Update docker.io/rcourtman/pulse Docker tag to v6.2.1
No problems upgrading the Docker container with a Docker compose yaml file by means of Watchtower DevOps resp. GitOps with dependency update facilitated by Mend's Renovate Bot.
Including updating all docker and host agents manually.
This MR contains the following updates:
| Package | Update | Change |
|---|---|---|
| docker.io/rcourtman/pulse | minor | 6.1.2 → 6.2.1 |
Release Notes
rcourtman/Pulse (docker.io/rcourtman/pulse)
v6.2.1: Pulse v6.2.1
✅ Release Asset Validation: PASSED
All release assets have been validated successfully!
Status: Ready for publication ✅
Validated: 2026-08-10 07:56:51 UTC
Workflow: Pulse Release Pipeline #346
Validation Summary
- All required assets present ✓
- Checksums verified ✓
- Version strings correct ✓
- Binary architectures validated ✓
Pulse v6.2.1 Release Notes
v6.2.1 is a stable patch release following v6.2.0. It is promoted through
the emergency hotfix path because it repairs active customer failures in agent
installation and subscription-backed automation, and makes license activation
discoverable on fresh Pulse Pro installs.
Highlights
- Agent download preflight follows redirects and validates final checksum and
signature headers. - Agent Doctor recovers stale credentials; subscription-backed Patrol tools use
strict provider schemas. - Fresh Pro installs expose activation; compiled Pro builds show commercial
context outside demo and white-label modes.
Fixed
- Redirecting agent artifact endpoints no longer lose the final response
headers needed for checksum and signature preflight (#1696). - Agent Doctor repairs stale local agent credentials through the governed
recovery flow instead of leaving the agent unable to report. - Subscription-provider tools no longer send schemas rejected for missing
strict object-field requirements (#1697). - New Pro deployments can reach Plans & Billing before activation and keep the
expected commercial navigation after activation. - Demo state converges after successful activation instead of retaining stale
pre-activation presentation. - The server updates panel labels cached "Up to date" verdicts with the age of
the check behind them, so a cached result no longer reads as a live comparison
(#1601).
Upgrade Notes
Use the normal v6 install or update flow for v6.2.1.
This is an emergency hotfix because the agent download issue crosses the
installer/updater risk boundary and causes active customer harm. The governed
release workflow still requires the integrated exact-SHA candidate checks,
immutable artifacts, published-digest verification, and definitive release
verdict.
Windows Unified Agent binaries in v6.2.1 are not Authenticode-signed under a
version-bound release-owner exception while the SignPath Release certificate 2026 CSR remains pending. Windows may therefore display an Unknown Publisher
warning. The immutable candidate manifest, checksums, detached .sig and
.sshsig signatures, and published-digest verification remain required.
The rollback target is v6.2.0. The exact rollback reinstall command is:
./scripts/install.sh --version v6.2.0
The server/mobile decision is no-mobile-impact. No mobile-facing API, Relay,
pairing, approval, push, authentication, or onboarding contract changed, so no
companion build upload or mobile-store rollout is required.
Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.
Installation
Docker (recommended):
docker pull rcourtman/pulse:6.2.1
Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.2.1
See the Installation Guide for complete setup instructions.
Review the Code signing policy for release provenance, approval roles, and signing scope.
Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.
Promotion Metadata
- Promotion channel: stable
- Candidate stable tag: v6.2.1
- Promoted prerelease tag: n/a
- Rollback target: v6.2.0
- Rollback command:
./scripts/install.sh --version v6.2.0 - Hotfix exception: true
- Hotfix reason: Active v6.2.0 customer harm: agent binary installs can fail checksum preflight after redirects, subscription-backed Patrol rejects strict tool schemas, installed-agent credentials cannot recover, and fresh Pro installs cannot discover license activation.
- Windows Authenticode required: false
- Unsigned Windows exception: true
- Unsigned Windows reason: SignPath Release certificate 2026 CSR remains pending; the release owner accepts unsigned Windows Unified Agent binaries for v6.2.1 with exact-SHA manifest, checksum, detached-signature, published-digest, and Unknown Publisher disclosure controls.
v6.2.0: Pulse v6.2.0
✅ Release Asset Validation: PASSED
All release assets have been validated successfully!
Status: Ready for publication ✅
Validated: 2026-08-09 17:13:35 UTC
Workflow: Pulse Release Pipeline #344
Validation Summary
- All required assets present ✓
- Checksums verified ✓
- Version strings correct ✓
- Binary architectures validated ✓
Pulse v6.2.0 Release Notes
v6.2.0 is a stable minor release for the Pulse v6 line. It follows stable
v6.1.2 and promotes the monitoring, alerting, agent lifecycle, security,
responsive-interface, and release-reliability work exercised across the
v6.2.0-rc.1 through v6.2.0-rc.11 line, plus the bounded fixes included in
the final stable cutoff.
Highlights
- Expanded monitoring covers libvirt, XCP-ng, external probes, certificates,
hardware, LXC filesystems, ZFS datasets, and PBS disks. - Actions provides a dedicated inbox; Operational Trust keeps evidence,
approval, execution, posture, and verification in one governed loop. - Safer agents, responsive role-correct UI, and an immutable release pipeline
improve supported platforms from install through rollout.
Added
- Agent-assigned external probes with signed configuration delivery and
governed outage alerts. - Local libvirt and XCP-ng monitoring, secure custom numeric sensors, Windows
NVIDIA and hardware metrics, LXC filesystem inventory, ZFS datasets, and PBS
physical-disk reporting. - Certificate-validity monitoring, VMware vCenter tags, application identity
customization, in-place API-token scope editing, and OpenShift-safe Helm
deployment options. - Resource-tag notification routing, per-resource alert delays, explicit
per-metric off controls, Docker update-target details, and in-app rendering
for Pulse documentation.
Improved
- Canonical resource identity and live-state convergence across Proxmox, PBS,
vCenter, agent auto-registration, WebSocket deltas, migrations, and safe
hostname repair. - Agent update selection, rollback, service recovery, process matching,
runtime discovery, watchdog shutdown, credential repair, and version-drift
presentation. - Responsive navigation, filters, settings, tables, workload identity, focus
restoration, touch targets, and localized date presentation. - Patrol and alert posture remain coherent when resources stop reporting,
backups remain protected, or a request must recover from stale live state. - Self-hosted commercial surfaces retain the deliberate opt-in boundary while
unproved plan and cadence transitions remain unavailable.
Fixed
- Blocked untrusted request-derived hosts, schemes, forwarded values, and SSH
cleanup targets from entering installer, diagnostic, sign-in, magic-link, or
legacy-removal paths. - Preserved configured notification metadata, provider incidents,
acknowledgements, disabled grouping, maintenance ingestion, protection
posture, and platform-scoped threshold identity. - Corrected Proxmox workload, storage, availability, RRD, LXC memory, PBS
attribution, QNAP RAID, TrueNAS, ZFS, disk I/O, Docker digest, and Kubernetes
cluster-scope behavior. - Prevented stale or oversized WebSocket state from becoming the canonical
recovery baseline and kept later resource deltas applied to raw server state. - Removed viewer-only access leaks, inaccessible Settings routes, privileged
background polling, responsive panel clipping, misleading Agent Doctor
states, stale agent-version warnings, and browser credential autofill in AI
provider controls.
Release Qualification
- The v6 control plane reports all 44 readiness assertions and all 26 release
gates passed, withrelease_ready=Trueat the stable cutoff. v6.2.0-rc.11was published through the governed prerelease path. The
release owner explicitly waived the remainder of its normal 72-hour soak for
v6.2.0; that version-bound decision is risk acceptance, not soak evidence.- The exact pushed stable SHA must pass the no-publication Release Dry Run
before the same SHA enters the single-build publication workflow. - Windows Unified Agent binaries in v6.2.0 are not Authenticode-signed and may
show an Unknown Publisher warning. Verify their checksums and detached
.sig/.sshsigsignatures. This is a v6.2.0-only owner exception while the
SignPath release certificate CSR remains pending; later releases restore the
signing requirement unless separately approved.
Upgrade Notes
Use the normal v6 install or update flow for v6.2.0. Existing configurations
remain valid and no manual data migration is required.
The rollback target is v6.1.2. The exact rollback reinstall command is:
./scripts/install.sh --version v6.1.2
This server release is compatible with the existing Pulse Mobile candidate.
Pulse Mobile 1.0.0 iOS build 12 remains on the TestFlight public beta and
Android versionCode 9 remains on Play open testing, both using runtime version
2. No companion upload or public mobile-store rollout is part of this server
release.
Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.
Unproved self-service commercial plan or billing-cadence transitions remain
disabled and are not introduced by this release.
Installation
Docker (recommended):
docker pull rcourtman/pulse:6.2.0
Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.2.0
See the Installation Guide for complete setup instructions.
Review the Code signing policy for release provenance, approval roles, and signing scope.
Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.
Promotion Metadata
- Promotion channel: stable
- Candidate stable tag: v6.2.0
- Promoted prerelease tag: v6.2.0-rc.11
- Rollback target: v6.1.2
- Rollback command:
./scripts/install.sh --version v6.1.2 - Hotfix exception: true
- Hotfix reason: Release-owner v6.2.0 cutoff approval on 2026-08-09; promote current main from v6.2.0-rc.11 without completing the 72-hour soak.
- Windows Authenticode required: false
- Unsigned Windows exception: true
- Unsigned Windows reason: Release-owner v6.2.0-only exception approved on 2026-08-09 after dry run
3130669confirmed the SignPath release certificate remains CSR pending; retain exact-SHA, checksum, detached-signature, manifest, and published-digest verification with public Unknown Publisher disclosure.