Server maintenance
Operating-system updates, Postgres major-version upgrades, point-in-time recovery, snapshots, hardened isolation and the security score.
Operating-system updates
Each server’s page has an Operating system card. The agent reports pending updates within half an hour of starting and then daily: how many in total, how many are security updates, and whether a restart is required.
- Install all updates or Install security updates and restart. Updating can restart Docker, so apps may blink for a few seconds; a restart takes the server’s apps down for about a minute.
- Nightly security updates apply unattended; a restart is never done automatically.
- The badge clears once the server has restarted.
Postgres major-version upgrades
A managed Postgres can move from 16 to 17 or 18 from its card. Railyard checks compatibility first, takes a backup, upgrades in place and verifies the table count. The old version is kept for seven days so you can roll back. New database servers default to Postgres 17.
Point-in-time recovery
Maintenance → Point-in-time recovery → Turn on archives every WAL segment and a base backup for the server’s Postgres to your team’s backup store, so any database on it can be rebuilt to any second in the last 7 days.
To restore, open the database’s console (App → Resources → Database card → Console) and use the Restore to a time tab: pick a second inside the archived window, then either Into a new copy (<db>_at_YYYYMMDDHHMM, inspect it and copy back what you need) or Replace the live database (everything after that time is lost). Restoring needs the same backup store used for regular backups.
Snapshots
Before a resize or an OS upgrade, take a provider snapshot from the server page and restore it if anything goes wrong. Snapshots are kept by your cloud provider and billed by them.
Hardened isolation (beta)
On an app’s Settings → General, two opt-in, off-by-default settings tighten the container boundary between apps sharing a server:
- Hardened isolation: the app’s container runs as its own non-root uid with capabilities dropped and its own Docker network, so it can’t reach or be reached by another app on the server. Test it first — it can break an image that needs root.
- Read-only filesystem: mounts the container’s root filesystem read-only with a writable
/tmp. Enable only once you’ve checked the app doesn’t write anywhere else.
Both take effect on the next deploy. Every server still shares one kernel; sandboxed-runtime isolation (gVisor) is on the roadmap but not built.
Security score
Settings → Security scores the team from 0 to 100 against a checklist, with a fix link per item; see Teams, SSO and access for the full list. Every connection between Railyard’s control plane and a server’s agent is mutually authenticated over TLS, issued per server.