Hey everyone, just saw the security bulletin. A CVE in an older Panther backend component, huh. That's a bit concerning as I'm still learning the ropes of the whole SIEM world.
I'm currently running Panther v4.3.1 in our test lab. Is anyone else on a similar version? The advisory mentions versions prior to v5.0.0 are affected. My main question is about the upgrade pathβis it generally a direct jump to the latest stable, or are there specific intermediate versions we should hit first for a smoother migration? I checked our Prometheus metrics and things look normal, but obviously need to patch.
Here's a snippet from our current deployment config (anonymized):
```
panther_version: "4.3.1"
backend_image: "pantherio/backend:v4.3.1"
```
Would appreciate any heads-up from those who've done this upgrade already. Any dashboard weirdness or collection gaps to watch for after? 😅
Been through this exact jump! The upgrade from 4.x to 5.x went pretty smooth for us. You can go straight to the latest stable (v5.4.x), but you'll definitely want to check the release notes for v5.0.0 itself, as there were some database schema migrations that need to run.
One watch-out: post-upgrade, some of our custom alert definitions needed tweaks because of a change in the rule syntax format. Dashboard metrics were fine, but give your saved queries a quick once-over. 😅
Here's the major version upgrade snippet from our Terraform that worked:
```
panther_version: "5.4.2"
backend_image: "pantherio/backend:5.4.2"
```
Make sure you snapshot your DB first, just in case.
Keep deploying!
Oh man, same boat here on a test setup! That's good to hear about the direct upgrade path to 5.4.x from user938's experience.
I'm wondering about that database schema migration step though. For a newbie, is running that migration usually a separate manual command, or does the new backend image handle it automatically when it starts up? Don't want to mess that part up.
Watching this thread, hope the upgrade goes smoothly for you!
Hey, good catch on the CVE. We're on a similar older version in a staging environment, so I feel the concern.
For the upgrade path, user938's direct jump to 5.4.x is spot on - that's what we did too. The key is that database migration. It's not a separate command; the new backend image should run the schema migrations automatically on its first startup. Just make sure your deployment has a health check or a long enough initial delay for that to complete, or you might see a brief "unhealthy" status.
On your question about dashboard gaps, we didn't see any data collection issues, but definitely review any custom alert rules after the upgrade. The rule syntax changed a bit in v5, so some of ours needed minor adjustments. Our saved queries and Prometheus metrics carried over just fine though. Good luck with the lab upgrade!
Integration Ian
Totally agree on the health check tip! We found that initial "unhealthy" blip freaked out our monitoring for a minute, but setting the initialDelaySeconds higher in the k8s liveness probe saved us from alert noise.
One extra nuance we noticed: sometimes the automatic migration runs, but if it hits a hiccup, the backend might start up without logging a clear failure. We ended up tailing the postgres logs directly during the first restart to watch for "migration completed" messages, just for peace of mind.
don't spam bro