Patch stuck in staging or fails to stage during upgrade - PAM
search cancel

Patch stuck in staging or fails to stage during upgrade - PAM

book

Article ID: 444083

calendar_today

Updated On:

Products

CA Privileged Access Manager - Server Control (PAMSC)

Issue/Introduction

When attempting to upgrade Broadcom Privileged Access Manager (PAM), a patch may remain in a "Pending" or "Staging" state indefinitely. This behavior typically prevents the application of any further patches or completion of the upgrade process.

  • The upgrade UI shows a patch stuck in "Staging" or "Uploading" indefinitely.
  • Attempts to "Restage" or "Cleanup" the patch do not resolve the status.
  • Live Upgrader logs show 503 Service Unavailable errors on secondary nodes.

Environment

  • CA Privileged Access Manager 4.3.0
  • Multi-site cluster configurations

or

  • Clusters where a VIP/NAT IP address has been defined for the different cluster nodes

Cause

This issue occurs due to a defect (DE660934) where the Live Upgrader stager fails to start if the primary site index in the cluster is not 0 and also in case the cluster nodes have VIP or NAT IP addresses assigned to them (DE66093). Other nodes are then unable to download the upgrade binary from the stager.

Resolution

This issue is fixed in release 4.3.1 and higher

To resolve the stuck state in version 4.3.0 and proceed with the upgrade, follow these steps:

  1. Download the PAM_LU_RESET.p.zip from the Generic Hotfix page for CA PAM
  2. Upload the utility patch to the node currently stuck in staging.
  3. Apply the patch to clear the staging area and reset the Live Upgrader service.
  4. Verify the "Pending" status is removed from the Configuration > Upgrade page.
  5. Proceed with the upgrade to version 4.3.1.

Additional Information

There is a similar patch for situations where the problem with the index is occurring in version 4.3.1. Fix can also be downloaded from the Generic Hotfix page