lxc-attach into an unprivileged guest writes /proc/<pid>/uid_map, which needs CAP_SETUID in the parent user namespace. NoNewPrivileges drops CAP_SETUID from the effective set and also stops lxc-attach falling back to the setuid newuidmap/newgidmap helpers, so the socket probe dies with "write_id_mapping: 61 Operation not permitted". install.sh already relaxed NoNewPrivileges for this, but only when the agent was installed with --enable-commands. Command execution is also togglable from the server afterwards: applyRemoteConfig starts the command client without rewriting the unit. An agent installed without the flag and switched on later therefore ends up able to run commands and unable to attach to unprivileged guests, so Docker inside every unprivileged LXC disappears from the Proxmox page. The probe failure is logged at debug level and retried on every poll, so the surface looks empty rather than broken while the agent re-probes the whole guest list. Grant CAP_SETUID/CAP_SETGID to any PVE agent rather than gating on the install-time flag, so the later toggle lands on a unit that can attach. Ambient capabilities restore exactly the privilege lxc-attach needs and leave the rest of the sandbox intact; the existing install-time relaxation is unchanged. Verified on a live PVE node. With the hardened unit the probe succeeded only on the three privileged guests and failed on every unprivileged one. After the ambient grant CapEff regained CAP_SETUID and both unprivileged Docker guests were discovered, taking that node from one Docker LXC to three.
Pulse
Pulse is a self-hosted monitoring workspace for Proxmox, Docker, Kubernetes, TrueNAS, physical and virtual machines, and early-access VMware vSphere environments. It combines live infrastructure state, history, alerts, recovery visibility, and scheduled health checks without requiring a conventional enterprise monitoring stack.
Why Pulse
- It watches between visits. Alerts and Pulse Patrol find failed backups, capacity pressure, restart loops, unhealthy containers, clock drift, and other problems that dashboards cannot surface when nobody is looking.
- It keeps each platform familiar. Proxmox, Docker, Kubernetes, TrueNAS, vSphere, and machines have dedicated views, backed by one shared resource model for search, alerts, history, and investigation.
- It stays operator-controlled. Credentials are encrypted at rest, API tokens are scoped, agent commands are disabled by default, and governed fixes require the configured policy and approval path.
Platform coverage
| Platform | Coverage |
|---|---|
| Proxmox VE, PBS, and PMG | Nodes, guests, storage, backups, replication, Ceph, mail gateways, and alerts |
| Docker and Podman | Hosts, containers, Compose projects, Swarm services, health, images, and updates |
| Kubernetes | Clusters, nodes, workloads, pods, services, storage, and events through the unified agent |
| TrueNAS SCALE and CORE | Pools, datasets, disks, snapshots, replication tasks, apps, VMs, and alerts |
| Linux, Windows, and macOS machines | Host health, filesystems, networking, temperatures, RAID, and availability through the unified agent |
| VMware vSphere | Early-access inventory, hosts, clusters, VMs, datastores, networks, snapshots, and recovery context; validate against your own vCenter before production use |
Platform pages keep storage and recovery information beside the infrastructure it belongs to. Alerts, Actions, and Patrol remain cross-platform views.
Patrol: monitoring that does rounds
Pulse Patrol runs scheduled checks across the current state and recent history of your infrastructure. Community installations can use a local model or their own AI provider for watch-only analysis. Pulse Pro adds investigation and policy-bound fixes with approval, verification, and an audit trail.
Pulse also includes an interactive Assistant and an MCP adapter for external clients such as Claude Code and OpenCode. Both sit on top of the same scoped inventory, metrics, alert, storage, and governed-action contracts.
Quick start
Choose an exact version from the latest release and keep that version pinned during installation.
Docker
docker run -d \
--name pulse \
-p 7655:7655 \
-v pulse_data:/data \
-e PULSE_DEPLOYMENT_METHOD=docker_run \
--restart unless-stopped \
rcourtman/pulse:vX.Y.Z
Open http://<your-ip>:7655 and follow the bootstrap-token setup. Docker host
monitoring is provided by the unified agent; the Pulse server container does
not need the Docker socket.
Proxmox LXC, Linux, and Kubernetes
The installer is signed. Verify install.sh against the pinned
pulse-installer key before running it:
export PULSE_VERSION=vX.Y.Z
curl -fsSLO "https://github.com/rcourtman/Pulse/releases/download/${PULSE_VERSION}/install.sh"
curl -fsSLO "https://github.com/rcourtman/Pulse/releases/download/${PULSE_VERSION}/install.sh.sshsig"
ssh-keygen -Y verify \
-f <(printf '%s\n' 'pulse-installer namespaces="pulse-install" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMZd/DaH+BldzOkq1A8KVTcFk73nAyrE8aJOyf7i00jm pulse-installer') \
-I pulse-installer \
-n pulse-install \
-s install.sh.sshsig < install.sh
bash install.sh --version "${PULSE_VERSION}"
rm -f install.sh install.sh.sshsig
The GitHub installer installs the Pulse server. Install and upgrade agents (including v5-to-v6 agent upgrades) with the per-host command generated under Settings → Infrastructure → Install on a host.
Important
GitHub release assets and
rcourtman/pulseimages are Community builds. Relay, Pro, and eligible legacy customers should use the private image or Linux archive provided by the Pulse download portal. Replacing a private Pro runtime with a public Community build removes its private runtime hooks.
Editions
- Community — self-hosted monitoring, seven days of metric history, core SSO, update alerts, and Patrol with your own provider or local model.
- Relay — Community plus secure remote web access, Pulse Mobile pairing, push notifications, and fourteen days of history.
- Pro — Relay plus Patrol investigation, governed fixes, ninety days of history, centralized agent profiles, RBAC, audit logging, and reporting.
- MSP — for managed service providers: one Pulse Account running many client workspaces, each with an isolated Pulse runtime — separate dashboards, alerts, users, audit history, and reports. Free sixty-day two-client evaluation at Pulse for MSPs.
Core self-hosted monitoring is not gated by monitored-system or child-resource volume. See the runtime-aligned capability reference and current plans for details.
Documentation
- Install and deployment
- Production deployment and security
- Upgrade from Pulse v5
- Configuration
- Platform and agent guides
- Pulse Intelligence
- Security and privacy
- Code signing policy
- Troubleshooting
- API reference and architecture
Localized getting started guides: Deutsch · Español
Development
Pulse uses Go 1.26 and a SolidJS/TypeScript frontend. The managed development
runtime starts the frontend at http://127.0.0.1:5173 and proxies API and
WebSocket traffic to the backend on port 7655.
npm ci
npm --prefix frontend-modern ci
npm run dev
Useful checks:
go test ./...
npm --prefix frontend-modern test
npm --prefix frontend-modern run type-check
python3 scripts/check_public_docs.py
See CONTRIBUTING.md before investing in a code change. Pulse uses an issue-first contribution process and does not normally accept unsolicited pull requests.
Community and support
- Ask questions in GitHub Discussions.
- Report reproducible bugs through GitHub Issues.
- Home Assistant users can use the community-maintained Pulse add-ons.
- If Pulse is useful to you, support its development through GitHub Sponsors or Ko-fi.
License
Everything in this repository is licensed under the MIT License. There is no dual licensing and no commercial or source-available code here.
Pulse Pro is a separate commercial product, built from private sources and distributed through pulserelay.pro. Its use is governed by the Terms of Service, which apply to that product only, not to anything in this repository.

