Schema v6 shipped audit_logging_persistent and audit_events_30d as Pro adoption signals. Neither discriminated. pkg/server installs the SQLite audit logger on every install for defense in depth and gates only the read/export endpoints, so the boolean was true on all 8 installs that had taken rc.8 and 0 rows in the retained table have ever had it false. The event count measured that background write volume: three of those eight unlicensed community installs were pegged at the receiver's 100000 clamp ceiling, with the rest between 4863 and 67509. Schema v7 replaces both with audit_reads_30d, a count of requests that cleared the license gate on an audit read or export surface. A read requires a human action, so unlike store presence or write volume it cannot settle into a constant. The recorder is wrapped INSIDE RequireLicenseFeature so unentitled requests never count, and the persisted marker carries a timestamp and a coarse activity class from a fixed allowlist. Query filters, actors, ranges, and every audit row read stay on the install. The retired columns are left in the live database. They hold real rc.8 rows and migrations only add, so dropping them would be a pointless risk; nothing writes them once the receiver struct loses the fields. Adds the guard this class needed. LicensedFeatureAdoptionFields registers every field that exists to measure licensed-feature adoption, and TestLicensedFeatureAdoptionFieldsDiscriminate builds an unused install through the real production snapshot paths, installs a real SQLite audit logger exactly as pkg/server does, records a baseline audit event, and fails if any registered field is non-zero. Pinning a console logger there would have made the guard pass while the payload lied, so it deliberately does not. The guard was verified by reintroducing the v6 sourcing and confirming it fails with the field named. A companion test pins the three retired fields so they cannot return under their old names. This is the third instance of one bug class. v6 removed pulse_intelligence_patrol_autofixes_30d, hardcoded to zero with no increment site, and then introduced two fields that were constant in the other direction. Three occurrences is a guard, not a habit. Verified end to end on a running unlicensed install: the payload that reported audit_logging_persistent true under v6 now reports audit_reads_30d 0, and seeding two in-window reads, one outside the window, and one with an invalid activity class yields 2.
📚 Pulse Documentation
Welcome to the Pulse documentation portal. Here you'll find everything you need to install, configure, and master Pulse.
🚀 Getting Started
- Localized getting started: Deutsch • Español. These first-wave pages cover the public install path and preserve commands, config keys, image names, activation keys, and product identifiers exactly.
- Installation Guide Step-by-step guides for Docker, Kubernetes, and bare metal.
- Configuration
Learn how to configure authentication, notifications (Email, Discord, etc.), and system settings. - Deployment Models
Where config lives, how updates work, and what differs per deployment. - Migration Guide
Moving to a new server? Here's how to export and import your data safely. - Upgrade to v6
Practical upgrade guidance and post-upgrade checks for Pulse v6. - FAQ Common questions and quick answers.
🛠️ Deployment & Operations
- Docker Guide – Advanced Docker & Compose configurations.
- Kubernetes – Helm charts, ingress, and HA setups.
- Reverse Proxy – Nginx, Caddy, Traefik, and Cloudflare Tunnel recipes.
- Troubleshooting – Deep dive into common issues and logs.
🔐 Security
- Security Policy – The core security model (Encryption, Auth, API Scopes).
- Privacy – What leaves your network (and what doesn’t).
- OIDC / SSO – OIDC Single Sign-On configuration (Authentik, Keycloak, Azure AD, etc.).
- Proxy Auth – Authentik/Authelia/Cloudflare proxy authentication configuration.
- Agent Security – Agent privilege model, Proxmox API-only choices, and self-update verification.
📖 Advanced Topics (Relay / Pro / legacy Pro+ / Cloud)
- AI Modes & Safety – Configure Patrol mode, assistant control levels, investigation tuning, and safety guardrails.
- Role-Based Access Control (RBAC) – Define custom roles, assign permissions, and integrate with OIDC group mapping.
- Audit Logging – Tamper-evident event logging for compliance, with query, export, and signature verification.
✨ New in 6.0
- Unified Resource Model – How all platforms merge into one model with task-based navigation.
- Unified Navigation Migration – Upgrading from platform-specific tabs to v6 navigation.
- TrueNAS Integration – First-class TrueNAS SCALE/CORE monitoring (pools, datasets, disks, snapshots, replication).
- Relay / Pulse Mobile Handoff – End-to-end encrypted relay for supported Pulse Mobile clients (Relay and above).
- Recovery Central – Unified backup, snapshot, and replication view across all providers.
- Pulse Cloud (Hosted) – Fully managed hosting with automatic updates and backups.
- Pulse Intelligence – Pulse Assistant, Patrol findings, alert analysis, governed actions, and forecasts.
- Metrics History – Persistent metrics storage with configurable retention.
- Mail Gateway – Proxmox Mail Gateway (PMG) monitoring.
- Auto Updates – One-click updates for supported deployments.
- Multi-Tenant Organizations – Isolate infrastructure by organization (Enterprise, opt-in).
- Pulse for MSPs – Provider operations guide: per-client isolation, split ingress, alert routing, branded reports.
- Entitlements Overhaul – Capability-key-based feature gating across Community/Relay/Pro/Cloud, with legacy Pro+ continuity still supported.
💳 Plans (Community / Relay / Pro / Cloud)
Pulse is available in three self-hosted tiers plus hosted Cloud:
-
Community: Free self-hosted monitoring with core monitoring included and 7-day history.
-
Relay: Adds secure remote access to the Pulse web UI, Pulse Mobile pairing for handoff, push notifications, and 14-day history.
-
Pro: Adds hands-on Patrol modes, issue investigation, governed fixes, verified outcomes, operations tooling, governance features, and 90-day history.
-
Cloud: Hosted Pulse with Pro-level capabilities; hosted pricing is unchanged by the self-hosted model lock.
-
Plans and entitlements (includes the Community/Relay/Pro/Cloud matrix)
-
Multi-Tenant Organizations (Enterprise) — Isolate infrastructure by organization for MSPs and multi-datacenter deployments.
📡 Monitoring & Agents
- Unified Agent – Single binary for host, Docker, and Kubernetes monitoring.
- Centralized Agent Management (Pro/Cloud) – Agent profiles and remote config.
- Proxmox Backup Server – PBS integration, direct API vs PVE passthrough, token setup.
- TrueNAS – TrueNAS SCALE/CORE integration.
- ZFS Monitoring – Proxmox-native ZFS pool monitoring.
- Storage Architecture – Proposed canonical storage, disk, S.M.A.R.T., and topology model for making storage genuinely operator-useful.
- VM Disk Monitoring – Enabling QEMU Guest Agent for disk stats.
- Temperature Monitoring – Agent-based temperature monitoring (
pulse-agent --enable-proxmox). Sensor proxy has been removed. - Webhooks – Custom notification payloads.
💻 Development
- API Reference – Complete REST API documentation.
- Architecture – System design and component interaction.
- Contributing – How to contribute to Pulse.
- AI-Assisted Development – How AI tools are used to build and maintain Pulse, and where their output is labelled.
📁 Previous Versions
- Upgrade to v5 – Upgrade guidance for v4 → v5 migrations.
- v6 Release Promotion Policy – Canonical stable-vs-prerelease promotion rules and rollback expectations.
- v6 Prerelease Runbook – Internal release operations used during the v6 prerelease period.
Found a bug or have a suggestion?