Junos rollback and Configuration Revision Identifiers - 夜莺博客

Junos rollback and Configuration Revision Identifiers

Junos keeps the last 50 committed configurations, which turns configuration mistakes from emergencies into routine corrections — provided you know which number to roll back to and how to prove afterwards that the device is running what you think it is. This article covers the rollback index, the rescue configuration, and the Configuration Revision Identifier introduced in Junos OS 20.4R1 that removes the ambiguity of shifting rollback numbers.

Where the configurations live

The operating configuration is juniper.conf in /config; the three most recent commits are juniper.conf.1 through .3 in the same directory, and numbers 4 through 49 live in /var/db/config on the hard disk. Rollback index 0 is the most recently committed configuration, and 49 the oldest retained.

Rolling back

# see the history and what each number contains
rollback ?
show system commit

# load a previous configuration into the candidate
rollback 3

# discard pending, uncommitted changes
rollback 0

# return to the rescue configuration
rollback rescue

rollback loads a configuration into the candidate; it does not activate it. You still need commit. And only objects that differ from the currently loaded configuration are marked as changed — equivalent to a load update — so the diff you review after a rollback is exactly the change that will be applied.

Rescue configuration

request system configuration rescue save
request system configuration rescue delete
show system configuration rescue

A rescue configuration is a known-good snapshot on the flash drive that survives version upgrades and reloads. Build one as soon as a device passes its acceptance test; it is the fastest road back from a change that locked you out of the management interface.

Configuration Revision Identifiers (20.4R1+)

A rollback number shifts every time a new commit is made, which makes change-request documentation awkward. A CRI is a fixed string tied to one specific commit, so it always refers to the same configuration.

show system commit include-configuration-revision
show system rollback 3 configuration-revision
show system configuration revision <cri-string>
rollback revision <cri-string>

You can also compare two configurations directly using their CRIs, which makes post-incident review far easier than reconstructing what a rollback number meant at the time.

Verification after a rollback

show system rollback compare 0 3
show configuration | compare rollback 0
show system commit
commit check

Always run commit check before commit after a rollback, and review the diff rather than assuming the loaded configuration is identical to what was running at the time. Pairing rollback with commit confirmed gives you both an automatic timeout and a manual escape hatch — the combination used by most production change windows.

Related reading: Junos commit confirmed safety net, IOS XR commit and rollback, Aruba NetEdit validated multi-device change.

原文链接:https://www.juniper.net/documentation/us/en/software/junos/cli-reference/topics/ref/command/rollback.html