Update docker.io/rcourtman/pulse Docker tag to v6.4.2
No problems upgrading the Docker container with a Docker compose yaml file by means of Watchtower DevOps resp. GitOps with dependency update facilitated by Mend's Renovate Bot.
Including updating all docker and host agents manually.
This MR contains the following updates:
| Package | Update | Change |
|---|---|---|
| docker.io/rcourtman/pulse | minor | 6.2.1 β 6.4.2 |
Release Notes
rcourtman/Pulse (docker.io/rcourtman/pulse)
v6.4.2
v6.4.2
v6.4.1: Pulse v6.4.1
β Release Asset Validation: PASSED
All release assets have been validated successfully!
Status: Ready for publication β
Validated: 2026-08-29 10:36:59 UTC
Workflow: Pulse Release Pipeline #β396
Validation Summary
- All required assets present β
- Checksums verified β
- Version strings correct β
- Binary architectures validated β
Pulse v6.4.1 Release Notes
v6.4.1 is a stable patch release for the Pulse v6 line. It follows stable
v6.4.0 and restores the embedded container agent while correcting first-load
Proxmox details and several storage, persistence, and AI budget edge cases.
What's improved
- Container agents start correctly - The embedded Unified Agent is executable in the server image, restoring Helm deployments with
agent.enabled=trueand direct agent entrypoints. - Proxmox details are correct on first load - VM and LXC backup status, uptime, and related guest details no longer appear missing until a later live update arrives.
- TrueNAS SMART evidence is parsed safely - Spare-block reserve percentages accept supported native TrueNAS representations while malformed, fractional, or out-of-range values are ignored.
- Credential changes fail safely - Token creation, migration, runtime preparation, and first-run reset restore prior live state when durable persistence fails.
- AI budgets cover current models - Anthropic Sonnet 5, Fable 5, and Mythos 5 usage remains accurately priced and enforceable in Assistant and Patrol summaries.
Before you upgrade
- Existing configurations remain valid and no manual data migration is required.
- Pulse Mobile remains compatible. This patch does not require a companion mobile release.
- Windows Unified Agent binaries are not Authenticode-signed while SignPath remains unavailable and may show an Unknown Publisher warning. Verify downloads with the published checksums and detached signatures.
- The rollback target is stable
v6.4.0. On systemd and Proxmox LXC installs, usesudo /bin/update --version v6.4.0to return to the previous stable release. For Docker Compose, pinrcourtman/pulse:6.4.0and recreate the container.
Install
For systemd and Proxmox LXC installs, use Settings β System β Updates or:
sudo /bin/update --version v6.4.1
For Docker:
docker pull rcourtman/pulse:6.4.1
For Docker Compose, update the image to rcourtman/pulse:6.4.1 and recreate the container.
Pulse Pro and Relay customers should continue using the private download page and private runtime image for paid features.
Roll back
The rollback target is v6.4.0:
sudo /bin/update --version v6.4.0
For Docker Compose, set the Pulse image to the rollback target and recreate the container.
v6.4.1: Pulse v6.4.1
β Release Asset Validation: PASSED
All release assets have been validated successfully!
Status: Ready for publication β
Validated: 2026-08-29 10:36:59 UTC
Workflow: Pulse Release Pipeline #β396
Validation Summary
- All required assets present β
- Checksums verified β
- Version strings correct β
- Binary architectures validated β
Pulse v6.4.1 Release Notes
v6.4.1 is a stable patch release for the Pulse v6 line. It follows stable
v6.4.0 and restores the embedded container agent while correcting first-load
Proxmox details and several storage, persistence, and AI budget edge cases.
What's improved
- Container agents start correctly - The embedded Unified Agent is executable in the server image, restoring Helm deployments with
agent.enabled=trueand direct agent entrypoints. - Proxmox details are correct on first load - VM and LXC backup status, uptime, and related guest details no longer appear missing until a later live update arrives.
- TrueNAS SMART evidence is parsed safely - Spare-block reserve percentages accept supported native TrueNAS representations while malformed, fractional, or out-of-range values are ignored.
- Credential changes fail safely - Token creation, migration, runtime preparation, and first-run reset restore prior live state when durable persistence fails.
- AI budgets cover current models - Anthropic Sonnet 5, Fable 5, and Mythos 5 usage remains accurately priced and enforceable in Assistant and Patrol summaries.
Before you upgrade
- Existing configurations remain valid and no manual data migration is required.
- Pulse Mobile remains compatible. This patch does not require a companion mobile release.
- Windows Unified Agent binaries are not Authenticode-signed while SignPath remains unavailable and may show an Unknown Publisher warning. Verify downloads with the published checksums and detached signatures.
- The rollback target is stable
v6.4.0. On systemd and Proxmox LXC installs, usesudo /bin/update --version v6.4.0to return to the previous stable release. For Docker Compose, pinrcourtman/pulse:6.4.0and recreate the container.
Install
For systemd and Proxmox LXC installs, use Settings β System β Updates or:
sudo /bin/update --version v6.4.1
For Docker:
docker pull rcourtman/pulse:6.4.1
For Docker Compose, update the image to rcourtman/pulse:6.4.1 and recreate the container.
Pulse Pro and Relay customers should continue using the private download page and private runtime image for paid features.
Roll back
The rollback target is v6.4.0:
sudo /bin/update --version v6.4.0
For Docker Compose, set the Pulse image to the rollback target and recreate the container.
v6.4.0: Pulse v6.4.0
β Release Asset Validation: PASSED
All release assets have been validated successfully!
Status: Ready for publication β
Validated: 2026-08-29 00:41:27 UTC
Workflow: Pulse Release Pipeline #β392
Validation Summary
- All required assets present β
- Checksums verified β
- Version strings correct β
- Binary architectures validated β
Pulse v6.4.0 Release Notes
v6.4.0 is a stable minor release that makes alerts more trustworthy and actionable, detects capacity and hardware risk earlier, and keeps large or mixed infrastructure estates fast, accurate, and easier to operate.
What's improved
- Alerts that survive restarts - Active incidents, acknowledgements, snoozes, resolutions, and delivery evidence now rebuild from a durable event log without briefly showing a false all-clear.
- More control over notifications - Use informational severity, snooze alerts, schedule scoped recurring maintenance, route destinations by severity, repeat critical escalations, and see why delivery was sent, held, suppressed, or failed.
- Earlier resource warnings - Rolling CPU averages detect sustained pressure instead of reacting to one sample, while predictive storage alerts warn when current growth could exhaust capacity.
- Stronger disk-health monitoring - Expanded SMART policies cover sector, media, endurance, spare, and CRC risks. TrueNAS evidence stays visible, empty Unraid slots stay neutral, and duplicate Proxmox disks merge.
- External monitoring for Pulse itself - Pulse can ping a Healthchecks-compatible service every minute, report interruptions after restart, and reject endpoints on the Pulse host that could mask an outage.
- Faster large estates - Windowed tables and keyed live updates cut the measured Storage cold load from about 15.6 seconds to 1.1 seconds. Docker also avoids re-inspecting unchanged stopped containers every 30 seconds.
- Clearer desktop and mobile workflows - Consistent tables, drawers, timelines, charts, touch controls, and searchable phone Settings make infrastructure details and alert investigations easier to navigate.
- More accurate Proxmox and PBS coverage - Node identity, history, networking, backups, RAID members, LXC filesystems, and linked agents now retain the correct source and context, even when installations reuse node names.
- More reliable agents and actions - Credential changes are atomic, re-enrolment is available from diagnostics, install tokens are easier to copy, and Proxmox VM or LXC actions no longer require a QEMU guest agent.
- More dependable Patrol runs - Patrol retries provider startup on each schedule, reconciles existing findings when enabled, verifies Docker recovery, and uses current Anthropic model pricing for budget enforcement.
- Updates that work through rate limits - If GitHub releases are rate limited, Pulse selects the correct release and signed archive for the current Linux architecture so in-app updates can still start.
Before you upgrade
- Existing configurations remain valid. Alert identity and history migrations run automatically, with no manual data migration required.
- Pulse Mobile iOS build 12 and Android versionCode 9 remain compatible. The new
alert_firedpush uses the existingview_alertaction, so no companion mobile release is required. - Windows Unified Agent binaries are not Authenticode-signed while SignPath remains unavailable and may show an Unknown Publisher warning. Verify downloads with the published checksums and detached signatures.
- The rollback target is stable
v6.3.2. On systemd and Proxmox LXC installs, usesudo /bin/update --version v6.3.2if you need to return to the previous stable release. For Docker Compose, pin the image torcourtman/pulse:6.3.2and recreate the container.
See the difference
Inline table view preferences
Shows how view options now expand below the filter bar without covering the resource table.
| Before | Now |
|---|---|
![]() |
![]() |
Clearer Settings on phones
Highlights the denser touch-friendly layout and persistent navigation context on smaller screens.
| Before | Now |
|---|---|
![]() |
![]() |
Install
For systemd and Proxmox LXC installs, use Settings β System β Updates or:
sudo /bin/update --version v6.4.0
For Docker:
docker pull rcourtman/pulse:6.4.0
For Docker Compose, update the image to rcourtman/pulse:6.4.0 and recreate the container.
Pulse Pro and Relay customers should continue using the private download page and private runtime image for paid features.
Roll back
The rollback target is v6.3.2.
For systemd and Proxmox LXC installs:
sudo /bin/update --version v6.3.2
For Docker Compose, set the Pulse image to rcourtman/pulse:6.3.2 and recreate the container.
v6.4.0: Pulse v6.4.0
β Release Asset Validation: PASSED
All release assets have been validated successfully!
Status: Ready for publication β
Validated: 2026-08-29 00:41:27 UTC
Workflow: Pulse Release Pipeline #β392
Validation Summary
- All required assets present β
- Checksums verified β
- Version strings correct β
- Binary architectures validated β
Pulse v6.4.0 Release Notes
v6.4.0 is a stable minor release that makes alerts more trustworthy and actionable, detects capacity and hardware risk earlier, and keeps large or mixed infrastructure estates fast, accurate, and easier to operate.
What's improved
- Alerts that survive restarts - Active incidents, acknowledgements, snoozes, resolutions, and delivery evidence now rebuild from a durable event log without briefly showing a false all-clear.
- More control over notifications - Use informational severity, snooze alerts, schedule scoped recurring maintenance, route destinations by severity, repeat critical escalations, and see why delivery was sent, held, suppressed, or failed.
- Earlier resource warnings - Rolling CPU averages detect sustained pressure instead of reacting to one sample, while predictive storage alerts warn when current growth could exhaust capacity.
- Stronger disk-health monitoring - Expanded SMART policies cover sector, media, endurance, spare, and CRC risks. TrueNAS evidence stays visible, empty Unraid slots stay neutral, and duplicate Proxmox disks merge.
- External monitoring for Pulse itself - Pulse can ping a Healthchecks-compatible service every minute, report interruptions after restart, and reject endpoints on the Pulse host that could mask an outage.
- Faster large estates - Windowed tables and keyed live updates cut the measured Storage cold load from about 15.6 seconds to 1.1 seconds. Docker also avoids re-inspecting unchanged stopped containers every 30 seconds.
- Clearer desktop and mobile workflows - Consistent tables, drawers, timelines, charts, touch controls, and searchable phone Settings make infrastructure details and alert investigations easier to navigate.
- More accurate Proxmox and PBS coverage - Node identity, history, networking, backups, RAID members, LXC filesystems, and linked agents now retain the correct source and context, even when installations reuse node names.
- More reliable agents and actions - Credential changes are atomic, re-enrolment is available from diagnostics, install tokens are easier to copy, and Proxmox VM or LXC actions no longer require a QEMU guest agent.
- More dependable Patrol runs - Patrol retries provider startup on each schedule, reconciles existing findings when enabled, verifies Docker recovery, and uses current Anthropic model pricing for budget enforcement.
- Updates that work through rate limits - If GitHub releases are rate limited, Pulse selects the correct release and signed archive for the current Linux architecture so in-app updates can still start.
Before you upgrade
- Existing configurations remain valid. Alert identity and history migrations run automatically, with no manual data migration required.
- Pulse Mobile iOS build 12 and Android versionCode 9 remain compatible. The new
alert_firedpush uses the existingview_alertaction, so no companion mobile release is required. - Windows Unified Agent binaries are not Authenticode-signed while SignPath remains unavailable and may show an Unknown Publisher warning. Verify downloads with the published checksums and detached signatures.
- The rollback target is stable
v6.3.2. On systemd and Proxmox LXC installs, usesudo /bin/update --version v6.3.2if you need to return to the previous stable release. For Docker Compose, pin the image torcourtman/pulse:6.3.2and recreate the container.
See the difference
Inline table view preferences
Shows how view options now expand below the filter bar without covering the resource table.
| Before | Now |
|---|---|
![]() |
![]() |
Clearer Settings on phones
Highlights the denser touch-friendly layout and persistent navigation context on smaller screens.
| Before | Now |
|---|---|
![]() |
![]() |
Install
For systemd and Proxmox LXC installs, use Settings β System β Updates or:
sudo /bin/update --version v6.4.0
For Docker:
docker pull rcourtman/pulse:6.4.0
For Docker Compose, update the image to rcourtman/pulse:6.4.0 and recreate the container.
Pulse Pro and Relay customers should continue using the private download page and private runtime image for paid features.
Roll back
The rollback target is v6.3.2.
For systemd and Proxmox LXC installs:
sudo /bin/update --version v6.3.2
For Docker Compose, set the Pulse image to rcourtman/pulse:6.3.2 and recreate the container.
v6.3.2: Pulse v6.3.2
β Release Asset Validation: PASSED
All release assets have been validated successfully!
Status: Ready for publication β
Validated: 2026-08-25 21:51:56 UTC
Workflow: Pulse Release Pipeline #β373
Validation Summary
- All required assets present β
- Checksums verified β
- Version strings correct β
- Binary architectures validated β
Pulse v6.3.2 Release Notes
v6.3.2 is a stable patch release for the Pulse v6 line. It follows
stable v6.3.1 and corrects memory retention, offline-alert policy handling,
self-container update detection, and fixed polling intervals.
Highlights
- Metrics history releases oversized backing arrays after dense historical
data ages out, preventing memory-limit wedges. - Disabled offline policies suppress platform connection alerts, including
per-resource overrides and expected-offline intent. - Pulse no longer reports its own container as outdated when the product
update service says the installation is current.
Fixed
- Metrics-history retention compacts trimmed windows and sheds seed-sized
capacity once only a small live window remains
(fix). - Platform connection alerts honor disabled resource and global offline
policies, expected-offline intent, and offline quiet-hours routing
(#β1721). - Pulse-managed public container references use the product update service and
no longer create a false self-update badge
(#β1774). - Availability targets keep their configured cadence when adaptive scheduling
is off rather than being re-armed on every monitor tick
(#β1745).
Release Qualification
- The release uses the urgent stable-patch path because metrics-history memory
growth can wedge Pulse under container memory limits and disabled offline
policies can still generate alert noise on stable. - The exact pushed release SHA must pass the governed single-build release
pipeline and its integrated exact-SHA candidate checks before publication. - Windows Unified Agent binaries are not Authenticode-signed for
v6.3.2and
may display an Unknown Publisher warning. The standing SignPath-unavailable
policy changes only Authenticode: exact-SHA candidate binding, checksums,
detached signatures, immutable-manifest verification, and published-digest
verification remain mandatory. - No mobile-facing path changed between
v6.3.1and this release, so the
mobile decision isno-mobile-impact; no companion build or store rollout
is required.
Upgrade Notes
Use the normal v6 install or update flow for v6.3.2. Existing configurations
remain valid and no manual data migration is required.
The rollback target is v6.3.1. The exact rollback reinstall command is:
./scripts/install.sh --version v6.3.1
Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.
Installation
Docker (recommended):
docker pull rcourtman/pulse:6.3.2
Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.2
See the Installation Guide for complete setup instructions.
Review the Code signing policy for release provenance, approval roles, and signing scope.
Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.
Promotion Metadata
- Promotion channel: stable
- Candidate stable tag: v6.3.2
- Promoted prerelease tag: n/a
- Rollback target: v6.3.1
- Rollback command:
./scripts/install.sh --version v6.3.1 - Hotfix exception: true
- Hotfix reason: Metrics-history memory growth can wedge Pulse under memory limits, and disabled offline policies generate alert noise on stable.
- Windows Authenticode required: false
- Unsigned Windows exception: true
- Unsigned Windows reason: SignPath production credentials and certificate authorization are unavailable; the release owner approved unsigned Windows Unified Agent artifacts until availability is explicitly restored.
v6.3.2: Pulse v6.3.2
β Release Asset Validation: PASSED
All release assets have been validated successfully!
Status: Ready for publication β
Validated: 2026-08-25 21:51:56 UTC
Workflow: Pulse Release Pipeline #β373
Validation Summary
- All required assets present β
- Checksums verified β
- Version strings correct β
- Binary architectures validated β
Pulse v6.3.2 Release Notes
v6.3.2 is a stable patch release for the Pulse v6 line. It follows
stable v6.3.1 and corrects memory retention, offline-alert policy handling,
self-container update detection, and fixed polling intervals.
Highlights
- Metrics history releases oversized backing arrays after dense historical
data ages out, preventing memory-limit wedges. - Disabled offline policies suppress platform connection alerts, including
per-resource overrides and expected-offline intent. - Pulse no longer reports its own container as outdated when the product
update service says the installation is current.
Fixed
- Metrics-history retention compacts trimmed windows and sheds seed-sized
capacity once only a small live window remains
(fix). - Platform connection alerts honor disabled resource and global offline
policies, expected-offline intent, and offline quiet-hours routing
(#β1721). - Pulse-managed public container references use the product update service and
no longer create a false self-update badge
(#β1774). - Availability targets keep their configured cadence when adaptive scheduling
is off rather than being re-armed on every monitor tick
(#β1745).
Release Qualification
- The release uses the urgent stable-patch path because metrics-history memory
growth can wedge Pulse under container memory limits and disabled offline
policies can still generate alert noise on stable. - The exact pushed release SHA must pass the governed single-build release
pipeline and its integrated exact-SHA candidate checks before publication. - Windows Unified Agent binaries are not Authenticode-signed for
v6.3.2and
may display an Unknown Publisher warning. The standing SignPath-unavailable
policy changes only Authenticode: exact-SHA candidate binding, checksums,
detached signatures, immutable-manifest verification, and published-digest
verification remain mandatory. - No mobile-facing path changed between
v6.3.1and this release, so the
mobile decision isno-mobile-impact; no companion build or store rollout
is required.
Upgrade Notes
Use the normal v6 install or update flow for v6.3.2. Existing configurations
remain valid and no manual data migration is required.
The rollback target is v6.3.1. The exact rollback reinstall command is:
./scripts/install.sh --version v6.3.1
Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.
Installation
Docker (recommended):
docker pull rcourtman/pulse:6.3.2
Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.2
See the Installation Guide for complete setup instructions.
Review the Code signing policy for release provenance, approval roles, and signing scope.
Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.
Promotion Metadata
- Promotion channel: stable
- Candidate stable tag: v6.3.2
- Promoted prerelease tag: n/a
- Rollback target: v6.3.1
- Rollback command:
./scripts/install.sh --version v6.3.1 - Hotfix exception: true
- Hotfix reason: Metrics-history memory growth can wedge Pulse under memory limits, and disabled offline policies generate alert noise on stable.
- Windows Authenticode required: false
- Unsigned Windows exception: true
- Unsigned Windows reason: SignPath production credentials and certificate authorization are unavailable; the release owner approved unsigned Windows Unified Agent artifacts until availability is explicitly restored.
v6.3.1: Pulse v6.3.1
β Release Asset Validation: PASSED
All release assets have been validated successfully!
Status: Ready for publication β
Validated: 2026-08-23 12:54:50 UTC
Workflow: Pulse Release Pipeline #β370
Validation Summary
- All required assets present β
- Checksums verified β
- Version strings correct β
- Binary architectures validated β
Pulse v6.3.1 Release Notes
v6.3.1 is a stable patch release for the Pulse v6 line. It follows stable
v6.3.0 and contains focused corrections for alert delivery, Unified Agent
control, local subscription providers, and Docker monitoring overhead.
Highlights
- Recover or dismiss terminal notification failures without losing delivery
history, while disabled PBS offline alerts remain silent. - Docker commands recover safely after token rotation, and Synology hosts avoid
repeated full-daemon storage scans on every report. - Local subscription providers now resolve and diagnose their CLIs as the
actual Pulse service account.
Improved
- Notification delivery history now exposes confirmed retry and dismiss
operations for terminal failures. Retried items receive a fresh bounded
attempt budget while their prior audit history remains available. - Refused governed actions record the resource, capability, stable refusal
code, and the specific Docker command-agent lookup that missed. - Standard systemd installs give the Pulse service account a private CLI home
and a deterministic executable search path. Explicit provider CLI path
overrides remain available for non-standard layouts. - Docker host storage totals are refreshed on a bounded 15-minute cadence and
retain the last good aggregate when a refresh fails. Live host and container
metrics continue on the configured reporting interval.
Fixed
- Disabled PBS offline alerts no longer enter the notification dispatch path;
enabled alerts and recovery notifications retain their existing lifecycle. - Docker start, stop, restart, remove, and update commands recover after an
agent reporting-token rotation by proving the exact tenant, agent ID, and
canonical hostname rather than weakening identity matching. - Docker update preflight once again routes through the Unified Agent, and
terminal digest-drift refusals no longer strand later update attempts. - Local subscription setup failures now distinguish a CLI that is missing or
not logged in for the Pulse service account from provider network
reachability failures. - Synology DSM Docker monitoring no longer launches a verbose daemon-wide disk
usage inventory every 30 seconds or immediately retries a slow failed scan.
Release Qualification
- The release uses the emergency stable-patch path because the fixes address
active customer harm across alert delivery, infrastructure control, local AI
setup, and Docker host load without introducing a same-version RC. - The exact pushed release SHA must pass the no-publication Release Dry Run and
its integrated exact-SHA candidate checks before that same SHA is submitted
to the single-build publication workflow. - The release owner approved a
v6.3.1-only exception because SignPath's
production certificate remains CSR pending. Windows Unified Agent binaries
are not Authenticode-signed and may display an Unknown Publisher warning;
exact-SHA checksums, detached signatures, immutable-manifest verification,
and published-digest verification remain mandatory. - No mobile-facing path changed between
v6.3.0and this release, so the mobile
decision isno-mobile-impact; no companion build or store rollout is
required.
Upgrade Notes
Use the normal v6 install or update flow for v6.3.1. Existing configurations
remain valid and no manual data migration is required.
The rollback target is v6.3.0. The exact rollback reinstall command is:
./scripts/install.sh --version v6.3.0
Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.
Installation
Docker (recommended):
docker pull rcourtman/pulse:6.3.1
Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.1
See the Installation Guide for complete setup instructions.
Review the Code signing policy for release provenance, approval roles, and signing scope.
Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.
Promotion Metadata
- Promotion channel: stable
- Candidate stable tag: v6.3.1
- Promoted prerelease tag: n/a
- Rollback target: v6.3.0
- Rollback command:
./scripts/install.sh --version v6.3.0 - Hotfix exception: true
- Hotfix reason: Active customer harm across notification delivery recovery, Docker command continuity, local subscription setup, and Synology Docker host load.
- Windows Authenticode required: false
- Unsigned Windows exception: true
- Unsigned Windows reason: SignPath production certificate remains CSR PENDING and the release-signing policy is invalid; the release owner accepts unsigned Windows Unified Agent artifacts for v6.3.1 with public Unknown Publisher disclosure and unchanged exact-SHA integrity controls.
v6.3.1: Pulse v6.3.1
β Release Asset Validation: PASSED
All release assets have been validated successfully!
Status: Ready for publication β
Validated: 2026-08-23 12:54:50 UTC
Workflow: Pulse Release Pipeline #β370
Validation Summary
- All required assets present β
- Checksums verified β
- Version strings correct β
- Binary architectures validated β
Pulse v6.3.1 Release Notes
v6.3.1 is a stable patch release for the Pulse v6 line. It follows stable
v6.3.0 and contains focused corrections for alert delivery, Unified Agent
control, local subscription providers, and Docker monitoring overhead.
Highlights
- Recover or dismiss terminal notification failures without losing delivery
history, while disabled PBS offline alerts remain silent. - Docker commands recover safely after token rotation, and Synology hosts avoid
repeated full-daemon storage scans on every report. - Local subscription providers now resolve and diagnose their CLIs as the
actual Pulse service account.
Improved
- Notification delivery history now exposes confirmed retry and dismiss
operations for terminal failures. Retried items receive a fresh bounded
attempt budget while their prior audit history remains available. - Refused governed actions record the resource, capability, stable refusal
code, and the specific Docker command-agent lookup that missed. - Standard systemd installs give the Pulse service account a private CLI home
and a deterministic executable search path. Explicit provider CLI path
overrides remain available for non-standard layouts. - Docker host storage totals are refreshed on a bounded 15-minute cadence and
retain the last good aggregate when a refresh fails. Live host and container
metrics continue on the configured reporting interval.
Fixed
- Disabled PBS offline alerts no longer enter the notification dispatch path;
enabled alerts and recovery notifications retain their existing lifecycle. - Docker start, stop, restart, remove, and update commands recover after an
agent reporting-token rotation by proving the exact tenant, agent ID, and
canonical hostname rather than weakening identity matching. - Docker update preflight once again routes through the Unified Agent, and
terminal digest-drift refusals no longer strand later update attempts. - Local subscription setup failures now distinguish a CLI that is missing or
not logged in for the Pulse service account from provider network
reachability failures. - Synology DSM Docker monitoring no longer launches a verbose daemon-wide disk
usage inventory every 30 seconds or immediately retries a slow failed scan.
Release Qualification
- The release uses the emergency stable-patch path because the fixes address
active customer harm across alert delivery, infrastructure control, local AI
setup, and Docker host load without introducing a same-version RC. - The exact pushed release SHA must pass the no-publication Release Dry Run and
its integrated exact-SHA candidate checks before that same SHA is submitted
to the single-build publication workflow. - The release owner approved a
v6.3.1-only exception because SignPath's
production certificate remains CSR pending. Windows Unified Agent binaries
are not Authenticode-signed and may display an Unknown Publisher warning;
exact-SHA checksums, detached signatures, immutable-manifest verification,
and published-digest verification remain mandatory. - No mobile-facing path changed between
v6.3.0and this release, so the mobile
decision isno-mobile-impact; no companion build or store rollout is
required.
Upgrade Notes
Use the normal v6 install or update flow for v6.3.1. Existing configurations
remain valid and no manual data migration is required.
The rollback target is v6.3.0. The exact rollback reinstall command is:
./scripts/install.sh --version v6.3.0
Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.
Installation
Docker (recommended):
docker pull rcourtman/pulse:6.3.1
Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.1
See the Installation Guide for complete setup instructions.
Review the Code signing policy for release provenance, approval roles, and signing scope.
Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.
Promotion Metadata
- Promotion channel: stable
- Candidate stable tag: v6.3.1
- Promoted prerelease tag: n/a
- Rollback target: v6.3.0
- Rollback command:
./scripts/install.sh --version v6.3.0 - Hotfix exception: true
- Hotfix reason: Active customer harm across notification delivery recovery, Docker command continuity, local subscription setup, and Synology Docker host load.
- Windows Authenticode required: false
- Unsigned Windows exception: true
- Unsigned Windows reason: SignPath production certificate remains CSR PENDING and the release-signing policy is invalid; the release owner accepts unsigned Windows Unified Agent artifacts for v6.3.1 with public Unknown Publisher disclosure and unchanged exact-SHA integrity controls.
v6.3.0: Pulse v6.3.0
β Release Asset Validation: PASSED
All release assets have been validated successfully!
Status: Ready for publication β
Validated: 2026-08-22 11:04:47 UTC
Workflow: Pulse Release Pipeline #β369
Validation Summary
- All required assets present β
- Checksums verified β
- Version strings correct β
- Binary architectures validated β
Pulse v6.3.0 Release Notes
v6.3.0 is a stable minor release for the Pulse v6 line. It follows stable
v6.2.1 and promotes the monitoring-first operations work exercised across
the v6.3.0-rc.1 through v6.3.0-rc.6 line, plus the bounded fixes included
in the final stable cutoff.
Highlights
- Patrol adds durable objectives and verified work receipts; Actions provides
a dedicated inbox for governed approvals and execution. - Estate-first pages add canonical search, status facets, relationships,
timelines, and Operational Trust signals across mixed infrastructure. - Safer Unified Agent operation, clearer delivery evidence, and a fail-closed
release pipeline strengthen monitoring and controlled action.
Added
- Durable scoped Patrol objectives, validated read-only observer missions, and
content-free telemetry for operational outcomes. - A first-class Actions workspace for approval requests, governed plans,
execution records, audit evidence, and verification state. - Typed Unified Agent action preflight for supported host and Docker
operations, with stable refusal codes for stale plans, changed targets,
missing prerequisites, policy decisions, and unavailable capabilities. - Canonical estate summaries, status facets, shared platform search, resource
relationship views, and resource-change timelines. - A seven-day activity log for real notification delivery attempts and a
supported least-privilege Unified Agent installation profile.
Improved
- Patrol surfaces provider-unavailable state directly and clears stale blocked
findings when a configured provider becomes available again. - Resource presentation keeps same-short-name hosts from separate estates
distinct instead of collapsing them into one row. - Per-resource severity overrides can re-enable an offline alert even when the
corresponding global threshold is disabled. - Subscription-backed turns bound canceled command cleanup so descendant-held
output pipes cannot extend the caller-owned idle timeout. - Docker-in-LXC discovery backs off against slow or failing Proxmox hosts, and
Unified Agent observers remain report-only with destination-scoped trust. - Release compilation, backend admission, container qualification, public and
private staging, and post-publication convergence make fuller use of the
dedicated PVE capacity without moving customer pointers before exact-SHA
readiness.
Fixed
- Release dry-run diagnostics now fail closed when the diagnostic runner or
stable-tier test path fails, while preserving actionable artifacts. - Native-agent fixtures are path-portable on Windows, and pre-commit Go linting
follows the repository toolchain declared bygo.mod. - Release qualification retains the resource controls required by the release
asset builder and rejects insufficient measured worker headroom before
backend shard execution starts. - Activation recovery, Helm convergence, private-license checks, and paid
runtime proof continue to join the canonical release result rather than
relying on duplicate or moving state.
Release Qualification
- The v6 control plane reports all 44 readiness assertions and all 26 release
gates passed, withrelease_ready=Trueat the stable cutoff. - Production telemetry on 2026-08-22 showed 18 active
v6.3.0-rc.6installs
across binary and Docker, 56 recorded update successes, zero update
failures, zero rollback or version-departure signals, and no new notification
or governed-action failure counters on follow-up heartbeats. - The preceding
v6.3.0-rc.5cohort likewise showed no rollback signal; one
install advanced tov6.3.0-rc.6, and its single rolling-window update
failure was already present on the first heartbeat rather than increasing on
the candidate. - The release owner explicitly accepted the shortened
rc.6soak and the
bounded post-RC cutoff forv6.3.0. This is version-bound risk acceptance,
not 72-hour soak evidence. - The exact pushed stable SHA must pass the no-publication Release Dry Run
before the same SHA enters the single-build publication workflow. - Windows Unified Agent binaries are not Authenticode-signed for
v6.3.0and
may display an Unknown Publisher warning. The release owner approved this
version-bound exception because Windows signing is not yet available. - The unsigned-Windows exception changes only Authenticode. Exact-SHA builds,
SHA-256 checksums, detached signatures, the immutable candidate manifest,
and published-digest verification remain required.
Upgrade Notes
Use the normal v6 install or update flow for v6.3.0. Existing configurations
remain valid and no manual data migration is required.
The rollback target is v6.2.1. The exact rollback reinstall command is:
./scripts/install.sh --version v6.2.1
This server release is compatible with the existing Pulse Mobile candidate.
The changes since v6.3.0-rc.6 preserve the checked-in mobile API, Relay,
pairing, approval, push, authentication, and onboarding contracts. No companion
upload or public mobile-store rollout is part of this server release.
Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.
Unproved self-service commercial plan or billing-cadence transitions remain
disabled and are not introduced by this release.
Installation
Docker (recommended):
docker pull rcourtman/pulse:6.3.0
Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.0
See the Installation Guide for complete setup instructions.
Review the Code signing policy for release provenance, approval roles, and signing scope.
Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.
Promotion Metadata
- Promotion channel: stable
- Candidate stable tag: v6.3.0
- Promoted prerelease tag: v6.3.0-rc.6
- Rollback target: v6.2.1
- Rollback command:
./scripts/install.sh --version v6.2.1 - Hotfix exception: true
- Hotfix reason: Release owner approved the v6.3.0 cutoff after clean privacy-safe production telemetry from rc.5 and rc.6 and accepted the shortened rc.6 soak and bounded post-RC changes.
- Windows Authenticode required: false
- Unsigned Windows exception: true
- Unsigned Windows reason: Windows Authenticode signing is not yet available; the release owner accepts unsigned Windows Unified Agent artifacts for v6.3.0 with public disclosure and unchanged exact-SHA integrity controls.
v6.3.0: Pulse v6.3.0
β Release Asset Validation: PASSED
All release assets have been validated successfully!
Status: Ready for publication β
Validated: 2026-08-22 11:04:47 UTC
Workflow: Pulse Release Pipeline #β369
Validation Summary
- All required assets present β
- Checksums verified β
- Version strings correct β
- Binary architectures validated β
Pulse v6.3.0 Release Notes
v6.3.0 is a stable minor release for the Pulse v6 line. It follows stable
v6.2.1 and promotes the monitoring-first operations work exercised across
the v6.3.0-rc.1 through v6.3.0-rc.6 line, plus the bounded fixes included
in the final stable cutoff.
Highlights
- Patrol adds durable objectives and verified work receipts; Actions provides
a dedicated inbox for governed approvals and execution. - Estate-first pages add canonical search, status facets, relationships,
timelines, and Operational Trust signals across mixed infrastructure. - Safer Unified Agent operation, clearer delivery evidence, and a fail-closed
release pipeline strengthen monitoring and controlled action.
Added
- Durable scoped Patrol objectives, validated read-only observer missions, and
content-free telemetry for operational outcomes. - A first-class Actions workspace for approval requests, governed plans,
execution records, audit evidence, and verification state. - Typed Unified Agent action preflight for supported host and Docker
operations, with stable refusal codes for stale plans, changed targets,
missing prerequisites, policy decisions, and unavailable capabilities. - Canonical estate summaries, status facets, shared platform search, resource
relationship views, and resource-change timelines. - A seven-day activity log for real notification delivery attempts and a
supported least-privilege Unified Agent installation profile.
Improved
- Patrol surfaces provider-unavailable state directly and clears stale blocked
findings when a configured provider becomes available again. - Resource presentation keeps same-short-name hosts from separate estates
distinct instead of collapsing them into one row. - Per-resource severity overrides can re-enable an offline alert even when the
corresponding global threshold is disabled. - Subscription-backed turns bound canceled command cleanup so descendant-held
output pipes cannot extend the caller-owned idle timeout. - Docker-in-LXC discovery backs off against slow or failing Proxmox hosts, and
Unified Agent observers remain report-only with destination-scoped trust. - Release compilation, backend admission, container qualification, public and
private staging, and post-publication convergence make fuller use of the
dedicated PVE capacity without moving customer pointers before exact-SHA
readiness.
Fixed
- Release dry-run diagnostics now fail closed when the diagnostic runner or
stable-tier test path fails, while preserving actionable artifacts. - Native-agent fixtures are path-portable on Windows, and pre-commit Go linting
follows the repository toolchain declared bygo.mod. - Release qualification retains the resource controls required by the release
asset builder and rejects insufficient measured worker headroom before
backend shard execution starts. - Activation recovery, Helm convergence, private-license checks, and paid
runtime proof continue to join the canonical release result rather than
relying on duplicate or moving state.
Release Qualification
- The v6 control plane reports all 44 readiness assertions and all 26 release
gates passed, withrelease_ready=Trueat the stable cutoff. - Production telemetry on 2026-08-22 showed 18 active
v6.3.0-rc.6installs
across binary and Docker, 56 recorded update successes, zero update
failures, zero rollback or version-departure signals, and no new notification
or governed-action failure counters on follow-up heartbeats. - The preceding
v6.3.0-rc.5cohort likewise showed no rollback signal; one
install advanced tov6.3.0-rc.6, and its single rolling-window update
failure was already present on the first heartbeat rather than increasing on
the candidate. - The release owner explicitly accepted the shortened
rc.6soak and the
bounded post-RC cutoff forv6.3.0. This is version-bound risk acceptance,
not 72-hour soak evidence. - The exact pushed stable SHA must pass the no-publication Release Dry Run
before the same SHA enters the single-build publication workflow. - Windows Unified Agent binaries are not Authenticode-signed for
v6.3.0and
may display an Unknown Publisher warning. The release owner approved this
version-bound exception because Windows signing is not yet available. - The unsigned-Windows exception changes only Authenticode. Exact-SHA builds,
SHA-256 checksums, detached signatures, the immutable candidate manifest,
and published-digest verification remain required.
Upgrade Notes
Use the normal v6 install or update flow for v6.3.0. Existing configurations
remain valid and no manual data migration is required.
The rollback target is v6.2.1. The exact rollback reinstall command is:
./scripts/install.sh --version v6.2.1
This server release is compatible with the existing Pulse Mobile candidate.
The changes since v6.3.0-rc.6 preserve the checked-in mobile API, Relay,
pairing, approval, push, authentication, and onboarding contracts. No companion
upload or public mobile-store rollout is part of this server release.
Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.
Unproved self-service commercial plan or billing-cadence transitions remain
disabled and are not introduced by this release.
Installation
Docker (recommended):
docker pull rcourtman/pulse:6.3.0
Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.0
See the Installation Guide for complete setup instructions.
Review the Code signing policy for release provenance, approval roles, and signing scope.
Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.
Promotion Metadata
- Promotion channel: stable
- Candidate stable tag: v6.3.0
- Promoted prerelease tag: v6.3.0-rc.6
- Rollback target: v6.2.1
- Rollback command:
./scripts/install.sh --version v6.2.1 - Hotfix exception: true
- Hotfix reason: Release owner approved the v6.3.0 cutoff after clean privacy-safe production telemetry from rc.5 and rc.6 and accepted the shortened rc.6 soak and bounded post-RC changes.
- Windows Authenticode required: false
- Unsigned Windows exception: true
- Unsigned Windows reason: Windows Authenticode signing is not yet available; the release owner accepts unsigned Windows Unified Agent artifacts for v6.3.0 with public disclosure and unchanged exact-SHA integrity controls.



