CITADELFind an image

MAINTENANCE POLICY · IMAGE LIFECYCLE

A new maintained image every month. A deliberate path for critical fixes.

Citadel's patch cadence applies to newly published image releases. Running instances do not patch or replace themselves.

LAST REVIEWED · AUGUST 4, 2026

01 · MONTHLY CYCLE

Base. Patch. Harden. Test. Publish.

01Base

Start from the approved upstream operating-system image.

02Patch

Apply available operating-system security and software updates.

03Harden

Apply the Citadel PCI-focused configuration baseline.

04Test

Validate image behavior, configuration, and release criteria.

05Publish

Release a new Marketplace image version for customer adoption.

02 · CRITICAL SECURITY UPDATES

Critical issues can enter an expedited release path.

When an upstream vendor publishes a critical security fix relevant to a maintained image, Citadel can prioritize an out-of-cycle rebuild. The image still has to pass release validation before publication.

No invented emergency SLA

Citadel has not published a fixed response-time commitment for emergency image releases. The policy is to move as quickly as responsible validation permits and communicate through the applicable product channel.

03 · RUNNING INSTANCES

Publishing a refreshed AMI does not modify your fleet.

Customers choose how to adopt a release: replace instances from the new image, patch running systems under their own process, or test and schedule a later rollout. Citadel does not access customer instances.

  1. 01
    Launch in non-production.

    Test the new image with the real application, agents, identity path, logging, and deployment automation.

  2. 02
    Compare the release.

    Review relevant patch notes, evidence, and expected configuration effects.

  3. 03
    Promote through your normal change process.

    Record the adopted image version as part of workload evidence.

04 · POLICY SUMMARY

Standard cadenceMonthly image publication
Critical pathExpedited review when a relevant upstream critical fix warrants it
Delivery mechanismNew image version through the applicable cloud marketplace
Customer actionTest and adopt the new release or maintain running instances under an approved patch process
In-place fleet patchingNot provided by the image product