Remote Control

Operator console

Sign in with an operator API key. Access is also limited by the proxy operator_ip_allowlist when configured.

Remote Control
Live off
Status Name / ID Client Host User Version Cert OS Uptime Remote IP Connected Last seen

No agents match.

Agent

Sessions

User State Session Client Idle

No interactive sessions reported.

Commands / audit

Time Operator Action Status Detail

No audit rows (CapAdmin required).

Patching

No patch inventory.

Hardware / software

No host inventory yet (awaiting agent report).
Mount Free Total FS
Name Version Publisher
Time Operator IP Action Agent Status Command / detail

No audit events.

Live Agent Client Score Compliance Missing Sec Installed Fails (30d) Oldest debt Last install Reboot Last scan

No patch inventory reported yet.

Agent patches

Missing / pending

KB Title Class State First seen

No pending rows.

Install history

Date KB Title Class Result

No history yet (run patch-history-scan).

Live Host Manufacturer Model Serial CPU RAM Disk Software # Collected

No host inventory reported yet (agents need a build that collects it).

Host inventory

Volumes

Mount Free Total % FS

No volumes.

Software

Name Version Publisher Installed

No software rows.

Version Channel Platform Size SHA-256 Published By ID Actions

No releases published.

Create deploy link

CapAdmin only. Install one-liners stay available on this list after create (copy anytime).

Link created — copy now

Token is not stored in recoverable form. Revoke the link if it leaks.

ID
Binary URL
Install script
One-liner

Install one-liners include the path token and can be copied anytime (revoke/delete to disable a link).

Platforms
Status Client Label Platform Channel / mode Install one-liner Uses Created Actions

No install links.

This is the signed command allowlist the agent trusts (A3 Ed25519 opk_* public keys from operators.v1.json), not proxy Bearer API keys. Bearer keys (name, caps, fingerprint — never the secret) are listed in Proxy API keys below. The UI shows the proxy’s verified in-memory copy — the browser does not fetch the allowlist URL (it 403s/CORS and would skip signature verify). Changing who is allowed still requires rc-optrust sign-allowlist + publish. Labels are a local overlay only and do not change what agents trust.

Source
Seq
Issued
Expires
Verified
Label key_id Allowlist name public_key Actions Clients Roles Revoked

No operators on the verified allowlist.

Proxy API keys

Proxy Bearer operators (separate from A3 signing keys). Config keys come from deploy/gce/.secrets.env + operators: YAML (source: config) — edit YAML and redeploy to change them. UI keys live in proxy sqlite under data_dir (source: ui); a volume wipe drops UI keys, YAML keys remain. The secret is shown once at create and is never listed again. CapAdmin can edit a live UI key’s caps and client scope without rotating the secret — keep pasting the same key.

CapAdmin is required to list or mint proxy API keys.

Create proxy API key

CapAdmin only. Copy the secret from the dialog — it will not be shown again.

Edit proxy API key

Changing capabilities does not rotate the key; keep pasting the same secret.

Name Caps Source Fingerprint Scopes Revoked Actions

No proxy API keys.

About this table

API key created — copy now

This secret will not be shown again. Store it like a production operator key.

Name
ID
Secret
· data via CapRead operator APIs · keys stay in this browser only