[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"docs:\u002Fdocs\u002Fguides\u002Fapps":3,"docs:nav":700,"docs:surround:\u002Fdocs\u002Fguides\u002Fapps":901},{"id":4,"title":5,"body":6,"description":690,"extension":691,"launchGate":692,"meta":693,"navigation":694,"path":695,"seo":696,"stem":697,"stub":698,"__hash__":699},"docs_en\u002Fdocs\u002F3.guides\u002F1.apps.md","Apps",{"type":7,"value":8,"toc":665},"minimark",[9,41,46,49,94,105,110,113,141,168,171,197,202,205,208,211,214,220,224,258,268,272,275,285,306,309,313,325,329,344,348,370,373,409,413,425,428,437,451,454,458,468,510,513,519,522,533,536,545,585,589,608,639,642,645,649],[10,11,12,13,18,19,23,24,23,27,23,30,23,33,36,37,40],"p",{},"An app is a container image that Velrix keeps running. ",[14,15,17],"a",{"href":16},"\u002Fdocs\u002Fget-started\u002Ffirst-app","Your first app"," deploys one; this page is about living with it. Its page has a head that says how it is doing, and tabs: ",[20,21,22],"strong",{},"Overview",", ",[20,25,26],{},"Variables",[20,28,29],{},"Volumes",[20,31,32],{},"Deployments",[20,34,35],{},"Logs"," and ",[20,38,39],{},"Settings",", with more when other parts of Velrix add their own.",[42,43,45],"h2",{"id":44},"how-it-is-doing","How it is doing",[10,47,48],{},"The status says it in one word, and on the Cockpit board with a mark:",[50,51,52,59,65,71,77,88],"ul",{},[53,54,55,58],"li",{},[20,56,57],{},"Healthy",", with a beating heart: it runs and every running copy passes its health check.",[53,60,61,64],{},[20,62,63],{},"Starting",": until every running copy passes.",[53,66,67,70],{},[20,68,69],{},"Unhealthy",", with a cracked heart: a copy fails its check.",[53,72,73,76],{},[20,74,75],{},"Running",": it runs and has no health check.",[53,78,79,82,83,87],{},[20,80,81],{},"Sleeping",", with a moon: it stopped because nobody asked for it (see ",[14,84,86],{"href":85},"#sleep-when-idle","Sleep when idle",").",[53,89,90,93],{},[20,91,92],{},"Offline",": nothing runs.",[10,95,96,97,100,101,87],{},"The head also shows the app’s first hostname, the zone of the server it runs on and how many copies it runs. An app that may not reach the internet says ",[20,98,99],{},"No internet access"," there (see ",[14,102,104],{"href":103},"#internet-access","Internet access",[10,106,107,109],{},[20,108,22],{}," lists recent events in sentences, such as who changed the variables, and when.",[42,111,32],{"id":112},"deployments",[10,114,115,116,119,120,122,123,126,127,23,130,36,133,136,137,140],{},"Every change that alters what runs is a ",[20,117,118],{},"revision",": a new image, a variables deploy, a resize. The ",[20,121,32],{}," tab shows the one that is live as a card: the commit’s first line, its author and time, where it came from, the last word of the rollout, and ",[20,124,125],{},"View logs",". Its menu has ",[20,128,129],{},"Restart",[20,131,132],{},"Redeploy",[20,134,135],{},"Remove",". With nothing live, it says ",[20,138,139],{},"No active deployment"," and offers to deploy.",[10,142,143,144,23,147,23,150,23,153,23,156,159,160,163,164,167],{},"Below it is the history, each revision ",[20,145,146],{},"Active",[20,148,149],{},"Deploying",[20,151,152],{},"Failed",[20,154,155],{},"Rolled back",[20,157,158],{},"Removed"," or ",[20,161,162],{},"Skipped",". ",[20,165,166],{},"Hide skipped"," tidies it.",[10,169,170],{},"A revision opens on its own page:",[50,172,173,184],{},[53,174,175,178,179,183],{},[20,176,177],{},"Details",": the outcome and the phases it went through, where it came from, what changed, its variables, and its configuration, readable or as ",[180,181,182],"code",{},"velrix.json"," or TOML to copy.",[53,185,186,189,190,36,193,196],{},[20,187,188],{},"Build logs"," for a revision built by CI, ",[20,191,192],{},"Deploy logs",[20,194,195],{},"Network logs"," over its time.",[198,199,201],"h3",{"id":200},"rollouts-without-downtime","Rollouts without downtime",[10,203,204],{},"A new revision of a container app starts as an extra copy beside the ones that run. Velrix waits until the new copy is up, passes its health check and is served by its hostnames, then replaces the old copies one at a time, each judged the same way. As many copies run as you asked for all along, so a one-copy app has no gap either.",[10,206,207],{},"If a new copy fails to start, crashes or fails its check, the revision fails and rolls back: only copies that took the new revision go back, and the extra copy goes. Copies the rollout never reached are left untouched.",[10,209,210],{},"Two kinds restart in place instead, stopping before they start: a VM, and an app whose volume only one copy may mount. The revision says so.",[42,212,26],{"id":213},"variables",[10,215,216,217,219],{},"The ",[20,218,26],{}," tab holds what the app starts with. Seal secrets: a sealed value is encrypted, never shown again, and only the container sees it.",[198,221,223],{"id":222},"staged-changes","Staged changes",[10,225,226,227,23,230,159,233,236,237,240,241,244,245,23,248,36,250,253,254,257],{},"Changes don’t run until you deploy them. Each edit is staged: the row is tinted and says ",[20,228,229],{},"New",[20,231,232],{},"Changed",[20,234,235],{},"Deleted",", the Cockpit card reads ",[20,238,239],{},"Edited · 3 changes",", and a bar over every tab of the app says ",[20,242,243],{},"Apply 3 changes",", with ",[20,246,247],{},"Discard",[20,249,177],{},[20,251,252],{},"Deploy"," (Shift+Enter). Deploy applies them all at once as one revision, whose number the app reads as ",[180,255,256],{},"VELRIX_REVISION",".",[10,259,260,263,264,267],{},[20,261,262],{},"Paste variables"," takes a ",[180,265,266],{},".env"," file or a JSON object, staged row by row. Beside the list, the same variables can be copied as ENV or JSON; sealed ones are left out.",[198,269,271],{"id":270},"references","References",[10,273,274],{},"A value can name another app’s variable or a shared one, and is resolved when you deploy:",[276,277,283],"pre",{"className":278,"code":280,"language":281,"meta":282},[279],"language-text","postgres:\u002F\u002Fapp:${{app:db.PASSWORD}}@${{app:db.INTERNAL_HOST}}:5432\u002Fapp\n","text","",[180,284,280],{"__ignoreMap":282},[50,286,287,300],{},[53,288,289,292,293,296,297,257],{},[180,290,291],{},"${{app:\u003Cname>.VAR}}",": another app of the same owner, by name or id. ",[180,294,295],{},"VAR"," may be one of its variables or one Velrix provides, such as ",[180,298,299],{},"INTERNAL_HOST",[53,301,302,305],{},[180,303,304],{},"${{shared.VAR}}",": a shared variable (below).",[10,307,308],{},"A reference that goes round in a circle, or names something that is not there, is refused with its name, and nothing changes. A reference to a sealed value is sealed in the app that reads it. You need the right to manage the app you read from.",[198,310,312],{"id":311},"shared-variables","Shared variables",[10,314,315,317,318,163,321,324],{},[20,316,312],{}," belong to the owner or the project, and any app there can read them as ",[180,319,320],{},"${{shared.NAME}}",[20,322,323],{},"Make shared"," on a row moves an app’s own variable there and leaves a reference behind. Each shared variable lists the apps that use it; one in use is not removed. Changing one stages the change in every app that reads it, so each deploys when its people say so.",[198,326,328],{"id":327},"generated-secrets","Generated secrets",[10,330,331,332,335,336,339,340,343],{},"A value of ",[180,333,334],{},"${{ secret(32) }}"," is made when it is first deployed: 32 letters and digits, or the characters you give, such as ",[180,337,338],{},"${{ secret(24, \"abcdef0123456789\") }}",". It is kept on every deploy after, until you change the text. ",[20,341,342],{},"Generator"," in the row’s menu writes it for you.",[198,345,347],{"id":346},"provided-by-velrix","Provided by Velrix",[10,349,350,351,23,354,23,357,36,360,363,364,23,366,369],{},"Every container also gets ",[180,352,353],{},"VELRIX_APP_ID",[180,355,356],{},"VELRIX_APP_NAME",[180,358,359],{},"VELRIX_INTERNAL_HOST",[180,361,362],{},"VELRIX_INTERNAL_URL"," (its name on the project network), ",[180,365,256],{},[180,367,368],{},"VELRIX_COMMIT",", and the zone and region of its server. A variable of your own with the same name wins.",[42,371,39],{"id":372},"settings",[10,374,375,376,378,379,382,383,36,386,389,390,23,392,23,395,23,398,23,401,404,405,408],{},"One ",[20,377,39],{}," tab holds everything else, a section each, with a filter at the top (",[20,380,381],{},"\u002F"," jumps to it): ",[20,384,385],{},"Source",[20,387,388],{},"Build"," when the owner has a Git server, ",[20,391,252],{},[20,393,394],{},"Health",[20,396,397],{},"Networking",[20,399,400],{},"Scale",[20,402,403],{},"Policies",", and ",[20,406,407],{},"Delete"," last.",[198,410,412],{"id":411},"resize","Resize",[10,414,415,417,418,421,422,424],{},[20,416,400],{}," has the app’s size: pick another from the catalogue, or ",[20,419,420],{},"Custom"," where your operator allows it, then ",[20,423,412],{},". The size is checked as at create, and against the servers the app runs on: they need the memory it grows by and the cores it asks for. The app is never moved for a resize. Every copy restarts with the new size, as one revision, so a rollback puts the old size back too.",[198,426,86],{"id":427},"sleep-when-idle",[10,429,430,431,433,434,436],{},"Turn on ",[20,432,86],{}," in ",[20,435,400],{}," and choose the idle minutes (10 by default). When nobody has asked for the app for that long, it stops, and the next request wakes it:",[50,438,439,442,445,448],{},[53,440,441],{},"Requests that arrive while it wakes wait, up to 30 seconds and up to 100 at a time. Past either, they get a page saying the app is waking, and are asked to try again in a few seconds.",[53,443,444],{},"The app’s page says how long the last wake took, so you can judge it.",[53,446,447],{},"Nothing is billed while it sleeps. A volume stays attached.",[53,449,450],{},"A deploy while it sleeps changes what runs next; the next wake runs it.",[10,452,453],{},"Only requests to its hostnames wake it, over HTTP\u002F1.1, HTTP\u002F2 or HTTP\u002F3. A load balancer port or a call from another app on the project network does not: keep Sleep off for an app reached that way. VMs don’t sleep.",[42,455,457],{"id":456},"hostnames-and-http3","Hostnames and HTTP\u002F3",[10,459,460,462,463,467],{},[20,461,397],{}," gives the app its names, once you have proved the domain (",[14,464,466],{"href":465},"\u002Fdocs\u002Foperators\u002Fpublic-address#hostnames-for-an-app","Public address and app hostnames","). Each name gets its certificate by itself and answers HTTP\u002F3, HTTP\u002F2 and HTTP\u002F1.1, with nothing to configure: HTTP\u002F3 is on for every app, and the sites on Velrix Public Cloud, this one included, are served that way. WebSockets work over HTTP\u002F1.1.",[50,469,470,476,486,492],{},[53,471,472,475],{},[20,473,474],{},"HTTPS record:"," Networking shows the DNS record to set for each name, so browsers use HTTP\u002F3 from their first visit. Without it, they move to HTTP\u002F3 after the first answer.",[53,477,478,481,482,485],{},[20,479,480],{},"Certificates:"," a name that does not point at the realm yet says ",[20,483,484],{},"Waiting for DNS to point here",", and its certificate is ordered as soon as it does.",[53,487,488,491],{},[20,489,490],{},"Redirects here:"," names that send visitors to one of the app’s names, with path and query kept (308 by default; 301, 302 or 307 if you choose).",[53,493,494,497,498,501,502,505,506,509],{},[20,495,496],{},"Access:"," who may open the names. ",[20,499,500],{},"Anyone","; ",[20,503,504],{},"Anyone signed in to this realm","; or ",[20,507,508],{},"Only those named below",": people, organisations and projects. Visitors then sign in at your realm’s own sign-in page first. A wildcard name can’t be protected.",[10,511,512],{},"When Velrix itself has to answer, because no copy is up, the app is starting or a visitor is not let in, the page shows where it broke, from the visitor through the realm to the app, with a request ID to quote.",[10,514,515,516,87],{},"Apps never publish ports on a server. Web traffic goes through hostnames; for other TCP or UDP, such as SSH, put a load balancer or a floating IP in front of the app (",[20,517,518],{},"Networks › Load balancers",[198,520,104],{"id":521},"internet-access",[10,523,524,525,404,527,529,530,532],{},"An app on a project network reaches the internet only when its owner allows it, and it is off until then. The app’s head says ",[20,526,99],{},[20,528,39],{}," has an ",[20,531,104],{}," line with the switch, for whoever may manage the owner’s networks.",[42,534,35],{"id":535},"logs",[10,537,216,538,540,541,544],{},[20,539,35],{}," tab is one view of everything the app said, with live tail, search and download. A chip for each kind it has lines in chooses what you see: ",[20,542,543],{},"Output",", the HTTP requests to its hostnames, and its own DNS lookups and network flows when your operator logs those for its network.",[50,546,547,567,573,579],{},[53,548,549,552,553,556,557,23,560,159,563,566],{},[20,550,551],{},"Filters:"," type ",[180,554,555],{},"@"," for the fields of the chosen kinds, such as ",[180,558,559],{},"@status:5*",[180,561,562],{},"@level:error",[180,564,565],{},"@domain:*.example.com",", beside free words. All of them must match. A filter no chosen kind can match is underlined and says why.",[53,568,569,572],{},[20,570,571],{},"Errors"," have a red edge. A stack trace after a warning or an error, a printed error object too, is one entry, folded to its first line.",[53,574,575,578],{},[20,576,577],{},"DNS"," lines say what a name resolved to.",[53,580,581,584],{},[20,582,583],{},"Columns"," chooses the columns for each kind, and local time or UTC.",[42,586,588],{"id":587},"deploy-from-your-own-git","Deploy from your own Git",[10,590,591,592,595,596,599,600,602,603,36,605,607],{},"Run Forgejo as an app from the ",[20,593,594],{},"Library",", connect it under ",[20,597,598],{},"Git servers",", and the app’s ",[20,601,39],{}," gain ",[20,604,385],{},[20,606,388],{},":",[50,609,610,633],{},[53,611,612,615,616,619,620,623,624,23,627,159,630,257],{},[20,613,614],{},"Source:"," the server, repository, branch and image to deploy. ",[20,617,618],{},"Deploys when pushed"," turns it on or off; ",[20,621,622],{},"Wait for CI"," deploys only after the commit’s CI run succeeded. The image name may use ",[180,625,626],{},"{sha}",[180,628,629],{},"{short}",[180,631,632],{},"{branch}",[53,634,635,638],{},[20,636,637],{},"Build:"," the Containerfile’s path and build-time variables, sealed and handed to the CI build.",[10,640,641],{},"People sign in to Forgejo with their Velrix account, and organisation members join its teams. CI runs as Velrix jobs, each in its own microVM, and the output reaches Forgejo while it runs. Each run gets a registry key that can push only to the repositories its commit’s rules name, and to their build cache: layers are kept in the registry between runs, so a build whose dependencies have not changed reuses them. In our tests, a build with a 200 MB dependency step took 20 seconds cold and 9 seconds with the cache.",[10,643,644],{},"Each deploy is a revision like any other, rolled out without downtime and rolled back if it fails, with the commit, its author and the CI run on its page. Git over SSH goes through a load balancer; HTTPS clone and push work through the app’s hostname.",[42,646,648],{"id":647},"as-code","As code",[10,650,651,652,655,656,660,661,664],{},"Everything here is an API call, documented in your realm’s ",[20,653,654],{},"Docs"," window (",[14,657,659],{"href":658},"\u002Fdocs\u002Freference\u002Fin-your-realm","The API reference in your realm","). An API key made with a whole capability, such as all of compute, follows releases: when a new release adds to that capability, the key gains it, and its page says ",[20,662,663],{},"Gained 2 rights from a new release",". A key made with single events or read-only access never widens.",{"title":282,"searchDepth":666,"depth":667,"links":668},2,3,[669,670,673,680,684,687,688,689],{"id":44,"depth":666,"text":45},{"id":112,"depth":666,"text":32,"children":671},[672],{"id":200,"depth":667,"text":201},{"id":213,"depth":666,"text":26,"children":674},[675,676,677,678,679],{"id":222,"depth":667,"text":223},{"id":270,"depth":667,"text":271},{"id":311,"depth":667,"text":312},{"id":327,"depth":667,"text":328},{"id":346,"depth":667,"text":347},{"id":372,"depth":666,"text":39,"children":681},[682,683],{"id":411,"depth":667,"text":412},{"id":427,"depth":667,"text":86},{"id":456,"depth":666,"text":457,"children":685},[686],{"id":521,"depth":667,"text":104},{"id":535,"depth":666,"text":35},{"id":587,"depth":666,"text":588},{"id":647,"depth":666,"text":648},"An app's page: deployments and their history, variables, settings, hostnames with HTTP\u002F3, sleeping when idle, logs, and deploying from your own Git.","md",null,{},true,"\u002Fdocs\u002Fguides\u002Fapps",{"title":5,"description":690},"docs\u002F3.guides\u002F1.apps",false,"N162rltLj8D1alP_Q6kFJjPS2uyFYhf7VxtiHFiRls4",[701],{"title":654,"path":702,"stem":703,"children":704,"page":-1},"\u002Fdocs","docs",[705,708,736,763,793,860,872,894],{"title":22,"path":702,"stem":706,"stub":698,"launchGate":692,"icon":707},"docs\u002Findex","i-lucide-house",{"title":709,"stub":698,"launchGate":692,"icon":710,"path":711,"stem":712,"children":713,"page":698},"Get started","i-lucide-rocket","\u002Fdocs\u002Fget-started","docs\u002F1.get-started",[714,718,722,726,730,732],{"title":715,"path":716,"stem":717,"stub":698,"launchGate":692},"What Velrix is","\u002Fdocs\u002Fget-started\u002Fwhat-is-velrix","docs\u002F1.get-started\u002F1.what-is-velrix",{"title":719,"path":720,"stem":721,"stub":698,"launchGate":692},"Ways to run Velrix","\u002Fdocs\u002Fget-started\u002Fways-to-run","docs\u002F1.get-started\u002F2.ways-to-run",{"title":723,"path":724,"stem":725,"stub":698,"launchGate":692},"Install from USB","\u002Fdocs\u002Fget-started\u002Finstall","docs\u002F1.get-started\u002F3.install",{"title":727,"path":728,"stem":729,"stub":698,"launchGate":692},"The setup wizard","\u002Fdocs\u002Fget-started\u002Fsetup-wizard","docs\u002F1.get-started\u002F4.setup-wizard",{"title":17,"path":16,"stem":731,"stub":698,"launchGate":692},"docs\u002F1.get-started\u002F5.first-app",{"title":733,"path":734,"stem":735,"stub":698,"launchGate":692},"Your first VM","\u002Fdocs\u002Fget-started\u002Ffirst-vm","docs\u002F1.get-started\u002F6.first-vm",{"title":737,"stub":698,"launchGate":692,"icon":738,"path":739,"stem":740,"children":741,"page":698},"Concepts","i-lucide-lightbulb","\u002Fdocs\u002Fconcepts","docs\u002F2.concepts",[742,746,750,754,758],{"title":743,"path":744,"stem":745,"stub":694,"launchGate":692},"Realms","\u002Fdocs\u002Fconcepts\u002Frealms","docs\u002F2.concepts\u002F1.realms",{"title":747,"path":748,"stem":749,"stub":694,"launchGate":692},"Instances and hosts","\u002Fdocs\u002Fconcepts\u002Finstances-and-hosts","docs\u002F2.concepts\u002F2.instances-and-hosts",{"title":751,"path":752,"stem":753,"stub":694,"launchGate":692},"Modules and the mesh","\u002Fdocs\u002Fconcepts\u002Fmodules-and-the-mesh","docs\u002F2.concepts\u002F3.modules-and-the-mesh",{"title":755,"path":756,"stem":757,"stub":694,"launchGate":692},"Organisations, projects and permissions","\u002Fdocs\u002Fconcepts\u002Forgs-projects-permissions","docs\u002F2.concepts\u002F4.orgs-projects-permissions",{"title":759,"path":760,"stem":761,"stub":694,"launchGate":762},"Host pools","\u002Fdocs\u002Fconcepts\u002Fhost-pools","docs\u002F2.concepts\u002F5.host-pools","A1",{"title":764,"stub":698,"launchGate":692,"icon":765,"path":766,"stem":767,"children":768,"page":698},"Guides for users","i-lucide-book-open","\u002Fdocs\u002Fguides","docs\u002F3.guides",[769,770,774,777,781,785,789],{"title":5,"path":695,"stem":697,"stub":698,"launchGate":692},{"title":771,"path":772,"stem":773,"stub":694,"launchGate":692},"Machines","\u002Fdocs\u002Fguides\u002Fmachines","docs\u002F3.guides\u002F2.machines",{"title":29,"path":775,"stem":776,"stub":694,"launchGate":692},"\u002Fdocs\u002Fguides\u002Fvolumes","docs\u002F3.guides\u002F3.volumes",{"title":778,"path":779,"stem":780,"stub":698,"launchGate":692},"Stacks","\u002Fdocs\u002Fguides\u002Fstacks","docs\u002F3.guides\u002F4.stacks",{"title":782,"path":783,"stem":784,"stub":694,"launchGate":692},"Terminal and cloud shells","\u002Fdocs\u002Fguides\u002Fterminal","docs\u002F3.guides\u002F5.terminal",{"title":786,"path":787,"stem":788,"stub":698,"launchGate":692},"Registry","\u002Fdocs\u002Fguides\u002Fregistry","docs\u002F3.guides\u002F6.registry",{"title":790,"path":791,"stem":792,"stub":694,"launchGate":692},"Kubernetes","\u002Fdocs\u002Fguides\u002Fkubernetes","docs\u002F3.guides\u002F7.kubernetes",{"title":794,"stub":698,"launchGate":692,"icon":795,"path":796,"stem":797,"children":798,"page":698},"Guides for operators","i-lucide-server-cog","\u002Fdocs\u002Foperators","docs\u002F4.operators",[799,803,807,811,815,818,822,825,828,832,837,841,845,849,853,856],{"title":800,"path":801,"stem":802,"stub":698,"launchGate":692},"Updates and maintenance windows","\u002Fdocs\u002Foperators\u002Fupdates","docs\u002F4.operators\u002F1.updates",{"title":804,"path":805,"stem":806,"stub":698,"launchGate":692},"Migrate: moving VMs from VMware","\u002Fdocs\u002Foperators\u002Fmigrate","docs\u002F4.operators\u002F10.migrate",{"title":808,"path":809,"stem":810,"stub":698,"launchGate":692},"Hardware","\u002Fdocs\u002Foperators\u002Fhardware","docs\u002F4.operators\u002F11.hardware",{"title":812,"path":813,"stem":814,"stub":698,"launchGate":692},"Billing","\u002Fdocs\u002Foperators\u002Fbilling","docs\u002F4.operators\u002F12.billing",{"title":403,"path":816,"stem":817,"stub":698,"launchGate":692},"\u002Fdocs\u002Foperators\u002Fpolicies","docs\u002F4.operators\u002F13.policies",{"title":819,"path":820,"stem":821,"stub":698,"launchGate":692},"Running the realm","\u002Fdocs\u002Foperators\u002Frealm-ops","docs\u002F4.operators\u002F14.realm-ops",{"title":466,"path":823,"stem":824,"stub":698,"launchGate":692},"\u002Fdocs\u002Foperators\u002Fpublic-address","docs\u002F4.operators\u002F15.public-address",{"title":594,"path":826,"stem":827,"stub":698,"launchGate":692},"\u002Fdocs\u002Foperators\u002Flibrary","docs\u002F4.operators\u002F16.library",{"title":829,"path":830,"stem":831,"stub":698,"launchGate":692},"Backups","\u002Fdocs\u002Foperators\u002Fbackups","docs\u002F4.operators\u002F2.backups",{"title":833,"path":834,"stem":835,"stub":694,"launchGate":836},"Availability and drain","\u002Fdocs\u002Foperators\u002Favailability","docs\u002F4.operators\u002F3.availability","A1, A2, A3",{"title":838,"path":839,"stem":840,"stub":694,"launchGate":692},"Federation","\u002Fdocs\u002Foperators\u002Ffederation","docs\u002F4.operators\u002F4.federation",{"title":842,"path":843,"stem":844,"stub":694,"launchGate":692},"Licensing","\u002Fdocs\u002Foperators\u002Flicensing","docs\u002F4.operators\u002F5.licensing",{"title":846,"path":847,"stem":848,"stub":694,"launchGate":692},"Branding: look and design","\u002Fdocs\u002Foperators\u002Fbranding","docs\u002F4.operators\u002F6.branding",{"title":850,"path":851,"stem":852,"stub":694,"launchGate":692},"Connectivity","\u002Fdocs\u002Foperators\u002Fconnectivity","docs\u002F4.operators\u002F7.connectivity",{"title":35,"path":854,"stem":855,"stub":694,"launchGate":692},"\u002Fdocs\u002Foperators\u002Flogs","docs\u002F4.operators\u002F8.logs",{"title":857,"path":858,"stem":859,"stub":698,"launchGate":692},"Directory sync: Entra ID and Okta","\u002Fdocs\u002Foperators\u002Fdirectory-sync","docs\u002F4.operators\u002F9.directory-sync",{"title":861,"stub":698,"launchGate":692,"icon":862,"path":863,"stem":864,"children":865,"page":698},"Reference","i-lucide-library","\u002Fdocs\u002Freference","docs\u002F5.reference",[866,868],{"title":659,"path":658,"stem":867,"stub":698,"launchGate":692},"docs\u002F5.reference\u002F1.in-your-realm",{"title":869,"path":870,"stem":871,"stub":698,"launchGate":692},"The velrix command","\u002Fdocs\u002Freference\u002Fcli","docs\u002F5.reference\u002F2.cli",{"title":873,"stub":698,"launchGate":692,"icon":874,"path":875,"stem":876,"children":877,"page":698},"Security and compliance","i-lucide-shield-check","\u002Fdocs\u002Fsecurity","docs\u002F6.security",[878,882,886,890],{"title":879,"path":880,"stem":881,"stub":694,"launchGate":692},"Post-quantum","\u002Fdocs\u002Fsecurity\u002Fpost-quantum","docs\u002F6.security\u002F1.post-quantum",{"title":883,"path":884,"stem":885,"stub":694,"launchGate":692},"GDPR","\u002Fdocs\u002Fsecurity\u002Fgdpr","docs\u002F6.security\u002F2.gdpr",{"title":887,"path":888,"stem":889,"stub":694,"launchGate":692},"NIS2 support","\u002Fdocs\u002Fsecurity\u002Fnis2","docs\u002F6.security\u002F3.nis2",{"title":891,"path":892,"stem":893,"stub":694,"launchGate":692},"Data residency","\u002Fdocs\u002Fsecurity\u002Fdata-residency","docs\u002F6.security\u002F4.data-residency",{"title":895,"path":896,"stem":897,"children":898,"stub":698,"launchGate":692,"icon":900},"Release notes","\u002Fdocs\u002Frelease-notes","docs\u002F7.release-notes\u002Findex",[899],{"title":895,"path":896,"stem":897,"stub":698,"launchGate":692},"i-lucide-scroll-text",[902,904],{"title":759,"path":760,"stem":761,"description":903,"children":-1},"Groups of servers with their own failover and maintenance rules, and the availability policies apps choose within them.",{"title":771,"path":772,"stem":773,"description":905,"children":-1},"Run virtual machines, Linux and Windows Server: images, sizes, consoles, remote desktop, licences and first-boot scripts."]