Reference

When Soviez Connects Online

Explicit online lifecycle operations

When Soviez connects online

Rule

Each connection to Soviez services is started by an operation you run (or approve). Before sensitive steps, the product discloses what is about to happen.

Operations that may need connectivity

OperationWhy connectivity is needed
Device authorizationLink this server to your Soviez account
New Production (--new)Verify license, select approved release, authorize download
Product updateVerify update entitlement and download the approved release
New Stage operationsVerify Stage entitlement

Operations that do not depend on continuous connectivity

OperationNotes
Running ERPContinues if Soviez is unreachable
Local backup / restoreAvailable on the host
Status / diagnosticsLocal inspection

Authorizing a server

When you authorize a device:

  • Your account is linked to that server for future authenticated requests
  • No business data is sent
  • Authorization alone does not consume a Production license slot
  • Authorization alone does not activate ERP
  • You can revoke the device later; revocation blocks future connected operations, not a running ERP

Image download (install / update)

What happensDetail
You start itNot a silent background sync
Exact releaseApproved digest — not a mutable latest tag
Temporary accessShort-lived pull-only credentials
No permanent Hub loginNot stored as a day-to-day host credential
If Soviez is downRunning ERP is unaffected; a new pull you requested may wait until service returns

New Production (--new)

Typical connected steps include device authorization (if needed), license verification, approved release selection, image download, environment creation, domain/HTTPS setup, and activation.

Activation secrets are stored with restricted permissions and are not written to logs or command arguments.

If the network drops mid-install, resume with the documented reattach flow for that operation when service returns.

Never sent

Accounting data, customer lists, attachments, database dumps, filestore files, passwords, activation secrets in logs, device private keys, or permanent organization registry tokens.

Source: canonical operator documentation · Permalink