Central Server Admin Console

Overview tab: control-plane runtime telemetry, auth posture, fleet sync health, and incident state.

Loading live status...

System Health
--score
Awaiting telemetry
Sync Success
--
Central sync engine
Active Devices
--of --
From device catalog
API Latency p95
--
Across /api/central/*
Open Incidents
--
0 critical
Queue / Throughput
--
Pending / per hour

Control Plane Health

Core settings and service beacons

Central API: --
Service: --
Sync engine: --
Central session: --
Provisioning DB: --
Auth state
--
Admin API
--
Active alerts
--
Deploy state
--

System Runtime

Central service and host telemetry

krypticframe service
--
nginx service
--
Release / build
--
Host / Uptime
--

Server / Host

Instance resource usage (live)

CPU load (1/5/15m)
--
Memory
--
Disk
--

Database

PostgreSQL central catalog

Tables
--

Size and connection counts need a new central DB stats query — not wired yet.

Fleet Sync Snapshot

Device sync health from central telemetry

Enabled / Running
--
Success rate
--
Sync lag p95
--
Queue depth / Throughput
--
Pull / Push counts
--
Last error
--

Incident Snapshot

Open incident pressure and latest event

Open / Acknowledged
--
Critical open incidents
--
Latest event
--
  • Loading incidents...--

Fleet Maintenance Jobs

Central maintenance scheduling — not implemented yet

The per-device console runs scheduled jobs (enrichment retry, face detection, thumbnail audit, and more) through a MaintenanceScheduler with Enable Autonomous / Pause window / Run now controls and a per-job enable/disable toggle list. Central has no equivalent fleet-wide job runner yet, so this page is a placeholder for where those controls will live once one exists. Today, Export Diagnostics above — moved here from the old Overview toolbar — is the one action already wired to a real endpoint.
Sync Success Rate
--
Last 60 minutes
Queue Depth
--
Pending entity batches
Job Throughput
--
Completed/hour
API Latency p95
--
Across /api/central/*

Metric Notes

Cards are wired for Central telemetry fields. Replace fallback defaults by exposing `/api/central/health` and `/api/central/incidents` payload contracts.

Incident Feed

  • stale-cursor / us-west-2aOpen
  • schema-mismatch / frame-019Critical
  • idempotency-retry-spikeOpen

Service Log

Live central service log tail for diagnostics and deployment verification.

Loading service log...
Loading service log...

Database

Browse tables and run read-only SQL queries against the central PostgreSQL database.

Table Explorer
Read-only PostgreSQL table browser.
Select a table to preview.
Schema
Rows
--
SQL Console (read-only)
SELECT / CTE / PRAGMA only

Places Catalog

Browse and manage central place records used for POI and metadata sync behavior.

Loading places...
API: --
Name Category Location Radius Photos Status
Loading places...

Place Editor

Create a new place or select a row to edit an existing place.

Nearby POI Candidates
Select Name Category Type Distance Mapped Place
Select a place and load nearby POIs.
Select a place and load nearby POIs.
Select a place to edit or create a new place.

Device Credentialing

Create or rotate per-device PostgreSQL credentials and generate ready-to-paste Sync config for the frame.

API keys for Weather, LocationIQ, and map thumbnails are configured under Settings > Shared API Services.
Checking provisioning DB role access...
Provide device ID and run provisioning.
Awaiting credential generation...

Pending Device Enrollment

Approve a short-lived code shown on a frame, then select the device group it should join. The frame receives its credential once and saves it locally.

Loading pending enrollment requests...
No pending enrollment requests.

Managed Devices

List all provisioned device credentials, rotate passwords, revoke access, or fully delete devices and related references.

Loading credential catalog...
Device ID Username Status Last Sync Updated Last Rotated
Loading credentials...

Members belong to your tenant; device groups connect members to devices. Tenant roles (owner, admin, member, viewer) control console access. Group roles (viewer, operator, manager) control how a member operates the devices in a group.

Members

Invite people and manage tenant roles.

UserRoleLast loginAction
Not loaded.

Device groups

Each group connects members to devices. Assign within a group — no global pickers.

Open Tenant Access to load members and groups.

Not loaded.

Devices

All devices visible to your tenant and the group each belongs to.

DeviceGroupStatusLast sync
Not loaded.

Shared Tenant Metadata

Metadata is shared within the active household or organization and isolated from every other tenant.

Choose a dataset to inspect tenant-shared metadata.
[]

Update Metadata

Only allowlisted fields are accepted. POI cache datasets are read-only.

OTA Repository

Read-only view of the release manifests and artifacts this central server serves to devices via /api/ota/manifest and /ota/releases/. Signed-in platform administrators do not need the device OTA bearer token to view this catalog.

Open OTA Releases to load the release catalog.
--
--
--
The snippet's token placeholder must be replaced with the same value as CentralOta:BearerToken. Uploads happen via deploy/publish_to_central.sh; there is intentionally no upload UI.

Releases

Versioned manifests found in the repository. The active release per channel is what enabled devices receive on their next check.

Version Channel Active Signed Artifact Published (UTC)
Not loaded.

Settings

Central connectivity, shared API services, sync runtime, admin access, and power controls.

Central Connectivity
Public endpoint and provisioning DB credentials. Host, port, DB name, and SSL use secure defaults.
Public Endpoint
Provisioning Database
Validate & Save checks DB connectivity before writing settings. Password is write-only.
Admin Web
Port and local-network guard for admin endpoints.
Access
Shared API Services
Configure the shared Weather, LocationIQ, and map thumbnail services used by devices and central tooling.
Weather & Location
Advanced URLs
Advanced Weather & Maps
Sync Engine
Controls this server's own sync client runtime. Leave disabled unless this central server needs to run sync jobs directly.
Runtime
Credentials
Advanced
Sync credentials are not loaded from server responses for security.
Manual sync has not been triggered from this console.
Power & Token
Token is used for authenticated API requests from this page and for power action controls.
Controls
Power actions require enabled controls and a valid token.
Open Settings to load current configuration.
krypticFrame Central
-- --
Loading...
Build Identity
Release Version--
Informational--
Git Tag--
Source Commit--
Schema Version--
Exact Release Tag--
Build Date (UTC)--
Update Channel--
Runtime Environment
.NET--
Linux Kernel--
Distribution--
Architecture--
Component--
● Status unknown
Press Check Now to query for updates.
Installed: --
Changelog
Loading changelog...