diff --git a/docs/docs.json b/docs/docs.json
index 64928a48..e53eb7b9 100644
--- a/docs/docs.json
+++ b/docs/docs.json
@@ -209,6 +209,41 @@
}
]
},
+ {
+ "tab": "Tutorials",
+ "groups": [
+ {
+ "group": "Fleet & nodes",
+ "pages": [
+ "tutorials/enroll-a-remote-node",
+ "tutorials/set-up-sencho-mesh",
+ "tutorials/set-up-fleet-federation",
+ "tutorials/configure-recovery-vault-backups"
+ ]
+ },
+ {
+ "group": "Deploy & automate",
+ "pages": [
+ "tutorials/create-and-approve-a-blueprint",
+ "tutorials/connect-a-git-source",
+ "tutorials/schedule-an-operation",
+ "tutorials/configure-auto-update-policies",
+ "tutorials/configure-auto-heal-policies",
+ "tutorials/set-up-deploy-enforcement"
+ ]
+ },
+ {
+ "group": "Secure & integrate",
+ "pages": [
+ "tutorials/connect-a-private-registry",
+ "tutorials/set-up-rbac",
+ "tutorials/configure-environment-guardrails",
+ "tutorials/set-up-a-webhook",
+ "tutorials/resolve-stack-drift"
+ ]
+ }
+ ]
+ },
{
"tab": "API Reference",
"openapi": "openapi.yaml",
diff --git a/docs/images/tutorials/enroll-a-remote-node/add-node-filled.png b/docs/images/tutorials/enroll-a-remote-node/add-node-filled.png
new file mode 100644
index 00000000..885e82ad
Binary files /dev/null and b/docs/images/tutorials/enroll-a-remote-node/add-node-filled.png differ
diff --git a/docs/images/tutorials/enroll-a-remote-node/edit-node-regenerate.png b/docs/images/tutorials/enroll-a-remote-node/edit-node-regenerate.png
new file mode 100644
index 00000000..58b46c41
Binary files /dev/null and b/docs/images/tutorials/enroll-a-remote-node/edit-node-regenerate.png differ
diff --git a/docs/images/tutorials/enroll-a-remote-node/fleet-view-two-nodes.png b/docs/images/tutorials/enroll-a-remote-node/fleet-view-two-nodes.png
new file mode 100644
index 00000000..fb3287ec
Binary files /dev/null and b/docs/images/tutorials/enroll-a-remote-node/fleet-view-two-nodes.png differ
diff --git a/docs/images/tutorials/enroll-a-remote-node/node-switcher-popover.png b/docs/images/tutorials/enroll-a-remote-node/node-switcher-popover.png
new file mode 100644
index 00000000..ae7ce7e0
Binary files /dev/null and b/docs/images/tutorials/enroll-a-remote-node/node-switcher-popover.png differ
diff --git a/docs/images/tutorials/enroll-a-remote-node/nodes-table-online.png b/docs/images/tutorials/enroll-a-remote-node/nodes-table-online.png
new file mode 100644
index 00000000..3e6cb8f3
Binary files /dev/null and b/docs/images/tutorials/enroll-a-remote-node/nodes-table-online.png differ
diff --git a/docs/images/tutorials/enroll-a-remote-node/pilot-enroll-modal.png b/docs/images/tutorials/enroll-a-remote-node/pilot-enroll-modal.png
new file mode 100644
index 00000000..7ac38620
Binary files /dev/null and b/docs/images/tutorials/enroll-a-remote-node/pilot-enroll-modal.png differ
diff --git a/docs/tutorials/configure-auto-heal-policies.mdx b/docs/tutorials/configure-auto-heal-policies.mdx
new file mode 100644
index 00000000..423a752a
--- /dev/null
+++ b/docs/tutorials/configure-auto-heal-policies.mdx
@@ -0,0 +1,26 @@
+---
+title: Configure Auto-Heal Policies
+sidebarTitle: Configure auto-heal policies
+description: Step-by-step instructions for setting up automatic recovery policies for unhealthy stacks.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Auto-Heal Policies feature page](/features/auto-heal-policies) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Automatically recover unhealthy stacks under a policy you define.
+
+
diff --git a/docs/tutorials/configure-auto-update-policies.mdx b/docs/tutorials/configure-auto-update-policies.mdx
new file mode 100644
index 00000000..8a1f0d97
--- /dev/null
+++ b/docs/tutorials/configure-auto-update-policies.mdx
@@ -0,0 +1,26 @@
+---
+title: Configure Auto-Update Policies
+sidebarTitle: Configure auto-update policies
+description: Step-by-step instructions for setting up automatic image update policies.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Auto-Update Policies feature page](/features/auto-update-policies) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Automatically update stacks under a policy you define.
+
+
diff --git a/docs/tutorials/configure-environment-guardrails.mdx b/docs/tutorials/configure-environment-guardrails.mdx
new file mode 100644
index 00000000..97e41b7b
--- /dev/null
+++ b/docs/tutorials/configure-environment-guardrails.mdx
@@ -0,0 +1,26 @@
+---
+title: Configure Environment Guardrails
+sidebarTitle: Configure environment guardrails
+description: Step-by-step instructions for setting up environment variable guardrail rules.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Environment Guardrails feature page](/features/environment-guardrails) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Rules that catch risky environment variable changes.
+
+
diff --git a/docs/tutorials/configure-recovery-vault-backups.mdx b/docs/tutorials/configure-recovery-vault-backups.mdx
new file mode 100644
index 00000000..52465356
--- /dev/null
+++ b/docs/tutorials/configure-recovery-vault-backups.mdx
@@ -0,0 +1,26 @@
+---
+title: Configure Recovery Vault Backups
+sidebarTitle: Configure Recovery Vault backups
+description: Step-by-step instructions for configuring and restoring fleet backups with Recovery Vault.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Fleet Backups feature page](/features/fleet-backups) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Configure Recovery Vault backups and restore stacks or nodes.
+
+
diff --git a/docs/tutorials/connect-a-git-source.mdx b/docs/tutorials/connect-a-git-source.mdx
new file mode 100644
index 00000000..a3fd4172
--- /dev/null
+++ b/docs/tutorials/connect-a-git-source.mdx
@@ -0,0 +1,26 @@
+---
+title: Connect a Git Source
+sidebarTitle: Connect a Git source
+description: Step-by-step instructions for connecting a Git repository as a compose source.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Git Sources feature page](/features/git-sources) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Sync compose files from a Git repository.
+
+
diff --git a/docs/tutorials/connect-a-private-registry.mdx b/docs/tutorials/connect-a-private-registry.mdx
new file mode 100644
index 00000000..88ba652b
--- /dev/null
+++ b/docs/tutorials/connect-a-private-registry.mdx
@@ -0,0 +1,26 @@
+---
+title: Connect a Private Registry
+sidebarTitle: Connect a private registry
+description: Step-by-step instructions for connecting a private container registry with credentials.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Private Registries feature page](/features/private-registries) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Authenticate against private container registries.
+
+
diff --git a/docs/tutorials/create-and-approve-a-blueprint.mdx b/docs/tutorials/create-and-approve-a-blueprint.mdx
new file mode 100644
index 00000000..bcab3b13
--- /dev/null
+++ b/docs/tutorials/create-and-approve-a-blueprint.mdx
@@ -0,0 +1,26 @@
+---
+title: Create and Approve a Blueprint
+sidebarTitle: Create and approve a blueprint
+description: Step-by-step instructions for authoring, previewing, and approving a rollout blueprint.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Blueprint Model feature page](/features/blueprint-model) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Author, preview, and approve fleet-wide rollouts.
+
+
diff --git a/docs/tutorials/enroll-a-remote-node.mdx b/docs/tutorials/enroll-a-remote-node.mdx
new file mode 100644
index 00000000..b05fad57
--- /dev/null
+++ b/docs/tutorials/enroll-a-remote-node.mdx
@@ -0,0 +1,96 @@
+---
+title: Enroll a Remote Node
+sidebarTitle: Enroll a remote node
+description: Bring a second server under management in the same Sencho console, without opening any inbound ports on it.
+---
+
+Say you run Sencho on one server already, and you separately have a home media server running a Jellyfin stack via Docker Compose, on a connection with no port forwarding. This walks through bringing that second server into your Sencho console as a remote node, using **Pilot Agent** mode: the remote host only needs outbound HTTPS, so nothing has to be opened on your router or firewall.
+
+By the end, both servers appear side by side in the same console, and Sencho can see the Jellyfin containers already running on the second one.
+
+This tutorial does not cover **Distributed API Proxy** mode (for a remote host you already expose on a stable URL), [Sencho Mesh](/features/sencho-mesh) cross-node networking, or adopting a discovered Compose file into a managed stack. See the [Multi-Node Management](/features/multi-node) feature page for those.
+
+## Prerequisites
+
+- An **admin** account on the Sencho instance that will act as the control instance. Adding, editing, and testing nodes requires admin.
+- Docker and the Docker Compose plugin installed on the second server, with SSH or console access as the user that owns the Docker socket.
+- The second server must be able to reach your control instance over outbound HTTPS (or HTTP, if both are on the same private network or VPN).
+
+
+ If your control instance is not reachable from the public internet or the remote server's network (for example, it only listens on `localhost` with no port forwarding and no `SENCHO_PUBLIC_URL` set), the agent will never dial home and the node will sit at `tunnel (waiting)` indefinitely. Confirm the remote host can reach your control instance's URL before starting.
+
+
+
+
+ On your control instance, click your avatar in the top-right and choose **Settings**. In the sidebar, under **Infrastructure**, pick **Nodes**, then click **Add node**.
+
+ Set **Name** to something that identifies the host (`media-server` here). Leave **Type** as **Remote** and **Mode** as **Pilot Agent**, both defaults. In **Compose Directory**, enter the absolute path on the remote host where its Compose stacks already live, or where you want them to live, `/home/ubuntu/docker` in this example. The agent mounts that same path inside its own container, so existing bind-mount paths in your Compose files keep working unchanged.
+
+
+
+
+
+ Click **Add node**.
+
+
+ A dialog opens with a generated Compose file and a start command.
+
+
+
+
+
+ Save Step 1's contents as `compose.yaml` in a directory on the remote host (it does not need to be the Compose Directory itself), then run Step 2's command in that same directory as the user that owns Docker:
+
+ ```bash
+ docker compose up -d
+ ```
+
+ This pulls the `saelix/sencho:latest` image, mounts the host's Docker socket, and starts a container named `sencho-agent` that dials out to your control instance. It does not touch or restart anything already running on the host, including your existing Jellyfin container.
+
+ The enrollment token embedded in the file is valid for **15 minutes and can only be used once**. If it expires before you run the command, see [If something goes wrong](#if-something-goes-wrong) below.
+
+
+ Back on the Nodes table, the new row starts at **Status: Unknown** with Endpoint `tunnel (waiting)`. Once the agent dials home, usually within a few seconds of `docker compose up -d` finishing, the row flips to **Status: Online** and the Endpoint reads `tunnel (seen Xs ago)`.
+
+
+
+
+
+
+
+## Verify it worked
+
+Check from two places, since either alone could be misleading (a stuck browser tab, or a table row that has not refreshed).
+
+**The node switcher.** Click the switcher at the top of the sidebar. Your new node appears in the **Connected** list with an `AGENT` kicker and a `SEEN Xm AGO` timestamp.
+
+
+
+
+
+**The Fleet view.** Switch back to Local if you navigated away, then open the **Fleet** tab. Both nodes show as separate cards with independent CPU, RAM, and disk stats pulled live from each host. The media-server card's running-container count reflects Jellyfin (and the agent itself), not just an empty shell.
+
+
+
+
+
+Click the node switcher and select your new node to confirm you can operate against it directly. Every top-level view scoped to that host, Home, Resources, Networking, Security, works the same way it does for Local. Fleet-wide views (Fleet itself, Schedules, Audit, Logs, Auto-Update) stay hidden until you switch back to Local, because they only make sense from the hub.
+
+## If something goes wrong
+
+The most common first-time snag is the 15-minute enrollment token expiring before you run `docker compose up -d`, usually because of a copy-paste detour or a slow SSH session. The node row stays on `tunnel (waiting)` indefinitely; it does not time out or show an error on its own. If more than 15 minutes have passed, open **Edit node** on that row, click **Regenerate enrollment token**, and repeat the save-and-run-compose steps with the fresh file. The previous tunnel attempt is closed automatically, so there is nothing to clean up on the remote host first.
+
+
+
+
+
+## Related
+
+
+
+ Distributed API Proxy mode, Sencho Mesh, license inheritance across nodes, and full troubleshooting.
+
+
+ Credential lifecycle, resource limits, and pilot-specific troubleshooting for the tunnel itself.
+
+
diff --git a/docs/tutorials/resolve-stack-drift.mdx b/docs/tutorials/resolve-stack-drift.mdx
new file mode 100644
index 00000000..b450879c
--- /dev/null
+++ b/docs/tutorials/resolve-stack-drift.mdx
@@ -0,0 +1,26 @@
+---
+title: Resolve Stack Drift
+sidebarTitle: Resolve stack drift
+description: Step-by-step instructions for choosing a drift policy mode and resolving a detected drift.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Stack Drift feature page](/features/stack-drift) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Detect and resolve configuration drift against the last deploy.
+
+
diff --git a/docs/tutorials/schedule-an-operation.mdx b/docs/tutorials/schedule-an-operation.mdx
new file mode 100644
index 00000000..0ad31506
--- /dev/null
+++ b/docs/tutorials/schedule-an-operation.mdx
@@ -0,0 +1,26 @@
+---
+title: Schedule an Operation
+sidebarTitle: Schedule an operation
+description: Step-by-step instructions for creating a scheduled stack operation.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Scheduled Operations feature page](/features/scheduled-operations) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Run stack operations on a recurring schedule.
+
+
diff --git a/docs/tutorials/set-up-a-webhook.mdx b/docs/tutorials/set-up-a-webhook.mdx
new file mode 100644
index 00000000..8351e8ef
--- /dev/null
+++ b/docs/tutorials/set-up-a-webhook.mdx
@@ -0,0 +1,26 @@
+---
+title: Set Up a Webhook
+sidebarTitle: Set up a webhook
+description: Step-by-step instructions for wiring an outbound webhook to an external consumer.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Webhooks feature page](/features/webhooks) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Send stack and fleet events to external consumers.
+
+
diff --git a/docs/tutorials/set-up-deploy-enforcement.mdx b/docs/tutorials/set-up-deploy-enforcement.mdx
new file mode 100644
index 00000000..7e954732
--- /dev/null
+++ b/docs/tutorials/set-up-deploy-enforcement.mdx
@@ -0,0 +1,26 @@
+---
+title: Set Up Deploy Enforcement
+sidebarTitle: Set up deploy enforcement
+description: Step-by-step instructions for configuring deploy gates and enforcement thresholds.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Deploy Enforcement feature page](/features/deploy-enforcement) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Gate deployments on vulnerability and drift policy.
+
+
diff --git a/docs/tutorials/set-up-fleet-federation.mdx b/docs/tutorials/set-up-fleet-federation.mdx
new file mode 100644
index 00000000..58a753fd
--- /dev/null
+++ b/docs/tutorials/set-up-fleet-federation.mdx
@@ -0,0 +1,26 @@
+---
+title: Set Up Fleet Federation
+sidebarTitle: Set up fleet federation
+description: Step-by-step instructions for federating multiple Sencho fleets.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Fleet Federation feature page](/features/fleet-federation) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Link separate Sencho fleets together.
+
+
diff --git a/docs/tutorials/set-up-rbac.mdx b/docs/tutorials/set-up-rbac.mdx
new file mode 100644
index 00000000..b558e498
--- /dev/null
+++ b/docs/tutorials/set-up-rbac.mdx
@@ -0,0 +1,26 @@
+---
+title: Set Up RBAC
+sidebarTitle: Set up RBAC
+description: Step-by-step instructions for configuring roles and scoped assignments.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [RBAC feature page](/features/rbac) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ Roles and scoped assignments for team access control.
+
+
diff --git a/docs/tutorials/set-up-sencho-mesh.mdx b/docs/tutorials/set-up-sencho-mesh.mdx
new file mode 100644
index 00000000..36b5f829
--- /dev/null
+++ b/docs/tutorials/set-up-sencho-mesh.mdx
@@ -0,0 +1,26 @@
+---
+title: Set Up Sencho Mesh
+sidebarTitle: Set up Sencho Mesh
+description: Step-by-step instructions for connecting fleet nodes into a Sencho Mesh network.
+---
+
+
+ This tutorial is a placeholder pending full content. See the [Sencho Mesh feature page](/features/sencho-mesh) for the current reference documentation.
+
+
+## What you'll do
+
+## Prerequisites
+
+
+
+
+
+
+## Related
+
+
+
+ A private overlay network connecting fleet nodes.
+
+