Skip to content

Fleet Management

Fleet Management is the operational inventory for every enrolled Telovix sensor. Use it to check current health, find a node, review deployment identity, inspect live system evidence, manage groups, start supported upgrades, and obtain the correct uninstall procedure.

Open Sensors > Fleet.

Telovix sensor fleet with health, deployment, version, and role information.
Use search, filters, and groups to narrow large fleets before opening sensor details. Click to enlarge

Fleet health

Fleet status updates automatically while the page is open. Use Refresh when validating a recent enrollment, restart, or upgrade immediately.

StateMeaning
HealthyThe sensor is reporting within the expected window and has no active critical health condition.
DegradedThe sensor is reporting, but one or more health, delivery, trust, or coverage conditions need attention.
StaleThe latest report is older than the expected window.
OfflineThe sensor has not reported for the offline threshold.
RevokedSensor trust has been revoked and normal operation is blocked.
DisabledThe sensor is intentionally disabled in the Console.

Open Sensors > Health Center for pipeline, trust, and reporting diagnostics. Do not rely on a cached browser tab when validating current fleet state.


Search and filters

Search and filtering apply to the server-side fleet result set. Use them to find sensors by:

  • node name or sensor ID;
  • host, IP address, architecture, or operating system;
  • Kubernetes cluster;
  • deployment type;
  • sensor flavor and version;
  • network-function role;
  • health or trust state;
  • group or tag.

Large fleets are paginated. Narrow by cluster, group, role, health, or version before loading more pages.

The sensor list with search and filters applied.
The sensor list with search and filters applied. Click to enlarge

Select targets across a large fleet

When an action opens Sensor Selector, search sensor metadata to find the hosts you need before selecting targets. Selections remain available while you move between result pages or change the search.

Select page selects only the displayed page, not every matching sensor in the fleet. Review the selected-target count and list before confirming. The selector chooses individual sensors. Group targeting, where supported by an action, uses a separate control.

Tags and groups

Tags add operator-defined context such as:

text
network:prod-5g
site:tokyo-1
environment:production
role:upf
owner:core-platform

Groups collect sensors for protection targeting and access scope.

  • Static groups contain sensors selected by an administrator.
  • Dynamic groups use matching criteria such as tags, role, cluster, flavor, or architecture.

Review dynamic group membership before using it for enforcement. A metadata change can add or remove sensors from the group.


Sensor details

Select a sensor to open its expandable detail workspace.

Sensor detail page showing trust health, heartbeat timeline, active protection, recent events, and resource metrics
Sensor detail - trust health, heartbeat timeline, active protection, recent events, and resource metrics Click to enlarge

Overview

Review identity, deployment type, host, version, flavor, trust, groups, tags, cluster, and recent reporting state.

Monitor

Use the subtabs for live node statistics, processes, network evidence, containers, and telecom network functions where applicable. Separate subtabs keep high-cardinality evidence bounded and easier to search.

Performance

Performance shows CPU, memory, power, and temperature evidence when the host provides it. Temperature cards and charts are hidden when no reliable sensor is available. Power expands to use the available space and is labelled as measured or estimated.

Power estimates are useful for comparison and capacity planning; they are not a replacement for metered energy data.

Security and enforcement

Review trust, runtime blocks, delivery state, and relevant sensor capabilities before changing protection. Use Inspect policy to read an active rule. Open Runtime Blocks to edit its configuration.

Kubernetes-specific evidence appears only for Kubernetes deployments. A VM or bare-metal sensor does not show Kubernetes API activity solely because that feature exists in the Console.


Managed upgrades

Open Upgrade Fleet for the Bare metal and Kubernetes upgrade views. When no update is needed, use Manage updates to review setup and recent plans.

The Bare metal view offers Rolling, Canary, and Immediate strategies for the staged version. Starting a plan targets all eligible non-Kubernetes sensors; inventory search does not narrow that scope.

For Kubernetes, choose manual Helm, Managed rollout, Flux, or Argo CD setup. Managed updates require a registered controller; GitOps updates also require repository automation.

See Upgrading Sensors for setup, eligibility, progress, and recovery. Automatic workflows do not offer arbitrary downgrades.


Uninstall a sensor

Open the sensor Overview and select Uninstall this sensor. Telovix shows instructions based on the deployment type.

DeploymentExpected guidance
Kubernetes or K3s with HelmRun the displayed Helm uninstall command for the release and namespace from a cluster administrator machine. Do not delete only one DaemonSet pod; it will be recreated.
Kubernetes or K3s with Flux or Argo CDRetire the deployment through its owning GitOps source and controller, then verify removal. Do not use a standalone Helm uninstall for a GitOps-owned deployment.
VM or bare metalRun the displayed curl or wget uninstall command on the sensor host.
Ephemeral VMRemove the sensor through the image, instance group, or infrastructure template that owns the instance, then retire its Console record when appropriate.

Review the release name, namespace, Console URL, and sensor identity before executing an uninstall command.

Uninstalling software does not automatically delete historical security evidence. Disabling or revoking a sensor record is a separate administrative action.


  1. Filter for degraded, stale, offline, or version-drifted sensors.
  2. Open each sensor and identify deployment type and last report time.
  3. Resolve trust or delivery problems before changing policy or version.
  4. Group sensors by operational role and maintenance scope.
  5. Use a canary strategy for supported upgrades; apply enforcement to a small test scope before expanding it.
  6. Confirm health after each wave.
  7. Review Audit Log for administrative changes.

Troubleshooting

SymptomCheck
A newly deployed sensor does not appearConfirm enrollment succeeded, Console URL and trust are correct, and the service or pod is running.
Health looks stale until refreshConfirm the browser can maintain live updates; use Refresh and compare with Health Center.
Temperature is absentThe host did not provide reliable temperature evidence. This is expected on some VMs and hardware.
Power is estimatedThe platform did not provide direct power telemetry. Use the estimate for trend comparison only.
Upgrade remains pendingConfirm the sensor is online, eligible, and not already at the target version.
Kubernetes uninstall command failsVerify Helm release name and namespace with helm list -A.
A sensor reappears after uninstallRemove it from the deployment controller, image, DaemonSet, instance group, or provisioning template that recreated it.

Released under the Telovix Commercial License.