Update Center
The Update Center is an admin-only, informational feature. A customer hxEASM installation checks a Central Update API for release metadata; it does not call GitHub directly.
hxEASM
-> Central Update API
-> Private GitHub Releases
The GitHub token is stored only in the Central Update API. Customer installations use only a customer Update Center API key. hxEASM never updates itself automatically, executes shell commands, accesses the Docker socket, runs git pull, or modifies local files.
Configuration
Runtime configuration lives in backend/configs/config.yaml under updates:
updates:
enabled: true
center_url: ""
api_key: ""
product: hxeasm
channel: stable
timeout_seconds: 10
check_interval_minutes: 360
current_version: ""
Fields:
| Field | Purpose |
|---|---|
enabled |
Enables or disables update checks |
center_url |
Central Update API base URL, for example https://updates.example.com |
api_key |
Customer Update Center API key; backend-only secret |
product |
Product identifier, defaults to hxeasm |
channel |
Release channel, defaults to stable |
timeout_seconds |
HTTP request timeout, defaults to 10 |
check_interval_minutes |
Cache TTL for status checks |
current_version |
Optional override; leave empty to use app.version |
Environment variables:
EASM_UPDATE_CENTER_URL=https://updates.example.com
EASM_UPDATE_CENTER_APIKEY=
EASM_UPDATE_CENTER_PRODUCT=hxeasm
EASM_UPDATE_CENTER_CHANNEL=stable
EASM_UPDATE_CENTER_TIMEOUT_SECONDS=10
Leave EASM_UPDATE_CENTER_URL or EASM_UPDATE_CENTER_APIKEY empty to disable update checks gracefully. API startup does not fail, and the UI shows Not configured.
Use HTTPS in production. http:// is accepted for local development only. The configured URL must be a base URL without /api/v1/update; hxEASM always requests the fixed /api/v1/update path.
EASM_UPDATES_GITHUB_TOKEN is deprecated and ignored. If it is present, the API logs a safe warning without printing the value.
Current Version
The backend exposes the current version through the existing version endpoint and uses it for update checks. In normal deployments, set only app.version; leave updates.current_version empty.
Versions such as 0.1.7 Vega are normalized before calling the Central Update API:
0.1.7 Vega -> 0.1.7
v0.1.7 -> v0.1.7
0.1.7 -> 0.1.7
The codename is not sent to the update service.
Central Update API Request
hxEASM calls:
GET {EASM_UPDATE_CENTER_URL}/api/v1/update?product=hxeasm¤t_version=0.1.7&channel=stable
Authorization: Bearer <EASM_UPDATE_CENTER_APIKEY>
Accept: application/json
The browser never calls the Central Update API directly. The API key is never returned through /api/v1/admin/updates/* or placed in frontend environment variables.
Local API
Admin-only local endpoints remain:
GET /api/v1/admin/updates/status
POST /api/v1/admin/updates/check
status uses the configured cache interval. check forces a refresh through the Central Update API.
Example local response:
{
"enabled": true,
"configured": true,
"current_version": "0.1.7",
"latest_version": "v0.2.0",
"update_available": true,
"cache_status": "refreshed",
"release_name": "hxEASM v0.2.0",
"release_notes": "Release notes from GitHub.",
"release_url": "",
"published_at": "2026-08-04T10:00:00Z",
"checked_at": "2026-08-04T12:00:00Z",
"error": ""
}
If the Central Update API does not expose a safe public release URL, release_url is empty and the frontend hides the GitHub release button.
Error Handling
Central Update API errors are mapped to safe admin UI messages:
| Condition | UI message |
|---|---|
| Missing URL or API key | Update Center is not configured |
| Invalid local URL/config | invalid Update Center configuration |
400 |
invalid update request or local configuration |
401 |
invalid Update Center API key |
403 |
this customer key cannot access the hxeasm product |
404 |
product or release not found |
429 |
Update Center rate limit exceeded |
502 |
release metadata temporarily unavailable |
| Timeout | Update Center request timed out |
| Connection failure | Update Center unavailable |
cache_status may be fresh, refreshed, or stale. Stale metadata is shown as a warning, not a hard failure, if the response is otherwise valid.
UI Behavior
Admins see Update Center in Settings under Administration.
The panel shows:
- current version
- latest version
- status badge
- last checked time
- release notes in a collapsible section
- optional release link if supplied by the Central Update API
Check nowbutton- copyable update commands
Admins also see a top banner when an update is available. The banner is not shown to hacker or client users.
Manual Update Commands
The UI only copies commands. It never executes them.
Source deployment:
git pull && docker compose up -d --build
Image deployment:
docker compose pull && docker compose up -d
Why One-Click Update Is Not Implemented
Self-updating a running security platform is risky. It would require command execution, write access to the deployment directory, process restarts, and possibly Docker socket access. Those capabilities increase the blast radius of any admin session compromise or implementation bug.
Update Center remains read-only and informational. Operators remain in control of when and how updates are applied.