Update docker.io/rcourtman/pulse Docker tag to v6.4.2

Share
Update docker.io/rcourtman/pulse Docker tag to v6.4.2
Photo by Joshua Chehov / Unsplash

No problems upgrading the Docker container with a Docker compose yaml file by means of Watchtower DevOps resp. GitOps with dependency update facilitated by Mend's Renovate Bot.
Including updating all docker and host agents manually.

This MR contains the following updates:

Package Update Change
docker.io/rcourtman/pulse minor 6.2.1 β†’ 6.4.2

Release Notes

rcourtman/Pulse (docker.io/rcourtman/pulse)

v6.4.2

Compare Source

v6.4.2

Compare Source

v6.4.1: Pulse v6.4.1

Compare Source

βœ… Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication βœ…
Validated: 2026-08-29 10:36:59 UTC
Workflow: Pulse Release Pipeline #​396

Validation Summary
  • All required assets present βœ“
  • Checksums verified βœ“
  • Version strings correct βœ“
  • Binary architectures validated βœ“

Pulse v6.4.1 Release Notes

v6.4.1 is a stable patch release for the Pulse v6 line. It follows stable
v6.4.0 and restores the embedded container agent while correcting first-load
Proxmox details and several storage, persistence, and AI budget edge cases.

What's improved

  • Container agents start correctly - The embedded Unified Agent is executable in the server image, restoring Helm deployments with agent.enabled=true and direct agent entrypoints.
  • Proxmox details are correct on first load - VM and LXC backup status, uptime, and related guest details no longer appear missing until a later live update arrives.
  • TrueNAS SMART evidence is parsed safely - Spare-block reserve percentages accept supported native TrueNAS representations while malformed, fractional, or out-of-range values are ignored.
  • Credential changes fail safely - Token creation, migration, runtime preparation, and first-run reset restore prior live state when durable persistence fails.
  • AI budgets cover current models - Anthropic Sonnet 5, Fable 5, and Mythos 5 usage remains accurately priced and enforceable in Assistant and Patrol summaries.

Before you upgrade

  • Existing configurations remain valid and no manual data migration is required.
  • Pulse Mobile remains compatible. This patch does not require a companion mobile release.
  • Windows Unified Agent binaries are not Authenticode-signed while SignPath remains unavailable and may show an Unknown Publisher warning. Verify downloads with the published checksums and detached signatures.
  • The rollback target is stable v6.4.0. On systemd and Proxmox LXC installs, use sudo /bin/update --version v6.4.0 to return to the previous stable release. For Docker Compose, pin rcourtman/pulse:6.4.0 and recreate the container.

Install

For systemd and Proxmox LXC installs, use Settings β†’ System β†’ Updates or:

sudo /bin/update --version v6.4.1

For Docker:

docker pull rcourtman/pulse:6.4.1

For Docker Compose, update the image to rcourtman/pulse:6.4.1 and recreate the container.

Pulse Pro and Relay customers should continue using the private download page and private runtime image for paid features.

Roll back

The rollback target is v6.4.0:

sudo /bin/update --version v6.4.0

For Docker Compose, set the Pulse image to the rollback target and recreate the container.

v6.4.1: Pulse v6.4.1

Compare Source

βœ… Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication βœ…
Validated: 2026-08-29 10:36:59 UTC
Workflow: Pulse Release Pipeline #​396

Validation Summary
  • All required assets present βœ“
  • Checksums verified βœ“
  • Version strings correct βœ“
  • Binary architectures validated βœ“
Pulse v6.4.1 Release Notes

v6.4.1 is a stable patch release for the Pulse v6 line. It follows stable
v6.4.0 and restores the embedded container agent while correcting first-load
Proxmox details and several storage, persistence, and AI budget edge cases.

What's improved
  • Container agents start correctly - The embedded Unified Agent is executable in the server image, restoring Helm deployments with agent.enabled=true and direct agent entrypoints.
  • Proxmox details are correct on first load - VM and LXC backup status, uptime, and related guest details no longer appear missing until a later live update arrives.
  • TrueNAS SMART evidence is parsed safely - Spare-block reserve percentages accept supported native TrueNAS representations while malformed, fractional, or out-of-range values are ignored.
  • Credential changes fail safely - Token creation, migration, runtime preparation, and first-run reset restore prior live state when durable persistence fails.
  • AI budgets cover current models - Anthropic Sonnet 5, Fable 5, and Mythos 5 usage remains accurately priced and enforceable in Assistant and Patrol summaries.
Before you upgrade
  • Existing configurations remain valid and no manual data migration is required.
  • Pulse Mobile remains compatible. This patch does not require a companion mobile release.
  • Windows Unified Agent binaries are not Authenticode-signed while SignPath remains unavailable and may show an Unknown Publisher warning. Verify downloads with the published checksums and detached signatures.
  • The rollback target is stable v6.4.0. On systemd and Proxmox LXC installs, use sudo /bin/update --version v6.4.0 to return to the previous stable release. For Docker Compose, pin rcourtman/pulse:6.4.0 and recreate the container.
Install

For systemd and Proxmox LXC installs, use Settings β†’ System β†’ Updates or:

sudo /bin/update --version v6.4.1

For Docker:

docker pull rcourtman/pulse:6.4.1

For Docker Compose, update the image to rcourtman/pulse:6.4.1 and recreate the container.

Pulse Pro and Relay customers should continue using the private download page and private runtime image for paid features.

Roll back

The rollback target is v6.4.0:

sudo /bin/update --version v6.4.0

For Docker Compose, set the Pulse image to the rollback target and recreate the container.

v6.4.0: Pulse v6.4.0

Compare Source

βœ… Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication βœ…
Validated: 2026-08-29 00:41:27 UTC
Workflow: Pulse Release Pipeline #​392

Validation Summary
  • All required assets present βœ“
  • Checksums verified βœ“
  • Version strings correct βœ“
  • Binary architectures validated βœ“

Pulse v6.4.0 Release Notes

v6.4.0 is a stable minor release that makes alerts more trustworthy and actionable, detects capacity and hardware risk earlier, and keeps large or mixed infrastructure estates fast, accurate, and easier to operate.

What's improved

  • Alerts that survive restarts - Active incidents, acknowledgements, snoozes, resolutions, and delivery evidence now rebuild from a durable event log without briefly showing a false all-clear.
  • More control over notifications - Use informational severity, snooze alerts, schedule scoped recurring maintenance, route destinations by severity, repeat critical escalations, and see why delivery was sent, held, suppressed, or failed.
  • Earlier resource warnings - Rolling CPU averages detect sustained pressure instead of reacting to one sample, while predictive storage alerts warn when current growth could exhaust capacity.
  • Stronger disk-health monitoring - Expanded SMART policies cover sector, media, endurance, spare, and CRC risks. TrueNAS evidence stays visible, empty Unraid slots stay neutral, and duplicate Proxmox disks merge.
  • External monitoring for Pulse itself - Pulse can ping a Healthchecks-compatible service every minute, report interruptions after restart, and reject endpoints on the Pulse host that could mask an outage.
  • Faster large estates - Windowed tables and keyed live updates cut the measured Storage cold load from about 15.6 seconds to 1.1 seconds. Docker also avoids re-inspecting unchanged stopped containers every 30 seconds.
  • Clearer desktop and mobile workflows - Consistent tables, drawers, timelines, charts, touch controls, and searchable phone Settings make infrastructure details and alert investigations easier to navigate.
  • More accurate Proxmox and PBS coverage - Node identity, history, networking, backups, RAID members, LXC filesystems, and linked agents now retain the correct source and context, even when installations reuse node names.
  • More reliable agents and actions - Credential changes are atomic, re-enrolment is available from diagnostics, install tokens are easier to copy, and Proxmox VM or LXC actions no longer require a QEMU guest agent.
  • More dependable Patrol runs - Patrol retries provider startup on each schedule, reconciles existing findings when enabled, verifies Docker recovery, and uses current Anthropic model pricing for budget enforcement.
  • Updates that work through rate limits - If GitHub releases are rate limited, Pulse selects the correct release and signed archive for the current Linux architecture so in-app updates can still start.

Before you upgrade

  • Existing configurations remain valid. Alert identity and history migrations run automatically, with no manual data migration required.
  • Pulse Mobile iOS build 12 and Android versionCode 9 remain compatible. The new alert_fired push uses the existing view_alert action, so no companion mobile release is required.
  • Windows Unified Agent binaries are not Authenticode-signed while SignPath remains unavailable and may show an Unknown Publisher warning. Verify downloads with the published checksums and detached signatures.
  • The rollback target is stable v6.3.2. On systemd and Proxmox LXC installs, use sudo /bin/update --version v6.3.2 if you need to return to the previous stable release. For Docker Compose, pin the image to rcourtman/pulse:6.3.2 and recreate the container.

See the difference

Inline table view preferences

Shows how view options now expand below the filter bar without covering the resource table.

Before Now
Inline table view preferences before Inline table view preferences now
Clearer Settings on phones

Highlights the denser touch-friendly layout and persistent navigation context on smaller screens.

Before Now
Clearer Settings on phones before Clearer Settings on phones now

Install

For systemd and Proxmox LXC installs, use Settings β†’ System β†’ Updates or:

sudo /bin/update --version v6.4.0

For Docker:

docker pull rcourtman/pulse:6.4.0

For Docker Compose, update the image to rcourtman/pulse:6.4.0 and recreate the container.

Pulse Pro and Relay customers should continue using the private download page and private runtime image for paid features.

Roll back

The rollback target is v6.3.2.

For systemd and Proxmox LXC installs:

sudo /bin/update --version v6.3.2

For Docker Compose, set the Pulse image to rcourtman/pulse:6.3.2 and recreate the container.

v6.4.0: Pulse v6.4.0

Compare Source

βœ… Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication βœ…
Validated: 2026-08-29 00:41:27 UTC
Workflow: Pulse Release Pipeline #​392

Validation Summary
  • All required assets present βœ“
  • Checksums verified βœ“
  • Version strings correct βœ“
  • Binary architectures validated βœ“
Pulse v6.4.0 Release Notes

v6.4.0 is a stable minor release that makes alerts more trustworthy and actionable, detects capacity and hardware risk earlier, and keeps large or mixed infrastructure estates fast, accurate, and easier to operate.

What's improved
  • Alerts that survive restarts - Active incidents, acknowledgements, snoozes, resolutions, and delivery evidence now rebuild from a durable event log without briefly showing a false all-clear.
  • More control over notifications - Use informational severity, snooze alerts, schedule scoped recurring maintenance, route destinations by severity, repeat critical escalations, and see why delivery was sent, held, suppressed, or failed.
  • Earlier resource warnings - Rolling CPU averages detect sustained pressure instead of reacting to one sample, while predictive storage alerts warn when current growth could exhaust capacity.
  • Stronger disk-health monitoring - Expanded SMART policies cover sector, media, endurance, spare, and CRC risks. TrueNAS evidence stays visible, empty Unraid slots stay neutral, and duplicate Proxmox disks merge.
  • External monitoring for Pulse itself - Pulse can ping a Healthchecks-compatible service every minute, report interruptions after restart, and reject endpoints on the Pulse host that could mask an outage.
  • Faster large estates - Windowed tables and keyed live updates cut the measured Storage cold load from about 15.6 seconds to 1.1 seconds. Docker also avoids re-inspecting unchanged stopped containers every 30 seconds.
  • Clearer desktop and mobile workflows - Consistent tables, drawers, timelines, charts, touch controls, and searchable phone Settings make infrastructure details and alert investigations easier to navigate.
  • More accurate Proxmox and PBS coverage - Node identity, history, networking, backups, RAID members, LXC filesystems, and linked agents now retain the correct source and context, even when installations reuse node names.
  • More reliable agents and actions - Credential changes are atomic, re-enrolment is available from diagnostics, install tokens are easier to copy, and Proxmox VM or LXC actions no longer require a QEMU guest agent.
  • More dependable Patrol runs - Patrol retries provider startup on each schedule, reconciles existing findings when enabled, verifies Docker recovery, and uses current Anthropic model pricing for budget enforcement.
  • Updates that work through rate limits - If GitHub releases are rate limited, Pulse selects the correct release and signed archive for the current Linux architecture so in-app updates can still start.
Before you upgrade
  • Existing configurations remain valid. Alert identity and history migrations run automatically, with no manual data migration required.
  • Pulse Mobile iOS build 12 and Android versionCode 9 remain compatible. The new alert_fired push uses the existing view_alert action, so no companion mobile release is required.
  • Windows Unified Agent binaries are not Authenticode-signed while SignPath remains unavailable and may show an Unknown Publisher warning. Verify downloads with the published checksums and detached signatures.
  • The rollback target is stable v6.3.2. On systemd and Proxmox LXC installs, use sudo /bin/update --version v6.3.2 if you need to return to the previous stable release. For Docker Compose, pin the image to rcourtman/pulse:6.3.2 and recreate the container.
See the difference
Inline table view preferences

Shows how view options now expand below the filter bar without covering the resource table.

Before Now
Inline table view preferences before Inline table view preferences now
Clearer Settings on phones

Highlights the denser touch-friendly layout and persistent navigation context on smaller screens.

Before Now
Clearer Settings on phones before Clearer Settings on phones now
Install

For systemd and Proxmox LXC installs, use Settings β†’ System β†’ Updates or:

sudo /bin/update --version v6.4.0

For Docker:

docker pull rcourtman/pulse:6.4.0

For Docker Compose, update the image to rcourtman/pulse:6.4.0 and recreate the container.

Pulse Pro and Relay customers should continue using the private download page and private runtime image for paid features.

Roll back

The rollback target is v6.3.2.

For systemd and Proxmox LXC installs:

sudo /bin/update --version v6.3.2

For Docker Compose, set the Pulse image to rcourtman/pulse:6.3.2 and recreate the container.

v6.3.2: Pulse v6.3.2

Compare Source

βœ… Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication βœ…
Validated: 2026-08-25 21:51:56 UTC
Workflow: Pulse Release Pipeline #​373

Validation Summary
  • All required assets present βœ“
  • Checksums verified βœ“
  • Version strings correct βœ“
  • Binary architectures validated βœ“

Pulse v6.3.2 Release Notes

v6.3.2 is a stable patch release for the Pulse v6 line. It follows
stable v6.3.1 and corrects memory retention, offline-alert policy handling,
self-container update detection, and fixed polling intervals.

Highlights

  • Metrics history releases oversized backing arrays after dense historical
    data ages out, preventing memory-limit wedges.
  • Disabled offline policies suppress platform connection alerts, including
    per-resource overrides and expected-offline intent.
  • Pulse no longer reports its own container as outdated when the product
    update service says the installation is current.

Fixed

  • Metrics-history retention compacts trimmed windows and sheds seed-sized
    capacity once only a small live window remains
    (fix).
  • Platform connection alerts honor disabled resource and global offline
    policies, expected-offline intent, and offline quiet-hours routing
    (#​1721).
  • Pulse-managed public container references use the product update service and
    no longer create a false self-update badge
    (#​1774).
  • Availability targets keep their configured cadence when adaptive scheduling
    is off rather than being re-armed on every monitor tick
    (#​1745).

Release Qualification

  • The release uses the urgent stable-patch path because metrics-history memory
    growth can wedge Pulse under container memory limits and disabled offline
    policies can still generate alert noise on stable.
  • The exact pushed release SHA must pass the governed single-build release
    pipeline and its integrated exact-SHA candidate checks before publication.
  • Windows Unified Agent binaries are not Authenticode-signed for v6.3.2 and
    may display an Unknown Publisher warning. The standing SignPath-unavailable
    policy changes only Authenticode: exact-SHA candidate binding, checksums,
    detached signatures, immutable-manifest verification, and published-digest
    verification remain mandatory.
  • No mobile-facing path changed between v6.3.1 and this release, so the
    mobile decision is no-mobile-impact; no companion build or store rollout
    is required.

Upgrade Notes

Use the normal v6 install or update flow for v6.3.2. Existing configurations
remain valid and no manual data migration is required.

The rollback target is v6.3.1. The exact rollback reinstall command is:

./scripts/install.sh --version v6.3.1

Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.

Installation

Docker (recommended):

docker pull rcourtman/pulse:6.3.2

Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.2

See the Installation Guide for complete setup instructions.

Review the Code signing policy for release provenance, approval roles, and signing scope.

Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.

Promotion Metadata

  • Promotion channel: stable
  • Candidate stable tag: v6.3.2
  • Promoted prerelease tag: n/a
  • Rollback target: v6.3.1
  • Rollback command: ./scripts/install.sh --version v6.3.1
  • Hotfix exception: true
  • Hotfix reason: Metrics-history memory growth can wedge Pulse under memory limits, and disabled offline policies generate alert noise on stable.
  • Windows Authenticode required: false
  • Unsigned Windows exception: true
  • Unsigned Windows reason: SignPath production credentials and certificate authorization are unavailable; the release owner approved unsigned Windows Unified Agent artifacts until availability is explicitly restored.

v6.3.2: Pulse v6.3.2

Compare Source

βœ… Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication βœ…
Validated: 2026-08-25 21:51:56 UTC
Workflow: Pulse Release Pipeline #​373

Validation Summary
  • All required assets present βœ“
  • Checksums verified βœ“
  • Version strings correct βœ“
  • Binary architectures validated βœ“
Pulse v6.3.2 Release Notes

v6.3.2 is a stable patch release for the Pulse v6 line. It follows
stable v6.3.1 and corrects memory retention, offline-alert policy handling,
self-container update detection, and fixed polling intervals.

Highlights
  • Metrics history releases oversized backing arrays after dense historical
    data ages out, preventing memory-limit wedges.
  • Disabled offline policies suppress platform connection alerts, including
    per-resource overrides and expected-offline intent.
  • Pulse no longer reports its own container as outdated when the product
    update service says the installation is current.
Fixed
  • Metrics-history retention compacts trimmed windows and sheds seed-sized
    capacity once only a small live window remains
    (fix).
  • Platform connection alerts honor disabled resource and global offline
    policies, expected-offline intent, and offline quiet-hours routing
    (#​1721).
  • Pulse-managed public container references use the product update service and
    no longer create a false self-update badge
    (#​1774).
  • Availability targets keep their configured cadence when adaptive scheduling
    is off rather than being re-armed on every monitor tick
    (#​1745).
Release Qualification
  • The release uses the urgent stable-patch path because metrics-history memory
    growth can wedge Pulse under container memory limits and disabled offline
    policies can still generate alert noise on stable.
  • The exact pushed release SHA must pass the governed single-build release
    pipeline and its integrated exact-SHA candidate checks before publication.
  • Windows Unified Agent binaries are not Authenticode-signed for v6.3.2 and
    may display an Unknown Publisher warning. The standing SignPath-unavailable
    policy changes only Authenticode: exact-SHA candidate binding, checksums,
    detached signatures, immutable-manifest verification, and published-digest
    verification remain mandatory.
  • No mobile-facing path changed between v6.3.1 and this release, so the
    mobile decision is no-mobile-impact; no companion build or store rollout
    is required.
Upgrade Notes

Use the normal v6 install or update flow for v6.3.2. Existing configurations
remain valid and no manual data migration is required.

The rollback target is v6.3.1. The exact rollback reinstall command is:

./scripts/install.sh --version v6.3.1

Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.

Installation

Docker (recommended):

docker pull rcourtman/pulse:6.3.2

Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.2

See the Installation Guide for complete setup instructions.

Review the Code signing policy for release provenance, approval roles, and signing scope.

Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.

Promotion Metadata
  • Promotion channel: stable
  • Candidate stable tag: v6.3.2
  • Promoted prerelease tag: n/a
  • Rollback target: v6.3.1
  • Rollback command: ./scripts/install.sh --version v6.3.1
  • Hotfix exception: true
  • Hotfix reason: Metrics-history memory growth can wedge Pulse under memory limits, and disabled offline policies generate alert noise on stable.
  • Windows Authenticode required: false
  • Unsigned Windows exception: true
  • Unsigned Windows reason: SignPath production credentials and certificate authorization are unavailable; the release owner approved unsigned Windows Unified Agent artifacts until availability is explicitly restored.

v6.3.1: Pulse v6.3.1

Compare Source

βœ… Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication βœ…
Validated: 2026-08-23 12:54:50 UTC
Workflow: Pulse Release Pipeline #​370

Validation Summary
  • All required assets present βœ“
  • Checksums verified βœ“
  • Version strings correct βœ“
  • Binary architectures validated βœ“

Pulse v6.3.1 Release Notes

v6.3.1 is a stable patch release for the Pulse v6 line. It follows stable
v6.3.0 and contains focused corrections for alert delivery, Unified Agent
control, local subscription providers, and Docker monitoring overhead.

Highlights

  • Recover or dismiss terminal notification failures without losing delivery
    history, while disabled PBS offline alerts remain silent.
  • Docker commands recover safely after token rotation, and Synology hosts avoid
    repeated full-daemon storage scans on every report.
  • Local subscription providers now resolve and diagnose their CLIs as the
    actual Pulse service account.

Improved

  • Notification delivery history now exposes confirmed retry and dismiss
    operations for terminal failures. Retried items receive a fresh bounded
    attempt budget while their prior audit history remains available.
  • Refused governed actions record the resource, capability, stable refusal
    code, and the specific Docker command-agent lookup that missed.
  • Standard systemd installs give the Pulse service account a private CLI home
    and a deterministic executable search path. Explicit provider CLI path
    overrides remain available for non-standard layouts.
  • Docker host storage totals are refreshed on a bounded 15-minute cadence and
    retain the last good aggregate when a refresh fails. Live host and container
    metrics continue on the configured reporting interval.

Fixed

  • Disabled PBS offline alerts no longer enter the notification dispatch path;
    enabled alerts and recovery notifications retain their existing lifecycle.
  • Docker start, stop, restart, remove, and update commands recover after an
    agent reporting-token rotation by proving the exact tenant, agent ID, and
    canonical hostname rather than weakening identity matching.
  • Docker update preflight once again routes through the Unified Agent, and
    terminal digest-drift refusals no longer strand later update attempts.
  • Local subscription setup failures now distinguish a CLI that is missing or
    not logged in for the Pulse service account from provider network
    reachability failures.
  • Synology DSM Docker monitoring no longer launches a verbose daemon-wide disk
    usage inventory every 30 seconds or immediately retries a slow failed scan.

Release Qualification

  • The release uses the emergency stable-patch path because the fixes address
    active customer harm across alert delivery, infrastructure control, local AI
    setup, and Docker host load without introducing a same-version RC.
  • The exact pushed release SHA must pass the no-publication Release Dry Run and
    its integrated exact-SHA candidate checks before that same SHA is submitted
    to the single-build publication workflow.
  • The release owner approved a v6.3.1-only exception because SignPath's
    production certificate remains CSR pending. Windows Unified Agent binaries
    are not Authenticode-signed and may display an Unknown Publisher warning;
    exact-SHA checksums, detached signatures, immutable-manifest verification,
    and published-digest verification remain mandatory.
  • No mobile-facing path changed between v6.3.0 and this release, so the mobile
    decision is no-mobile-impact; no companion build or store rollout is
    required.

Upgrade Notes

Use the normal v6 install or update flow for v6.3.1. Existing configurations
remain valid and no manual data migration is required.

The rollback target is v6.3.0. The exact rollback reinstall command is:

./scripts/install.sh --version v6.3.0

Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.

Installation

Docker (recommended):

docker pull rcourtman/pulse:6.3.1

Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.1

See the Installation Guide for complete setup instructions.

Review the Code signing policy for release provenance, approval roles, and signing scope.

Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.

Promotion Metadata

  • Promotion channel: stable
  • Candidate stable tag: v6.3.1
  • Promoted prerelease tag: n/a
  • Rollback target: v6.3.0
  • Rollback command: ./scripts/install.sh --version v6.3.0
  • Hotfix exception: true
  • Hotfix reason: Active customer harm across notification delivery recovery, Docker command continuity, local subscription setup, and Synology Docker host load.
  • Windows Authenticode required: false
  • Unsigned Windows exception: true
  • Unsigned Windows reason: SignPath production certificate remains CSR PENDING and the release-signing policy is invalid; the release owner accepts unsigned Windows Unified Agent artifacts for v6.3.1 with public Unknown Publisher disclosure and unchanged exact-SHA integrity controls.

v6.3.1: Pulse v6.3.1

Compare Source

βœ… Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication βœ…
Validated: 2026-08-23 12:54:50 UTC
Workflow: Pulse Release Pipeline #​370

Validation Summary
  • All required assets present βœ“
  • Checksums verified βœ“
  • Version strings correct βœ“
  • Binary architectures validated βœ“
Pulse v6.3.1 Release Notes

v6.3.1 is a stable patch release for the Pulse v6 line. It follows stable
v6.3.0 and contains focused corrections for alert delivery, Unified Agent
control, local subscription providers, and Docker monitoring overhead.

Highlights
  • Recover or dismiss terminal notification failures without losing delivery
    history, while disabled PBS offline alerts remain silent.
  • Docker commands recover safely after token rotation, and Synology hosts avoid
    repeated full-daemon storage scans on every report.
  • Local subscription providers now resolve and diagnose their CLIs as the
    actual Pulse service account.
Improved
  • Notification delivery history now exposes confirmed retry and dismiss
    operations for terminal failures. Retried items receive a fresh bounded
    attempt budget while their prior audit history remains available.
  • Refused governed actions record the resource, capability, stable refusal
    code, and the specific Docker command-agent lookup that missed.
  • Standard systemd installs give the Pulse service account a private CLI home
    and a deterministic executable search path. Explicit provider CLI path
    overrides remain available for non-standard layouts.
  • Docker host storage totals are refreshed on a bounded 15-minute cadence and
    retain the last good aggregate when a refresh fails. Live host and container
    metrics continue on the configured reporting interval.
Fixed
  • Disabled PBS offline alerts no longer enter the notification dispatch path;
    enabled alerts and recovery notifications retain their existing lifecycle.
  • Docker start, stop, restart, remove, and update commands recover after an
    agent reporting-token rotation by proving the exact tenant, agent ID, and
    canonical hostname rather than weakening identity matching.
  • Docker update preflight once again routes through the Unified Agent, and
    terminal digest-drift refusals no longer strand later update attempts.
  • Local subscription setup failures now distinguish a CLI that is missing or
    not logged in for the Pulse service account from provider network
    reachability failures.
  • Synology DSM Docker monitoring no longer launches a verbose daemon-wide disk
    usage inventory every 30 seconds or immediately retries a slow failed scan.
Release Qualification
  • The release uses the emergency stable-patch path because the fixes address
    active customer harm across alert delivery, infrastructure control, local AI
    setup, and Docker host load without introducing a same-version RC.
  • The exact pushed release SHA must pass the no-publication Release Dry Run and
    its integrated exact-SHA candidate checks before that same SHA is submitted
    to the single-build publication workflow.
  • The release owner approved a v6.3.1-only exception because SignPath's
    production certificate remains CSR pending. Windows Unified Agent binaries
    are not Authenticode-signed and may display an Unknown Publisher warning;
    exact-SHA checksums, detached signatures, immutable-manifest verification,
    and published-digest verification remain mandatory.
  • No mobile-facing path changed between v6.3.0 and this release, so the mobile
    decision is no-mobile-impact; no companion build or store rollout is
    required.
Upgrade Notes

Use the normal v6 install or update flow for v6.3.1. Existing configurations
remain valid and no manual data migration is required.

The rollback target is v6.3.0. The exact rollback reinstall command is:

./scripts/install.sh --version v6.3.0

Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.

Installation

Docker (recommended):

docker pull rcourtman/pulse:6.3.1

Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.1

See the Installation Guide for complete setup instructions.

Review the Code signing policy for release provenance, approval roles, and signing scope.

Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.

Promotion Metadata
  • Promotion channel: stable
  • Candidate stable tag: v6.3.1
  • Promoted prerelease tag: n/a
  • Rollback target: v6.3.0
  • Rollback command: ./scripts/install.sh --version v6.3.0
  • Hotfix exception: true
  • Hotfix reason: Active customer harm across notification delivery recovery, Docker command continuity, local subscription setup, and Synology Docker host load.
  • Windows Authenticode required: false
  • Unsigned Windows exception: true
  • Unsigned Windows reason: SignPath production certificate remains CSR PENDING and the release-signing policy is invalid; the release owner accepts unsigned Windows Unified Agent artifacts for v6.3.1 with public Unknown Publisher disclosure and unchanged exact-SHA integrity controls.

v6.3.0: Pulse v6.3.0

Compare Source

βœ… Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication βœ…
Validated: 2026-08-22 11:04:47 UTC
Workflow: Pulse Release Pipeline #​369

Validation Summary
  • All required assets present βœ“
  • Checksums verified βœ“
  • Version strings correct βœ“
  • Binary architectures validated βœ“

Pulse v6.3.0 Release Notes

v6.3.0 is a stable minor release for the Pulse v6 line. It follows stable
v6.2.1 and promotes the monitoring-first operations work exercised across
the v6.3.0-rc.1 through v6.3.0-rc.6 line, plus the bounded fixes included
in the final stable cutoff.

Highlights

  • Patrol adds durable objectives and verified work receipts; Actions provides
    a dedicated inbox for governed approvals and execution.
  • Estate-first pages add canonical search, status facets, relationships,
    timelines, and Operational Trust signals across mixed infrastructure.
  • Safer Unified Agent operation, clearer delivery evidence, and a fail-closed
    release pipeline strengthen monitoring and controlled action.

Added

  • Durable scoped Patrol objectives, validated read-only observer missions, and
    content-free telemetry for operational outcomes.
  • A first-class Actions workspace for approval requests, governed plans,
    execution records, audit evidence, and verification state.
  • Typed Unified Agent action preflight for supported host and Docker
    operations, with stable refusal codes for stale plans, changed targets,
    missing prerequisites, policy decisions, and unavailable capabilities.
  • Canonical estate summaries, status facets, shared platform search, resource
    relationship views, and resource-change timelines.
  • A seven-day activity log for real notification delivery attempts and a
    supported least-privilege Unified Agent installation profile.

Improved

  • Patrol surfaces provider-unavailable state directly and clears stale blocked
    findings when a configured provider becomes available again.
  • Resource presentation keeps same-short-name hosts from separate estates
    distinct instead of collapsing them into one row.
  • Per-resource severity overrides can re-enable an offline alert even when the
    corresponding global threshold is disabled.
  • Subscription-backed turns bound canceled command cleanup so descendant-held
    output pipes cannot extend the caller-owned idle timeout.
  • Docker-in-LXC discovery backs off against slow or failing Proxmox hosts, and
    Unified Agent observers remain report-only with destination-scoped trust.
  • Release compilation, backend admission, container qualification, public and
    private staging, and post-publication convergence make fuller use of the
    dedicated PVE capacity without moving customer pointers before exact-SHA
    readiness.

Fixed

  • Release dry-run diagnostics now fail closed when the diagnostic runner or
    stable-tier test path fails, while preserving actionable artifacts.
  • Native-agent fixtures are path-portable on Windows, and pre-commit Go linting
    follows the repository toolchain declared by go.mod.
  • Release qualification retains the resource controls required by the release
    asset builder and rejects insufficient measured worker headroom before
    backend shard execution starts.
  • Activation recovery, Helm convergence, private-license checks, and paid
    runtime proof continue to join the canonical release result rather than
    relying on duplicate or moving state.

Release Qualification

  • The v6 control plane reports all 44 readiness assertions and all 26 release
    gates passed, with release_ready=True at the stable cutoff.
  • Production telemetry on 2026-08-22 showed 18 active v6.3.0-rc.6 installs
    across binary and Docker, 56 recorded update successes, zero update
    failures, zero rollback or version-departure signals, and no new notification
    or governed-action failure counters on follow-up heartbeats.
  • The preceding v6.3.0-rc.5 cohort likewise showed no rollback signal; one
    install advanced to v6.3.0-rc.6, and its single rolling-window update
    failure was already present on the first heartbeat rather than increasing on
    the candidate.
  • The release owner explicitly accepted the shortened rc.6 soak and the
    bounded post-RC cutoff for v6.3.0. This is version-bound risk acceptance,
    not 72-hour soak evidence.
  • The exact pushed stable SHA must pass the no-publication Release Dry Run
    before the same SHA enters the single-build publication workflow.
  • Windows Unified Agent binaries are not Authenticode-signed for v6.3.0 and
    may display an Unknown Publisher warning. The release owner approved this
    version-bound exception because Windows signing is not yet available.
  • The unsigned-Windows exception changes only Authenticode. Exact-SHA builds,
    SHA-256 checksums, detached signatures, the immutable candidate manifest,
    and published-digest verification remain required.

Upgrade Notes

Use the normal v6 install or update flow for v6.3.0. Existing configurations
remain valid and no manual data migration is required.

The rollback target is v6.2.1. The exact rollback reinstall command is:

./scripts/install.sh --version v6.2.1

This server release is compatible with the existing Pulse Mobile candidate.
The changes since v6.3.0-rc.6 preserve the checked-in mobile API, Relay,
pairing, approval, push, authentication, and onboarding contracts. No companion
upload or public mobile-store rollout is part of this server release.

Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.
Unproved self-service commercial plan or billing-cadence transitions remain
disabled and are not introduced by this release.

Installation

Docker (recommended):

docker pull rcourtman/pulse:6.3.0

Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.0

See the Installation Guide for complete setup instructions.

Review the Code signing policy for release provenance, approval roles, and signing scope.

Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.

Promotion Metadata

  • Promotion channel: stable
  • Candidate stable tag: v6.3.0
  • Promoted prerelease tag: v6.3.0-rc.6
  • Rollback target: v6.2.1
  • Rollback command: ./scripts/install.sh --version v6.2.1
  • Hotfix exception: true
  • Hotfix reason: Release owner approved the v6.3.0 cutoff after clean privacy-safe production telemetry from rc.5 and rc.6 and accepted the shortened rc.6 soak and bounded post-RC changes.
  • Windows Authenticode required: false
  • Unsigned Windows exception: true
  • Unsigned Windows reason: Windows Authenticode signing is not yet available; the release owner accepts unsigned Windows Unified Agent artifacts for v6.3.0 with public disclosure and unchanged exact-SHA integrity controls.

v6.3.0: Pulse v6.3.0

Compare Source

βœ… Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication βœ…
Validated: 2026-08-22 11:04:47 UTC
Workflow: Pulse Release Pipeline #​369

Validation Summary
  • All required assets present βœ“
  • Checksums verified βœ“
  • Version strings correct βœ“
  • Binary architectures validated βœ“
Pulse v6.3.0 Release Notes

v6.3.0 is a stable minor release for the Pulse v6 line. It follows stable
v6.2.1 and promotes the monitoring-first operations work exercised across
the v6.3.0-rc.1 through v6.3.0-rc.6 line, plus the bounded fixes included
in the final stable cutoff.

Highlights
  • Patrol adds durable objectives and verified work receipts; Actions provides
    a dedicated inbox for governed approvals and execution.
  • Estate-first pages add canonical search, status facets, relationships,
    timelines, and Operational Trust signals across mixed infrastructure.
  • Safer Unified Agent operation, clearer delivery evidence, and a fail-closed
    release pipeline strengthen monitoring and controlled action.
Added
  • Durable scoped Patrol objectives, validated read-only observer missions, and
    content-free telemetry for operational outcomes.
  • A first-class Actions workspace for approval requests, governed plans,
    execution records, audit evidence, and verification state.
  • Typed Unified Agent action preflight for supported host and Docker
    operations, with stable refusal codes for stale plans, changed targets,
    missing prerequisites, policy decisions, and unavailable capabilities.
  • Canonical estate summaries, status facets, shared platform search, resource
    relationship views, and resource-change timelines.
  • A seven-day activity log for real notification delivery attempts and a
    supported least-privilege Unified Agent installation profile.
Improved
  • Patrol surfaces provider-unavailable state directly and clears stale blocked
    findings when a configured provider becomes available again.
  • Resource presentation keeps same-short-name hosts from separate estates
    distinct instead of collapsing them into one row.
  • Per-resource severity overrides can re-enable an offline alert even when the
    corresponding global threshold is disabled.
  • Subscription-backed turns bound canceled command cleanup so descendant-held
    output pipes cannot extend the caller-owned idle timeout.
  • Docker-in-LXC discovery backs off against slow or failing Proxmox hosts, and
    Unified Agent observers remain report-only with destination-scoped trust.
  • Release compilation, backend admission, container qualification, public and
    private staging, and post-publication convergence make fuller use of the
    dedicated PVE capacity without moving customer pointers before exact-SHA
    readiness.
Fixed
  • Release dry-run diagnostics now fail closed when the diagnostic runner or
    stable-tier test path fails, while preserving actionable artifacts.
  • Native-agent fixtures are path-portable on Windows, and pre-commit Go linting
    follows the repository toolchain declared by go.mod.
  • Release qualification retains the resource controls required by the release
    asset builder and rejects insufficient measured worker headroom before
    backend shard execution starts.
  • Activation recovery, Helm convergence, private-license checks, and paid
    runtime proof continue to join the canonical release result rather than
    relying on duplicate or moving state.
Release Qualification
  • The v6 control plane reports all 44 readiness assertions and all 26 release
    gates passed, with release_ready=True at the stable cutoff.
  • Production telemetry on 2026-08-22 showed 18 active v6.3.0-rc.6 installs
    across binary and Docker, 56 recorded update successes, zero update
    failures, zero rollback or version-departure signals, and no new notification
    or governed-action failure counters on follow-up heartbeats.
  • The preceding v6.3.0-rc.5 cohort likewise showed no rollback signal; one
    install advanced to v6.3.0-rc.6, and its single rolling-window update
    failure was already present on the first heartbeat rather than increasing on
    the candidate.
  • The release owner explicitly accepted the shortened rc.6 soak and the
    bounded post-RC cutoff for v6.3.0. This is version-bound risk acceptance,
    not 72-hour soak evidence.
  • The exact pushed stable SHA must pass the no-publication Release Dry Run
    before the same SHA enters the single-build publication workflow.
  • Windows Unified Agent binaries are not Authenticode-signed for v6.3.0 and
    may display an Unknown Publisher warning. The release owner approved this
    version-bound exception because Windows signing is not yet available.
  • The unsigned-Windows exception changes only Authenticode. Exact-SHA builds,
    SHA-256 checksums, detached signatures, the immutable candidate manifest,
    and published-digest verification remain required.
Upgrade Notes

Use the normal v6 install or update flow for v6.3.0. Existing configurations
remain valid and no manual data migration is required.

The rollback target is v6.2.1. The exact rollback reinstall command is:

./scripts/install.sh --version v6.2.1

This server release is compatible with the existing Pulse Mobile candidate.
The changes since v6.3.0-rc.6 preserve the checked-in mobile API, Relay,
pairing, approval, push, authentication, and onboarding contracts. No companion
upload or public mobile-store rollout is part of this server release.

Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.
Unproved self-service commercial plan or billing-cadence transitions remain
disabled and are not introduced by this release.

Installation

Docker (recommended):

docker pull rcourtman/pulse:6.3.0

Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.0

See the Installation Guide for complete setup instructions.

Review the Code signing policy for release provenance, approval roles, and signing scope.

Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.

Promotion Metadata
  • Promotion channel: stable
  • Candidate stable tag: v6.3.0
  • Promoted prerelease tag: v6.3.0-rc.6
  • Rollback target: v6.2.1
  • Rollback command: ./scripts/install.sh --version v6.2.1
  • Hotfix exception: true
  • Hotfix reason: Release owner approved the v6.3.0 cutoff after clean privacy-safe production telemetry from rc.5 and rc.6 and accepted the shortened rc.6 soak and bounded post-RC changes.
  • Windows Authenticode required: false
  • Unsigned Windows exception: true
  • Unsigned Windows reason: Windows Authenticode signing is not yet available; the release owner accepts unsigned Windows Unified Agent artifacts for v6.3.0 with public disclosure and unchanged exact-SHA integrity controls.

Read more

Me on Mastodon - This link is here for verification purposes.