Terminal notification failures are 36% of resolved delivery outcomes fleet-wide (126,337 dead-lettered against 224,692 delivered in the week to 2026-09-03, over 6,668 clean installs), and the category breakdown could not say why: unknown was the modal bucket at 31,218. The class was being derived by substring-matching the Go error message. That fails in two ways. Any failure whose text carries none of the ~50 recognised tokens falls through to unknown, which is most of what SMTP produces: net/smtp reports the server's verdict as a reply code, and only 535 was ever matched, so a 550 relay refusal and a 451 temporary failure both recorded as unknown. Worse, the text being matched includes the destination's own response body, so a third party can choose the reason code Pulse records and shows the operator - a 500 whose body contains "rate limit" was recorded as rate_limited rather than server_error. Senders now declare the class where they already know it, and the classifier reads Go's own error types before it reads any prose: *textproto.Error for SMTP reply codes, x509 and tls for certificate failures, net.DNSError and timeouts for connectivity. HTTP status codes set the class at the five sites that build a status error, so the response body is preserved for the operator's audit row but can no longer influence the classification. Prose matching remains only as the last resort for paths that declare nothing. SMTP 5xx is deliberately not mapped the way HTTP 5xx is: a 550 is the destination refusing the message, not the destination breaking, so only the transient 4xx replies count as server_error. Registers the wider finding as a coverage gap. The 36% is concentration, not breadth - 72 installs that delivered nothing at all in seven days account for half of all terminal failures, and Pulse neither backs off nor tells those operators the destination has never once succeeded.
Pulse documentation
Start here for installation, platform setup, security, operations, and Pulse Intelligence. Commands, configuration keys, image names, API fields, and product identifiers remain untranslated in localized guides.
Start here
- Install Pulse — signed Proxmox/Linux installation, Docker, Docker Compose, Kubernetes, and first-run setup.
- Production deployment and security — least-privilege Proxmox setup, root-agent boundaries, discovery, supply-chain verification, plan limits, scale evidence, and a rollout checklist.
- Upgrade from Pulse v5 — migration prerequisites, rollback, agent continuity, and post-upgrade checks.
- Configure Pulse — authentication, notifications, discovery, retention, and system settings.
- Deployment models — data locations, lifecycle, and differences between supported deployment paths.
- Troubleshooting and FAQ — common failures, diagnostics, and operator questions.
Localized getting started guides: Deutsch · Español
Platforms and agents
- Proxmox Backup Server
- Proxmox Mail Gateway
- Docker and Podman
- Kubernetes and Helm
- TrueNAS SCALE and CORE
- Unified Agent
- Agent security
- VM disk monitoring
- ZFS monitoring
- Temperature monitoring
VMware vSphere support is early access. Current builds expose dedicated vSphere inventory and recovery context, but operators should validate the integration against their own vCenter before production use.
Monitoring and operations
- Metrics history
- Recovery data
- Webhooks
- Automatic updates
- Centralized agent management (Pro)
- Operational trust model
- Current product screenshots
Pulse Intelligence
- Assistant, Patrol, and external-agent overview
- Patrol modes and safety
- Assistant safety model
- External agent HTTP and MCP substrate
Patrol watch-only analysis is available on Community with a local model or the operator's own provider. Investigation and governed fixes require the relevant Pulse Pro capabilities.
Security, privacy, and access
- Production deployment and security
- Security review scope
- Authentication and credential storage review packet
- Security guide
- Privacy and telemetry disclosure
- OIDC and SSO
- Proxy authentication
- Role-based access control (Pro)
- Audit logging (Pro)
- Reverse proxy configuration
- Code-signing policy
Plans and managed access
- Community, Relay, and Pro capabilities
- Relay and Pulse Mobile handoff
- Multi-tenant organizations (Enterprise/custom)
- Provider-hosted MSP operations (request-assisted)
Pulse Cloud is not generally available. Ordinary self-hosted Pulse remains the primary installation path; MSP and Enterprise access are explicit commercial paths rather than defaults in self-hosted setup.
Development and reference
Detailed design notes and dated migration specifications may remain in this directory for maintainers, but they are not operator setup guides unless they are linked from the sections above.
Previous versions and migrations
- Upgrade from v4 to v5
- Retired unified-navigation migration — historical context only; current Pulse uses platform-shaped navigation.
- Move a Pulse installation
Found a bug? Use the issue forms. For setup questions, use GitHub Discussions.