Operate and troubleshoot on-prem
Monitor readiness, diagnose identity and proxy failures, and safely upgrade or roll back your installation.
Journey overview · Installation · Key renewal
Where can I see my installation status?
Open Platform → Your OnPrem installations in the partner dashboard. MyStocks operations reads the same license records in Partner admin → Licenses & installations. The page shows the domain, temporary/permanent access, expiry, approved image digest, last successful cloud verification and operator acceptance. License activation does not mean the installation has passed acceptance.
Production API clients with accounts:read scope can also use the installation inventory. Member sessions additionally need organization.read. This endpoint is unavailable in sandbox.
The response contains installations and a nullable nextCursor. Pass a returned cursor as ?after=… to request the next page (25 records per page). Credentials, private operator evidence URLs and administrator identifiers are omitted.
awaiting_installation means no successful verification has been observed; license_verified means the cloud accepted the credential; operator_verified means an administrator recorded installation acceptance; access_blocked means the license check fails. Cloud verification is recorded at most once per five minutes on a best-effort basis. These are point-in-time observations, not continuous availability guarantees. Use readiness monitoring below for current service health.
For installation support, submit a partner support case with the domain and request reference, but no key or password. The administrator can review the shared conversation, reply and request further evidence. Failed lifecycle emails can be requeued by operations; queued or sent status does not prove the message was read.
How do I check current readiness?
/api/live checks the running process. /api/health performs a fresh license check and returns 503 when the license is invalid, expired or revoked, cloud verification is unavailable, or required sign-in configuration is missing. A page loading or container running does not prove the gateway is ready.
Monitor the public HTTPS URL, readiness, certificate expiry and application logs. Keep secrets and authorization headers out of logs and alerts.
Diagnose by symptom
| Symptom | Check next |
|---|---|
| Registry pull fails | Separate registry reader permission, correct registry and approved immutable image digest. A license does not grant registry login. |
| DNS or TLS failure | A/AAAA records, hostname, certificate chain, ports 80/443 and proxy challenge configuration. Compare IPv4 and IPv6 reachability. |
/api/live succeeds, /api/health returns 503 | License status/domain, outbound cloud access, system time and runtime sign-in configuration. Do not bypass verification. |
| API returns 401 | Required caller API credential or user token; installation credential alone is insufficient. |
| API returns 403 | Organization membership, scope, SSO/MFA requirements and permitted domain; inspect the response error code. |
| Login rejects the domain/provider | Authorized Firebase domain and the exact organization provider ID; rerun installer after approved configuration changes. |
| Sandbox operation is rejected | Published endpoint availability and required sub-account fields before assuming a platform failure. |
| Events stall or repeatedly disconnect | Proxy buffering/timeouts and outbound connectivity. Reconnection within five minutes is expected. |
| Access wall appears | Expiry/revocation and cloud verification; submit a renewal request when needed. |
For a default installer-managed Docker deployment, inspect service status without displaying the secret environment file:
For native deployment, inspect systemctl status mystocks-onprem.service. If you selected a different output directory, substitute it in operational commands. Review logs locally and redact credentials before sharing diagnostics.
Upgrade and rollback
- Obtain the next approved digest and confirm cloud compatibility. Back up configuration securely and record the prior approved digest.
- Test the release in a dedicated installation, including readiness, login, permitted reads, sandbox and license lifecycle.
- Schedule the change. Rerun the installer with the new digest, verified domain and current valid license; preserve your proxy/mode choices explicitly.
- Recheck public TLS, readiness and authenticated functionality after restart.
- If rollback is required, use the prior cloud-compatible image and current valid credentials. Never restore a revoked key or an obsolete image that allowed anonymous proxy access.
For an installer-managed Docker/Caddy deployment, an upgrade or rollback uses the same command. Supply the selected, approved digest and current valid key at the hidden prompt:
Use the matching proxy/mode command for Nginx, Traefik, external TLS or native installations. Reuse the checksum-verified installer approved for that release; replacing an image is not a backup restore.
The installer performs no production data migration. Your team owns server patches, TLS, local configuration backups and operational monitoring; agree incident responsibilities and service terms during onboarding.
Ask for help
Contact support@mystocks.africa with the installation domain, image digest, UTC timestamp, failing path, HTTP status and request ID where available. Include redacted symptoms and whether liveness/readiness pass. Never send passwords, tokens, installation keys or complete environment files.
Where can I see my contract, invoice and image access?
Open Platform → Contracts, billing and operational records in the partner dashboard. A member needs reports.read; an API key needs reports:read. Operators use the corresponding partner Commercial workspace. Contract tier, invoice payment, registry reader access and installation-license validity are separate approvals.
Use kind=contracts, invoices, registry or periods. Each page returns at most 25 records. Follow nextCursor using after with the same kind. The endpoint is available in production, not sandbox, and does not return private administrator evidence or keys.
For private images, supply your organization's verified Google user or service-account identity to Partner Operations. After approval, sign in as that identity and configure Docker for the registry host stated in your installation instructions. Workload identity is appropriate for automated deployment; do not send passwords or private keys in an access request. The registry grant expires at the earlier approved contract or license boundary. A scheduled cleanup worker removes managed reader access after that boundary or revocation; download access can persist until cleanup succeeds. The installation expiry wall remains independent. Other active grants for the same Google identity retain its reader membership. An installation key itself does not authenticate Docker.
Historical cash reports use dated USD statement boundaries and full resumable ledger scans. They are separate from current-state securities and custody reconciliation. Missing or changed source records block sign-off; contact Treasury with the report reference for corrections.
Was this page useful?
Your signal helps us tighten partner onboarding docs.
Last updated on