Files
sencho/docs/reference/settings.mdx
T
Anso b1decbb32a docs: v1 docs refresh (batch 7) (#1627)
* docs(introduction): refresh screenshots and correct stale nav/tab coverage

Replace all 5 screenshots with fresh 1920x1080 production captures.
Document the shipped Take down stack action, the Compose Labels stack
tab, and the Docker Labels Fleet tab, none of which were mentioned.
Correct the Console nav item to note it is a limited-availability
surface rather than a plain role/tier-gated view.

* docs(quickstart): refresh screenshots and correct preflight, dashboard, and menu drift

Replace all three quickstart screenshots with fresh captures and correct
several claims that drifted from the current UI:

- Document the environment preflight's 7th check (Sencho compose
  location), previously missing entirely from both the text and the
  screenshot alt text.
- Add the Stack health table's Source and Port columns, and note that
  columns are sortable and default to load order.
- Note the masthead's running-container count, live CPU/memory readout,
  and alert count.
- Fix the profile menu list: replace the nonexistent "Feedback" entry
  with "Open New Issue", drop "Appearance" (it lives in Settings, not
  the profile menu), and add the conditional "Billing" entry.
- Note that the sidebar groups stacks by Docker Compose label once
  labels are assigned, with pinned stacks first.

* docs(configuration): document missing env vars and fix JWT secret wording

Add SENCHO_UPLOAD_DIR, TRIVY_CACHE_DIR, SENCHO_MESH_RECONCILE_INTERVAL_MS,
SENCHO_MESH_PROXY_TUNNEL_IDLE_MS, SENCHO_COMPOSE_COMMAND_TIMEOUT_MS, and
SSO_OIDC_CUSTOM_ENABLED, all real environment variables that were missing
from the reference tables. Clarify that the JWT signing secret has no
environment variable at all, generated and stored in the database only,
rather than implying an unused JWT_SECRET var exists.

* docs(stack-management): refresh against current live app and source

Rewrites the Stack Management page against the production node and
frontend source: adds the Compose Labels anatomy tab (new since the
last refresh), the Mute action on the stack header and sidebar
context menu, corrects the update-available banner wording and the
sidebar context menu's lifecycle ordering, notes the Doctor tab's
severity dot and the scan-status banner, and replaces all 14
screenshots with fresh production captures.

* docs(editor): refresh against current live app and source

Replace all 8 screenshots with fresh 1920x1080 production captures (mobile
shot at phone viewport). Document the self-stack protection dialog that
blocks deploy/delete actions on the stack running the current Sencho
instance, the multi-container summary strip and Compact/Detailed density
toggle, the mutually exclusive Expand containers / Expand logs controls,
the Files tab full-screen toggle, and the post-deploy scan-status banner
on the Anatomy panel, none of which were previously covered.

* docs(editor): recapture mobile compose screenshot without redaction

The previous mobile screenshot used the plex stack, whose compose volume
mount includes a real host path that had to be blacked out and overlaid
with placeholder text, leaving a visible seam. Recapture against the
dozzle stack instead, whose only volume is the Docker socket, so the
screenshot needs no editing.

* docs(stack-file-explorer): refresh page against current app and code

Renames "Files & Volumes tab" references to the current "Files" tab
label, documents the full-screen toggle and word-wrap control, expands
the non-browsable-volume reasons to match the current containment
logic (single-file binds, the full protected host-path list, and the
Docker-unreachable named-volume case), documents the 100-item bulk
selection cap and the 5000-file/1 GiB archive limits, corrects the
non-existent DISK_FULL error code, notes that override compose files
are unprotected, and scopes the atomic-write claim to fs-backed roots.
Replaces all 9 screenshots with fresh production captures taken in the
Files tab's full-screen mode, so no other stack UI (health metrics,
logs) appears in the background.

* docs(resources): refresh against current live app and source

* docs(dashboard): refresh against current live app and source

* docs(app-store): refresh against current live app and source

Replaces all 6 screenshots with fresh production captures and corrects
the Environment Variables and About-panel metadata claims to match what
the bundled LinuxServer.io registry actually returns today.

* fix(docs): recapture app-store advanced-tab screenshot without scroll cut-off

The prior capture was taken mid-scroll to reveal the Security checkbox,
leaving the template logo and About text cropped awkwardly at the top.

* docs(global-search): refresh against current live app and source

* docs(deep-links): refresh against current live app and source

- Add App Store, Logs, Update, Console, and Audit to the URL table (previously undocumented)
- Document hub-only URL redirect behavior and cross-link to Multi-Node Fleet
- Note Fleet tab URL segments do not always match their on-screen label (Status/configuration, Map/dependencies)
- Document the no-env-files edge case (Env tab absent, falls back to compose)
- Clarify Settings section-list state is phone-only; desktop always normalizes to /settings/appearance
- Note which top-level views share identical URLs between desktop and phone
- Remove greenfield-violating temporal phrasing ("now has", "as today")
- Replace em dashes in touched bullet list

* docs(appearance): refresh against current live app and source

* docs(stack-activity): refresh against current live app and source

Add the missing "Stack taken down" event category, cross-link the
Suppressed badge to notification mute rules, list the new Compose
Labels tab in the Anatomy panel strip, and replace both screenshots
with current production captures.

* docs(dossier): fix generated-facts wording, add rollback readiness section

Corrects three Dossier tab Generated Facts rows against current frontend
behavior: the Ports count is not filtered to host-published mappings, the
Network row's "bridge" label is fixed text rather than a derived driver,
and missing env var names appear only in the Markdown export, not the
live tab. Adds a Rollback Readiness subsection under Connected Features
(previously only an orphaned Limitations bullet), links to Compose
Networking and Storage Portability, and clarifies that a missing export
section can mean either an older node build or a failed on-demand fetch,
not only a version gap. Recaptures all three screenshots against
production.

* docs(stack-drift): refresh against current live app and source

Fixes the stack detail tab bar description (Compose Labels tab was
missing, Files/Edit compose were wrongly listed as tabs), documents
that re-check only requires read access to the stack (so viewer and
auditor roles can trigger a ledger write), and cross-links the network
findings to the Networking tab's runtime drift section and the Fleet
Overview's Drift filter. Replaces all four screenshots with fresh
1920x1080 production captures.

* docs(compose-doctor): refresh against current live app and source

Corrects the rule count from 31 to 32 and documents the previously
undocumented self-managed-stack guard rule and enforcement, the
per-browser dismiss control for the summary card and Doctor tab dot,
the acknowledged summary state, the full Health-Gated Updates verdict
mapping, and the temporary exposure intent option. Replaces all four
screenshots with production captures.

* docs(compose-networking): refresh against current live app and source

Adds cross-links to the new node-wide Networking operator page, documents
the "view node networking" link and the unset/inherit exposure-intent pill
labels, corrects the stale Resources Hub network-tab reference, and
replaces all screenshots against the production node.

* fix(docs): unbreak stack-activity page render

The screenshot alt text used backslash-escaped quotes, which is
invalid MDX/HTML attribute syntax. Mintlify failed to parse the file
and silently dropped it from routing, so the page 404'd despite being
listed in docs.json navigation.

* docs(environment-guardrails): refresh against current live app and source

Fix the ENV FILES section description: it lists env_file: entries and
project files with an existence problem, not every declared env file.
A cleanly-resolving project file is already named in the Project
Environment File panel above it. Replace all three screenshots with
current production captures.

* docs(docker-label-audit): refresh against current live app and source

Add production screenshots (page had none), a Capability gating
section, a Limitations section, and a Troubleshooting accordion.
Tighten the secret-redaction heuristic description and cross-link
Stack Labels, Compose Doctor, Environment Guardrails, and Node
Compatibility.

* docs(compose-storage): refresh against current live app and source

Captured fresh production screenshots (both prior images were stale)
and fixed a leftover pre-rename card title pointing at the Files tab.

* docs(stack-labels): refresh against current live app and source

Removed the stale trailing-dot sidebar claim (that rendering was
removed from the sidebar in a prior UI pass), documented the new
label-scoped notification muting available from the sidebar, stack
context menu, and Settings panel, corrected the Fleet Actions card
copy to match the redesigned cards, added the previously undocumented
bulk-assign size cap and the node-scoped label bulk-action API, and
replaced all 8 screenshots with fresh production captures.

* docs(sidebar): refresh against current live app and source

Removes the stale per-row label dot claim (removed from StackRow), corrects the update indicator and Updates chip color from orange to fuchsia, and documents Mute/Take down in the context menu, the label group mute kebab, Ctrl+A/Esc bulk-mode shortcuts, pin-eviction toast, and the offline-node skip behavior in cross-node search. Replaces all 8 screenshots with fresh production captures.

* docs(deploy-progress): refresh against current live app and source

Corrected the Scan entry point (node-wide Scan this node from Security
Overview, not a per-stack config scan), added the missing Take down
verb and entry point, broadened recovery actions to cover restart and
rollback failures, fixed the modal status text and raw-output color
claims to match the live UI, and replaced all screenshots with fresh
captures from a throwaway demo stack on the production node.

* docs(atomic-deployments): refresh against current live app and source

* docs(health-gated-updates): refresh against current live app and source

* docs(deploy-enforcement): refresh against current live app and source

Correct the tier note to every-tier (verified against the current
policy gate, which no longer has a paid-only blocking switch), add the
Security Overview deploy-enforcement summary card, tighten the honor-
suppressions default wording, cross-link the separate pre-deploy scan
advisory dialog to avoid confusion with the block dialog, and replace
all three screenshots against the current production UI.

* docs(blueprint-model): refresh against current live app and source

Replaced all 11 screenshots with fresh production captures. Corrected
the volume-destroying-drift Enforce-downgrade claim (appeared three
times): that code path has no call sites in the runtime reconciler, so
any compose edit on a stateful or state-unknown blueprint always
re-enters Awaiting confirmation regardless of drift mode. Corrected
the Create workflow (creation does not trigger an immediate
reconciliation tick) and the Delete workflow (now requires typing the
blueprint name to confirm).

* docs(scheduled-operations): refresh against current live app and source

* docs(blueprint-model): drop tier framing, treat as Community-native

Blueprints carry no tier gate, so "available on every tier" implied a
comparison that doesn't exist. Removed the tier framing from the intro
note, the Prerequisites table, and the Security section; the role
requirement (admin to write, every role to read) already says
everything that matters.

* docs(auto-update-policies): refresh against current live app and source

Documents that every update trigger on this page, Apply now and
scheduled Auto-update tasks alike, runs through the same atomic backup,
build-aware rebuild, and post-update health gate as a manual update
from the stack editor, and is subject to the same deploy enforcement
policy gate. Corrects the readiness-computation description to scope it
to registry-image services and cross-links to Health-Gated Updates,
Atomic Deployments, Deploy Enforcement, and Stack Management. Replaces
the readiness board screenshot with a fresh production capture and
removes three orphaned screenshots left over from the page's prior
CRUD-policy layout.

* docs(auto-heal-policies): refresh against current live app and source

Correct the admin-only prerequisite: viewing policies and history is
open to every signed-in role, only creating/toggling/deleting requires
admin. Rewrite the matching troubleshooting entry to match, note the
overlap behavior between an All-services and a named-service policy on
the same container, and replace all three screenshots with a real
production policy.

* docs(webhooks): refresh against current live app and source

Replaced all three screenshots with fresh production captures (single
webhook create/reveal flow, two-card configured list), verified every
claim against WebhookService/StackOpLockService/registry.ts, and added
the previously undocumented per-stack lock skip behavior for
non-Git-source-sync actions with a matching troubleshooting entry.

* docs(global-observability): refresh against current live app and source

* docs(audit-log): refresh against current live app and source

- Fix nav terminology: Audit is a top navigation tab, not a sidebar tab.
- Correct retention claim: Admiral shows full retained history (default
  90 days), not a fixed 14-day window; the 14-day clamp only applies to
  the Community API, which has no navigation entry point at all.
- Fix settings path: Settings - Operations - Data Retention (previously
  pointed at the now-split Developer Diagnostics section).
- Restore current Recovery Vault naming (was stale Sencho Cloud Backup).
- Expand the tracked-actions list: stack take-down, label management,
  MFA reset, and notification suppression rules were missing.
- Note that assigning the Auditor role itself requires Admiral.
- Replace all four screenshots with fresh production captures (Stream,
  Table, expanded row, Data Retention) reflecting the current five-row
  retention card.

* fix(audit-log): reframe data-retention screenshot to card content only

The prior crop included the Settings sub-navigation panel, which isn't
part of what the surrounding text describes. Retake tightly cropped to
match the page's other screenshots (card content only, no chrome).

* docs(multi-node): refresh against current live app and source

Rewrites the Pilot Agent enrollment flow (now a generated compose.yaml
plus docker compose up -d, not a single docker run command) and the
Settings scope table (current registry: Stacks, Container Alerts,
Docker & Storage, Data Retention, Mute Rules, Recovery, and the
Admiral Account / Recovery Vault renames). Adds a Sencho Mesh
cross-link matching the live add-node form copy. Replaces all eight
screenshots with sanitized production captures.

* docs(pilot-agent): refresh against current live app and source

* docs(readme): refresh GitHub README against current live app

Replace all 9 screenshots (stale top nav showing a removed Console
item and missing the new Networking page); document Take down,
Drift Detection, Environment and Secrets Guardrails, Storage
Portability, Docker Label Audit, Remote Updates, and the node-wide
Networking dashboard; fix a broken non-root-user anchor link; correct
the notification channels list (no email channel exists yet) and the
global search scope (pages, nodes, and stacks, not containers or
services); rename "scan policy packs" to the current "scan policies"
terminology; broaden the App Store bullet to cover custom registries.

* docs(readme): reposition intro copy and refresh badge row

Lead with DevOps/platform/sysadmin framing instead of homelab-first,
drop pre-1.0 "production" language, state plainly that Sencho
provides a UI instead of promotional "does the work you do" phrasing,
and call out that multi-node was part of the architecture from the
start. Swap the Discussions badge for CodeQL, last-commit, open
issues, and live website/docs status badges, and add a blog link.

* docs: retake Dashboard and Global Search screenshots for accuracy

Configuration Status now shows Recovery Vault instead of the stale
Cloud Backup label, and the search palette capture includes the
Networking page entry added after the prior screenshot batch.

* docs: refresh Fleet View page against current app

Fleet View has drifted since its last rewrite: the Docker Labels tab,
Export Dossier action, Networking filter/badge, node label pills and
latency in topology, the Policy sync status row, and the node card
Mute submenu were all shipped but undocumented. The Check Updates and
Add Node actions also moved into the Overview toolbar (renamed Node
Update / Manage Nodes) and no longer sit in the shared action row.

Replaces all five screenshots with fresh production captures and
corrects the masthead's motion description (a calm shimmer on Healthy,
a steady glow on Degraded/Critical, not a pulsing dot). Also fixes a
Fleet Sync limitation that claimed no first-party sync-status panel
exists, now that the Status tab surfaces one.

* docs: refresh Fleet Dossier page against current app

Adds the page's first screenshot, documents the network exposure summary now included per stack, documents the storage-summary omission versus the Stack Dossier export, and adds two troubleshooting entries.

* docs(fleet-federation): deep rewrite for the rollout-approval gate

Federation's cordon and pin controls no longer take effect by
themselves: the reconciler requires a confirmed rollout preview
(Apply now -> Confirm Apply) before it mutates the fleet, and pinning
or unpinning always clears a blueprint's approval. Rewrote the mental
model, step-by-step, lifecycle table, security section, limitations,
practical workflows, troubleshooting, and cross-links to reflect that
gate. Also corrected the audit-log claims: cordon/uncordon/pin are not
filterable by a node.cordon/blueprint.pin action taxonomy, only by the
free-text search box against the method, path, and summary.

Replaced 4 screenshots and added 3 new ones (production fleet plus an
isolated instance to capture the rollout preview dialog in both a
safe and a blocked state), and fixed one stale pin-workflow sentence
in blueprint-model.mdx that the same audit surfaced.

* docs(fleet-federation): drop tier-availability framing

The feature isn't tier-gated, so calling out "every tier" reads as an
unnecessary advertisement. Removed the tier note and the Community/
Admiral prerequisite row, and reworded two role-visibility sentences
that had conflated tier with role.

* docs(fleet-actions): deep rewrite for the v2 action-card redesign

Rewrites the page against the shipped Fleet Action Card redesign: a
single cyan rail with per-card action-class chips instead of the old
per-card rose/purple/amber rails, plus the live blast-radius preview,
dry-run, and confirmed-target binding mechanics that replaced the old
static warning banners. Documents two previously-undocumented
endpoints (match-preview, prune/estimate), the preview-confirm-execute
model shared by all three cards, per-node locking, timeouts, and the
version-gated confirmed-target contract for mixed-version fleets. All
five screenshots recaptured against the live production UI.

* docs(fleet-actions): fix nested quote in screenshot alt text

* docs(fleet-sync): refresh against current app and document proxy gap

Retake all screenshots against the live fleet (control authoring view,
a genuine replica showing the read-only banner, and replicated
suppression rows) and document a previously-unwritten behavior: scan
policies, CVE suppressions, and misconfig acknowledgements are fetched
localOnly and are not proxied through the node switcher like most
other Security page tabs, so viewing a remote's Fleet Sync state
requires signing into that instance directly.

* docs(fleet-backups): refresh against current app and note new integration points

Replaces all 6 screenshots with fresh 1920x1080 production captures and
corrects several drifted details: the Cloud Snapshots panel's pagination
and per-item delete action, the exact Recovery Vault storage-mode label,
and the real per-file size-cap behavior (an oversized compose.yaml skips
the whole stack; an oversized .env is dropped but the stack still
captures). Documents two entry points that were missing from the page:
the pre-update snapshot checkbox in Health-Gated Updates and the snapshot
coverage nudge on the Storage Portability tab. Expands the single warning
banner description in the detail view to cover all four banner types,
notes the Snapshots tab and Recovery Vault are hub-only, and adds a
Where Fleet Backups fits table cross-linking the six adjacent features.

* docs(remote-updates): refresh against current app and add hardened-channel notes

Replace all screenshots with fresh 1920x1080 production captures and fix the
Node Updates trigger label (Check Updates -> Node Update). Add the Changelog
tab, correct the reconnect overlay's stale 'Update timed out'/Try Reloading
copy to the current Taking longer than expected/Reload to check text, and
document the Admiral Hardened Build channel's carve-outs (pinned-but-not-blocked,
entitlement-gated local update path). Disambiguate this page from the
unrelated top-level Update (Health-Gated Updates) nav tab.

* docs(node-compatibility): refresh against current app and expand capability list

Replace all screenshots with fresh production captures (node switcher,
capability lock card, connection test panel) and swap the lock-card example
from a now-hidden Host Console to Audit Log, which is directly reachable.
Bring the capability table from 26 to 35 entries to match the current
registry, add a Mute Rules row, and split out fine-grained fallback
capabilities (update-guard, service-scoped-update, cross-node-rbac,
stack-down-remove-volumes) with their non-lock-card fallback behavior.
Fix the compose-networking row, which incorrectly claimed to also gate the
node-level Networking overview. Note that Pilot Agent nodes never advertise
host-console regardless of version.

* docs(security): refresh against current app and document scan-node launcher

Replaces all screenshots with fresh production captures, documents the
Scan this node launcher and the third Scanner setup toggle (pre-deploy
scan advisory), tightens the Compose risks example list and the Policies
block-condition description to match the live app, and adds an On a
phone section.

* docs(vulnerability-scanning): refresh for exploit intel and risk-based policies

Documents exploit intelligence (KEV/EPSS evidence tags), the redesigned
risk-based scan policies (severity/known-exploited/fixable block
conditions replacing the single max-severity field), and the new
Findings badge state. Replaces all screenshots with fresh production
captures and adds a Secrets tab example.

* docs: refresh CVE suppressions page

Retook all screenshots against production (prior ones predated the
triage-status/OpenVEX UI and the edit capability). Documented the
suppression edit flow, which the page previously described as
delete-and-recreate only. Corrected the remote-node banner copy on the
Suppressions tab and added a screenshot of it. Cross-linked the
Misconfig acknowledgements panel that now sits on the same tab.

* docs(two-factor-authentication): refresh screenshots and document rate-limit layers

Replace all 11 non-count-variant screenshots with fresh production captures.
Document the throttled sign-in state precisely (kicker/hero/caption change,
not just the input), that a replayed TOTP counts toward the lockout counter,
and the separate per-network-address sign-in rate limit that sits in front
of the per-account MFA lockout.

* docs(api-tokens): refresh screenshots and document service-scoped deploy actions

Deploy Only now authorizes eight lifecycle POSTs (was six): the per-service
update and restore endpoints were missing from the scope table. Universal
restrictions gained a row for image channel management, which was already
rejecting API tokens in code but undocumented. Replaced all five screenshots
with fresh captures showing the current three-scope create flow and a
populated list with one token of each scope.

* docs(upgrade): refresh against current app and remove legacy-version framing

Fixes migration-list inaccuracies (registry credentials were never
plaintext, unlike node API tokens), rephrases the SSH/TLS and JSON-config
migration bullets to drop version-numbered legacy framing, adds a GHCR
mirror note matching the quickstart pattern, and cross-links the Hardened
Build entitlement-gated update path so digest-pinned installs aren't sent
down the manual docker pull steps.

* docs: refresh Backup & Restore against current backend

Broadens the encryption.key warning to cover everything CryptoService
actually encrypts (node tokens, Git source and Fleet Secrets, SSO/MFA,
Recovery Vault, fleet snapshot contents), not just registry credentials.
Adds the built-in backupData CLI as a no-host-tooling alternative to the
sqlite3 .backup command, cross-linked to Emergency command-line recovery.
Corrects node-token migration guidance: tokens are signed with a secret
stored in sencho.db and remain valid after a host move, so no
regeneration is required.

* docs: refresh Recovery guide against current Settings page and CLI

Documents the Settings · Recovery page's full System health / Environment /
Safe actions / Command-line hub instead of only its environment-preflight
section, adds the missing "Sencho compose location" preflight check, adds the
SSO/OIDC/LDAP lockout scenario now that disableSso.js exists, and corrects the
rollback description (exact UI label, backup-required and image-layer caveats).

* docs(emergency-cli): sync in-app page description, add CLI operational details

Aligns the "in-app Recovery page" summary with the freshly refreshed Recovery
guide (System health / Environment / Safe actions / Command-line recovery, SSO
providers, one-click command download). Adds constraints verified against the
CLI source: password/username minimums, the valid SSO provider identifiers with
an example, and a note that diagnostics.js always reports Docker as unreachable
(it runs without a live Docker connection, unlike the in-app page).

* docs(troubleshooting): refresh against current backend and nav

Corrects several claims that had drifted from the implementation:
network name validation (underscore is not a valid leading character),
the remote-update delayed-failure window (3 minutes, not 90 seconds),
and an unsubstantiated version-compatibility check on the Admiral 403
entry. Removes two entries describing legacy pre-v0.39 node behavior
that no longer applies to any currently shipped build. Replaces stale
"Profile > Settings > X" navigation with the current Settings hub
paths, and "wifi icon" with the current Test Connection label. Adds
Pilot Agent awareness to the remote-offline entry with a cross-link to
its dedicated troubleshooting section, and trims the docker-run
converter entry to point at the fuller, already-current version on the
Stack Management page instead of duplicating it with a broken anchor.

* docs(verifying-images): document the :dev GHCR integration tag

Verified the existing cosign/SBOM/VEX/tag-policy content against
docker-publish.yml and docker-preview.yml; all accurate. Added the
previously undocumented :dev/:dev-<sha> integration tag published on
every push to main via docker-dev.yml.

* docs(trivy-setup): sync install guide with node-scoped scanner and current Trivy upstream docs

Documents that Trivy installs independently per node, adds the TRIVY_BIN
override and non-PATH mounting option, fixes the deprecated apt-key install
flow and RHEL repo gpgkey placement, notes the Exploit intelligence toggle
for air-gapped hosts, and replaces the stale Scanner setup screenshot.

* docs(two-factor-admin): document lockout recovery and self-reset gotcha

Verified the reset flow, CLI recovery, and SSO toggle claims against
current source and replaced the stale admin-reset modal screenshot.
Added the failed-attempt lockout behavior (undocumented despite being
promised in the page description) and a warning about resetting your
own 2FA from the Users list, which signs you out immediately unlike
the self-service disable flow.

* fix(docs): make Settings and Self-hosting discoverable in the sidebar

The Reference and Operations groups used root pages that were only
reachable by clicking the ambiguous group label, and that click also
triggered an unwanted double action (expand plus navigate). List both
pages as explicit sidebar entries and disable global drilldown so group
headers only expand or collapse.

* docs(settings): sync reference page with current Settings Hub

Renamed License to Admiral Account throughout (Hardened Build channel
switch, image channel display, DURATION pill), corrected the password
policy, documented the new Appearance navigation and log-chip-color
controls plus font options, noted Mesh data plane is not on every
installation, fixed the label cap (50, not 100), and replaced every
screenshot with a fresh capture from the production node.

* fix(docs): apply the sidebar toggle-only fix to Start here and Product guide

These two groups had the same click-to-navigate-and-expand pattern as
Reference and Operations. Flattening them is safe here too: the
Product guide root page has no directory listing depending on it, and
the Start here root page's own hand-authored Next steps CardGroup
already covers the same links the auto-generated listing duplicated.

* docs(licensing): refresh licensing page for Hardened Build and sales-led Admiral pricing

Admiral pricing moved from self-serve checkout to a contact-sales model, and
a new Hardened Build image-channel switcher shipped in the Admiral Account
settings page; neither was reflected in the docs. Also documents the
lifetime-license edge case (no Manage subscription button, no Billing row)
and refreshes all four screenshots against the current UI.

* docs(security): sync reference page with current API-token and encryption scope

Verified every claim against the live implementation: the API-token universal
restrictions list was missing MFA management, Recovery Vault, and image
channel management; the encryption-at-rest field list was missing Recovery
Vault credentials; added a note on the password strength indicator's
recommended-vs-enforced distinction. Refreshed the SSO settings, API tokens,
and audit log screenshots against the production node.

* docs(settings): fix password policy and session-invalidation claims

Cross-checked against auth.ts while verifying the same claims on the
security reference page: the enforced minimum is 8 characters (the
12+/mixed-case/number text is a frontend strength hint, not a validated
rule), and a password change invalidates every other session for the
account rather than leaving them valid.

* docs(contact): sync contact channels with sales-led pricing and current support gating

Replace the retired contact@sencho.io with hello@sencho.io (the address actually
used in the website footer and the pricing page's Get in touch CTA), narrow the
licensing@sencho.io scope to existing-license activation/billing/refunds now that
new Admiral conversations route through hello@sencho.io, drop the stale LICENSE-file
and in-app upgrade-prompt claims (the AGPLv3 relicense removed both), correct the
Support settings path and add the published response-time targets, and remove the
unsubstantiated bug bounty mention.
2026-07-21 09:13:12 -04:00

748 lines
38 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: Settings Reference
sidebarTitle: Settings
description: Complete reference for every option in the Sencho Settings Hub.
---
Open the Settings Hub by clicking the **Profile** icon in the top bar and selecting **Settings**. The sidebar groups every section into themed groups so related settings live together.
<Frame>
<img src="/images/settings/settings-hub-grouped.png" alt="Settings Hub with the grouped sidebar" />
</Frame>
### Sidebar groups
| Group | What it covers |
|-------|----------------|
| **Personal** | Account, Appearance |
| **Access** | Admiral Account, Users, SSO, API Tokens |
| **Infrastructure** | Nodes, Stacks, Fleet, Registries, Recovery Vault, App Store |
| **Monitoring** | Host Alerts, Container Alerts, Docker & Storage |
| **Notifications** | Channels, Notification Routing, Mute Rules |
| **Automation** | Image update checks, Webhooks |
| **Organization** | Labels |
| **Operations** | Data Retention, Developer Diagnostics, Recovery |
| **Help** | Support, About |
Vulnerability scanning is no longer a Settings section: scanner setup, scan policies, suppressions, and acknowledgements now live on the dedicated [Security page](/features/security).
Sections that require a higher license tier or the admin role are limited to operators who meet that requirement (Users, SSO, API Tokens, Fleet, Registries, Recovery Vault, Notification Routing are admin-only).
### Page chrome
Every section renders inside the same masthead-and-sidebar layout. The masthead breadcrumb on the left tells you exactly where you are. Metadata pills on the right tell you what's loaded.
| Pill | Meaning |
|------|---------|
| **SCOPE** `operator` / `browser` / `global` | Setting applies to your account (`operator`), to this browser only (`browser`, for browser-local sections such as Appearance), or to the whole instance (`global`, every other non-node group) |
| **NODE** `<node name>` | Setting is per-node and is currently being edited against this node |
| **EDITED** `<count>` pending / `saved` | The current section has unsaved changes |
| Section-specific stats | Each section can publish its own pills: `2FA on`/`off` and `BACKUP <n> left` (Account); `PLAN`, `DURATION`, `TRIAL <n>d left`, `RENEWS`, `STATUS` (Admiral Account); `OPERATORS` (Users); `PROVIDERS`, `ENABLED` (SSO); `CHANNELS` (Channels); `ROUTES`, `ENABLED` (Notification Routing); `WEBHOOKS` and `ENABLED` (Webhooks); `LABELS` (Labels); `PROVIDER`, `USED` (Recovery Vault); `DEV MODE` (Developer Diagnostics) |
### Quick search
Click **Filter** at the top of the sidebar, or press `Ctrl+K` / `⌘K` while the hub is open, to open the command palette. Type any section name, keyword, or synonym (for example, `saml` finds SSO) and press Enter to jump to it.
<Frame>
<img src="/images/settings/settings-search.png" alt="Settings command palette filtered to a webhook query" />
</Frame>
### Node scope
For node-scoped sections the masthead replaces the **SCOPE** pill with a **NODE** pill showing the active node name. Switch the active node from the top bar's **Switch node** button to edit a different node's per-node settings.
If settings for the active node fail to load, Sencho shows an error and keeps Save unavailable until an authoritative load for that node succeeds.
<Frame>
<img src="/images/settings/settings-node-scope.png" alt="Host Alerts section showing the NODE pill in the masthead" />
</Frame>
---
## Account
**Scope:** Operator (applies to the signed-in account)
The Account section manages password and two-factor authentication for the operator currently signed in. The masthead publishes a **2FA** pill so you can see at a glance whether the second factor is enabled.
<Frame>
<img src="/images/settings/settings-account-2fa.png" alt="Account section showing the Password form and the Two-factor authentication card" />
</Frame>
### Password
| Field | Description |
|-------|-------------|
| **Current password** | Your existing password. Required to change any auth setting. |
| **New password** | 8 characters minimum, enforced. The strength indicator recommends 12+ characters with mixed case and a number, but this is guidance only. |
| **Confirm new password** | Must match New password. |
Click **Update password** to apply. Your current session stays signed in; every other session for this account is invalidated immediately.
### Two-factor authentication
When 2FA is off, a **Set up 2FA** button opens the enrolment dialog. The dialog walks through scanning the QR code in an authenticator app (Authy, 1Password, Aegis, etc.) and verifying a code.
Once enrolled, the card shows:
| Element | Description |
|---------|-------------|
| **Authenticator app** | Confirms the enrolment is active. |
| **Backup codes** | Shows how many single-use recovery codes remain. **Regenerate** issues a fresh set; the count resets to ten. |
| **Require 2FA on SSO sign-in** | Visible only when an SSO provider is configured. When on, SSO logins must also pass the second factor; when off, SSO logins skip it. |
| **Disable 2FA** | Removes the second factor after a confirmation prompt. |
See [Two-Factor Authentication](/features/two-factor-authentication) for the enrolment walkthrough and recovery options. If you lose access to your authenticator and have no backup codes left, an admin can clear your second factor from the [Users](#users) section.
---
## Appearance
**Scope:** This browser (preferences are saved to local storage)
Control how Sencho looks and how dense the workspace feels. Each browser remembers its own choices so a compact laptop setup does not force the same rhythm on a larger desktop. See [Appearance](/features/appearance) for the full walkthrough.
<Frame>
<img src="/images/settings/appearance-density.png" alt="Appearance settings showing the Density selector" />
</Frame>
### Visual style and readability
| Control | What it does |
|---------|--------------|
| **Visual style** | Master switch between **Calm** (upright headings, muted charts, reduced effects, the default) and **Signature** (italic Instrument Serif headings, saturated charts). |
| **Readability mode** | One switch for the most legible result: upright headings, muted charts, reduced effects, and a contrast lift. Locks the heading and chart controls while on. |
| **Header style** | Clean (upright interface face) or Signature (italic serif). |
| **Contrast** | Spreads the page tone, borders, and text tiers together. |
### Charts and effects
| Control | What it does |
|---------|--------------|
| **Chart palette** | Colors the Security page charts: **Muted**, **Heat** (one warm ramp), or **Signature** (saturated). |
| **Reduced motion** | Minimizes interface animations and transitions. Calm enables it by default; Signature disables it. Independently toggleable afterward. First control to try for high idle GPU use on constrained graphics. Toasts are unaffected. |
| **Reduced effects** | Flattens card bevels, the accent glow, and chart gradients, turns off glass blur with solid chrome fills, and stops decorative masthead rail animations. Optional secondary material simplification; not a substitute for Reduced motion on the reported idle-GPU symptom. |
| **Ambient glow** | Intensity of the accent-tinted page glow. |
### Theme and typography
A live preview card shows a sample fleet-status tile so you can see a color choice before committing to it. The **Mode** (Dim, OLED, Light, Auto) and **Accent** (one of eight hues) set the surface palette and data color; **Border brightness** tunes every hairline.
| Control | Options |
|---------|---------|
| **Interface font** | Geist, IBM Plex, or Hanken. The sans face for body text, labels, navigation, and buttons. Heading style follows your Visual style choice. |
| **Data font** | Geist Mono, Plex Mono, or Fira Code. The monospace face for terminal output, stats, codes, and timestamps. |
| **Text size** | Scales the whole interface from a single root multiplier. Default 1.00x. |
### Display
| Control | What it does |
|---------|--------------|
| **Density** | **Comfortable** (default spacing, roomier rows and tiles for review and orientation) or **Compact** (tighter rows and tiles, fits more stacks, tasks, and audit entries on screen at once). Affects the dashboard stack table, the resource gauge strip, the Settings Hub sidebar, the Schedules and Audit Log tables, and every other data table in Sencho. Typography, color, and layout structure stay the same; only vertical padding compresses. |
| **Log chip color** | **Unified** uses the accent color for every service's log chip. **Per service** assigns each service a stable label color for faster visual scanning across a busy log stream. |
### Navigation
| Control | What it does |
|---------|--------------|
| **Navigation style** | **Smart bar** (recommended default): primary destinations stay visible in the top bar and the rest live under **More**. **Classic bar** keeps the full horizontal strip of destinations. **Compact launcher** puts every destination in a menu, with optional quick links. |
| **Top navigation labels** | On by default. Shows text labels beside the top navigation icons; turn off for a more compact bar with icons only. |
Deploy-progress behavior and the diff-preview-before-save step are stack workflow preferences and live in their own [Stacks](#stacks) section under Infrastructure.
---
## Admiral Account
**Scope:** Operator-facing, but reflects the instance license
Activate, view, or deactivate the license for this Sencho control plane, and see which image channel it is tracking. The masthead publishes a **PLAN** pill showing the current tier, a **DURATION** pill (for example `lifetime` or a renewal cadence), a **TRIAL** pill with days remaining if a trial is active, a **RENEWS** pill with the next renewal date, and a **STATUS** pill if the license is in an unusual state (expired, error).
<Frame>
<img src="/images/settings/settings-license.png" alt="Admiral Account section showing the Plan, image channel, Customer, Product, and License key" />
</Frame>
| Element | Description |
|---------|-------------|
| **Sencho Admiral** | The active license on this control plane, with a tier badge. Community instances see an upgrade prompt here instead. |
| **Recovery Vault** | Whether the current subscription includes Recovery Vault entitlement. |
| **Hardened Build** | Switches this control plane between the Community image channel and the Admiral Hardened Build channel. Review entitlement and registry access before switching; see [Plans](/features/licensing#feature-breakdown) for what Hardened Build changes. |
| **Current image** | The image reference this control plane is currently running, so you can confirm which channel took effect after a switch. |
| **Channel** | The active image channel (Community or Hardened). |
| **Customer** | The customer name on file with Lemon Squeezy (paid plans only). |
| **Product** | The product (paid plans only). |
| **License key** | The active key, masked to the last four characters. |
| **Trial countdown** | Days remaining. Visible only while a trial is active. |
| **Manage subscription** | Opens the Lemon Squeezy customer portal to update payment, view invoices, or cancel. |
| **Deactivate** | Releases the key from this instance and reverts to Community features. |
| **See pricing** | Direct link to the pricing page; visible on Community or when an existing license has expired. |
Lemon Squeezy manages billing for Admiral subscriptions; the customer portal link and invoice history live there, not in Sencho.
See [Licensing & Billing](/features/licensing) for the full walkthrough including trial activation.
---
## Users
<Note>
User management requires an admin role. Community supports unlimited accounts with the Admin and Viewer roles.
</Note>
**Scope:** Global
Create and manage user accounts with role-based access. The masthead publishes an **OPERATORS** pill with the total user count.
| Action | Description |
|--------|-------------|
| **Create user** | Add a new account with username, password, and role. |
| **Edit user** | Change an existing user's password or role. |
| **Delete user** | Remove a user account (you cannot delete your own account). |
| **Reset MFA** | Clears the second factor for a user who has lost access to their authenticator. |
**Available roles:**
| Role | Tier | Description |
|------|------|-------------|
| **Admin** | Community | Full access to all features |
| **Viewer** | Community | Read-only access to stacks and nodes |
| **Deployer** | Admiral | Can view stacks and trigger deployments |
| **Node Admin** | Admiral | Full stack and node management, no system settings |
| **Auditor** | Admiral | Read-only plus audit log access |
See [RBAC & User Management](/features/rbac) for details on what each role can access.
---
## SSO
<Note>
Custom OIDC and the preset providers (Google, GitHub, Okta) are available on Community; LDAP / Active Directory requires Admiral.
</Note>
**Scope:** Global, admin-only
Configure Single Sign-On providers for centralized authentication. Each provider type has its own configuration card with connection fields, a test button, and an active toggle.
See [SSO](/features/sso) for the full configuration walkthrough.
---
## API Tokens
<Note>
API Tokens are available on every tier. Creation, listing, and revocation require an admin role.
</Note>
**Scope:** Global, admin-only
Create and manage long-lived API tokens for external integrations and automation. Tokens can be scoped to specific permissions.
See [API Tokens](/features/api-tokens) for the full walkthrough.
---
## Host Alerts
**Scope:** Per-node (applies to the currently selected node)
Configure the host resource thresholds that trigger warnings and the suppression cadence for repeated alerts. These are alerting thresholds, not enforcement: Sencho warns when a metric crosses a line, it never throttles or kills containers. The masthead **NODE** pill names which node you are configuring; the **EDITED** pill counts unsaved changes.
<Frame>
<img src="/images/settings/settings-host-alerts.png" alt="Host Alerts section showing the Host thresholds subsection with the master toggle and CPU, RAM, Disk, and Alert suppression controls" />
</Frame>
| Setting | Default | Description |
|---------|---------|-------------|
| **Host threshold alerts** | On | Master switch for CPU, RAM, and disk threshold alerts only. When OFF, no host threshold checks run and the controls below are inactive. |
| **CPU limit** | 90% | Alerts fire when host CPU utilization exceeds this percentage. The input warns at values above 95%. |
| **RAM limit** | 90% | Set this below the point at which the host starts paging to swap. |
| **Disk limit** | 90% | Low free space slows image pulls and backups. |
| **Alert suppression** | 60 min | How long to wait before resending a host alert while the metric stays over threshold. The follow-up message includes a count of suppressed cycles. Range 1 to 1,440 minutes. |
Click **Save alerts** to apply.
---
## Container Alerts
**Scope:** Per-node (applies to the currently selected node)
<Frame>
<img src="/images/settings/settings-container-alerts.png" alt="Container Alerts section showing the crash and health alerts toggle" />
</Frame>
Controls whether Sencho watches every managed container on this node for unexpected exits, OOM kills, and Docker healthcheck failures, and dispatches alerts for each. Auto-Heal observes crash signals independently regardless of this toggle, so turning it off stops alerts but does not stop Auto-Heal.
| Setting | Default | Description |
|---------|---------|-------------|
| **Container crash & health alerts** | On | Send alerts for unexpected container exits, OOM kills, and Docker healthcheck failures. Auto-Heal can still observe crash signals independently. |
Click **Save settings** to apply.
---
## Docker & Storage
**Scope:** Per-node (applies to the currently selected node)
Configure the reclaimable-space alert, the reclaimable-space banner, and automatic image cleanup after updates.
### Storage alerts
| Setting | Default | Description |
|---------|---------|-------------|
| **Reclaimable Docker data threshold** | 5 GiB | Alert when reclaimable Docker data (images, volumes, build cache that `docker prune` could free) exceeds this size. Set to `0` to disable the alert. |
| **Show reclaimable-space banner** | On | Show the reclaimable-space banner at the top of the Resource Hub when this node has unused images, stopped containers, or dangling volumes to clear. |
### Image cleanup
| Setting | Default | Description |
|---------|---------|-------------|
| **Prune dangling images after updates** | On | When a stack update or a Sencho self-update finishes, remove the node's dangling (untagged) image layers, including the one the update just orphaned. Only untagged layers are touched: tagged images, your volumes, and your data are never removed. Turn it off to keep every old layer. |
Click **Save settings** to apply.
---
## Fleet
<Note>
Fleet is admin-only.
</Note>
**Scope:** Per-node (applies to the currently selected node)
<Frame>
<img src="/images/settings/settings-fleet.png" alt="Fleet section showing the Documentation snapshots subsection" />
</Frame>
### Mesh data plane
<Note>
This subsection is not on every installation. It appears once mesh discovery is turned on for this control plane.
</Note>
| Setting | Default | Description |
|---------|---------|-------------|
| **Auto-recreate mesh network** | Off | If `sencho_mesh` is removed at runtime, rebuild it at the same subnet on the next 10-second tick. Off by default; leave it off and restart Sencho manually for the safest path. See [Sencho Mesh](/features/sencho-mesh) for the reconciler behavior. |
### Documentation snapshots
| Setting | Default | Description |
|---------|---------|-------------|
| **Capture stack documentation in snapshots** | Off | Preserve each stack's Dossier notes alongside its captured files when a fleet snapshot is taken. Restoring a stack never overwrites current notes unless you explicitly choose to. |
Click **Save settings** to apply.
---
## Registries
<Note>
Docker Hub, GHCR, and custom registry credentials are available on every tier. AWS ECR requires a Sencho Admiral license.
</Note>
**Scope:** Global, admin-only
Configure private Docker registries so Sencho can pull images that require authentication.
See [Private Registries](/features/private-registries) for the full walkthrough.
---
## Recovery Vault
<Note>
Custom S3-compatible storage is available on every tier. Recovery Vault is an Admiral feature.
</Note>
**Scope:** Global, admin-only
Mirror fleet snapshots to Recovery Vault or any S3-compatible storage so a control-plane loss does not take the recovery history with it. The masthead publishes a **PROVIDER** pill (`sencho` / `s3` / `disabled`) and a **USED** pill showing storage consumption; the object count appears inline in the Storage used row.
<Frame>
<img src="/images/settings/settings-cloud-backup.png" alt="Recovery Vault section with Recovery Vault mode selected" />
</Frame>
### Storage modes
| Mode | When to pick it |
|------|-----------------|
| **Disabled** | Snapshots stay on the control plane's local disk only. Default for fresh installs. |
| **Recovery Vault (included)** | Replicate snapshots to managed storage that ships with the Admiral subscription. On first selection, click **Activate** to provision the 500 MB allowance. Auto-upload is always on for this mode. The **Test** and **Reprovision** buttons appear on the activated card if you need to verify connectivity or replace the credentials. |
| **Custom S3 (BYOB)** | Point Sencho at your own S3-compatible bucket (AWS S3, Cloudflare R2, MinIO, Backblaze B2). Required fields: **Endpoint URL**, **Region**, **Bucket**, **Path Prefix** (default `sencho/`), **Access Key ID**, **Secret Access Key**. The secret access key is masked after save. Use **Test connection** to verify credentials, then toggle **Auto-upload** to start replicating snapshots. |
The **Cloud Snapshots** list at the bottom of the section is an inventory of objects currently in the configured destination. Each row exposes a **Download** icon and a **Delete** icon.
See [Fleet Snapshots & Backups](/features/fleet-backups) for restore workflows.
---
## Nodes
**Scope:** Global
Manage connections to local and remote Sencho instances. This is the same interface as the [Multi-Node](/features/multi-node) feature; see that page for the full walkthrough.
Quick reference:
| Action | How |
|--------|-----|
| Add a remote node | Click **+ Add Node** |
| Generate a token for this instance | Click **Generate Token** |
| Test an existing node's connectivity | Click the wifi icon on any row |
| Edit a node | Click the pencil icon |
| Delete a node | Click the trash icon (remote nodes only) |
---
## Channels
**Scope:** Per-node (each node has its own notification agents; remote nodes dispatch alerts through their own channels)
Configure external destinations for alert notifications. Four agent types are available on separate tabs: **Discord**, **Slack**, **Webhook**, and **Apprise**. The masthead publishes a **CHANNELS** pill showing how many agents are enabled (for example, `2/4`).
**Delivery retries** (admin-only) sets how many extra in-process attempts (0 to 3, default 0) this node makes after a transient channel failure, with a fixed one-second delay between attempts. There is no durable queue; ambiguous network failures can produce duplicate notifications.
For each agent:
| Field | Description |
|-------|-------------|
| **Enabled** toggle | Activates or deactivates this agent. Disabled agents receive no messages even if a URL is saved. |
| **Webhook URL** | The endpoint Sencho will POST to when an alert fires. |
| **Apprise** | Use a keyed `/notify/<key>` endpoint with optional tags, or a stateless `/notify` endpoint with destination URLs. Apprise accepts HTTP or HTTPS. |
Click **Save** to persist changes. Click **Test** to send a test payload immediately and verify delivery.
At least one agent must be enabled for stack alerts to deliver notifications. See [Alerts & Notifications](/features/alerts-notifications) for how to create alert rules.
---
## Notification Routing
<Note>
Creating, editing, and deleting routes is admin-only.
</Note>
**Scope:** Global, admin-only
Create routing rules that direct specific alert types to specific notification channels. Rules let you send critical alerts to one channel and informational alerts to another. The masthead publishes a **ROUTES** pill with the active rule count.
| Field | Description |
|-------|-------------|
| **Name** | Operator-facing label for the rule. |
| **Node** | Specific node, or all nodes if left empty. |
| **Stack patterns** | Glob patterns with `*` (for example `prod-*`) matching stack names. |
| **Labels** | Apply this rule to stacks that carry any of the selected labels. |
| **Categories** | Event categories that trigger the rule (crash, deploy, vulnerability, etc.). |
| **Severity** | Info, warning, and/or error levels. Empty matches any severity. |
| **Channel type** | `discord`, `slack`, `webhook`, or `apprise`. |
| **Channel URL** | The destination endpoint for this rule. |
| **Priority** | Sort order among matching rules. Every matching route fires; priority does not stop later matches. |
| **Enabled** toggle | Mute a rule without deleting it. |
Each rule keeps an execution history (collapsible per row) showing which alerts triggered it, when, and whether the delivery succeeded.
See [Notification Routing](/features/alerts-notifications#notification-routing) for the full walkthrough.
---
## Mute Rules
<Note>
Creating, editing, and deleting mute rules is admin-only.
</Note>
**Scope:** Global, admin-only
Create notification suppression rules that mute or drop matching alerts from the bell, external channels, or both. Suppression is evaluated before routing. The masthead publishes **RULES** and **ACTIVE** counts.
| Field | Description |
|-------|-------------|
| **Name** | Operator-facing label for the rule. |
| **Node** | Specific node, or all nodes if left empty. |
| **Stack patterns** | Glob patterns with `*` matching stack names (for example `prod-*`). |
| **Labels** | Match stacks that carry any selected label. |
| **Categories** | Notification categories to suppress. |
| **Severity** | Info, warning, and/or error levels to suppress. |
| **Apply to** | Bell only, external channels only, or both. |
| **Expiration** | Forever, 1 hour, 24 hours, or a custom timestamp. |
| **Enabled** toggle | Disable a rule without deleting it. |
See [Mute Rules](/features/alerts-notifications#mute-rules) for the full walkthrough, compose-first shortcuts, and bell quick-mute.
---
## Image update checks
**Scope:** Per-node (applies to the currently selected node)
<Frame>
<img src="/images/settings/settings-image-updates.png" alt="Image update checks section showing the scheduling mode selector and interval dropdown" />
</Frame>
Configure how often this node polls container registries to detect available image updates. The masthead publishes an **INTERVAL** pill showing the current check cadence. Each node checks on its own independent schedule.
### Registry checks
| Setting | Default | Description |
|---------|---------|-------------|
| **Scheduling mode** | Interval | **Interval**: check every fixed period. **Cron**: check on a precise cron schedule (runs in the node's local timezone). |
| **Check interval** | 2 hours | How often to poll registries when in Interval mode. Presets: 15 min, 30 min, 1 h, 2 h, 6 h, 12 h, 24 h. Selecting a new preset saves immediately. |
| **Cron expression** | - | A standard five-field cron expression (for example, `0 3 * * 1` for every Monday at 03:00). A human-readable description appears below the field as you type. Click **Save schedule** to apply. |
The section footer shows the last-checked timestamp and when the next check is scheduled.
### Sidebar
| Setting | Default | Description |
|---------|---------|-------------|
| **Show update status in sidebar** | On | When on, the sidebar shows a pulsing dot on stacks with an available update, a warning icon when a check fails, and an Updates filter chip. The Stack Health table on the home page always shows update status regardless of this setting. Notifications are unaffected. |
<Note>
Nodes running older versions of Sencho do not expose this setting. Upgrade the node to enable the toggle.
</Note>
---
## Webhooks
<Note>
Managing webhooks is admin-only.
</Note>
**Scope:** Global
Create and manage HTTP webhooks that external systems (CI/CD pipelines, automation tools) can call to trigger stack actions. The masthead publishes **WEBHOOKS** and **ENABLED** counts.
| Field | Description |
|-------|-------------|
| **Name** | Operator-facing label. |
| **Stack** | Target stack for this webhook. |
| **Action** | `deploy`, `restart`, `update`, etc. |
| **Secret** | Auto-generated on create. Shown once in a confirmation dialog so you can copy it into your CI secret store; recoverable later via **Copy secret** on the row. |
| **Enabled** toggle | Mute a webhook without deleting it. |
Each row exposes an execution history with timestamp, trigger source, duration, and any error returned to the caller.
See [Webhooks](/features/webhooks) for the full walkthrough including authentication and CI examples.
---
## Labels
<Note>
Label organization (create, edit, assign, remove) and bulk label actions (apply or remove a label across multiple stacks in one operation) are available on every tier.
</Note>
**Scope:** Per-node
Create, edit, and delete labels used to organize and filter stacks across your fleet. Each label has a name and one of ten available colors. Up to 50 labels per node. The masthead publishes a **LABELS** pill with the current and maximum counts.
See [Stack Labels](/features/stack-labels) for the full walkthrough.
---
## Data Retention
**Scope:** Per-node
How long Sencho keeps historical data on this node before pruning it.
| Setting | Default | Max | Description |
|---------|---------|-----|-------------|
| **Container metrics** | 24 hrs | 8,760 (1 year) | How long to keep per-container CPU, RAM, and network history for dashboard charts. |
| **Notification log** | 30 days | 365 | How long to keep alert and notification history. |
| **Scan history per digest** | 50 scans | 1,000 | How many vulnerability scans to keep per image digest (or per image reference when no digest is stored). Older scans beyond the cap are pruned. |
| **Remove scans for deleted images and stacks** | On | - | When on, scan results are deleted once their image is gone from this node or their stack is deleted, so the Security Overview stays tied to what still exists. Turn it off to keep scan history for removed images and stacks. |
| **Audit log** | 90 days | 365 | How long to keep audit trail entries. Requires Admiral. |
Removing scans for deleted artifacts runs in the background a few minutes after an image or stack disappears, and immediately when you delete a stack. An image that is still present on the node keeps its scan results, even when no stack uses it.
Click **Save settings** to apply.
---
## Developer Diagnostics
**Scope:** Per-node
Debug diagnostics for this node. Most operators can leave this off. The masthead publishes a **DEV MODE** pill (`on` / `off`).
| Setting | Default | Description |
|---------|---------|-------------|
| **Developer mode** | Off | Enables real-time metrics streams and verbose debug diagnostics in the UI. Does not affect [Global Observability](/features/global-observability) streaming, which is always on. |
<Note>
With Developer mode on, reload the dashboard to capture the startup timeline. A small timing chip appears in the lower corner showing how long the stack list took to become visible from boot; click it to expand the full phase report, which you can copy as JSON. The overlay follows the active node, so switching nodes starts a fresh timeline.
For the matching server-side timings, filter the backend logs for `[Stacks:debug]` (stack list, statuses, and per-container timing, including the Docker call duration), `[Nodes:debug]`, and `[Proxy:debug]`. When the active node is remote, the `[Nodes:debug]` and `[Proxy:debug]` lines, along with the overlay's proxy note, depend on Developer mode being enabled on the gateway you sign in to, while the destination route logs and the overlay itself follow Developer mode on the active node.
</Note>
Click **Save settings** to apply.
---
## Recovery
<Note>
Recovery is admin-only and is not visible on remote nodes.
</Note>
**Scope:** Global, admin-only
A read-only diagnostic panel and safe recovery tools for the control plane. It is the first place to look when the dashboard behaves unexpectedly.
<Frame>
<img src="/images/settings/settings-recovery.png" alt="Recovery section showing the System health snapshot with database, encryption key, Docker, and administrator status" />
</Frame>
### System health
A read-only snapshot of the control plane. It loads without Docker or live metrics, so it stays available when the dashboard does not. **Refresh** reloads the snapshot. **Export diagnostics** downloads the full report as a JSON file.
| Field | Status indicators |
|-------|------------------|
| **Version** | Current Sencho version string |
| **Database** | `Healthy` (green check) or `Problem detected` (red X) |
| **Encryption key** | `Present` (green check), `Missing`, or `Invalid` (red X) |
| **Docker** | `Reachable` (green check) or `Unreachable` (amber warning) |
| **Administrators** | Count of admin accounts out of total users |
| **Two-factor enrolled** | Count of users with an active second factor |
| **SSO providers** | Each configured provider and whether it is enabled |
### Environment (preflight)
Checks what deployments depend on: the Docker engine, the Compose plugin, the compose directory and its host path mapping, TLS, and disk headroom. Each failed check includes a fix.
### Safe actions
| Action | Description |
|--------|-------------|
| **Reset interface preferences** | Clears density and editor display options from this browser's local storage and reloads the page. Use this if a display setting wedges the layout. |
| **Recovery guide** | Opens the step-by-step recovery guide at docs.sencho.io. |
### Command-line recovery
When the UI is fully unreachable, run these from a shell on the host. Prefix each with `docker compose exec sencho`:
| Command | What it does |
|---------|-------------|
| `node dist/cli/resetMfa.js <username>` | Clear a user's two-factor enrolment |
| `node dist/cli/resetPassword.js <username> <new-password>` | Reset a local user's password |
| `node dist/cli/createEmergencyAdmin.js <username> <password>` | Create a new admin account |
| `node dist/cli/clearSessions.js` | Sign every user out |
| `node dist/cli/disableSso.js [provider]` | Disable a broken SSO provider |
| `node dist/cli/diagnostics.js` | Print the diagnostics report as JSON |
| `node dist/cli/validateDb.js` | Check database and encryption-key integrity |
| `node dist/cli/backupData.js [dir]` | Back up the data directory |
**Download commands** saves a plain-text copy of the reference so it is on hand when the dashboard is unavailable.
---
## App Store
**Scope:** Per-node
Configure the template source used by the App Store.
| Element | Description |
|---------|-------------|
| **Default registry** | `api.linuxserver.io/api/v1/images` (read-only; used when no custom URL is set). |
| **Custom registry URL** | A URL pointing to a Portainer v2 compatible template JSON file. Overrides the default registry. Leave empty to use the default. |
| **Reset to default** | Clears the custom URL and reverts to the default registry. |
| **Save & refresh** | Saves the URL and immediately refreshes the cached template list. |
See [App Store](/features/app-store#custom-template-registry) for more on custom registries.
---
## Stacks
Stack editor, lifecycle workflow preferences, and deploy guardrails. The Workflow controls are browser-local (each browser remembers its own choices). The Deploy Guardrails are node-scoped backend settings. The masthead shows the **NODE** pill for this section.
### Workflow
**Scope:** This browser (preferences are saved to local storage)
#### Deploy progress
Sencho streams live output whenever you deploy, restart, update, install, or run a Git operation. It is on by default; turn it off to run operations without it. When it is on, **Progress style** chooses how it appears: **Modal** (a centered overlay that closes automatically on success or stays open on failure) or **Inline** (a quiet status band on the stack detail). See [Deploy Progress](/features/deploy-progress) for the full reference.
| Value | Behavior |
|-------|----------|
| **Enabled** (default) | A progress surface (the Modal overlay or the Inline band, per Progress style) shows for every long-running operation |
| **Disabled** | Operations run without it; results surface via toast notifications, and a failed operation still shows recovery actions on the stack page |
#### Diff preview before save
When enabled, clicking **Save & Deploy** or **Save Only** in the compose or env editor opens a side-by-side diff modal before writing anything to disk. The left pane shows the current on-disk content; the right pane shows your unsaved edits, with additions highlighted green and removals highlighted red.
| Value | Behavior |
|-------|----------|
| **Enabled** | Diff modal opens on every save that has unsaved changes |
| **Disabled** (default) | File is saved directly without a review step |
If there are no unsaved changes the modal is skipped and the save proceeds immediately. See [Diff preview before save](/features/editor#diff-preview-before-save) in the Editor guide for the full workflow.
### Deploy Guardrails
**Scope:** Per-node (saved on the active node, admin-only)
<Frame>
<img src="/images/settings/settings-stacks-guardrails.png" alt="Stacks section showing the Deploy Guardrails subsection with health gate and env-var block controls" />
</Frame>
Node-level safety checks and post-deploy observation used during stack deploys and updates.
| Setting | Default | Description |
|---------|---------|-------------|
| **Observe health after updates** | On | After a stack deploy or update succeeds, watch its containers for the observation window and record a passed or failed verdict on the stack timeline. Observational only: nothing is restarted or rolled back automatically. |
| **Observation window** | 90 s | How long to watch containers before declaring the update healthy. Raise it for stacks that take a while to settle. Range 15 to 600 seconds. |
| **Block deploy on missing required env vars** | Off | When on, a deploy or update is refused before it starts if a required `${VAR:?message}` variable is unset or empty, so the stack fails fast with a clear message instead of mid-deploy. |
| **Automatically create missing external networks during deploy** | Off | When on, safe missing external bridge networks are created automatically before deploy continues. When off, interactive deploy prompts first. Advanced drivers and custom options are never auto-created. |
Click **Save settings** to apply.
---
## Support
**Scope:** Global
Links to help resources, with an additional channel for Admiral operators.
### Resources (all tiers)
| Resource | Description |
|----------|-------------|
| **Documentation** | Opens docs.sencho.io. |
| **GitHub Issues** | Report bugs and request features on GitHub. |
### Admiral support
| Channel | Tier | Description |
|---------|------|-------------|
| **Priority Email Support** | Admiral | Direct email support during business hours (MonFri 09:0017:00 America/New_York). We aim to first-respond within one business day. This is not a contractual SLA or 24/7 service. |
Community operators see an upgrade callout with a link to the pricing page in place of the support channels.
---
## About
**Scope:** Global
Displays instance information at a glance.
| Field | Description |
|-------|-------------|
| **Version** | Current Sencho version. |
| **Tier** | Community or Admiral badge. |
| **Plan Status** | active, trial, expired, or community (Admiral entitlement state, not the AGPL software license). |
| **Instance ID** | First eight characters of the unique identifier for this Sencho control plane (used by the license server to identify it). |
The **Links** section contains Source code, AGPLv3 License, Licensing documentation, and Changelog links.