Refused: the registry has no such version. Gitea answered "not found" for that version, so there is no checksum to record. Manifest unchanged. Check the version number, or publish that version first, then vouch it here again.
{{end}}
{{if eq .Flash "golden_behind_fleet"}}
Refused: that golden is older than the controller the fleet already runs. A fresh install would land on stale application code — which is R-120, where new boxes shipped a controller that told customers the wrong thing about a missing backup drive. Manifest unchanged. Re-bake the golden on the current controller, publish it, then vouch it here.
{{end}}
{{if eq .Flash "artifact_tag_missing"}}
Refused: that version has no usable git tag. The installer fetches an agent's config files from raw/tag/v<version>/configs/, so a version published without its tag makes every fresh install and reinstall fail at step 5 of 8 — as root, on a virgin machine. That is exactly what happened on 2026-08-09. Manifest unchanged. Fix it by pushing the tag for that release: git tag -a v<version> <released-commit> && git push origin v<version>, then vouch it here again.
{{end}}
{{if eq .Flash "artifact_pkg_missing"}}
Refused: that version's artifact is not downloadable. The version is tagged but its package is not in the registry, so a box would 404 fetching the binary itself. Manifest unchanged. Publish it — bash scripts/release-agent.sh <version> for the agent, or re-bake and publish the golden — then vouch it here again.
{{end}}
{{if eq .Flash "artifact_unverifiable"}}
Refused: could not verify — this does not mean anything is missing. The registry did not answer, so the hub cannot tell whether that version is installable. It refuses rather than saving with a warning, because a warning beside a success reads as a success. Manifest unchanged. Check that Gitea is up, then try again. There is deliberately no override: the registry is on your own server, so if it is unreachable the vouch can wait.
{{end}}
{{if eq .Flash "artifact_sha_missing"}}
Refused: no checksum for a chosen version. The hub records the sha256 it reads from Gitea, and that lookup came back empty — so saving would vouch bytes nobody verified. Manifest unchanged.
{{end}}
{{if eq .Flash "pw_changed"}}
Login password changed. It is already in effect — use it next time you sign in. Existing sessions stay logged in.
{{end}}
{{if eq .Flash "pw_current_wrong"}}
Current password is incorrect — password unchanged.
{{end}}
{{if eq .Flash "pw_too_short"}}
New password is too short (minimum 8 characters) — password unchanged.
{{end}}
{{if eq .Flash "pw_too_long"}}
New password is too long (maximum 72 characters) — password unchanged.
{{end}}
{{if eq .Flash "pw_mismatch"}}
New password and confirmation don't match — password unchanged.
{{end}}
{{if eq .Flash "pw_unchanged"}}
New password is the same as the current one — nothing changed.
{{end}}
Managed updates — global floor
The minimum controller version every box auto-updates to (unless a per-customer override is set).
Saving takes effect immediately — boxes below the floor update on their next
report, no customer action. Blank = no global floor. This setting is independent of the Day-0
artifact manifest below.
Effective floor:
{{if .FloorRes.Effective}}v{{.FloorRes.Effective}}{{else}}none{{end}}
{{if eq .FloorRes.Source "db"}}
— source: DB (hub_settings){{if .FloorRes.EnvValue}}; env fallback would be v{{.FloorRes.EnvValue}}{{end}}
{{else if eq .FloorRes.Source "env"}}
— source: env fallback (DEFAULT_MIN_CONTROLLER_VERSION); no DB override set
{{else}}
— no floor from either source
{{end}}
…
Type the version again to confirm (or CLEAR to remove the DB override):
Day-0 artifacts — agent & golden
The current agent binary + golden archive the host-bootstrap script fetches from Gitea and
verifies (sha256) before installing. The hub vouches for these checksums (a different trust
root than Gitea). Pick a version — the sha256 is read from Gitea automatically (no manual
copy). Choose — none — to clear an artifact.
Login password
The password for signing in to this hub UI. Changing it takes effect immediately
for the next sign-in — your current session stays logged in. Enter your current password to confirm.
If you ever lose it, the deployment ConfigMap (auth.password_hash) remains the reset path.
Assets
App logos and screenshots served to controllers. Assets are seeded from the Docker image
and synced to controllers daily via the asset manifest API.