Troubleshooting
Every message below is quoted from the source named beside it. Placeholders in angle brackets stand for values the console fills in.
Sign-in and permissions
{"error":"unauthorized"}(401) (auth.go,requireSession)- There is no valid console session. Sign in again. If nobody can sign in, check the boot log for the next entry.
🛑 CONSOLE SIGN-IN DISABLED — a sign-in method is configured but the session store (appfs core-console/run/sessions) cannot be mounted …(auth.go)- Sessions live in the console’s appfs root. Check
CORE_ENVELOPE_KEKand theOBJECTSTORE_*/CONSOLE_APPFS_DIRwiring. The mount is retried on the next sign-in. <you> is not permitted to change connections on this console (CORE_CONNECTION_ADMINS)(adminRefusal)- The allowlist is set and does not name you. The same shape appears with
CORE_RUNNER_ADMINS,CONSOLE_AGENT_ADMINS(“act on harness findings”) and the other lists. Ask an admin to add you.GET /api/accessshows which lists are set and whether you are on each. this console has no sign-in configured, so a connection change would be unattributable — set GOOGLE_CLIENT_ID or CONSOLE_ADMIN_PASSWORD before storing or removing tenant credentials(connections.go)- Writes are refused outright on an open console. Configure a sign-in method. Runners have the equivalent message: “…a runner enrolment or revocation would be unattributable…”.
no verified console identity on this request(adminRefusal)- The session carries no verified email. Sign out and sign in again.
Connections
the connection registry is not configured on this console(connections.go), orGET /api/connectionsanswering 503- The registry did not open at boot. The console log says
connection registry unavailable — /api/connections will report it. The usual cause is that the console cannot resolveCORE_ENVELOPE_KEK:store/connectionsseals unconditionally and refuses to open without it. no connection with id <id>(404)- A stale id, for example from a cached list. Reload the page.
expected /api/connections/{id}(404)- The path is nested (
a/b). Ids are plain identifiers, because each id names a credential file.
core connection register
no console named: pass --console-url or set CORE_CONSOLE_URL.- There is no default console, by design.
console URL "<url>" must be https: this request carries your console session AND the credential bundle this manifest declares- Use https. Only loopback hosts may be plain http.
no console session: set CORE_CONSOLE_SESSION to an existing … cookie value, or set CORE_CONSOLE_USER and CORE_CONSOLE_PASSWORD …- Export one of these. Neither is read from
core.yaml. the console at <url> has no password sign-in configured (CONSOLE_ADMIN_PASSWORD is unset there); use CORE_CONSOLE_SESSION with a session cookie instead- The console only offers Google sign-in. Copy a session cookie instead.
the console at <url> could not issue a session (its session store, appfs core-console/run/sessions, is unavailable) …- This is a server-side fault, and no client setting can work around it. Fix the console’s session store.
connection "<id>" has type "<t>", which this console's connection catalog does not describe …- The type is not in the target console’s catalog (
GET /api/connection-types). The message lists the described types. connection "<id>": settings["<k>"] is not a setting the <type> connector reads, and this console would drop it silently rather than refuse it.- Use the setting names the catalog reports. The message lists them.
fromEnv is required — it is the NAME of the environment variable the credential is read from- A credential entry needs
fromEnv, and avalue:field is a parse error. BLOCKEDin the report- A declared credential or a
${VAR}is unset or empty. Nothing was written. Export the named variables. DRIFTED, exit code 1- The console’s record differs from the manifest. It was probably edited in the console. Decide which side is right, then re-run with
--adopt-driftif the manifest wins.
Runners
the runner CA is not available on this console: <why> — the core-operator mints core-system/core-runner-ca on its first reconcile and mounts it at CORE_RUNNER_CA_DIR(runners_ca.go)- Enrolment is disabled until the CA exists and is mounted. Let the core-operator reconcile. Never regenerate the CA: every runner would have to re-enrol.
address "<a>" … — enter host:port, where host is an IPv4 address, a [bracketed] IPv6 address or a DNS name(runners_address.go)- Remove any scheme (
://), userinfo (@) or zone id. Bracket IPv6 addresses, and use a port from 1 to 65535. a runner named "<n>" is already registered- Runner names are unique. Pick another.
runner <id> "<n>" is pending and CORE holds no live ticket for it (expired, used, revoked, or the console restarted since it was issued) — issue a new token(runners_enrol.go)- The 15-minute ticket lapsed, or the console restarted, because the proof key lives in memory only. Choose New ticket and restart
core-runnerwith it. runner <id> "<n>" is already enrolled; a token enrols a PENDING runner only — revoke it and enrol a new one to replace it- Tokens exist only for pending runners.
runner <id> "<n>" is revoked and can never enrol again — enrol a new runner- Revocation is permanent. Enrol a new runner with a fresh state directory.
the built-in "console" runner cannot be revoked — it is this console process (§4)- Runink managed has no lifecycle.
core-runner: refusing a ticket on the command line — argv is readable by every local user; pass it in CORE_RUNNER_TICKET(cmd/core-runner)- Put the ticket in the environment.
core-runner: both CORE_RUNNER_TICKET and CORE_RUNNER_TICKET_FILE are set; give the ticket one way- Unset one of them.
the ticket file <path> is readable by group or others (mode …); it must be 0600 or 0400- Run
chmod 600on the file. - A Resolve action or CapEx pull ends
runner_offlinewith “connected; dispatch arrives in rollout step 6” - This is expected. No work is sent to a self-hosted runner before step 6. Choose Runink managed (
console) for the action. runner_unknown,runner_revoked, orfailed“runner registry unavailable”- See the refusal table in Data-access runners. None of them falls back to another runner.
Judgements
judgement submission is not configured (CORE_JUDGEMENT_INGEST_TOKEN unset), so this endpoint accepts nothing(503,judgement.go)- This is the deployed state. No manifest provides the token, so the judge reports unable-to-judge.
bad ingest token(403)- The submitter’s bearer does not match
CORE_JUDGEMENT_INGEST_TOKEN. the submission ingest token has no authority here: a platform that submits findings does not judge them. …(403,judgements.go)- A submitter’s token was presented at
POST /api/judgements. Only CORE’s judge agent, with the GitHub App token, may post verdicts. token does not carry the App's rights for org "<org>"(sessionreports.go)- The agent’s bearer is not an installation token or user token of CORE’s GitHub App for this org.
this console does not know its GitHub org: the CORE GitHub App names no installation it can read and CORE_GITHUB_ORG is unset …- Mount the App key or set
CORE_GITHUB_ORG. Every App-token door (/api/judgements,/api/data-governance-*,/api/session-runs) refuses until one of them is present.
Model plane
modelrouter: inference queue full; retry laterormodelrouter: no inference slot within <wait>; retry later(503 withRetry-After)- The plane decodes one request at a time. Wait for the
Retry-After. Model-calling agents already wait out a 503 inside their own window. modelrouter: no <tier> backend configured(503)BACKEND_<TIER>is unset for an embedding or voxtral request. Those tiers have no general fallback.- A model card shows a tier as unhealthy while it serves
- The verdict requires the tier to run what its card names. Compare the card’s pin with the live model in
GET /api/models.