Kubernetes OS Maintenance Needs Storage Safety Gates
Updating Kubernetes nodes is not just an apt-get dist-upgrade loop. The safe boundary is different for package download staging, package application, reboot, etcd quorum, CSI detach behavior, and Longhorn replica health. A node can be Ready and still be the wrong node to reboot next. Separate Staging From Applying Use download-only staging when the goal is to warm package caches before a maintenance window: sudo bash -lc ' set -euo pipefail export DEBIAN_FRONTEND=noninteractive apt-get -o DPkg::Lock::Timeout=300 update -qq apt-get -y \ -o DPkg::Lock::Timeout=300 \ --download-only \ -o Dpkg::Options::=--force-confdef \ -o Dpkg::Options::=--force-confold \ dist-upgrade echo "STAGED_DOWNLOAD_ONLY rc=0" echo "upgradable_count=$(apt list --upgradable 2>/dev/null | grep -c upgradable)" echo "cache_mb=$(du -sm /var/cache/apt/archives 2>/dev/null | awk '\''{print $1}'\'')" echo "reboot_required=$(test -f /var/run/reboot-required && echo YES || echo no)" ' After download-only staging, apt list --upgradable can still show the same updates. That is expected. The packages were downloaded, not installed. ...