> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sesameterminal.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Day to day

# Day to day

> **In short.** After the setup, you run the app with one `task deploy:...` command for each
> job: install a release, go back to the previous one, read the logs, change a setting, back
> up and restore. This page also turns on Telegram notifications. Look up the job you need.

## Before you run a command

* Type each `task deploy:...` command on **your computer**, in the repository folder, in the
  terminal. On Windows, use Git Bash.
* Each command asks for the security key's PIN and a touch, or for the key's passphrase.
* The server runs one command at a time. A second command while one runs stops with
  `sesamectl: another sesamectl run is in progress`. Wait, then try again.
* The commands use the newest `release-*` tag on your computer. If you work in a new copy of
  the repository, get the tags first:

  ```sh theme={null}
  git fetch origin 'refs/tags/release-*:refs/tags/release-*'
  ```

## Commands

| To | Run on your computer |
| - | - |
| [Install a new release](#install-a-new-release) | `task deploy -- <tag>` |
| [Go back to the previous release](#go-back-to-the-previous-release) | `task deploy:rollback` |
| [See which release runs](#see-which-release-runs) | `task deploy:status` |
| [Read the app's last 300 log lines](#read-the-logs) | `task deploy:logs -- sesame` |
| [Read the web server's last 300 log lines](#read-the-logs) | `task deploy:logs -- caddy` |
| [Apply a change to `sesame.env`](#change-a-setting) | `task deploy:start` |
| [Turn trading off](#turn-trading-off) | `LIVE_TRADING=false` in `sesame.env`, then `task deploy:start` |
| [Back up now](#back-up-now) | `task deploy:backup-now` |
| [List the backups on the server](#restore-a-backup) | `task deploy:list-backups` |
| [Restore a backup](#restore-a-backup) | `task deploy:restore -- <file name>` |
| Start the app after a failed restore | `task deploy:start` |

## Install a new release

1. Sign and push a new release tag, as in
   [Prepare the server, step 8, item 3](1-prepare-server.md#step-8-set-up-release-signing-and-sign-the-first-release).
2. On **your computer**, install it:

   ```sh theme={null}
   task deploy -- <tag>
   ```

   The server checks the tag's signature and builds the app. If the app runs, the server
   then backs up the database, before it starts the new release. You can then go back to the
   data from before the update. The command ends with:

   ```text theme={null}
   sesamectl: <tag> is running at https://<your-domain> (previous tag: <old tag>)
   ```

If the command also prints
`deploy/sesamectl in <tag> differs from /usr/local/sbin/sesamectl`, follow
[Updating the server scripts](advanced.md#updating-the-server-scripts).

## Go back to the previous release

On **your computer**:

```sh theme={null}
task deploy:rollback
```

It prints `sesamectl: rolling back from <tag> to <previous tag>`. The command swaps the current
release and the previous release. Run it a second time to return to the newer release.

To go back to an older release that is still on the server, name its tag:

```sh theme={null}
task deploy:rollback -- <tag>
```

A rollback does not change the data. If the newer release changed the database, the older
release does not start. Its log then shows `is newer than the` and a number of
`known migrations`. In that case, restore the backup that the update took
([Restore a backup](#restore-a-backup)). Changes made after the update are lost.

## See which release runs

On **your computer**:

```sh theme={null}
task deploy:status
```

It shows `SESAME_IMAGE_TAG=<tag>` (the release that runs), `SESAME_PREVIOUS_IMAGE_TAG=<tag>`
(the release a rollback goes to) and the state of the two containers.

## Read the logs

On **your computer**, read the app's last 300 log lines:

```sh theme={null}
task deploy:logs -- sesame
```

Read the web server's last 300 log lines:

```sh theme={null}
task deploy:logs -- caddy
```

For more than 300 lines, run this on **the server**:

```sh theme={null}
cd /opt/sesame && sudo docker compose logs sesame
```

## Change a setting

1. On **the server**, open the settings file:

   ```sh theme={null}
   sudoedit /opt/sesame/sesame.env
   ```

2. Change the line, then save and close the file. Each setting is explained in
   [configuration.md](../configuration.md).

3. On **your computer**, restart the app with the new values:

   ```sh theme={null}
   task deploy:start
   ```

   The command ends with a list of the two containers. If it stops with an error, see
   [The deploy stops and the app does not start](troubleshooting.md#the-deploy-stops-and-the-app-does-not-start).

## Turn trading off

Do this to stop all real orders at once, for example when something looks wrong.

1. In the app, press **Cancel all**.

2. On **the server**, open the settings file:

   ```sh theme={null}
   sudoedit /opt/sesame/sesame.env
   ```

3. Change the `LIVE_TRADING` line to:

   ```dotenv theme={null}
   LIVE_TRADING=false
   ```

4. On **your computer**, restart the app:

   ```sh theme={null}
   task deploy:start
   ```

The app then shows **Trading off**. To turn trading on again, set `LIVE_TRADING=true` and run
`task deploy:start`. If a key may be exposed, follow the
[incident runbook](../../runbooks/incident.md) as well.

## Back up now

On **your computer**:

```sh theme={null}
task deploy:backup-now
```

It prints the name of the new backup, for example `sesame-20261001T040000Z.db`. It also
encrypts the backup for the backup machine.

## Restore a backup

A restore replaces the app's data with a backup. The app stops while the restore runs.

CAUTION: Cancel your open orders first if they matter. The app cannot act on them while it is
stopped.

1. On **your computer**, take a backup, so you can undo the restore:

   ```sh theme={null}
   task deploy:backup-now
   ```

2. List the backups on the server:

   ```sh theme={null}
   task deploy:list-backups
   ```

   Each backup is a `sesame-<time>.db` file, with a `.mac` file beside it. The time is UTC.

3. Restore the backup you want:

   ```sh theme={null}
   task deploy:restore -- <file name>
   ```

4. The command asks `restore <file name> over the database on <your-domain>? sesame stops
   meanwhile [y/N]`. Type `y` and press Enter.

5. Read the result. It shows `MAC verified; audit chain continues into the current
   database's` and `known-device cookies revoked`. The command ends with a list of the two
   containers.

6. Log in again. A restore logs out every browser.

7. Check the data.

The data that the restore replaced stays on the server as `sesame.pre-restore-<time>.db`.

The app refuses a backup that was changed or damaged, or that was written with another
session secret. If a restore fails, the app stays stopped. The output says if the data
changed. Start the app again:

```sh theme={null}
task deploy:start
```

To restore an encrypted copy from the backup machine, see
[Restore an off-site copy](advanced.md#restore-an-off-site-copy).

## Free disk space

Each release stays on the server after you install the next one. On **the server**, delete a
release you no longer need:

```sh theme={null}
sudo docker image rm sesame:<tag> sesame-caddy:<tag>
```

CAUTION: Do not delete the release that runs or the previous release. A rollback needs them.
`task deploy:status` shows both tags.

## Telegram notifications

Telegram sends the app's notifications to your phone. This is optional.

1. Create a bot and get your chat id. Follow steps 1 and 2 of the
   [Telegram runbook](../../runbooks/telegram.md).

2. On **the server**, open the settings file:

   ```sh theme={null}
   sudoedit /opt/sesame/sesame.env
   ```

3. Add both lines, with your values:

   ```dotenv theme={null}
   TELEGRAM_BOT_TOKEN=<token from @BotFather>
   TELEGRAM_CHAT_ID=<your chat id>
   ```

4. On **your computer**, restart the app:

   ```sh theme={null}
   task deploy:start
   ```

WARNING: The bot token is a secret. Keep it only in `sesame.env`. Do not paste it into a chat,
a ticket or an agent session.

**Is it working?**

| Check | Expected |
| - | - |
| After the restart | The bot sends `Server started`. It does this only when at least one notification kind goes to Telegram. The defaults send several |
| In the app, open **Settings**, then **Notifications**, and press **Send test** | The bot sends `Test notification` |

If the app shows `Not sent · Telegram refused the message`, see
[the Telegram runbook](../../runbooks/telegram.md#5-when-the-test-says-not-sent--telegram-refused-the-message).
To choose which notifications go to Telegram, see
[Choose where notifications go](../user/alerts-and-notifications.md#choose-where-notifications-go).

Previous: [4. Go live](4-go-live.md) · Next: [Troubleshooting](troubleshooting.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.