mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-09-23 19:57:09 +00:00
dd5ee8120f
- Fix Export/Import API token authentication (wasn't sending X-API-Token header) - Add client-side passphrase validation (12+ chars with visual feedback) - Fix settings persistence for AllowedOrigins field - Fix hardcoded port display in diagnostics (now shows actual port) - Add .env file support for non-sensitive configuration (ports, logging, etc) - Keep sensitive data (API tokens, passwords) using secure methods (systemd env vars) - Update documentation with configuration guide and latest features - Document auto-discovery, cluster detection, and export/import features
3.4 KiB
3.4 KiB
Pulse Configuration Guide
Configuration Methods
Pulse uses different methods for different types of settings:
1. Web UI Configuration
Most settings are configured through the web interface:
- Nodes:
- Auto-discovers nodes on your network
- One-click setup with generated scripts
- Automatic cluster detection
- Manual add/remove also available
- Alerts: Set thresholds and notification rules
- Updates: Configure update channels and auto-update
- Security: Export/import encrypted configurations
2. Environment File (.env)
For non-sensitive system settings that require a restart:
# Copy the example file
sudo cp /opt/pulse/.env.example /etc/pulse/.env
# Edit settings
sudo nano /etc/pulse/.env
# Restart to apply changes
sudo systemctl restart pulse-backend
Available .env settings:
FRONTEND_PORT- Web UI port (default: 7655)ALLOWED_ORIGINS- CORS settings for reverse proxiesPOLLING_INTERVAL- How often to check nodes (seconds)LOG_LEVEL- Logging verbosity (debug/info/warn/error)UPDATE_CHANNEL- stable/beta/devMETRICS_RETENTION_DAYS- How long to keep metrics
3. Secure Environment Variables
For sensitive data like API tokens and passwords:
# Edit systemd service
sudo systemctl edit pulse-backend
# Add secure environment variables:
[Service]
Environment="API_TOKEN=your-secure-token"
Environment="ALLOW_UNPROTECTED_EXPORT=true"
# Restart service
sudo systemctl restart pulse-backend
Docker users:
docker run -e API_TOKEN=secure-token -p 7655:7655 rcourtman/pulse:latest
Data Storage
Encrypted Storage
All sensitive data is automatically encrypted at rest using AES-256-GCM:
- Node passwords and API tokens
- Email server passwords
- PBS credentials
The encryption key is auto-generated and stored at /etc/pulse/.encryption.key with restricted permissions.
File Locations
- Configuration:
/etc/pulse/(or./dataif not writable).env- Non-sensitive settings.encryption.key- Auto-generated encryption key (do not share!)nodes.enc- Encrypted node credentialsemail.enc- Encrypted email settingssystem.json- General settings
- Metrics:
/etc/pulse/metrics/ - Logs:
/etc/pulse/pulse.log
Common Configuration Tasks
Change the Web Port
echo "FRONTEND_PORT=8080" >> /etc/pulse/.env
sudo systemctl restart pulse-backend
Enable API Authentication
sudo systemctl edit pulse-backend
# Add: Environment="API_TOKEN=your-secure-token"
sudo systemctl restart pulse-backend
Configure for Reverse Proxy
echo "ALLOWED_ORIGINS=https://pulse.example.com" >> /etc/pulse/.env
sudo systemctl restart pulse-backend
Enable Debug Logging
echo "LOG_LEVEL=debug" >> /etc/pulse/.env
sudo systemctl restart pulse-backend
tail -f /etc/pulse/pulse.log
Security Notes
⚠️ Never put sensitive data in .env files!
- .env files are not encrypted
- Use systemd environment variables for API_TOKEN
- Node credentials are always stored encrypted
Troubleshooting
Port Already in Use
Check what's using the port:
sudo lsof -i :7655
Permission Denied
Ensure Pulse has write access:
sudo chown -R pulse:pulse /etc/pulse
Changes Not Taking Effect
Always restart after configuration changes:
sudo systemctl restart pulse-backend