[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"docs:\u002Fdocs\u002Foperators\u002Frealm-ops":3,"docs:nav":314,"docs:surround:\u002Fdocs\u002Foperators\u002Frealm-ops":523},{"id":4,"title":5,"body":6,"description":304,"extension":305,"launchGate":306,"meta":307,"navigation":308,"path":309,"seo":310,"stem":311,"stub":312,"__hash__":313},"docs_en\u002Fdocs\u002F4.operators\u002F14.realm-ops.md","Running the realm",{"type":7,"value":8,"toc":292},"minimark",[9,18,22,29,64,67,72,75,86,89,93,99,119,125,137,148,152,155,178,185,189,199,203,210,231,234,258,261,267,271,288],[10,11,12,13,17],"p",{},"Velrix is made of modules, each running in its own container on one or more of your servers. ",[14,15,16],"strong",{},"Manager › Realm"," shows all of them. When the web client itself can’t be reached, the console on each server does the same job.",[19,20,16],"h2",{"id":21},"manager-realm",[10,23,24,25,28],{},"Open ",[14,26,27],{},"Realm"," in the Manager. Seeing it needs the platform settings permission; restarting, stopping and starting modules needs the permission to run them. Without it, the window is read-only.",[30,31,32,43,58],"ul",{},[33,34,35,38,39,42],"li",{},[14,36,37],{},"Modules"," lists every server (instance) and the modules it runs, with each one’s state, version, uptime and restarts. A module that crashed again and again is shown as ",[14,40,41],{},"Held after crashing",".",[33,44,45,46,49,50,53,54,57],{},"Choose a module to see its details and its log lines, live, and to ",[14,47,48],{},"Restart",", ",[14,51,52],{},"Stop"," or ",[14,55,56],{},"Start"," it. With a logs module running, a module’s lines are kept there like any workload’s.",[33,59,60,63],{},[14,61,62],{},"Replicas"," shows each module’s copies: on which servers it runs, how many are running, and whether one copy writes for all of them. There you add, move and remove copies.",[10,65,66],{},"Every action is recorded in the audit trail with who did it. A module you stop stays stopped, through restarts of its server, until you start it again; it is never reported as a crash.",[68,69,71],"h3",{"id":70},"what-the-window-wont-do","What the window won’t do",[10,73,74],{},"Some actions would leave you with no way back, so the window refuses them and points you to the console:",[30,76,77,80,83],{},[33,78,79],{},"Stopping the edge your own window is connected through.",[33,81,82],{},"Stopping the last running copy of a module needed to start others again (sign-in, permissions, the realm view itself).",[33,84,85],{},"Restarting or stopping a server’s own host module.",[10,87,88],{},"Stopping anything else asks you to confirm first.",[19,90,92],{"id":91},"adding-moving-and-removing-copies","Adding, moving and removing copies",[10,94,95,96,98],{},"In ",[14,97,62],{},", choose a module:",[30,100,101,107,113],{},[33,102,103,106],{},[14,104,105],{},"Add a copy"," runs it on one more server. For a module where one copy writes, the new copy stands by.",[33,108,109,112],{},[14,110,111],{},"Move"," adds a copy on the new server, waits until it runs and has caught up, then removes the old one. If that takes longer than 15 minutes, both copies stay: a move never leaves none.",[33,114,115,118],{},[14,116,117],{},"Remove"," stops a copy. It always asks first, and asks you to type the name for a module the realm needs or for an edge.",[10,120,121,124],{},[14,122,123],{},"Recent changes"," shows each request: in progress, done, failed or refused. The window refuses the host module, a module’s last copy, the edge you came through, and a second copy of a module whose data sits on one server’s disk (such as the registry).",[10,126,127,128,131,132,136],{},"A new copy needs an identity signed with the realm key. If the key is offline, the request waits and ",[14,129,130],{},"Realm key"," in the Manager says so; release it there, or at the server’s console. The same changes can be made on a server with ",[133,134,135],"code",{},"velrix replicas add|remove \u003Cmodule> --instance \u003Cname>",". A change is made on the server of the instance concerned; your other servers learn the new number of copies at their next release.",[10,138,139,140,143,144,147],{},"An older installation needs one mount for its host module first: in deploy.json, add ",[133,141,142],{},"{\"hostPath\": \"\u002Frun\u002Fvelrix\u002Freplicas\", \"path\": \"\u002Frun\u002Fvelrix\u002Freplicas\"}"," to ",[133,145,146],{},"mounts.host",", then render the host module. Until then the window says the host can’t place copies.",[19,149,151],{"id":150},"several-edges","Several edges",[10,153,154],{},"The edge is where browsers connect. Run it on more than one server, and a browser whose edge goes down reconnects through another within seconds, without signing in again.",[156,157,158,165,175],"ol",{},[33,159,160,161,164],{},"Add a copy of ",[133,162,163],{},"edge"," on each server that should take connections.",[33,166,167,168,171,172,42],{},"In deploy.json, put the realm’s name first in ",[133,169,170],{},"settings.edge.altNames",", and give each edge its own public address in ",[133,173,174],{},"instances.\u003Cname>.settings.edge.publicAddresses",[33,176,177],{},"In DNS, add one A or AAAA record per edge for the realm’s name, with a short TTL.",[10,179,180,181,184],{},"With a certificate from a CA (",[14,182,183],{},"Certificate"," in the Manager), every edge serves the same name.",[19,186,188],{"id":187},"when-the-web-client-cant-be-reached","When the web client can’t be reached",[10,190,191,192,194,195,198],{},"The edge keeps a copy of the last web client it served. If the web client module is down, browsers still get the desktop from that copy, so you can sign in and restart it from ",[14,193,16],{},". A part of the client nobody opened while it was up shows ",[14,196,197],{},"Reload"," until the module is back.",[19,200,202],{"id":201},"the-console-on-each-server","The console on each server",[10,204,205,206,209],{},"When the edge itself is the problem, log in to the server at its own screen or over SSH, as root or as the ",[133,207,208],{},"velrix"," user, and run:",[211,212,217],"pre",{"className":213,"code":214,"language":215,"meta":216,"style":216},"language-bash shiki shiki-themes github-light-high-contrast github-light-high-contrast github-dark-high-contrast","velrix console\n","bash","",[133,218,219],{"__ignoreMap":216},[220,221,224,227],"span",{"class":222,"line":223},"line",1,[220,225,208],{"class":226},"szw1H",[220,228,230],{"class":229},"semJd"," console\n",[10,232,233],{},"It needs no browser and no edge. It shows:",[30,235,236,239,242,245],{},[33,237,238],{},"the server’s modules, with state, restarts, uptime, version and holds, and lets you restart, stop or start one and read its logs;",[33,240,241],{},"every server and module the realm’s mesh can see;",[33,243,244],{},"the edge’s address and the SHA-256 fingerprint of its certificate;",[33,246,247,248,251,252,257],{},"releases staged on this server, to apply with ",[133,249,250],{},"velrix release apply"," (",[253,254,256],"a",{"href":255},"\u002Fdocs\u002Foperators\u002Fupdates#at-a-servers-console","Updates",").",[10,259,260],{},"Actions go through the server’s host module, which records them. If the host module is down too, the console works on the containers directly.",[10,262,263,264,266],{},"The console asks for nothing more than the login: whoever is root or ",[133,265,208],{}," on a server already holds its data and keys. Guard SSH and the server’s screen as you guard the realm.",[19,268,270],{"id":269},"next","Next",[30,272,273,279],{},[33,274,275],{},[253,276,278],{"href":277},"\u002Fdocs\u002Foperators\u002Fupdates","Updates and maintenance windows",[33,280,281],{},[253,282,284,285,287],{"href":283},"\u002Fdocs\u002Freference\u002Fcli","The ",[133,286,208],{}," command",[289,290,291],"style",{},"html pre.shiki code .szw1H, html code.shiki .szw1H{--shiki-light:#702C00;--shiki-default:#702C00;--shiki-dark:#FFB757}html pre.shiki code .semJd, html code.shiki .semJd{--shiki-light:#032563;--shiki-default:#032563;--shiki-dark:#ADDCFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":216,"searchDepth":293,"depth":294,"links":295},2,3,[296,299,300,301,302,303],{"id":21,"depth":293,"text":16,"children":297},[298],{"id":70,"depth":294,"text":71},{"id":91,"depth":293,"text":92},{"id":150,"depth":293,"text":151},{"id":187,"depth":293,"text":188},{"id":201,"depth":293,"text":202},{"id":269,"depth":293,"text":270},"See every module on every server, restart, stop or move one, run several edges, and reach your servers when the web client can't be reached.","md",null,{},true,"\u002Fdocs\u002Foperators\u002Frealm-ops",{"title":5,"description":304},"docs\u002F4.operators\u002F14.realm-ops",false,"m-Dg7NsAqt7Y13bCcVeBgVcnj1EgiKytGPMzK-jc5ks",[315],{"title":316,"path":317,"stem":318,"children":319,"page":-1},"Docs","\u002Fdocs","docs",[320,324,354,381,415,481,494,516],{"title":321,"path":317,"stem":322,"stub":312,"launchGate":306,"icon":323},"Overview","docs\u002Findex","i-lucide-house",{"title":325,"stub":312,"launchGate":306,"icon":326,"path":327,"stem":328,"children":329,"page":312},"Get started","i-lucide-rocket","\u002Fdocs\u002Fget-started","docs\u002F1.get-started",[330,334,338,342,346,350],{"title":331,"path":332,"stem":333,"stub":312,"launchGate":306},"What Velrix is","\u002Fdocs\u002Fget-started\u002Fwhat-is-velrix","docs\u002F1.get-started\u002F1.what-is-velrix",{"title":335,"path":336,"stem":337,"stub":312,"launchGate":306},"Ways to run Velrix","\u002Fdocs\u002Fget-started\u002Fways-to-run","docs\u002F1.get-started\u002F2.ways-to-run",{"title":339,"path":340,"stem":341,"stub":312,"launchGate":306},"Install from USB","\u002Fdocs\u002Fget-started\u002Finstall","docs\u002F1.get-started\u002F3.install",{"title":343,"path":344,"stem":345,"stub":312,"launchGate":306},"The setup wizard","\u002Fdocs\u002Fget-started\u002Fsetup-wizard","docs\u002F1.get-started\u002F4.setup-wizard",{"title":347,"path":348,"stem":349,"stub":312,"launchGate":306},"Your first app","\u002Fdocs\u002Fget-started\u002Ffirst-app","docs\u002F1.get-started\u002F5.first-app",{"title":351,"path":352,"stem":353,"stub":312,"launchGate":306},"Your first VM","\u002Fdocs\u002Fget-started\u002Ffirst-vm","docs\u002F1.get-started\u002F6.first-vm",{"title":355,"stub":312,"launchGate":306,"icon":356,"path":357,"stem":358,"children":359,"page":312},"Concepts","i-lucide-lightbulb","\u002Fdocs\u002Fconcepts","docs\u002F2.concepts",[360,364,368,372,376],{"title":361,"path":362,"stem":363,"stub":308,"launchGate":306},"Realms","\u002Fdocs\u002Fconcepts\u002Frealms","docs\u002F2.concepts\u002F1.realms",{"title":365,"path":366,"stem":367,"stub":308,"launchGate":306},"Instances and hosts","\u002Fdocs\u002Fconcepts\u002Finstances-and-hosts","docs\u002F2.concepts\u002F2.instances-and-hosts",{"title":369,"path":370,"stem":371,"stub":308,"launchGate":306},"Modules and the mesh","\u002Fdocs\u002Fconcepts\u002Fmodules-and-the-mesh","docs\u002F2.concepts\u002F3.modules-and-the-mesh",{"title":373,"path":374,"stem":375,"stub":308,"launchGate":306},"Organisations, projects and permissions","\u002Fdocs\u002Fconcepts\u002Forgs-projects-permissions","docs\u002F2.concepts\u002F4.orgs-projects-permissions",{"title":377,"path":378,"stem":379,"stub":308,"launchGate":380},"Host pools","\u002Fdocs\u002Fconcepts\u002Fhost-pools","docs\u002F2.concepts\u002F5.host-pools","A1",{"title":382,"stub":312,"launchGate":306,"icon":383,"path":384,"stem":385,"children":386,"page":312},"Guides for users","i-lucide-book-open","\u002Fdocs\u002Fguides","docs\u002F3.guides",[387,391,395,399,403,407,411],{"title":388,"path":389,"stem":390,"stub":312,"launchGate":306},"Apps","\u002Fdocs\u002Fguides\u002Fapps","docs\u002F3.guides\u002F1.apps",{"title":392,"path":393,"stem":394,"stub":308,"launchGate":306},"Machines","\u002Fdocs\u002Fguides\u002Fmachines","docs\u002F3.guides\u002F2.machines",{"title":396,"path":397,"stem":398,"stub":308,"launchGate":306},"Volumes","\u002Fdocs\u002Fguides\u002Fvolumes","docs\u002F3.guides\u002F3.volumes",{"title":400,"path":401,"stem":402,"stub":312,"launchGate":306},"Stacks","\u002Fdocs\u002Fguides\u002Fstacks","docs\u002F3.guides\u002F4.stacks",{"title":404,"path":405,"stem":406,"stub":308,"launchGate":306},"Terminal and cloud shells","\u002Fdocs\u002Fguides\u002Fterminal","docs\u002F3.guides\u002F5.terminal",{"title":408,"path":409,"stem":410,"stub":312,"launchGate":306},"Registry","\u002Fdocs\u002Fguides\u002Fregistry","docs\u002F3.guides\u002F6.registry",{"title":412,"path":413,"stem":414,"stub":308,"launchGate":306},"Kubernetes","\u002Fdocs\u002Fguides\u002Fkubernetes","docs\u002F3.guides\u002F7.kubernetes",{"title":416,"stub":312,"launchGate":306,"icon":417,"path":418,"stem":419,"children":420,"page":312},"Guides for operators","i-lucide-server-cog","\u002Fdocs\u002Foperators","docs\u002F4.operators",[421,423,427,431,435,439,440,444,448,452,457,461,465,469,473,477],{"title":278,"path":277,"stem":422,"stub":312,"launchGate":306},"docs\u002F4.operators\u002F1.updates",{"title":424,"path":425,"stem":426,"stub":312,"launchGate":306},"Migrate: moving VMs from VMware","\u002Fdocs\u002Foperators\u002Fmigrate","docs\u002F4.operators\u002F10.migrate",{"title":428,"path":429,"stem":430,"stub":312,"launchGate":306},"Hardware","\u002Fdocs\u002Foperators\u002Fhardware","docs\u002F4.operators\u002F11.hardware",{"title":432,"path":433,"stem":434,"stub":312,"launchGate":306},"Billing","\u002Fdocs\u002Foperators\u002Fbilling","docs\u002F4.operators\u002F12.billing",{"title":436,"path":437,"stem":438,"stub":312,"launchGate":306},"Policies","\u002Fdocs\u002Foperators\u002Fpolicies","docs\u002F4.operators\u002F13.policies",{"title":5,"path":309,"stem":311,"stub":312,"launchGate":306},{"title":441,"path":442,"stem":443,"stub":312,"launchGate":306},"Public address and app hostnames","\u002Fdocs\u002Foperators\u002Fpublic-address","docs\u002F4.operators\u002F15.public-address",{"title":445,"path":446,"stem":447,"stub":312,"launchGate":306},"Library","\u002Fdocs\u002Foperators\u002Flibrary","docs\u002F4.operators\u002F16.library",{"title":449,"path":450,"stem":451,"stub":312,"launchGate":306},"Backups","\u002Fdocs\u002Foperators\u002Fbackups","docs\u002F4.operators\u002F2.backups",{"title":453,"path":454,"stem":455,"stub":308,"launchGate":456},"Availability and drain","\u002Fdocs\u002Foperators\u002Favailability","docs\u002F4.operators\u002F3.availability","A1, A2, A3",{"title":458,"path":459,"stem":460,"stub":308,"launchGate":306},"Federation","\u002Fdocs\u002Foperators\u002Ffederation","docs\u002F4.operators\u002F4.federation",{"title":462,"path":463,"stem":464,"stub":308,"launchGate":306},"Licensing","\u002Fdocs\u002Foperators\u002Flicensing","docs\u002F4.operators\u002F5.licensing",{"title":466,"path":467,"stem":468,"stub":308,"launchGate":306},"Branding: look and design","\u002Fdocs\u002Foperators\u002Fbranding","docs\u002F4.operators\u002F6.branding",{"title":470,"path":471,"stem":472,"stub":308,"launchGate":306},"Connectivity","\u002Fdocs\u002Foperators\u002Fconnectivity","docs\u002F4.operators\u002F7.connectivity",{"title":474,"path":475,"stem":476,"stub":308,"launchGate":306},"Logs","\u002Fdocs\u002Foperators\u002Flogs","docs\u002F4.operators\u002F8.logs",{"title":478,"path":479,"stem":480,"stub":312,"launchGate":306},"Directory sync: Entra ID and Okta","\u002Fdocs\u002Foperators\u002Fdirectory-sync","docs\u002F4.operators\u002F9.directory-sync",{"title":482,"stub":312,"launchGate":306,"icon":483,"path":484,"stem":485,"children":486,"page":312},"Reference","i-lucide-library","\u002Fdocs\u002Freference","docs\u002F5.reference",[487,491],{"title":488,"path":489,"stem":490,"stub":312,"launchGate":306},"The API reference in your realm","\u002Fdocs\u002Freference\u002Fin-your-realm","docs\u002F5.reference\u002F1.in-your-realm",{"title":492,"path":283,"stem":493,"stub":312,"launchGate":306},"The velrix command","docs\u002F5.reference\u002F2.cli",{"title":495,"stub":312,"launchGate":306,"icon":496,"path":497,"stem":498,"children":499,"page":312},"Security and compliance","i-lucide-shield-check","\u002Fdocs\u002Fsecurity","docs\u002F6.security",[500,504,508,512],{"title":501,"path":502,"stem":503,"stub":308,"launchGate":306},"Post-quantum","\u002Fdocs\u002Fsecurity\u002Fpost-quantum","docs\u002F6.security\u002F1.post-quantum",{"title":505,"path":506,"stem":507,"stub":308,"launchGate":306},"GDPR","\u002Fdocs\u002Fsecurity\u002Fgdpr","docs\u002F6.security\u002F2.gdpr",{"title":509,"path":510,"stem":511,"stub":308,"launchGate":306},"NIS2 support","\u002Fdocs\u002Fsecurity\u002Fnis2","docs\u002F6.security\u002F3.nis2",{"title":513,"path":514,"stem":515,"stub":308,"launchGate":306},"Data residency","\u002Fdocs\u002Fsecurity\u002Fdata-residency","docs\u002F6.security\u002F4.data-residency",{"title":517,"path":518,"stem":519,"children":520,"stub":312,"launchGate":306,"icon":522},"Release notes","\u002Fdocs\u002Frelease-notes","docs\u002F7.release-notes\u002Findex",[521],{"title":517,"path":518,"stem":519,"stub":312,"launchGate":306},"i-lucide-scroll-text",[524,526],{"title":436,"path":437,"stem":438,"description":525,"children":-1},"Every module's policies in one place, where each value was set, and how to copy them to another installation.",{"title":441,"path":442,"stem":443,"description":527,"children":-1},"One public IP address for the realm and its apps, hostnames with certificates for apps, and the addresses for the registry and MCP."]