Appearance
Troubleshooting
| Symptom | Check |
|---|---|
configure tls.endpoint or trusted_proxies at start | Outside dev mode Sentinel refuses plain HTTP without a trusted TLS proxy. |
/readyz returns 503 | Database reachability and credentials (sentinel config check); pending migrations with auto_migrate: false (sentinel migrate status). |
Devices get Request timestamp expired | Device or server clock is off by more than 5 minutes; enable NTP. |
Devices get Invalid signature behind a proxy | The proxy rewrites paths or bodies; forward them unchanged. |
| Enrollment page link opens the wrong host | public_url must be the URL devices and browsers use. |
| Console sign-in loops back to the sign-in page | Cookies blocked, or the console is served over plain HTTP outside dev mode (cookies are Secure). |
| Integration deliveries fail | Console Integrations → delivery history shows status codes and errors; loopback and link-local destinations are blocked. |
| Audit verification reports a broken chain | Database rows were changed outside Sentinel, or a backup from a different key file was restored. Preserve the database and contact support. |
Still stuck? Contact enterprise@klipsu.com with the Sentinel version (sentinel version), the relevant log lines and what you tried. Never send the key file, passwords or the evidence passphrase.