Skip to content
Troubleshooting

Troubleshooting

Every message below is quoted from the source named beside it. Placeholders in angle brackets stand for values the console fills in.

Sign-in and permissions

{"error":"unauthorized"} (401) (auth.go, requireSession)
There is no valid console session. Sign in again. If nobody can sign in, check the boot log for the next entry.
🛑 CONSOLE SIGN-IN DISABLED — a sign-in method is configured but the session store (appfs core-console/run/sessions) cannot be mounted … (auth.go)
Sessions live in the console’s appfs root. Check CORE_ENVELOPE_KEK and the OBJECTSTORE_* / CONSOLE_APPFS_DIR wiring. The mount is retried on the next sign-in.
<you> is not permitted to change connections on this console (CORE_CONNECTION_ADMINS) (adminRefusal)
The allowlist is set and does not name you. The same shape appears with CORE_RUNNER_ADMINS, CONSOLE_AGENT_ADMINS (“act on harness findings”) and the other lists. Ask an admin to add you. GET /api/access shows which lists are set and whether you are on each.
this console has no sign-in configured, so a connection change would be unattributable — set GOOGLE_CLIENT_ID or CONSOLE_ADMIN_PASSWORD before storing or removing tenant credentials (connections.go)
Writes are refused outright on an open console. Configure a sign-in method. Runners have the equivalent message: “…a runner enrolment or revocation would be unattributable…”.
no verified console identity on this request (adminRefusal)
The session carries no verified email. Sign out and sign in again.

Connections

the connection registry is not configured on this console (connections.go), or GET /api/connections answering 503
The registry did not open at boot. The console log says connection registry unavailable — /api/connections will report it. The usual cause is that the console cannot resolve CORE_ENVELOPE_KEK: store/connections seals unconditionally and refuses to open without it.
no connection with id <id> (404)
A stale id, for example from a cached list. Reload the page.
expected /api/connections/{id} (404)
The path is nested (a/b). Ids are plain identifiers, because each id names a credential file.

core connection register

no console named: pass --console-url or set CORE_CONSOLE_URL.
There is no default console, by design.
console URL "<url>" must be https: this request carries your console session AND the credential bundle this manifest declares
Use https. Only loopback hosts may be plain http.
no console session: set CORE_CONSOLE_SESSION to an existing … cookie value, or set CORE_CONSOLE_USER and CORE_CONSOLE_PASSWORD …
Export one of these. Neither is read from core.yaml.
the console at <url> has no password sign-in configured (CONSOLE_ADMIN_PASSWORD is unset there); use CORE_CONSOLE_SESSION with a session cookie instead
The console only offers Google sign-in. Copy a session cookie instead.
the console at <url> could not issue a session (its session store, appfs core-console/run/sessions, is unavailable) …
This is a server-side fault, and no client setting can work around it. Fix the console’s session store.
connection "<id>" has type "<t>", which this console's connection catalog does not describe …
The type is not in the target console’s catalog (GET /api/connection-types). The message lists the described types.
connection "<id>": settings["<k>"] is not a setting the <type> connector reads, and this console would drop it silently rather than refuse it.
Use the setting names the catalog reports. The message lists them.
fromEnv is required — it is the NAME of the environment variable the credential is read from
A credential entry needs fromEnv, and a value: field is a parse error.
BLOCKED in the report
A declared credential or a ${VAR} is unset or empty. Nothing was written. Export the named variables.
DRIFTED, exit code 1
The console’s record differs from the manifest. It was probably edited in the console. Decide which side is right, then re-run with --adopt-drift if the manifest wins.

Runners

the runner CA is not available on this console: <why> — the core-operator mints core-system/core-runner-ca on its first reconcile and mounts it at CORE_RUNNER_CA_DIR (runners_ca.go)
Enrolment is disabled until the CA exists and is mounted. Let the core-operator reconcile. Never regenerate the CA: every runner would have to re-enrol.
address "<a>" … — enter host:port, where host is an IPv4 address, a [bracketed] IPv6 address or a DNS name (runners_address.go)
Remove any scheme (://), userinfo (@) or zone id. Bracket IPv6 addresses, and use a port from 1 to 65535.
a runner named "<n>" is already registered
Runner names are unique. Pick another.
runner <id> "<n>" is pending and CORE holds no live ticket for it (expired, used, revoked, or the console restarted since it was issued) — issue a new token (runners_enrol.go)
The 15-minute ticket lapsed, or the console restarted, because the proof key lives in memory only. Choose New ticket and restart core-runner with it.
runner <id> "<n>" is already enrolled; a token enrols a PENDING runner only — revoke it and enrol a new one to replace it
Tokens exist only for pending runners.
runner <id> "<n>" is revoked and can never enrol again — enrol a new runner
Revocation is permanent. Enrol a new runner with a fresh state directory.
the built-in "console" runner cannot be revoked — it is this console process (§4)
Runink managed has no lifecycle.
core-runner: refusing a ticket on the command line — argv is readable by every local user; pass it in CORE_RUNNER_TICKET (cmd/core-runner)
Put the ticket in the environment.
core-runner: both CORE_RUNNER_TICKET and CORE_RUNNER_TICKET_FILE are set; give the ticket one way
Unset one of them.
the ticket file <path> is readable by group or others (mode …); it must be 0600 or 0400
Run chmod 600 on the file.
A Resolve action or CapEx pull ends runner_offline with “connected; dispatch arrives in rollout step 6”
This is expected. No work is sent to a self-hosted runner before step 6. Choose Runink managed (console) for the action.
runner_unknown, runner_revoked, or failed “runner registry unavailable”
See the refusal table in Data-access runners. None of them falls back to another runner.

Judgements

judgement submission is not configured (CORE_JUDGEMENT_INGEST_TOKEN unset), so this endpoint accepts nothing (503, judgement.go)
This is the deployed state. No manifest provides the token, so the judge reports unable-to-judge.
bad ingest token (403)
The submitter’s bearer does not match CORE_JUDGEMENT_INGEST_TOKEN.
the submission ingest token has no authority here: a platform that submits findings does not judge them. … (403, judgements.go)
A submitter’s token was presented at POST /api/judgements. Only CORE’s judge agent, with the GitHub App token, may post verdicts.
token does not carry the App's rights for org "<org>" (sessionreports.go)
The agent’s bearer is not an installation token or user token of CORE’s GitHub App for this org.
this console does not know its GitHub org: the CORE GitHub App names no installation it can read and CORE_GITHUB_ORG is unset …
Mount the App key or set CORE_GITHUB_ORG. Every App-token door (/api/judgements, /api/data-governance-*, /api/session-runs) refuses until one of them is present.

Model plane

modelrouter: inference queue full; retry later or modelrouter: no inference slot within <wait>; retry later (503 with Retry-After)
The plane decodes one request at a time. Wait for the Retry-After. Model-calling agents already wait out a 503 inside their own window.
modelrouter: no <tier> backend configured (503)
BACKEND_<TIER> is unset for an embedding or voxtral request. Those tiers have no general fallback.
A model card shows a tier as unhealthy while it serves
The verdict requires the tier to run what its card names. Compare the card’s pin with the live model in GET /api/models.