve every finding marked
critical; the upgrade refuses to start while one remains. Findings markedwarningdon’t block the upgrade.Terminal window kindo doctor -
Preview the upgrade.
Terminal window kindo upgrade --version 2026.09.0 --planIf you changed Helm values directly, for example with
helm upgrade --set, the upgrade resets them. The plan lists them under Helm Values. To keep one, save it as an override:Terminal window kindo config helm-override set <release> <path>=<value>Fix every blocking issue the plan reports, then run the plan again.
-
Apply the upgrade.
Terminal window kindo upgrade --version 2026.09.0 --applyIf the run fails, fix the cause and run the same command again; it is safe to repeat. If it completes with warnings, run the
kindo install --stepcommand each warning names. -
Store the superadmin key. The upgrade prints it once. Keys expire after 90 days by default.
-
Add the superadmin routes. Create one Ingress in each backend’s namespace for
superadmin.<domain>:Path prefix Namespace / Service Port Health check /auth,/superadminapi/api80 /healthcheck/superadmin/superadmin80 /healthGive the
/authand/superadminroutes priority over/, so those paths reach the API. -
Sign in to the superadmin dashboard. Open
https://superadmin.<domain>, enter youroperatorEmail, and sign in with the emailed code.Until the superadmin’s organization has a SAML connection configured, the superadmin can sign in with an emailed code even if the organization enforces SSO. Once its IdP metadata is uploaded, the superadmin signs in with SSO like everyone else.
Restore SSO for each organization
Section titled “Restore SSO for each organization”Create a SAML connection for each organization that uses SSO, and update its IdP application. Members of an organization that enforces SSO can’t sign in until its connection works. Members of an organization without enforcement can use Continue with email in the meantime.
Restore SSO for your own organization last, and keep your superadmin dashboard session open until its SSO works. For each organization:
-
Open an Admin session. In the superadmin dashboard, open the organization’s Users tab, open an active Admin’s actions menu, and select Impersonate… → Prepare session. Confirm with the emailed code, then select Open customer app. Impersonation works with SSO enforcement on, and the session lasts one hour. If the organization has no eligible Admin, select Add user in the Users tab, set Organization role to Admin, and impersonate the new user.
-
Create the SAML connection. In Kindo, open Settings → SSO and select Create SAML connection. Under Identity Provider (IdP) Configuration, import the metadata from the organization’s existing Kindo application in the IdP: select Upload metadata XML and choose the file, or paste the XML and select Import. To enter the values by hand instead, fill in IdP Entity ID, Redirect URL, and Signing certificate, then select Save. The Provider notes below show where Okta and Microsoft Entra ID keep these. Confirm that the certificate shows
Valid until <date>. If Kindo reports that the organization has no SSO email domain, open the organization’s Domains tab in the superadmin dashboard, select Edit domains, turn on Verified for its domain, and select Save domains. -
Update the existing IdP application. Copy the ACS URL and SP Entity ID from Service Provider Configuration and give them to the IdP administrator. In the existing Kindo application, have them replace the ACS URL and SP Entity ID with the new values.
-
Confirm SSO and end the Admin session. In a private window, sign in with SSO as a member of the organization; for your own organization, that can be you. If sign-in fails, fix the connection in the Admin session. Once it works, return to the superadmin dashboard, open Overview → Active impersonations, and select End for the session.
Provider notes
Section titled “Provider notes”Okta
- Create the SAML connection:
- Option 1, upload metadata: on the Kindo application’s Sign On tab, open the Metadata URL and save the page as an
.xmlfile. - Option 2, enter the values by hand: from More details on the same tab:
- IdP Entity ID: Issuer
- Redirect URL: Sign on URL
- Signing certificate: the full contents of
okta.cert, from Download on the Signing Certificate row
- Option 1, upload metadata: on the Kindo application’s Sign On tab, open the Metadata URL and save the page as an
- Update the existing IdP application: open General → SAML Settings → Edit. Set Single sign-on URL, Recipient, and Destination to the ACS URL, and Audience URI (SP Entity ID) to the SP Entity ID.
Microsoft Entra ID
- Create the SAML connection:
- Option 1, upload metadata: download Federation Metadata XML from the Kindo application’s SAML Certificates section.
- Option 2, enter the values by hand:
- IdP Entity ID: Microsoft Entra Identifier
- Redirect URL: Login URL
- Signing certificate: the full contents of the Certificate (Base64) download
- Update the existing IdP application: open Single sign-on and select Edit in Basic SAML Configuration. Set Reply URL (Assertion Consumer Service URL) to the ACS URL, and Identifier (Entity ID) to the SP Entity ID.
Finish the upgrade
Section titled “Finish the upgrade”-
Verify the install. Confirm that
kindo statusshows 2026.09 andkindo doctorreports no critical findings, then sign in to Kindo, open a chat, and run an agent:Terminal window kindo statuskindo doctor -
Back up the configuration again. The upgrade generates new credentials that the pre-upgrade bundle doesn’t have. Keep the pre-upgrade bundle for rolling back to 2026.07.
Terminal window kindo config backup --context <kube-context> -
Switch sandboxes to OpenShell.
- Sign in to Unleash at
https://unleash.<domain>asadmin. The password isunleash.adminPasswordin the secrets config; read it withkindo config edit, then quit the editor without saving. - Open the
SANDBOX_PROVIDERflag and edit its strategy in theproductionenvironment. Give theopenshellvariant all of the weight and the other variants none, then save. - Run an agent that executes code, and confirm it succeeds.
- Sign in to Unleash at
-
Retire the model proxy hostname. Remove the DNS record and certificate for
litellm.<domain>. -
Remove SSOReady once every organization’s SSO works:
-
Set
applications.ssoready: falseininstall-contract.yaml. -
Uninstall the release:
Terminal window helm uninstall ssoready -n ssoready -
Retire the
sso.,sso-auth.,sso-api., andsso-app.DNS records and certificates.
-
Roll back to 2026.07
Section titled “Roll back to 2026.07”Kindo supports fixing forward: fix the cause of a failed upgrade and run kindo upgrade --apply again, which is safe to repeat.
If you can’t fix forward and need to return to 2026.07:
-
Prepare an empty cluster and reinstall the 2026.07 CLI from the artifact you kept:
Terminal window uv tool install --force <2026.07-artifact-dir>/kindo_cli-2026.7.*.whl -
Restore the pre-upgrade database snapshots at their original hostnames. Everything written after the snapshots is lost.
-
Restore the configuration backup with the 2026.07 CLI, from an empty directory:
Terminal window kindo config extract <bundle>kindo restore <bundle>kindo statuskindo doctor -
Revert each IdP application. Have each IdP administrator put back the ACS URL and SP Entity ID the Kindo application used on 2026.07.
