Upgrade Apstra DCD on New VM (VM-VM)
Upgrading Apstra DCD on a new VM includes Ubuntu Linux OS fixes and security updates. You need Apstra DCD OS admin privileges and admin group permissions for the upgrade.
Step 1: Pre-Upgrade Validation
Step 2: Deploy New Apstra DCD Server
If you customized the /etc/aos/aos.conf file on the old
Apstra DCD server (for example, if you updated the metadb
field to use a different network interface), re-apply those changes to the
new Apstra DCD server VM. Automatic migration doesn't occur.
Step 3: Import State
Avoid performing API/GUI write operations on the old Apstra DCD server after starting the new VM import. Changes made won't transfer to the new Apstra DCD server.
Step 4: Import State for Intent-Based Analytics
As of Apstra DCD 5.0.0, we no longer assign tags to probes and stages or
support the evpn-host-flap-count telemetry service.
To remove or disable any widgets or probes for intent-based analytics, add the
following arguments to the sudo aos_import_state command:
-
--iba-remove-unused widgets: Remove unused widgets from the dashboard. -
--iba-remove-probe-and-stage-tags: Remove tags from probes and stages. -
--iba-number-non-unique-probe-labels: Add serial numbers to non-unique probe labels. -
--iba-number-non-unique-dashboard-labels: Add serial numbers to non-unique dashboard labels. -
--iba-disable-probe-with-evpn-host-flap-count-service: Disable non-predefined probes using the evpn-host-flap-count service. -
--iba-strip-dashboard-labels-widget-labels: Remove leading/trailing spaces from dashboard and widget labels. -
--iba-strip-probe-labels-processor-names: Remove leading/trailing spaces from probe labels and processor names.
Step 5: Keep Old VM's IP Address (Optional)
Perform the following steps before changing the Operation Mode and upgrading the devices' agent.
To keep the old VM's IP address:
Step 6: Modify Apstra DCD IP in Flow Config After Apstra DCD Upgrade (if not resusing original IP)
During the Apstra DCD upgrade with VM-to-VM, the Apstra DCD IP address changes unless you reuse the old IP in Step 5.
If the IP address changes, update the Apstra DCD Flow component to capture the new IP as follows:
- SSH to the Apstra DCD Flow CLI (default credentials are Apstra DCD/Apstra DCD).
-
Open
/etc/juniper/flowcoll.yml. - Modify the EF_JUNIPER_Apstra DCD_API_ADDRESS field with the new IP address.
-
Run
sudo systemctl restart flowcoll.service.
Step 7: Change Operation Mode to Normal
When you start an Apstra DCD server upgrade, the mode switches from Normal to Maintenance automatically. Maintenance mode blocks offbox agents from going online, halts configuration pushes, and stops telemetry pulls. To revert to the previous version, shut down the new server. To complete the upgrade, switch the mode back to Normal.
Step 8: Upgrade Agents for Devices
Upgrade Onbox Agent(s)
The Apstra DCD server and onbox agents must be running the same Apstra DCD version. If versions are different the agents won't connect to the Apstra DCD server.
If you're running a multi-state blueprint, especially 5-stage, upgrade agents in stages:
-
First, upgrade superspines.
-
Next, upgrade spines.
-
Finally, upgrade leafs.
This order minimizes path hunting issues. Routing may temporarily go from leaf to spine, back to another leaf, and then to another spine. Staged upgrades reduce this risk.
To upgrade an Onbox agent:
Log in to the Apstra DCD GUI as user admin.
From the left navigation menu, navigate to Devices > Managed Devices and select the check boxes for the device(s) to upgrade (up to 100 devices at a time). You can upgrade multiple onbox agents at the same time, but the order of device upgrade is important.
- Upgrade agents for superspines first.
- Upgrade agents for spines second.
- Upgrade agents for leafs third.
When you select one or more devices the Device and Agent menus appear above the table.
Click the Install button to initiate the install process.

The job state changes to IN PROGRESS. If agents are using a previous version of the Apstra DCD software, they are automatically upgraded to the new version. Then they connect to the server and push any pending configuration changes to the devices. Telemetry also resumes, and the job states change to SUCCESS.
In the Liveness section of the blueprint dashboard confirm there are no device anomalies.
Note: To roll back to the previous Apstra DCD version after and agent upgrade, build a new VM with the previous Apstra DCD version and restore the configuration to the new VM. Contact Technical Support for assistance
Upgrade OffBox Agent(s)
Starting in Apstra DCD 6.1, click the Update Host Keys button for offbox agents in the managed device.

Step 9: Shut Down Old Apstra DCD Server
- Update any DNS entries to use the new Apstra DCD server IP/FQDN based on your configuration.
- If you're using a proxy for the Apstra DCD server, ensure it points to the new server.
-
Gracefully shut down the old Apstra DCD server. If you confirmed shutting
it down, the
service aos stopcommand runs automatically. - If you're upgrading an Apstra DCD cluster and you replaced your worker nodes with new VMs, shut down the old worker VMs.
Upgrade your device NOS versions to a qualified version if they are not compatible with the new Apstra DCD version, See the Apstra Data Center Director User Guide for details.




