Skip to content

Operating a Dispatcher

ctf_Bruce edited this page Sep 30, 2026 · 5 revisions

A dispatcher exposes the HTTP API, stores accounts and measurement results, schedules jobs, and coordinates executors. It owns persistent SQLite state and must be backed up before an upgrade.

Published v0.2.0 includes this daemon in the full bundle. Newer source builds provide a separate dispatcher package; see component installation and use the package version selected by your deployment.

Service checklist

  • Bind network listeners only for the authenticated deployment profile.
  • Terminate TLS at the dispatcher or a reverse proxy that verifies the backend certificate.
  • Keep the dispatcher database, TLS private key, signing material, and identity-provider secrets readable only by the service account.
  • Register executors with distinct stable IDs and verify their readiness after every dispatcher restart.
  • Back up the database before a version or schema migration.

Verify a deployment

From a trusted client, check the service and executors:

curl --cacert ca.crt https://dispatcher.example/version
dbl --dispatcher research nodes

/version reports the binary version, the HTTP API contract version, and the executor control protocol version separately. A healthy dispatcher is not sufficient: verify that the expected executors are listed and ready.

Authentication

The loopback-only local profile is the only credential-free mode. A managed dispatcher authenticates every non-public operation and authorizes access to the account that owns the resource or to an operator. Use the authentication flow enabled by the selected release and deployment. Managed browser deployments use configured OAuth sign-in; CLI account-key commands apply only where that mode is enabled and do not perform browser OAuth. See the CLI authentication scope.

Read the configuration reference, API authorization matrix, and security model before changing authentication or exposure.

For port, executor connection, OAuth, readiness or state-version failures, start with the troubleshooting guide for the package you installed.

Clone this wiki locally