Skip to main content

Day to day

In short. After the setup, you run the app with one task deploy:... command for each job: install a release, go back to the previous one, read the logs, change a setting, back up and restore. This page also turns on Telegram notifications. Look up the job you need.

Before you run a command

  • Type each task deploy:... command on your computer, in the repository folder, in the terminal. On Windows, use Git Bash.
  • Each command asks for the security key’s PIN and a touch, or for the key’s passphrase.
  • The server runs one command at a time. A second command while one runs stops with sesamectl: another sesamectl run is in progress. Wait, then try again.
  • The commands use the newest release-* tag on your computer. If you work in a new copy of the repository, get the tags first:

Commands

Install a new release

  1. Sign and push a new release tag, as in Prepare the server, step 8, item 3.
  2. On your computer, install it:
    The server checks the tag’s signature and builds the app. If the app runs, the server then backs up the database, before it starts the new release. You can then go back to the data from before the update. The command ends with:
If the command also prints deploy/sesamectl in <tag> differs from /usr/local/sbin/sesamectl, follow Updating the server scripts.

Go back to the previous release

On your computer:
It prints sesamectl: rolling back from <tag> to <previous tag>. The command swaps the current release and the previous release. Run it a second time to return to the newer release. To go back to an older release that is still on the server, name its tag:
A rollback does not change the data. If the newer release changed the database, the older release does not start. Its log then shows is newer than the and a number of known migrations. In that case, restore the backup that the update took (Restore a backup). Changes made after the update are lost.

See which release runs

On your computer:
It shows SESAME_IMAGE_TAG=<tag> (the release that runs), SESAME_PREVIOUS_IMAGE_TAG=<tag> (the release a rollback goes to) and the state of the two containers.

Read the logs

On your computer, read the app’s last 300 log lines:
Read the web server’s last 300 log lines:
For more than 300 lines, run this on the server:

Change a setting

  1. On the server, open the settings file:
  2. Change the line, then save and close the file. Each setting is explained in configuration.md.
  3. On your computer, restart the app with the new values:
    The command ends with a list of the two containers. If it stops with an error, see The deploy stops and the app does not start.

Turn trading off

Do this to stop all real orders at once, for example when something looks wrong.
  1. In the app, press Cancel all.
  2. On the server, open the settings file:
  3. Change the LIVE_TRADING line to:
  4. On your computer, restart the app:
The app then shows Trading off. To turn trading on again, set LIVE_TRADING=true and run task deploy:start. If a key may be exposed, follow the incident runbook as well.

Back up now

On your computer:
It prints the name of the new backup, for example sesame-20261001T040000Z.db. It also encrypts the backup for the backup machine.

Restore a backup

A restore replaces the app’s data with a backup. The app stops while the restore runs. CAUTION: Cancel your open orders first if they matter. The app cannot act on them while it is stopped.
  1. On your computer, take a backup, so you can undo the restore:
  2. List the backups on the server:
    Each backup is a sesame-<time>.db file, with a .mac file beside it. The time is UTC.
  3. Restore the backup you want:
  4. The command asks restore <file name> over the database on <your-domain>? sesame stops meanwhile [y/N]. Type y and press Enter.
  5. Read the result. It shows MAC verified; audit chain continues into the current database's and known-device cookies revoked. The command ends with a list of the two containers.
  6. Log in again. A restore logs out every browser.
  7. Check the data.
The data that the restore replaced stays on the server as sesame.pre-restore-<time>.db. The app refuses a backup that was changed or damaged, or that was written with another session secret. If a restore fails, the app stays stopped. The output says if the data changed. Start the app again:
To restore an encrypted copy from the backup machine, see Restore an off-site copy.

Free disk space

Each release stays on the server after you install the next one. On the server, delete a release you no longer need:
CAUTION: Do not delete the release that runs or the previous release. A rollback needs them. task deploy:status shows both tags.

Telegram notifications

Telegram sends the app’s notifications to your phone. This is optional.
  1. Create a bot and get your chat id. Follow steps 1 and 2 of the Telegram runbook.
  2. On the server, open the settings file:
  3. Add both lines, with your values:
  4. On your computer, restart the app:
WARNING: The bot token is a secret. Keep it only in sesame.env. Do not paste it into a chat, a ticket or an agent session. Is it working? If the app shows Not sent · Telegram refused the message, see the Telegram runbook. To choose which notifications go to Telegram, see Choose where notifications go. Previous: 4. Go live · Next: Troubleshooting