rcourtman 2dca000416 Author per-command-class preflight context for approval review
Operators about to approve a Pulse-driven action need to know what the
command actually touches before saying yes. Until now the preflight
shown at approval time was the same generic boilerplate for every
action: "approval is scoped, hash must match, etc." — useful safety
posture but no operational specifics. The dry-run summary said the
same thing for 99% of actions.

Adds classifyApprovalCommand and approvalCommandClassPreflightAdditions
in tools_control.go that bucket common Pulse remediation actions and
return hand-authored safety + verification additions per class:
- service-restart  (systemctl restart, service restart)
- service-stop     (systemctl stop, service stop)
- service-start    (systemctl start, service start)
- service-reload   (systemctl reload)
- container-restart (docker / podman restart)
- container-stop   (docker / podman stop)
- k8s-rollout-restart (kubectl rollout restart)

The additions name concrete operational facts the operator needs:
- For service-restart: "Service will be briefly unavailable; no other
  unit dependencies altered" plus verification "Read back
  systemctl is-active <unit>" and "tail journal for crash patterns".
- For container-restart: "Container will be briefly unavailable;
  image and volume mounts unchanged" plus "Read back via docker
  inspect" verification.
- For k8s-rollout-restart: "Pods rolled in waves per deployment
  strategy; PodDisruptionBudget continues to apply" plus "watch
  kubectl rollout status" verification.

approvalPreflight now appends class-specific safety and verification
content onto the existing default content rather than replacing it,
so the broker's structural safety posture (org scope, hash match,
single-use approval) remains visible alongside the operational copy.

Unknown command classes return nil/nil — no fabricated padding for
commands the bucket does not recognize. The default preflight stands
on its own, matching the no-fabrication rule that runs through the
rest of the trust-record arc.

Tests cover: each known class returns non-empty additions with the
expected operational tokens; unknown commands return nil; the
end-to-end approvalPreflight merge surfaces both default and
class-specific safety/verification entries. ai-runtime contract
pinned with the per-class enrichment rule and the no-fabrication
boundary for unknown classes.
2026-05-09 09:29:13 +01:00
2026-05-05 13:03:13 +01:00
2026-03-18 16:06:30 +00:00
2026-05-08 10:06:06 +01:00
2026-05-05 15:12:31 +01:00
2026-03-18 16:06:30 +00:00
2026-03-18 16:06:30 +00:00
2025-10-11 23:29:47 +00:00
2026-05-01 21:36:28 +01:00
2026-03-18 16:06:30 +00:00
2026-05-05 15:32:32 +01:00

Pulse

Pulse Logo

Real-time monitoring for Proxmox, Docker, Kubernetes, and TrueNAS infrastructure.

GitHub Stars GitHub release Docker Pulls License

Live DemoPulse ProDocumentationReport Bug


Issue-first contribution policy: please open an issue or discussion before investing time in a code change. External pull requests are not part of the normal contribution flow for this repository. See CONTRIBUTING.md.

🚀 Overview

Pulse is a modern, unified monitoring workspace for your infrastructure across Proxmox, Docker, Kubernetes, and TrueNAS. It consolidates metrics, alerts, and AI-powered insights from all your systems into a single, beautiful interface.

Designed for homelabs, sysadmins, and MSPs who need a "single pane of glass" without the complexity of enterprise monitoring stacks.

Pulse Infrastructure

🧭 Unified Navigation

Pulse now groups everything by task instead of data source:

  • Infrastructure for hosts and nodes
  • Workloads for VMs, containers, and Kubernetes pods
  • Storage and Backups as top-level views
  • PMG now routes into Infrastructure (source filter), and Kubernetes routes into Workloads (K8s filter)
  • Legacy URLs are no longer routed as compatibility aliases; use canonical v6 routes.

Power-user shortcuts:

  • g i → Infrastructure, g w → Workloads, ? → shortcuts help
  • / or Cmd/Ctrl+K → global search

Features

Core Monitoring

  • Unified Monitoring: View health and metrics for PVE, PBS, PMG, Docker, Kubernetes, and TrueNAS in one place
  • Smart Alerts: Get notified via Discord, Slack, Telegram, Email, and more
  • Auto-Discovery: Automatically finds Proxmox nodes on your network
  • Metrics History: Persistent storage with configurable retention
  • Recovery Central: Unified backup/snapshot/replication timeline across PBS and TrueNAS

AI-Powered

  • Chat Assistant (BYOK): Ask questions about your infrastructure in natural language
  • Patrol: Background health checks that generate findings on a schedule. Community self-hosted installs can run Patrol with your own AI provider or a local model.
  • Alert Analysis (Pro / hosted Cloud): Optional AI analysis when alerts fire
  • Cost Tracking: Track usage and costs per provider/model

Multi-Platform

  • Proxmox VE/PBS/PMG: Full monitoring and management
  • TrueNAS: Pools, datasets, disks, ZFS snapshots, replication tasks, and alerts
  • Kubernetes: Complete K8s cluster monitoring via agents
  • Docker/Podman: Container and Swarm service monitoring
  • OCI Containers: Proxmox 9.1+ native container support

Security & Operations

  • Secure by Design: Credentials encrypted at rest, strict API scoping, agent commands disabled by default
  • One-Click Updates: Easy upgrades for supported deployments
  • OIDC/SSO/SAML: Single sign-on with multi-provider support
  • Mobile Remote Access: Relay protocol with end-to-end encryption for supported Pulse Mobile clients (Relay and above)
  • Privacy Focused: Anonymous outbound telemetry is enabled by default and fully documented — no hostnames, credentials, or personal data is ever sent. Disable any time in Settings or via PULSE_TELEMETRY=false.

Quick Start

Paid Pulse Pro / Relay / legacy customers: GitHub release assets and the public rcourtman/pulse Docker image are community builds. They can accept an activation key, but they do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux archive.

Replace vX.Y.Z with the exact release tag you want, verify the signed installer, then run it on your Proxmox host:

export PULSE_VERSION=vX.Y.Z
curl -fsSLO "https://github.com/rcourtman/Pulse/releases/download/${PULSE_VERSION}/install.sh"
curl -fsSLO "https://github.com/rcourtman/Pulse/releases/download/${PULSE_VERSION}/install.sh.sshsig"
ssh-keygen -Y verify \
  -f <(printf '%s\n' 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIDs21c5oPk2khrdHlsw1aZ9EJKoTsyalGzhb0hdwJrkV pulse-installer') \
  -I pulse-installer \
  -n pulse-install \
  -s install.sh.sshsig < install.sh
bash install.sh --version "${PULSE_VERSION}"
rm -f install.sh install.sh.sshsig

Note: this installs the Pulse server. Agent installs use the command generated in Settings → Unified Agents → Installation commands (served from /install.sh on your Pulse server).

Option 2: Docker

docker run -d \
  --name pulse \
  -p 7655:7655 \
  -v pulse_data:/data \
  --restart unless-stopped \
  rcourtman/pulse:vX.Y.Z

Open Pulse at http://<your-ip>:7655.

Local Development

Use the managed dev runtime from the repo root:

npm run dev

Open http://127.0.0.1:5173 in the browser. 5173 is the frontend dev shell, and it proxies /api and /ws to the backend on 7655. 7655 is the backend dependency for API and websocket traffic, not the primary browser URL for local frontend development.

The managed dev runtime resets its local login to admin / adminadminadmin on startup unless you override it with HOT_DEV_AUTH_USER and HOT_DEV_AUTH_PASS.

Canonical local dev commands:

  • npm run dev — start the managed runtime and reclaim the canonical dev ports if an older unmanaged session is still using them
  • npm run dev:status — show frontend shell health, proxied API health, direct backend health, and listener ownership
  • npm run dev:verify — run the managed browser proof pack against the live dev runtime, including runtime recovery, the Patrol blocked-runtime page contract, and the desktop Recovery layout guard while the launcher suppresses unrelated backend rebuild churn for the duration of the proof pack
  • npm run dev:logs — tail the managed runtime log
  • npm run dev:backend-restart — bounce only the managed backend through the launcher contract
  • npm run dev:stop — stop the managed runtime
  • npm run dev:foreground — run the foreground hot-reload launcher intentionally if you need an attached shell

If npm run dev:verify passes, the managed dev shell, proxy path, backend health endpoint, browser recovery path, Patrol blocked-runtime page behavior, and Recovery desktop history-table layout are all aligned.

📚 Documentation

🌐 Community Integrations

Community-maintained integrations and addons:

💳 Plans (Community / Relay / Pro / Cloud)

Pulse is full-featured for core monitoring in every self-hosted tier. Self-hosted pricing no longer sells more room for monitoring volume; paid value comes from convenience, history, AI operations, and advanced administration. Cloud and MSP pricing are unchanged.

Self-hosted tiers:

Plan Price Core monitoring Metric history Main value
Community Free Included 7 days Full self-hosted monitoring
Relay $39/yr or $4.99/mo Included 14 days Remote web access, mobile app pairing, and push notifications
Pro $79/yr or $8.99/mo Included 90 days Root-cause analysis, safe remediation workflows, and operations tooling

Pulse still counts top-level monitored systems once no matter how they are collected. VMs, containers, pods, disks, backups, and other child resources under that system are included rather than counted separately, but that count is no longer the self-hosted paid gate.

Community keeps Patrol available with your own provider or local model. Relay remains the convenience tier, and Pro is the paid operations tier.

Runtime-aligned capability summary:

Capability Community Relay Pro Cloud
Pulse Patrol (Background Health Checks)
Remote Access / Mobile / Push
Alert-Triggered Root-Cause Analysis
Safe Remediation Workflows
Centralized Agent Profiles
Update Alerts (Container/Package Updates)
SSO (OIDC/SAML/Multi-Provider)
Role-Based Access Control (RBAC)
Enterprise Audit Logging
Advanced Infrastructure Reporting (PDF/CSV)
Extended Metric History 7 days 14 days 90 days 90 days

Pulse Patrol runs on your schedule (every 10 minutes to every 7 days, default 6 hours) and finds:

  • ZFS pools approaching capacity
  • Backup jobs that silently failed
  • VMs stuck in restart loops
  • Clock drift across cluster nodes
  • Container health check failures

On self-hosted installs, Pulse Patrol uses the provider you configure from your Pulse server. That can be a commercial API key or a local model endpoint. Chat Assistant follows the same self-managed provider model.

Technical highlights:

  • Cross-system context (nodes, VMs, backups, containers, and metrics history)
  • LLM analysis with your provider plus alert-triggered root-cause investigations (Pro / hosted Cloud)
  • Optional safe remediation execution with command safety policies and audit trail
  • Centralized agent profiles for consistent fleet settings

Try the live demo → or learn more at pulserelay.pro

Pulse plan technical details: docs/PULSE_PRO.md

❤️ Support Pulse Development

Pulse is maintained by one person. Sponsorships help cover the costs of the demo server, development tools, and domains. If Pulse saves you time, please consider supporting the project!

GitHub Sponsors ko-fi

📄 License

MIT © Richard Courtman. Use of Pulse Pro is subject to the Terms of Service.

S
Description
Monitoring for Proxmox, Docker, Kubernetes, TrueNAS, and vSphere that watches your infrastructure for you: smart alerts, AI patrols that catch silent failures, and verified fixes
Readme MIT 446 MiB
Languages
Go 61.4%
TypeScript 31.7%
Python 3.9%
Shell 1.8%
JavaScript 0.9%
Other 0.2%