Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
57 changes: 57 additions & 0 deletions pages/clustering/high-availability/setup-ha-cluster-k8s.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -78,6 +78,63 @@ the cluster.
the `latest` tag can lead to unexpected behavior if pods restart and pull newer,
incompatible images. </Callout>

### Rotate the license

When your license expires or you receive a new key, you can rotate it without
restarting any pod. The chart injects the `memgraph-secrets` keys as
environment variables, and Kubernetes resolves them only when a container
starts. Editing the Secret therefore has no effect on running pods, and neither
a Secret edit nor `helm upgrade` triggers a rollout on its own. Rotating the
license is a two-step process: apply the new key at runtime on every instance,
then update the Secret so future restarts pick it up.

<Steps>

{<h4 className="custom-header">Set the new license at runtime</h4>}

Connect to **every** coordinator and **every** data instance and run:

```cypher
SET DATABASE SETTING 'enterprise.license' TO '<new-license-key>';
SET DATABASE SETTING 'organization.name' TO '<your-organization-name>';
SHOW LICENSE INFO;
```

Database settings are per instance and are not replicated, so the queries must
be run on each instance separately. They work on replicas as well as on the
main, and coordinators accept them too (the `COORDINATOR_WRITE` privilege is
required when [coordinator
authentication](/clustering/high-availability/coordinator-authentication) is
enabled). The new value is persisted in the data directory on the instance's
PersistentVolumeClaim.

{<h4 className="custom-header">Update the Secret</h4>}

The Secret is not managed by Helm, so patch it directly:

```bash
kubectl create secret generic memgraph-secrets \
--from-literal=MEMGRAPH_ENTERPRISE_LICENSE='<new-license-key>' \
--from-literal=MEMGRAPH_ORGANIZATION_NAME='<your-organization-name>' \
--dry-run=client -o yaml | kubectl apply -f -
```

This does not restart anything. It only changes what the next container start
sees. Adjust the Secret name and keys if you overrode `secrets.name`,
`secrets.licenseKey` or `secrets.organizationKey`.

</Steps>

<Callout type="warning">
Do not skip the Secret update. On Memgraph v3.9.0 and newer, a restarted pod
compares the persisted setting with the environment variable and keeps the
license with the furthest expiry, so the runtime-set key wins over a stale
Secret. On older versions, the environment variable overwrites the persisted
setting at startup and a restarted pod falls back to the expired key. In both
cases, a data instance recreated with a fresh volume has no persisted setting
and relies solely on the Secret.
</Callout>

### Install Memgraph HA with `kind`

For local development, we suggest using `kind`. Running:
Expand Down
8 changes: 8 additions & 0 deletions pages/database-management/enabling-memgraph-enterprise.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -139,6 +139,14 @@ data stored in the database will remain intact. You will still be able to add
more data, but any enterprise features that require specific actions will no
longer function. For example, you will not be able to create any new databases.

To renew an expired license, set the new key with `SET DATABASE SETTING` as
shown in [Providing the license](#providing-the-license). The change applies
immediately and no restart is needed. If Memgraph also receives the license
through a CLI flag or an environment variable, update that source as well so
the new key is used on the next restart. For a step-by-step guide for a
Kubernetes HA deployment, see [Rotate the
license](/clustering/high-availability/setup-ha-cluster-k8s#rotate-the-license).

## Switching between Community and Enterprise editions

Enterprise user and role details are persisted in the database across editions,
Expand Down
Loading