Find a file
pulse-triage[bot] 44e70a8042
Some checks are pending
Build and Test / Secret Scan (push) Waiting to run
Build and Test / Detect changed areas (push) Waiting to run
Build and Test / Frontend (push) Blocked by required conditions
Build and Test / Backend tests (api) (push) Blocked by required conditions
Build and Test / Backend tests (rest-0) (push) Blocked by required conditions
Build and Test / Backend tests (rest-1) (push) Blocked by required conditions
Build and Test / Script smoke tests & backend build (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 2/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 3/8) (push) Blocked by required conditions
Build and Test / Benchmarks (push) Blocked by required conditions
Core E2E Tests / Validate E2E tier selection (push) Waiting to run
Core E2E Tests / Offline Organization provisioning (push) Waiting to run
Core E2E Tests / Playwright Core E2E (shard 1/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 4/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 5/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 7/8) (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 8/8) (push) Blocked by required conditions
Core E2E Tests / E2E verdict (push) Blocked by required conditions
Core E2E Tests / Playwright Core E2E (shard 6/8) (push) Blocked by required conditions
Core E2E Tests / Agent registration lifecycle (push) Waiting to run
Reduce repeated SMART History and configuration audit writes on v6.5 (#2408)
## What changes

Reduce the repeated writes reported in #2319 and #2320 on
`release/v6.5`:

- Keep linked Agent-only SMART disks visible without turning their
presentation scope into a Proxmox inventory observation during skipped
polls.
- Treat equivalent hostname, IP and MAC lists as sets when recording
identity changes, while preserving real identity changes.
- Record successful configuration fetches at first delivery,
token/configuration changes and daily continued access, rather than
every minute. Every failed fetch remains audited. Existing history and
audit records are not deleted.

These are compatible backports of
`0204fe000f`,
`a5aa881ac5` and
`8098b97825` from main. The frozen v6.4.6
candidate is unchanged; containing release selection and installed
acceptance remain separate.

## Included source

Publication range:
`f034dc65180104ef6a08a32d684a8f7901a2b9fe..e9da04c77efe22d2a093a6dbfe0eaf17c09bda22`.
Reviewed candidate: `190b8a0500`. The
publication merge has exactly the candidate's tree and retains the
published frontier and all reviewed commit identities.

```
b566983788 Backport SMART provenance and quiet config audits to v6.5
190b8a0500 Compose no-op identity journal repair with v6.5 polling fixes
e9da04c77e Merge reviewed polling write repairs on release/v6.5
```

## Validation

Recorded exact-candidate source proof `source-ggie00_8`: 1,348 connected
correctness tests, selected API/monitor and full unified-resource race
checks, vet, real embedded/server/agent builds, 20 contract tests and
three deliberate fault controls. The controls fail as expected, restore
exact source bytes, and pass final regressions; complete-output hashes
and guest shutdown were verified in the reviewed evidence. Fixtures
include three unchanged SMART full/skip cycles, real identity changes,
1,440 unchanged minute configuration polls producing one success audit,
daily/restart/tenant isolation, concurrent access and failed fetches.

Publication checks confirm clean committed source, provenance, unchanged
candidate tree, retained upstream ancestry and no whitespace errors.
Heavy checks were not repeated on the identical tree.

The local proof used Go 1.26.7, not the declared 1.26.8.
Declared-toolchain CI and release qualification remain required; the
local proof is not exact-toolchain qualification.

The audit tracker prunes stale entries at its threshold but does not
impose a hard cap on recent keys; that known follow-up remains separate.
These synthetic checks do not establish installed disk-write rates,
fleet CPU relief or complete reporter outcomes. Required exact-head CI
must pass before landing; this proposal does not approve a release.


[How Pulse handles
triage](https://github.com/rcourtman/Pulse/blob/main/docs/AI_TRANSPARENCY.md)
2026-10-02 21:04:29 +00:00
.devcontainer Bump golang in /.devcontainer 2026-09-23 08:03:42 +00:00
.github fix(ci): freeze reviewed action pins from Dependabot version updates 2026-09-23 08:04:21 +01:00
.husky Stop retrying unchanged credential blocks 2026-09-04 00:14:40 +01:00
cmd Stabilise v6.5 candidate qualification tests 2026-09-28 15:22:22 +01:00
deploy release: prepare v6.5.0-rc.1 on the v6.5 line 2026-09-23 18:11:24 +01:00
dev/oidc feat: Pulse v6 release 2026-03-18 16:06:30 +00:00
docs Compose no-op identity journal repair with v6.5 polling fixes 2026-10-02 20:34:14 +01:00
frontend-modern Backport SMART provenance and quiet config audits to v6.5 2026-10-02 20:05:35 +01:00
internal Compose no-op identity journal repair with v6.5 polling fixes 2026-10-02 20:34:14 +01:00
pkg Backport the atomic time-major metrics identity index to v6.5 2026-10-01 11:28:40 +01:00
scripts Backport private Apprise diagnostics and bounded TrueNAS RPC to v6.5 2026-10-02 14:05:08 +01:00
testdata Fix Unraid SMART probing and disk authority 2026-07-24 09:38:39 +01:00
testing-tools test: add soak test with runtime instrumentation (Phase 2 Task 9d) 2025-10-20 15:13:38 +00:00
tests build(deps): land the reviewed @types/node 26.6.2 refresh 2026-09-23 09:26:24 +01:00
.air.toml chore: Add Air hot-reload configuration 2026-01-19 19:26:50 +00:00
.dockerignore Exclude nested node_modules from the Docker build context 2026-07-08 00:57:35 +01:00
.env.example docs: update API documentation and config file references 2026-02-01 23:26:42 +00:00
.gitattributes chore: optimize PNG images and add .gitattributes 2025-11-24 23:44:55 +00:00
.gitguardian.yaml
.gitignore fix(ci): select governed source for scheduled release rehearsals 2026-09-08 08:30:38 +01:00
.gitleaks.toml fix(settings): restore token dialog focus 2026-08-06 00:04:40 +01:00
.gitleaksignore Record schema v6 secure runtime qualification 2026-08-31 01:12:15 +01:00
.golangci.yml Dedupe internal/api handler families behind shared flows and generics 2026-06-10 10:52:05 +01:00
.markdownlint-cli2.jsonc docs: standardize markdown syntax and remove deprecated sensor-proxy docs 2026-01-20 09:43:49 +00:00
.markdownlint.json docs: standardize markdown syntax and remove deprecated sensor-proxy docs 2026-01-20 09:43:49 +00:00
analyze_coverage.py docs: update AI evaluation matrix and approval workflow documentation 2026-01-30 19:00:40 +00:00
ARCHITECTURE.md Align TrueNAS guidance with JSON-RPC runtime 2026-09-01 18:32:39 +01:00
CONTRIBUTING.md Keep release toolchains within support 2026-08-30 06:40:25 +01:00
cr.yaml Add GitHub Pages Helm repository distribution (#686) 2025-11-11 19:26:18 +00:00
docker-compose.yml release: prepare v6.5.0-rc.1 on the v6.5 line 2026-09-23 18:11:24 +01:00
docker-entrypoint.sh Avoid tenant runtime image copy-up 2026-04-24 09:21:42 +01:00
docker-healthcheck.sh feat: Pulse v6 release 2026-03-18 16:06:30 +00:00
Dockerfile build(deps): refresh governed container image digests 2026-09-23 05:23:41 +01:00
go.mod build(deps): qualify the go-minor-patch dependency group 2026-09-23 06:49:52 +01:00
go.sum build(deps): qualify the go-minor-patch dependency group 2026-09-23 06:49:52 +01:00
install.sh fix(installer): discard unneeded config backup when staging cannot start 2026-09-20 17:44:43 +01:00
LICENSE
Makefile Give release backend tests hosted-runner headroom 2026-08-21 08:49:05 +01:00
package-lock.json feat: Pulse v6 release 2026-03-18 16:06:30 +00:00
package.json Route mock toggle npm scripts through toggle-mock.sh 2026-08-04 00:30:28 +01:00
playwright.config.ts fix(frontend): sync summary hover cursor and proof 2026-04-01 14:48:47 +01:00
README.md docs: explain release channels and qualification 2026-09-08 12:51:15 +01:00
SECURITY.md Point security disclosures at security@pulserelay.pro 2026-09-01 15:21:23 +01:00
TERMS.md Clarify that TERMS.md covers only the commercial Pro distribution 2026-08-12 16:01:46 +01:00
VERSION release: prepare v6.5.0-rc.1 on the v6.5 line 2026-09-23 18:11:24 +01:00

Pulse

Pulse logo

Infrastructure monitoring that finds what needs attention.

GitHub Stars GitHub Release Docker Pulls License

Live demo · Documentation · Releases · Discussions

Pulse is a self-hosted monitoring workspace for Proxmox, Docker, Kubernetes, TrueNAS, physical and virtual machines, and early-access VMware vSphere environments. It combines live infrastructure state, history, alerts, recovery visibility, and scheduled health checks without requiring a conventional enterprise monitoring stack.

Pulse Proxmox workspace

Why Pulse

  • It watches between visits. Alerts and Pulse Patrol find failed backups, capacity pressure, restart loops, unhealthy containers, clock drift, and other problems that dashboards cannot surface when nobody is looking.
  • It keeps each platform familiar. Proxmox, Docker, Kubernetes, TrueNAS, vSphere, and machines have dedicated views, backed by one shared resource model for search, alerts, history, and investigation.
  • It stays operator-controlled. Credentials are encrypted at rest, API tokens are scoped, agent commands are disabled by default, and governed fixes require the configured policy and approval path.

Platform coverage

Platform Coverage
Proxmox VE, PBS, and PMG Nodes, guests, storage, backups, replication, Ceph, mail gateways, and alerts
Docker and Podman Hosts, containers, Compose projects, Swarm services, health, images, and updates
Kubernetes Clusters, nodes, workloads, pods, services, storage, and events through the unified agent
TrueNAS SCALE and CORE Pools, datasets, disks, snapshots, replication tasks, apps, VMs, and alerts
Linux, Windows, and macOS machines Host health, filesystems, networking, temperatures, RAID, and availability through the unified agent
VMware vSphere Early-access inventory, hosts, clusters, VMs, datastores, networks, snapshots, and recovery context; validate against your own vCenter before production use

Platform pages keep storage and recovery information beside the infrastructure it belongs to. Alerts, Actions, and Patrol remain cross-platform views.

Patrol: monitoring that does rounds

Pulse Patrol runs scheduled checks across the current state and recent history of your infrastructure. Community installations can use a local model or their own AI provider for watch-only analysis. Pulse Pro adds investigation and policy-bound fixes with approval, verification, and an audit trail.

Pulse Patrol attention queue

Pulse also includes an interactive Assistant and an MCP adapter for external clients such as Claude Code and OpenCode. Both sit on top of the same scoped inventory, metrics, alert, storage, and governed-action contracts.

Quick start

Choose an exact version from the latest release and keep that version pinned during installation.

Docker

docker run -d \
  --name pulse \
  -p 7655:7655 \
  -v pulse_data:/data \
  -e PULSE_DEPLOYMENT_METHOD=docker_run \
  --restart unless-stopped \
  rcourtman/pulse:vX.Y.Z

Open http://<your-ip>:7655 and follow the bootstrap-token setup. Docker host monitoring is provided by the unified agent; the Pulse server container does not need the Docker socket.

Proxmox LXC, Linux, and Kubernetes

The installer is signed. Verify install.sh against the pinned pulse-installer key before running it:

export PULSE_VERSION=vX.Y.Z
curl -fsSLO "https://github.com/rcourtman/Pulse/releases/download/${PULSE_VERSION}/install.sh"
curl -fsSLO "https://github.com/rcourtman/Pulse/releases/download/${PULSE_VERSION}/install.sh.sshsig"
ssh-keygen -Y verify \
  -f <(printf '%s\n' 'pulse-installer namespaces="pulse-install" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMZd/DaH+BldzOkq1A8KVTcFk73nAyrE8aJOyf7i00jm pulse-installer') \
  -I pulse-installer \
  -n pulse-install \
  -s install.sh.sshsig < install.sh
bash install.sh --version "${PULSE_VERSION}"
rm -f install.sh install.sh.sshsig

The GitHub installer installs the Pulse server. Install and upgrade agents (including v5-to-v6 agent upgrades) with the per-host command generated under Settings → Infrastructure → Install on a host.

Do you need an agent?

Often not. Proxmox VE, PBS, and PMG are monitored through the Proxmox API with a read-only token, so nothing runs on the host and the generated setup script creates a privilege-separated monitoring user. Install the unified agent only where you want data the platform API cannot provide, such as host SMART health, temperatures, Docker hosts, or standalone machines.

The agent is operator-controlled by design. Command execution is off by default, the local listener binds to localhost, and generated systemd units ship hardened. On Linux, the installer's --least-privilege profile runs the service as a dedicated non-root user, with optional scoped sudo grants for the few collectors that need elevation. The agent security model documents exactly what the agent can and cannot do at each privilege level.

Important

GitHub release assets and rcourtman/pulse images are Community builds. Relay, Pro, and eligible legacy customers should use the private image or Linux archive provided by the Pulse download portal. Replacing a private Pro runtime with a public Community build removes its private runtime hooks.

Editions

  • Community — self-hosted monitoring, seven days of metric history, core SSO, update alerts, and Patrol with your own provider or local model.
  • Relay — Community plus secure remote web access, Pulse Mobile pairing, push notifications, and fourteen days of history.
  • Pro — Relay plus Patrol investigation, governed fixes, ninety days of history, centralized agent profiles, RBAC, audit logging, and reporting.
  • MSP — for managed service providers: one Pulse Account running many client workspaces, each with an isolated Pulse runtime — separate dashboards, alerts, users, audit history, and reports. Free sixty-day two-client evaluation at Pulse for MSPs.

Core self-hosted monitoring is not gated by monitored-system or child-resource volume. See the runtime-aligned capability reference and current plans for details.

Documentation

Localized getting started guides: Deutsch · Español

Development

Pulse uses Go 1.26 and a SolidJS/TypeScript frontend. The managed development runtime starts the frontend at http://127.0.0.1:5173 and proxies API and WebSocket traffic to the backend on port 7655.

npm ci
npm --prefix frontend-modern ci
npm run dev

Useful checks:

go test ./...
npm --prefix frontend-modern test
npm --prefix frontend-modern run type-check
python3 scripts/check_public_docs.py

See CONTRIBUTING.md before investing in a code change. Pulse uses an issue-first contribution process and does not normally accept unsolicited pull requests.

Community and support

License

Everything in this repository is licensed under the MIT License. There is no dual licensing and no commercial or source-available code here.

Pulse Pro is a separate commercial product, built from private sources and distributed through pulserelay.pro. Its use is governed by the Terms of Service, which apply to that product only, not to anything in this repository.