Find a file
rcourtman e06fa88c22 fix(updates): stop non-admin sessions polling the admin update-status route
GlobalUpdateProgressWatcher ran a 5s fallback poll of
UpdatesAPI.getUpdateStatus() for every session, but /api/updates/status is
registered with RequireAdmin + RequireScope(settings:read). An authenticated
non-admin session -- an SSO user with read-only roles, say -- therefore 403'd
on every tick, and each denial logged a warn. The frontend swallowed the
error, so the only symptom was backend log spam every few seconds, which
misled the #1601 rc.9 reporter into diagnosing an RBAC break when the actual
bug was a websocket delta regression.

Gate the watcher on securityStatus detailLevel === 'privileged'. That is the
served mirror of the exact route gate: the security-status handler promotes a
response to 'privileged' if and only if the session passes
canAccessAdminSurface(settings:read), the same predicate RequireAdmin and
RequireScope enforce on the route. Instances that require no auth keep
polling, because there the update routes really are reachable by anonymous
loopback callers while security status is still served at detail level
'public' -- gating on detailLevel alone would have broken the update modal for
the most common self-hosted install.

UpdateProgressModal's own getUpdateStatus poll needs no separate gate: its
only mount site is inside this watcher.

Verified on an isolated instance with proxy auth and two header-injecting
proxies supplying identities that differ only in the role header:

  bob-viewer    detailLevel=authenticated  GET /api/updates/status -> 403
                0 requests per 60s window at 1280x800 and at 375x812,
                windows that previously held ~13 poll ticks each
  alice-admin   detailLevel=privileged     GET /api/updates/status -> 200
                22 requests across both viewports, all 200 (unchanged)

Zero /api/updates/status denials in the backend log across the whole session.
The non-admin shell still renders normally at both viewports; only the poll
is gone.

Contract-Neutral: Frontend-only behavioral fix: gates the GlobalUpdateProgressWatcher fallback poll so non-admin sessions stop issuing GET /api/updates/status requests the RequireAdmin+settings:read route always refused with 403. No public-contract delta - no API/endpoint/type/prop change, no new component, admin behavior byte-identical (22 polls verified), non-admin behavior was already a silent 403. App.tsx is only a high-fanout Extension Points reference for ai-runtime/cloud-paid/storage-recovery; none of those subsystems' surfaces change.
2026-08-07 19:45:08 +01:00
.devcontainer Update pinned Go toolchain to 1.25.9 2026-04-18 10:04:34 +01:00
.github fix(release): stage artifacts before publication 2026-08-07 12:27:36 +01:00
.husky Make prepare-commit-msg executable so worktree commits keep the trailer 2026-08-04 11:28:05 +01:00
cmd feat(agent): converge agent self-update within one report cycle 2026-08-07 11:40:46 +01:00
deploy Keep the operator .env out of the Traefik container and unhardcode the DNS-01 provider 2026-08-07 10:47:13 +01:00
dev/oidc feat: Pulse v6 release 2026-03-18 16:06:30 +00:00
docs feat(commercial): revise self-hosted commercial surfaces (supersede RA5 opt-in posture) 2026-08-07 13:47:46 +01:00
frontend-modern fix(updates): stop non-admin sessions polling the admin update-status route 2026-08-07 19:45:08 +01:00
internal feat(commercial): revise self-hosted commercial surfaces (supersede RA5 opt-in posture) 2026-08-07 13:47:46 +01:00
pkg test(reporting): slice PDF streams by declared /Length in text extraction 2026-08-06 09:51:01 +01:00
scripts fix(release-control): unblock RA10 documentation currentness proof 2026-08-07 13:17:19 +01:00
testdata Fix Unraid SMART probing and disk authority 2026-07-24 09:38:39 +01:00
testing-tools test: add soak test with runtime instrumentation (Phase 2 Task 9d) 2025-10-20 15:13:38 +00:00
tests feat(commercial): revise self-hosted commercial surfaces (supersede RA5 opt-in posture) 2026-08-07 13:47:46 +01:00
.air.toml chore: Add Air hot-reload configuration 2026-01-19 19:26:50 +00:00
.dockerignore Exclude nested node_modules from the Docker build context 2026-07-08 00:57:35 +01:00
.env.example docs: update API documentation and config file references 2026-02-01 23:26:42 +00:00
.gitattributes chore: optimize PNG images and add .gitattributes 2025-11-24 23:44:55 +00:00
.gitguardian.yaml
.gitignore chore: require live proof for hardware fix claims 2026-08-04 23:57:44 +01:00
.gitleaks.toml fix(settings): restore token dialog focus 2026-08-06 00:04:40 +01:00
.gitleaksignore Fix RC metrics, agent state, and bundle regressions 2026-08-05 00:32:24 +01:00
.golangci.yml Dedupe internal/api handler families behind shared flows and generics 2026-06-10 10:52:05 +01:00
.markdownlint-cli2.jsonc docs: standardize markdown syntax and remove deprecated sensor-proxy docs 2026-01-20 09:43:49 +00:00
.markdownlint.json docs: standardize markdown syntax and remove deprecated sensor-proxy docs 2026-01-20 09:43:49 +00:00
analyze_coverage.py docs: update AI evaluation matrix and approval workflow documentation 2026-01-30 19:00:40 +00:00
ARCHITECTURE.md docs: refresh public repository surface 2026-08-06 01:00:41 +01:00
CONTRIBUTING.md docs: refresh public repository surface 2026-08-06 01:00:41 +01:00
cr.yaml Add GitHub Pages Helm repository distribution (#686) 2025-11-11 19:26:18 +00:00
docker-compose.yml Prepare v6.2.0-rc.9 release 2026-08-07 10:03:16 +01:00
docker-entrypoint.sh Avoid tenant runtime image copy-up 2026-04-24 09:21:42 +01:00
docker-healthcheck.sh feat: Pulse v6 release 2026-03-18 16:06:30 +00:00
Dockerfile Restore Apprise Telegram topic delivery 2026-07-30 13:10:59 +01:00
go.mod Modernize Unified Agent lifecycle and platform support 2026-07-09 23:20:35 +01:00
go.sum Modernize Unified Agent lifecycle and platform support 2026-07-09 23:20:35 +01:00
install.sh fix(install): use absolute binary path in pct exec instructions 2026-08-06 12:08:13 +01:00
LICENSE
Makefile Add lab-agent hot-dev mode 2026-06-14 09:55:56 +01:00
package-lock.json feat: Pulse v6 release 2026-03-18 16:06:30 +00:00
package.json Route mock toggle npm scripts through toggle-mock.sh 2026-08-04 00:30:28 +01:00
playwright.config.ts fix(frontend): sync summary hover cursor and proof 2026-04-01 14:48:47 +01:00
README.md fix(release-control): unblock RA10 documentation currentness proof 2026-08-07 13:17:19 +01:00
SECURITY.md Clarify agent upgrade and notification docs 2026-06-12 19:26:26 +01:00
TERMS.md Keep trial starts out of feature gates 2026-04-28 11:47:06 +01:00
VERSION Prepare v6.2.0-rc.9 release 2026-08-07 10:03:16 +01:00

Pulse

Pulse logo

Infrastructure monitoring that finds what needs attention.

GitHub Stars GitHub Release Docker Pulls License

Live demo · Documentation · Releases · Discussions

Pulse is a self-hosted monitoring workspace for Proxmox, Docker, Kubernetes, TrueNAS, physical and virtual machines, and early-access VMware vSphere environments. It combines live infrastructure state, history, alerts, recovery visibility, and scheduled health checks without requiring a conventional enterprise monitoring stack.

Pulse Proxmox workspace

Why Pulse

  • It watches between visits. Alerts and Pulse Patrol find failed backups, capacity pressure, restart loops, unhealthy containers, clock drift, and other problems that dashboards cannot surface when nobody is looking.
  • It keeps each platform familiar. Proxmox, Docker, Kubernetes, TrueNAS, vSphere, and machines have dedicated views, backed by one shared resource model for search, alerts, history, and investigation.
  • It stays operator-controlled. Credentials are encrypted at rest, API tokens are scoped, agent commands are disabled by default, and governed fixes require the configured policy and approval path.

Platform coverage

Platform Coverage
Proxmox VE, PBS, and PMG Nodes, guests, storage, backups, replication, Ceph, mail gateways, and alerts
Docker and Podman Hosts, containers, Compose projects, Swarm services, health, images, and updates
Kubernetes Clusters, nodes, workloads, pods, services, storage, and events through the unified agent
TrueNAS SCALE and CORE Pools, datasets, disks, snapshots, replication tasks, apps, VMs, and alerts
Linux, Windows, and macOS machines Host health, filesystems, networking, temperatures, RAID, and availability through the unified agent
VMware vSphere Early-access inventory, hosts, clusters, VMs, datastores, networks, snapshots, and recovery context; validate against your own vCenter before production use

Platform pages keep storage and recovery information beside the infrastructure it belongs to. Alerts, Actions, and Patrol remain cross-platform views.

Patrol: monitoring that does rounds

Pulse Patrol runs scheduled checks across the current state and recent history of your infrastructure. Community installations can use a local model or their own AI provider for watch-only analysis. Pulse Pro adds investigation and policy-bound fixes with approval, verification, and an audit trail.

Pulse Patrol attention queue

Pulse also includes an interactive Assistant and an MCP adapter for external clients such as Claude Code and OpenCode. Both sit on top of the same scoped inventory, metrics, alert, storage, and governed-action contracts.

Quick start

Choose an exact version from the latest release and keep that version pinned during installation.

Docker

docker run -d \
  --name pulse \
  -p 7655:7655 \
  -v pulse_data:/data \
  -e PULSE_DEPLOYMENT_METHOD=docker_run \
  --restart unless-stopped \
  rcourtman/pulse:vX.Y.Z

Open http://<your-ip>:7655 and follow the bootstrap-token setup. Docker host monitoring is provided by the unified agent; the Pulse server container does not need the Docker socket.

Proxmox LXC, Linux, and Kubernetes

The installer is signed. Verify install.sh against the pinned pulse-installer key before running it:

export PULSE_VERSION=vX.Y.Z
curl -fsSLO "https://github.com/rcourtman/Pulse/releases/download/${PULSE_VERSION}/install.sh"
curl -fsSLO "https://github.com/rcourtman/Pulse/releases/download/${PULSE_VERSION}/install.sh.sshsig"
ssh-keygen -Y verify \
  -f <(printf '%s\n' 'pulse-installer namespaces="pulse-install" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIMZd/DaH+BldzOkq1A8KVTcFk73nAyrE8aJOyf7i00jm pulse-installer') \
  -I pulse-installer \
  -n pulse-install \
  -s install.sh.sshsig < install.sh
bash install.sh --version "${PULSE_VERSION}"
rm -f install.sh install.sh.sshsig

The GitHub installer installs the Pulse server. Install and upgrade agents (including v5-to-v6 agent upgrades) with the per-host command generated under Settings → Infrastructure → Install on a host.

Important

GitHub release assets and rcourtman/pulse images are Community builds. Relay, Pro, and eligible legacy customers should use the private image or Linux archive provided by the Pulse download portal. Replacing a private Pro runtime with a public Community build removes its private runtime hooks.

Editions

  • Community — self-hosted monitoring, seven days of metric history, core SSO, update alerts, and Patrol with your own provider or local model.
  • Relay — Community plus secure remote web access, Pulse Mobile pairing, push notifications, and fourteen days of history.
  • Pro — Relay plus Patrol investigation, governed fixes, ninety days of history, centralized agent profiles, RBAC, audit logging, and reporting.
  • MSP — for managed service providers: one Pulse Account running many client workspaces, each with an isolated Pulse runtime — separate dashboards, alerts, users, audit history, and reports. Free sixty-day two-client evaluation at Pulse for MSPs.

Core self-hosted monitoring is not gated by monitored-system or child-resource volume. See the runtime-aligned capability reference and current plans for details.

Documentation

Localized getting started guides: Deutsch · Español

Development

Pulse uses Go 1.26 and a SolidJS/TypeScript frontend. The managed development runtime starts the frontend at http://127.0.0.1:5173 and proxies API and WebSocket traffic to the backend on port 7655.

npm ci
npm --prefix frontend-modern ci
npm run dev

Useful checks:

go test ./...
npm --prefix frontend-modern test
npm --prefix frontend-modern run type-check
python3 scripts/check_public_docs.py

See CONTRIBUTING.md before investing in a code change. Pulse uses an issue-first contribution process and does not normally accept unsolicited pull requests.

Community and support

License

Pulse Community is available under the MIT License. Pulse Pro is subject to the Terms of Service.