Files
pulse/docs
rcourtman e8455e84b7 fix(resources): pin canonical host IDs to durable identity so they survive restarts
Canonical IDs for merged-source hosts (PVE node + pulse-agent) were minted
from whichever identity keys the creating record happened to carry: the
agent record knows the machine ID, the Proxmox node record only knows
cluster+hostname. The registry rebuilds from scratch every tick, so a boot
window where the agent had not checked in yet minted a cluster-keyed ID
(agent-7a62... for delly) while steady state minted a machine-keyed one
(agent-bdd4...). Every restart re-ran the race, fragmenting the
resource_changes journal into per-boot eras (9.4k vs 6.1k rows for the
same host) and silently truncating report availability and UI timelines.

Fix, in the layer that owns identity:
- Persist identity pins (canonical_id <-> machine_id/dmi/cluster/hostname)
  in the previously schema-only resource_identities table, written by the
  store-backed registry after monitor-adapter rebuilds, diff-aware so
  steady-state ticks cost no writes.
- Complete weak incoming identities from the pins before matching and ID
  derivation, so a node-only boot window derives the same machine-keyed
  canonical ID as steady state. Derivation itself is unchanged; ephemeral
  nil-store registries behave exactly as before.
- Expand change-journal reads (Get/Count families, SQLite and memory) to
  the full era set recomputed from the pinned identity keys, healing
  historical journals at query time with no row migration. Reads keyed by
  a stale era ID resolve to the same merged timeline.

Regression tests cover both ingest orders, restart simulation via the
monitor adapter, era ID derivation, and era-merged journal reads on both
store implementations. Contracts updated: unified-resources obligation 25
(durable identity pins), monitoring obligation 10 (adapter rebuild
persistence).
2026-06-11 08:33:00 +01:00
..
2026-06-04 18:44:47 +01:00
2026-06-02 19:14:18 +01:00
2026-06-02 19:14:18 +01:00
2026-06-04 14:07:14 +01:00

📚 Pulse Documentation

Welcome to the Pulse documentation portal. Here you'll find everything you need to install, configure, and master Pulse.


v6 Execution Canonical Source

For Pulse v6 build/release execution work, do not start from this broad docs index. Use:

  1. docs/release-control/v6/internal/SOURCE_OF_TRUTH.md for stable human governance and locked decisions
  2. docs/release-control/v6/internal/status.json for live lane state, lane-to-subsystem ownership, structured evidence references, typed lane/subsystem decision records, and canonical ordered lists
  3. docs/release-control/v6/status.schema.json for the machine-readable status contract
  4. docs/release-control/v6/internal/subsystems/registry.json and docs/release-control/v6/internal/subsystems/registry.schema.json for subsystem ownership, explicit shared-ownership exceptions, and proof-routing rules
  5. python3 scripts/release_control/status_audit.py --check if you need a machine-derived evidence health audit
  6. python3 scripts/release_control/registry_audit.py --check if you need a machine-derived subsystem registry audit
  7. python3 scripts/release_control/contract_audit.py --check if you need a machine-derived subsystem contract audit, including explicit cross-subsystem dependency checks and exact registry-derived shared-boundary wording Local pre-commit runs the v6 machine audits against staged control-file content so partial staging cannot hide governance drift. Local pre-commit also blocks partial staging for hook-sensitive governance files under docs/release-control/v6/, scripts/release_control/, internal/repoctl/, .husky/pre-commit, and .github/workflows/canonical-governance.yml, because those checks still execute or structurally read the working-tree versions locally.
  8. python3 scripts/release_control/subsystem_lookup.py <path> [<path> ...] --pretty --lean if you need subsystem ownership, proof routing, exact contract-focus lines, and compact lane context for a change

For governed runtime changes, a staged subsystem contract only counts if its diff updates a substantive contract section such as Purpose, Canonical Files, Shared Boundaries, Extension Points, Forbidden Paths, Completion Obligations, or Current State, rather than metadata alone.

All other documents are supporting references unless explicitly required for evidence.


🚀 Getting Started

  • Installation Guide Step-by-step guides for Docker, Kubernetes, and bare metal.
  • Configuration
    Learn how to configure authentication, notifications (Email, Discord, etc.), and system settings.
  • Deployment Models
    Where config lives, how updates work, and what differs per deployment.
  • Migration Guide
    Moving to a new server? Here's how to export and import your data safely.
  • Upgrade to v6
    Practical upgrade guidance and post-upgrade checks for Pulse v6.
  • FAQ Common questions and quick answers.

🛠️ Deployment & Operations

🔐 Security

  • Security Policy The core security model (Encryption, Auth, API Scopes).
  • Privacy What leaves your network (and what doesnt).
  • OIDC / SSO OIDC Single Sign-On configuration (Authentik, Keycloak, Azure AD, etc.).
  • Proxy Auth Authentik/Authelia/Cloudflare proxy authentication configuration.
  • Agent Security Agent privilege model, Proxmox API-only choices, and self-update verification.

📖 Advanced Topics (Relay / Pro / legacy Pro+ / Cloud)

  • AI Autonomy & Safety Configure patrol autonomy levels, assistant control levels, investigation tuning, and safety guardrails.
  • Role-Based Access Control (RBAC) Define custom roles, assign permissions, and integrate with OIDC group mapping.
  • Audit Logging Tamper-evident event logging for compliance, with query, export, and signature verification.

New in 6.0

  • Unified Resource Model How all platforms merge into one model with task-based navigation.
  • Unified Navigation Migration Upgrading from platform-specific tabs to v6 navigation.
  • TrueNAS Integration First-class TrueNAS SCALE/CORE monitoring (pools, datasets, disks, snapshots, replication).
  • Relay / Pulse Mobile Handoff End-to-end encrypted relay for supported Pulse Mobile clients (Relay and above).
  • Recovery Central Unified backup, snapshot, and replication view across all providers.
  • Pulse Cloud (Hosted) Fully managed hosting with automatic updates and backups.
  • Pulse AI Chat assistant, patrol findings, alert analysis, intelligence, and forecasts.
  • Metrics History Persistent metrics storage with configurable retention.
  • Mail Gateway Proxmox Mail Gateway (PMG) monitoring.
  • Auto Updates One-click updates for supported deployments.
  • Multi-Tenant Organizations Isolate infrastructure by organization (Enterprise, opt-in).
  • Pulse for MSPs Provider operations guide: per-client isolation, split ingress, alert routing, branded reports.
  • Entitlements Overhaul Capability-key-based feature gating across Community/Relay/Pro/Cloud, with legacy Pro+ continuity still supported.

💳 Plans (Community / Relay / Pro / Cloud)

Pulse is available in three self-hosted tiers plus hosted Cloud:

  • Community: Free self-hosted monitoring with core monitoring included and 7-day history.

  • Relay: Adds secure remote access to the Pulse web UI, Pulse Mobile pairing for handoff, push notifications, and 14-day history.

  • Pro: Adds alert-triggered root-cause analysis, safe remediation workflows, operations tooling, governance features, and 90-day history.

  • Cloud: Hosted Pulse with Pro-level capabilities; hosted pricing is unchanged by the self-hosted model lock.

  • Learn more at pulserelay.pro

  • Plans and entitlements (includes the Community/Relay/Pro/Cloud matrix)

  • AI deep dive

  • Multi-Tenant Organizations (Enterprise) — Isolate infrastructure by organization for MSPs and multi-datacenter deployments.

📡 Monitoring & Agents

💻 Development

📁 Previous Versions


Found a bug or have a suggestion?

GitHub Issues