The retry hardening added in #1885 bounded attempts but not time. npm's own fetch-timeout defaults to five minutes and it retries internally, so three "attempts" against a hanging advisory endpoint ran for 10m56s on job 100986651307, and a second audit step added 3m36s. The Frontend job was cancelled 31s into type-check with all 1183 test files already passing, and a cancelled job reports as a failed required check, so a green run blocked every pull request. #1888 raised the job timeout to 40 minutes to unblock delivery; this decides the policy instead. Each attempt now runs under a hard wall-clock bound and the sequence stops at a total deadline (60s and 240s by default). npm's internal retry loop is disabled in favour of this one, since it was the hidden multiplier. The bound is enforced by a watchdog subshell rather than timeout(1), which is not present on every developer machine. What happens when the endpoint stays unreachable is unchanged, because that split was already right: the run fails when the change touches the dependency graph and the answer is genuinely unknown, and warns without failing when it does not, because the graph is then identical to a base commit that already produced a passing answer. Any advisory at any severity still fails. Also drops the production-only audit from the per-pull-request path. It audits a subset of the same packages, so it reports a subset of the same advisories, and because the complete audit fails the job on any finding, the production step could only ever execute in the cases where it was already guaranteed clean. The dev-versus-production split still runs for every npm workspace in the scheduled security-scan job, where it informs rather than blocks delivery, and Dependabot security updates remain the route for advisories published against unchanged dependencies. With the audit bounded to 4 minutes against an ~11 minute baseline, the job timeout returns to 30: a stalled endpoint should surface as a warning, not be absorbed by a budget large enough to hide it.
Pulse documentation
Start here for installation, platform setup, security, operations, and Pulse Intelligence. Commands, configuration keys, image names, API fields, and product identifiers remain untranslated in localized guides.
Start here
- Install Pulse — signed Proxmox/Linux installation, Docker, Docker Compose, Kubernetes, and first-run setup.
- Production deployment and security — least-privilege Proxmox setup, root-agent boundaries, discovery, supply-chain verification, plan limits, scale evidence, and a rollout checklist.
- Upgrade from Pulse v5 — migration prerequisites, rollback, agent continuity, and post-upgrade checks.
- Configure Pulse — authentication, notifications, discovery, retention, and system settings.
- Deployment models — data locations, lifecycle, and differences between supported deployment paths.
- Troubleshooting and FAQ — common failures, diagnostics, and operator questions.
Localized getting started guides: Deutsch · Español
Platforms and agents
- Proxmox Backup Server
- Proxmox Mail Gateway
- Docker and Podman
- Kubernetes and Helm
- TrueNAS SCALE and CORE
- Unified Agent
- Agent security
- VM disk monitoring
- ZFS monitoring
- Temperature monitoring
VMware vSphere support is early access. Current builds expose dedicated vSphere inventory and recovery context, but operators should validate the integration against their own vCenter before production use.
Monitoring and operations
- Metrics history
- Recovery data
- Webhooks
- Automatic updates
- Centralized agent management (Pro)
- Operational trust model
- Current product screenshots
Pulse Intelligence
- Assistant, Patrol, and external-agent overview
- Patrol modes and safety
- Assistant safety model
- External agent HTTP and MCP substrate
Patrol watch-only analysis is available on Community with a local model or the operator's own provider. Investigation and governed fixes require the relevant Pulse Pro capabilities.
Security, privacy, and access
- Production deployment and security
- Security review scope
- Authentication and credential storage review packet
- Security guide
- Privacy and telemetry disclosure
- OIDC and SSO
- Proxy authentication
- Role-based access control (Pro)
- Audit logging (Pro)
- Reverse proxy configuration
- Code-signing policy
Plans and managed access
- Community, Relay, and Pro capabilities
- Relay and Pulse Mobile handoff
- Multi-tenant organizations (Enterprise/custom)
- Provider-hosted MSP operations (request-assisted)
Pulse Cloud is not generally available. Ordinary self-hosted Pulse remains the primary installation path; MSP and Enterprise access are explicit commercial paths rather than defaults in self-hosted setup.
Development and reference
Detailed design notes and dated migration specifications may remain in this directory for maintainers, but they are not operator setup guides unless they are linked from the sections above.
Previous versions and migrations
- Upgrade from v4 to v5
- Retired unified-navigation migration — historical context only; current Pulse uses platform-shaped navigation.
- Move a Pulse installation
Found a bug? Use the issue forms. For setup questions, use GitHub Discussions.