Version distribution
Ring health
| Customer | Licence | Plan | Seats / Tenants | Utilisation | Version | Health | Licence status | Last seen |
|---|---|---|---|---|---|---|---|---|
| Loading… | ||||||||
Data-free control plane — appliance health only, never customer tenant data. Auto-refreshes every 30s.
Onboard a customer
Customers
| Customer | Org | Billing | Licence | Version | Last seen | Actions |
|---|---|---|---|---|---|---|
| Loading… | ||||||
Provision mints + delivers the appliance licence; Subscribe opens a Stripe checkout bound to the customer.
Release rings
| Ring | Target version | Target digest | Status | Appliances | On target | Actions |
|---|---|---|---|---|---|---|
| Loading… | ||||||
Promote points a ring at an image digest (validate on staging first, then promote the same digest to stable). A degraded appliance on the target auto-halts the ring.
Plan mix (live licences)
Customer status
Expiring licences
Subscription renewals
Registry-tier business facts from Core's own licence + billing tables — capacity sold (the licence claim), never a customer's actual tenant/seat usage. No revenue figures yet (billing structure pending).
Pending approvals
| Action | Target | Status | Requested by | Requested | Expires | |
|---|---|---|---|---|---|---|
| Loading… | ||||||
A destructive request (licence revoke · promote to stable or a halted ring · halt override) stages here and mutates nothing until a second owner approves it. Approvals are bound to the exact arguments, single-use, and expire in 1h.
Chain integrity
Checking…
| Seq | When | Actor | Action | Target | Outcome | Detail |
|---|---|---|---|---|---|---|
| Loading… | ||||||
Every staff mutation is appended to a tamper-evident hash chain (hash = sha256(prev_hash || JCS(entry))). Verification recomputes the whole chain and compares against a monotonic high-water mark, so a truncation is caught too.