Update docker.io/rcourtman/pulse Docker tag to v6.2.1

Share
Update docker.io/rcourtman/pulse Docker tag to v6.2.1
Photo by Joshua Chehov / Unsplash

No problems upgrading the Docker container with a Docker compose yaml file by means of Watchtower DevOps resp. GitOps with dependency update facilitated by Mend's Renovate Bot.
Including updating all docker and host agents manually.

This MR contains the following updates:

Package Update Change
docker.io/rcourtman/pulse minor 6.1.26.2.1

Release Notes

rcourtman/Pulse (docker.io/rcourtman/pulse)

v6.2.1: Pulse v6.2.1

Compare Source

✅ Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication ✅
Validated: 2026-08-10 07:56:51 UTC
Workflow: Pulse Release Pipeline #​346

Validation Summary
  • All required assets present ✓
  • Checksums verified ✓
  • Version strings correct ✓
  • Binary architectures validated ✓
Pulse v6.2.1 Release Notes

v6.2.1 is a stable patch release following v6.2.0. It is promoted through
the emergency hotfix path because it repairs active customer failures in agent
installation and subscription-backed automation, and makes license activation
discoverable on fresh Pulse Pro installs.

Highlights
  • Agent download preflight follows redirects and validates final checksum and
    signature headers.
  • Agent Doctor recovers stale credentials; subscription-backed Patrol tools use
    strict provider schemas.
  • Fresh Pro installs expose activation; compiled Pro builds show commercial
    context outside demo and white-label modes.
Fixed
  • Redirecting agent artifact endpoints no longer lose the final response
    headers needed for checksum and signature preflight (#​1696).
  • Agent Doctor repairs stale local agent credentials through the governed
    recovery flow instead of leaving the agent unable to report.
  • Subscription-provider tools no longer send schemas rejected for missing
    strict object-field requirements (#​1697).
  • New Pro deployments can reach Plans & Billing before activation and keep the
    expected commercial navigation after activation.
  • Demo state converges after successful activation instead of retaining stale
    pre-activation presentation.
  • The server updates panel labels cached "Up to date" verdicts with the age of
    the check behind them, so a cached result no longer reads as a live comparison
    (#​1601).
Upgrade Notes

Use the normal v6 install or update flow for v6.2.1.

This is an emergency hotfix because the agent download issue crosses the
installer/updater risk boundary and causes active customer harm. The governed
release workflow still requires the integrated exact-SHA candidate checks,
immutable artifacts, published-digest verification, and definitive release
verdict.

Windows Unified Agent binaries in v6.2.1 are not Authenticode-signed under a
version-bound release-owner exception while the SignPath Release certificate 2026 CSR remains pending. Windows may therefore display an Unknown Publisher
warning. The immutable candidate manifest, checksums, detached .sig and
.sshsig signatures, and published-digest verification remain required.

The rollback target is v6.2.0. The exact rollback reinstall command is:

./scripts/install.sh --version v6.2.0

The server/mobile decision is no-mobile-impact. No mobile-facing API, Relay,
pairing, approval, push, authentication, or onboarding contract changed, so no
companion build upload or mobile-store rollout is required.

Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.

Installation

Docker (recommended):

docker pull rcourtman/pulse:6.2.1

Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.2.1

See the Installation Guide for complete setup instructions.

Review the Code signing policy for release provenance, approval roles, and signing scope.

Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.

Promotion Metadata
  • Promotion channel: stable
  • Candidate stable tag: v6.2.1
  • Promoted prerelease tag: n/a
  • Rollback target: v6.2.0
  • Rollback command: ./scripts/install.sh --version v6.2.0
  • Hotfix exception: true
  • Hotfix reason: Active v6.2.0 customer harm: agent binary installs can fail checksum preflight after redirects, subscription-backed Patrol rejects strict tool schemas, installed-agent credentials cannot recover, and fresh Pro installs cannot discover license activation.
  • Windows Authenticode required: false
  • Unsigned Windows exception: true
  • Unsigned Windows reason: SignPath Release certificate 2026 CSR remains pending; the release owner accepts unsigned Windows Unified Agent binaries for v6.2.1 with exact-SHA manifest, checksum, detached-signature, published-digest, and Unknown Publisher disclosure controls.

v6.2.0: Pulse v6.2.0

Compare Source

✅ Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication ✅
Validated: 2026-08-09 17:13:35 UTC
Workflow: Pulse Release Pipeline #​344

Validation Summary
  • All required assets present ✓
  • Checksums verified ✓
  • Version strings correct ✓
  • Binary architectures validated ✓
Pulse v6.2.0 Release Notes

v6.2.0 is a stable minor release for the Pulse v6 line. It follows stable
v6.1.2 and promotes the monitoring, alerting, agent lifecycle, security,
responsive-interface, and release-reliability work exercised across the
v6.2.0-rc.1 through v6.2.0-rc.11 line, plus the bounded fixes included in
the final stable cutoff.

Highlights
  • Expanded monitoring covers libvirt, XCP-ng, external probes, certificates,
    hardware, LXC filesystems, ZFS datasets, and PBS disks.
  • Actions provides a dedicated inbox; Operational Trust keeps evidence,
    approval, execution, posture, and verification in one governed loop.
  • Safer agents, responsive role-correct UI, and an immutable release pipeline
    improve supported platforms from install through rollout.
Added
  • Agent-assigned external probes with signed configuration delivery and
    governed outage alerts.
  • Local libvirt and XCP-ng monitoring, secure custom numeric sensors, Windows
    NVIDIA and hardware metrics, LXC filesystem inventory, ZFS datasets, and PBS
    physical-disk reporting.
  • Certificate-validity monitoring, VMware vCenter tags, application identity
    customization, in-place API-token scope editing, and OpenShift-safe Helm
    deployment options.
  • Resource-tag notification routing, per-resource alert delays, explicit
    per-metric off controls, Docker update-target details, and in-app rendering
    for Pulse documentation.
Improved
  • Canonical resource identity and live-state convergence across Proxmox, PBS,
    vCenter, agent auto-registration, WebSocket deltas, migrations, and safe
    hostname repair.
  • Agent update selection, rollback, service recovery, process matching,
    runtime discovery, watchdog shutdown, credential repair, and version-drift
    presentation.
  • Responsive navigation, filters, settings, tables, workload identity, focus
    restoration, touch targets, and localized date presentation.
  • Patrol and alert posture remain coherent when resources stop reporting,
    backups remain protected, or a request must recover from stale live state.
  • Self-hosted commercial surfaces retain the deliberate opt-in boundary while
    unproved plan and cadence transitions remain unavailable.
Fixed
  • Blocked untrusted request-derived hosts, schemes, forwarded values, and SSH
    cleanup targets from entering installer, diagnostic, sign-in, magic-link, or
    legacy-removal paths.
  • Preserved configured notification metadata, provider incidents,
    acknowledgements, disabled grouping, maintenance ingestion, protection
    posture, and platform-scoped threshold identity.
  • Corrected Proxmox workload, storage, availability, RRD, LXC memory, PBS
    attribution, QNAP RAID, TrueNAS, ZFS, disk I/O, Docker digest, and Kubernetes
    cluster-scope behavior.
  • Prevented stale or oversized WebSocket state from becoming the canonical
    recovery baseline and kept later resource deltas applied to raw server state.
  • Removed viewer-only access leaks, inaccessible Settings routes, privileged
    background polling, responsive panel clipping, misleading Agent Doctor
    states, stale agent-version warnings, and browser credential autofill in AI
    provider controls.
Release Qualification
  • The v6 control plane reports all 44 readiness assertions and all 26 release
    gates passed, with release_ready=True at the stable cutoff.
  • v6.2.0-rc.11 was published through the governed prerelease path. The
    release owner explicitly waived the remainder of its normal 72-hour soak for
    v6.2.0; that version-bound decision is risk acceptance, not soak evidence.
  • The exact pushed stable SHA must pass the no-publication Release Dry Run
    before the same SHA enters the single-build publication workflow.
  • Windows Unified Agent binaries in v6.2.0 are not Authenticode-signed and may
    show an Unknown Publisher warning. Verify their checksums and detached
    .sig/.sshsig signatures. This is a v6.2.0-only owner exception while the
    SignPath release certificate CSR remains pending; later releases restore the
    signing requirement unless separately approved.
Upgrade Notes

Use the normal v6 install or update flow for v6.2.0. Existing configurations
remain valid and no manual data migration is required.

The rollback target is v6.1.2. The exact rollback reinstall command is:

./scripts/install.sh --version v6.1.2

This server release is compatible with the existing Pulse Mobile candidate.
Pulse Mobile 1.0.0 iOS build 12 remains on the TestFlight public beta and
Android versionCode 9 remains on Play open testing, both using runtime version
2. No companion upload or public mobile-store rollout is part of this server
release.

Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.
Unproved self-service commercial plan or billing-cadence transitions remain
disabled and are not introduced by this release.

Installation

Docker (recommended):

docker pull rcourtman/pulse:6.2.0

Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.2.0

See the Installation Guide for complete setup instructions.

Review the Code signing policy for release provenance, approval roles, and signing scope.

Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.

Promotion Metadata
  • Promotion channel: stable
  • Candidate stable tag: v6.2.0
  • Promoted prerelease tag: v6.2.0-rc.11
  • Rollback target: v6.1.2
  • Rollback command: ./scripts/install.sh --version v6.1.2
  • Hotfix exception: true
  • Hotfix reason: Release-owner v6.2.0 cutoff approval on 2026-08-09; promote current main from v6.2.0-rc.11 without completing the 72-hour soak.
  • Windows Authenticode required: false
  • Unsigned Windows exception: true
  • Unsigned Windows reason: Release-owner v6.2.0-only exception approved on 2026-08-09 after dry run 3130669 confirmed the SignPath release certificate remains CSR pending; retain exact-SHA, checksum, detached-signature, manifest, and published-digest verification with public Unknown Publisher disclosure.

Read more

Me on Mastodon - This link is here for verification purposes.