Pilot Observe-only — mutations and Enforce are off. Discover and vault still work. Scorecard · Settings
License
Control reports seat count only — never people payloads — to the license authority.
Pilot mode
Read-only pilot (Observe-only) disables mutations and Enforce auto-queue. Discover and vault remain available.
Product SKU
| SKU | OPERANET_CLOUD_SELFHOST |
|---|---|
| Features |
Updates (License authority)
WARNING: OPERANET_ALLOW_UNSIGNED_UPDATES is enabled (lab). Unsigned License manifests may be accepted/applied. Set to false in production.
| Local Control | Installer 2026.09.12 |
|---|---|
| License channel | —
|
| Available versions | No License manifest yet — check LICENSE_AUTHORITY_URL and seed releases. |
| Status | Not checked / License unreachable |
| Last check | 2026-09-13T01:19:33+00:00 |
| Last apply | — |
| Auto-update | on (default) · OPERANET_AUTO_UPDATE |
| Unsigned updates | allowed (lab) · OPERANET_ALLOW_UNSIGNED_UPDATES |
| Authority | http://127.0.0.1:8091 |
License is the sole release authority (HMAC + sha256). Workers pull Worker packages from this Control cache — they do not need License reachability.
Auto-apply extracts a declared tarball (never curl | bash). Restart only if OPERANET_UPDATE_RESTART=true; otherwise a restart-needed flag is written.
See docs/updates.md.
Lease / heartbeat
| Customer | lab-customer-1 |
|---|---|
| SKU | OPERANET_CLOUD_SELFHOST |
| Authority | http://127.0.0.1:8091 |
| Lease token | 88080ed45b6cc312b38978a95dc929c0 |
| Last heartbeat | 2026-09-13 01:19:33.288986+00 |
| Reported count | 1 |
Accounts receivable
Operanet license invoices are issued through Copper Finance (copperfin.app — books, invoices & bank sync), not Copper CRM. Billing runs on this Control (vendor License plane). Open Billing to generate the period invoice. Cloud / MSP must not store the Copper API key — they ask Control for status.
Workers
Enrolled Worker last-seen and online/offline (5 minutes). Last command refusal when the Worker reported one. Open Workers
Cloud pull
| CLOUD_URL | http://127.0.0.1:8090 |
|---|---|
| Last cloud pull | — · Control→Cloud outbox (last_pull_at) |
Same path as php control/bin/cloud-poll.php / POST /api/v1/cloud/pull
— drains Cloud outbox via CloudOpsService::pullFromCloud().
Backup
Postgres dump/restore is host-side (lab compose or Ubuntu /opt/operanet).
See docs/backup-restore.md on the Control host — Control .env / tls and Cloud/License /opt/operanet-cloud/.env + cloud/data are not in pg_dump.