Skip to main content
Troubleshooting

FAQ

Find the cause of installation, connection, query, alert, notification and license problems by symptom.

Installation and access

/v2/ does not open

Check docker compose -f docker-compose.prod.yml logs caddy gateway. Make sure inbound 443 is open (on cloud hosts, in the security group too) and that CADDY_SITE_ADDRESS is the host name or IP actually used.

The browser warns about the certificate

The default certificate is self-signed by Caddy's internal CA. Have the operators' machines trust its root certificate, or switch to your own; see Requirements.

HTTPS handshake fails with a bare IP

Make sure Caddy receives CADDY_DEFAULT_SNI, then run docker restart rst-ai-copilot-for-prometheus-caddy.

Sign-in says the password is rejected

RST_ADMIN_PASSWORD_HASH is missing from .env; generate it as described in Configuration.

The one-command install reports a failed signature check

The script only installs a bundle whose signed manifest and SHA-256 both match; when a check fails it installs nothing. Run it again; if it still fails, pin a version with --version or download by hand, and contact Reallysec.

Connections

/readyz returns 503 with db: unreachable

Check the database container with docker compose -f docker-compose.prod.yml ps postgres, and make sure the password in RST_DB_URL matches RST_DB_PASSWORD in .env.

/readyz returns 503 and prometheus is not ok

Check that the gateway reaches Prometheus: docker exec rst-ai-copilot-for-prometheus-gateway curl -s $PROMETHEUS_URL/-/ready, and that the credentials and CA are right.

Using the product

Queries fail or return nothing

Test the data sources under Settings > Data sources. When PromQL validation fails, the page shows Prometheus's own error. Check the model key and address; without a model, queries fall back to keyword generation.

The Alerts page is empty

Check the Alertmanager address and credentials, whether Alertmanager itself has active alerts, and whether Prometheus has alert rules loaded.

An interface went down but nothing alerted

By default only interfaces with a description (ifAlias) alert when they go down. Add a description, or set the interface to key on Devices. Also make sure the inventory scrape job is in Prometheus; see Data sources.

An approved alert rule has no effect

Make sure RST_PROM_RULES_DIR is set, and that Prometheus loads the same directory and runs with --web.enable-lifecycle.

Notifications are not delivered

Look at the error under Notifications > Delivery log, and check outbound access to the channel's domain. Click Resend once it is fixed.

License

Activation says it cannot reach the license server

Make sure outbound access to license.reallysec.com:443 is open. Hosts without internet access use offline activation (Enterprise).

The license suddenly stopped working

Check whether state/machine-id or state/server_guid was regenerated, and restore the original files from a backup.

Problems after an update

Run ./deploy/rst-update.sh --rollback in the install directory to go back to the previous version.

On this page