Skip to main content

Update

Update your self-hosted Menace Voice stack to a newer image version
4 min read

This guide covers updating a Menace Voice stack you've already deployed with Docker or a custom domain. You run commands from the same directory that contains your docker-compose.yaml (this is the dograh/ directory if you used setup_remote.sh).

There are three update flows depending on how you deployed:

Find an image version#

Menace Voice publishes two images — dograh-api and dograh-ui — to the container registry configured for your deployment.

Each release is published under release tags. update_remote.sh understands the supported release formats and normalizes them for you.

WhereTag formatExampleWhen to use
Release tagdograh-vX.Y.Zdograh-v1.28.0Use when selecting a published release
Docker image tag (semver)X.Y.Z1.28.0Stable, recommended for production
Docker image tag (latest)latestlatestTracks the most recent release tag
Warning

Always update dograh-api and dograh-ui to the same tag. The two images are built from the same commit and the UI expects API responses in a matching shape — mixing versions will break the app. update_remote.sh handles this for you automatically.

update_remote.sh is the supported path for updating a stack created with setup_remote.sh. In one shot it:

  • Asks for a target version (defaults to the latest release tag).
  • Pulls docker-compose.yaml at that version and pins both api and ui images to it.
  • Refreshes the remote helper bundle (remote_up.sh plus shared templates/helpers).
  • Synchronizes the canonical remote keys in .env and validates the runtime config that dograh-init will render from it.
  • Backs up every file it changes with a .bak.<timestamp> suffix.

From your install directory:

You'll be prompted for the target version, defaulting to the most recent release. Accepted forms: bare semver (1.28.0), v-prefixed (v1.28.0), the full release tag (dograh-v1.28.0), or main to refresh deployment files from the default branch — the script normalizes them. Non-interactive callers can set it via environment variable and skip the confirmation prompt:

After the script finishes, apply the update through the validated startup wrapper:

Note

The script overwrites docker-compose.yaml and the remote helper bundle (remote_up.sh, scripts/run_dograh_init.sh, scripts/lib/setup_common.sh, and deploy/templates/*) from the shared upstream deployment bundle. If you've made local edits to any of these, check the .bak.<timestamp> files after the update and re-apply your edits.

Local deployment#

For local Docker installs (the Quick Start flow or setup_local.sh / setup_local.ps1), refresh docker-compose.yaml and the startup script, stop the stack, then run the startup script. The script preserves existing .env secrets, creates REDIS_PASSWORD and MinIO credentials if they are missing, and only creates POSTGRES_PASSWORD for brand-new .env files. If a retained local Postgres volume already exists, it syncs the database user's password to .env before starting the full stack:

To pin a specific version instead of latest, edit docker-compose.yaml and change both image: lines for api and ui to the same tag (e.g. :1.28.0 — Docker image tags use bare semver, no v prefix), then run the commands above.

Verify the update#

Check the running image tags:

You should see the API and UI both running the tag you pinned.

Hit the health endpoint to confirm the API is responding:

Roll back#

update_remote.sh saves backups of every file it touched. To roll back, restore them and recreate the stack — the exact commands (including the timestamp it used) are printed at the end of the script's output. The generic form:

Your Postgres data volume persists across down/up cycles, so agents and call history are preserved.

Warning

Rolling back across a database migration is not always safe — if the newer release ran a schema migration, downgrading may leave the DB in a state the older API doesn't understand. If in doubt, contact your designated Menace support channel before rolling back.

Updating a source build#

If you deployed in build mode (you'll have a docker-compose.override.yaml in your install directory), update_remote.sh deliberately refuses to run — you already have the full repo locally and update via git:

Warning

If you update the pipecat submodule, you must run git submodule update --init --recursive before rebuilding, or the Docker build will not pick up pipecat changes.

If you maintain a fork with local customizations on top of upstream, merging conflicts in docker-compose.yaml, remote_up.sh, scripts/run_dograh_init.sh, deploy/templates/*, or setup_remote.sh is up to you — resolve them as you would any other git merge. Leave OSS_JWT_SECRET, TURN_SECRET, POSTGRES_PASSWORD, REDIS_PASSWORD, MINIO_ROOT_USER, and MINIO_ROOT_PASSWORD in .env unchanged across updates to preserve sessions, WebRTC auth, and service credentials.

The same migration warning above applies: rolling back across a schema change can leave the DB in a state the older API can't read.