# Elastic-agent \>= 8.13.x - Apt upgrade not copying state.enc to new installation dir

**URL:** <https://discuss.elastic.co/t/elastic-agent-8-13-x-apt-upgrade-not-copying-state-enc-to-new-installation-dir/362752>\
**Category:** Beats\
**Tags:** fleet\
**Created:** [July 9, 2024, 2:32am UTC](https://discuss.elastic.co/t/elastic-agent-8-13-x-apt-upgrade-not-copying-state-enc-to-new-installation-dir/362752 "2024-07-09T02:32:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ceekay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ceekay/32/5687_2.png) [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Post date:** [July 9, 2024, 2:32am UTC](https://discuss.elastic.co/t/elastic-agent-8-13-x-apt-upgrade-not-copying-state-enc-to-new-installation-dir/362752/1 "2024-07-09T02:32:40Z")

</div>

Hi there,

It's taken me a while to get to the bottom of this.

We're in an airgapped environment and upgrade agents from our local apt mirror of [artifacts.elastic.co](http://artifacts.elastic.co).

Recently, any agents that are upgraded via apt have been hanging with a status of `(STARTING) Waiting for initial configuration and composable variables`.

This appears to be an issue with the packaged `postinst` script not correctly identifying the existing agent installation directory, and therefore not copying `state.enc` to the new directory.

I've narrowed it down to the following cases:

- **Agent 8.12.x upgraded to any 8.13.x or above:** `state.enc` is copied to the new installation directory, and the agent starts normally.
- **Agent 8.13.x upgraded to any 8.13.x or above:** `state.enc` is not copied to the new directory, and the agent fails to join Fleet when restarted.

The main difference with 8.13.x is the inclusion of the version number in the install directory, rather than just the commit hash as in 8.12.x and below. While I'm not sure how relevant that is, I suspect the actual problem lies with the `postinst` script being unable to follow the symlink for `/usr/share/elastic-agent/bin/elastic-agent`, determining that there is no old install directory, and therefore not copying `state.enc` (or `state.yml`, if it exists).

At any rate, I'm quite convinced that the issue is with the `postinst` script, and it's causing significant problems when it comes to upgrading existing agents. The only workaround I've found is to manually copy `state.enc` to the new install directory and restart the agent, or to re-enroll the agent back into its policy. Neither of these solutions are viable to automate or maintain at scale.

Can someone take a look and confirm if they are seeing the same issue? I'm happy to open a GitHub issue if it's confirmed.

Cheers.

---

<div class="post-metadata">

**Author:** ![Lee\_Hinman](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lee_hinman/32/74973_2.png) [@Lee\_Hinman](https://discuss.elastic.co/u/Lee_Hinman)\
**Post date:** [July 10, 2024, 9:19pm UTC](https://discuss.elastic.co/t/elastic-agent-8-13-x-apt-upgrade-not-copying-state-enc-to-new-installation-dir/362752/2 "2024-07-10T21:19:20Z")

</div>

@ceekay yes please open a GitHub issue.

I'm very suspicious the issue is with [elastic-agent/dev-tools/packaging/templates/linux/postrm.sh.tmpl at ca5a07cb239d9770e50d7ec6be34a00514cdba9f · elastic/elastic-agent · GitHub](https://github.com/elastic/elastic-agent/blob/ca5a07cb239d9770e50d7ec6be34a00514cdba9f/dev-tools/packaging/templates/linux/postrm.sh.tmpl#L12-L26), where the symlink is getting deleted on an upgrade.

---

<div class="post-metadata">

**Author:** ![ceekay](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ceekay/32/5687_2.png) [@ceekay](https://discuss.elastic.co/u/ceekay)\
**Post date:** [July 10, 2024, 10:16pm UTC](https://discuss.elastic.co/t/elastic-agent-8-13-x-apt-upgrade-not-copying-state-enc-to-new-installation-dir/362752/3 "2024-07-10T22:16:48Z")

</div>

Thanks @Lee_Hinman

This problem has stopped me in my tracks, so I got impatient and opened one already at [Agent .deb install: state.enc not copied during Elastic Agent upgrade from 8.13 and above · Issue #5101 · elastic/elastic-agent · GitHub](https://github.com/elastic/elastic-agent/issues/5101)

Looks like it's been assigned just now.

Cheers
