Sites Dashboard¶
The Sites Dashboard is the Hub operator's home screen. It lists every registered site, shows live status pulled from each site's heartbeat, and provides toolbar actions for managing sites and opening the per-site admin UI through the proxy.
In hub mode the Sites page replaces the engine's home view. It auto-refreshes every 3 seconds.
Two subjects the dashboard leads to have their own pages: Site Details, the read-only view of a single site, and Licensed Site Count, which governs how many sites may be registered and what the Hub refuses at the limit.
Layout¶
The page is a single Sites content panel containing a toolbar and a
grid. The toolbar holds row-action buttons on the left, a counters
summary in the middle, and a free-text filter field on the right. The
grid lists one row per site.
Toolbar¶
| Control | Behavior |
|---|---|
| Add New Client | Opens the Add New Client dialog. Always clickable; the prerequisites are checked on the click, not by disabling the button. A Hub that cannot issue bundles yet names whichever of the server certificate, internal CA and host name is unset; a Hub mid-CA rotation says so; at the licensed site count it reports the limit; and before the first configuration poll answers it asks you to try again. In every case the dialog does not open |
| Pending Bundles | Opens the Pending Bundles dialog: the bundles issued and not yet redeemed, newest first, with a Cancel Bundle action. The newest 500 are listed and the status bar says so when there are more. Cancelling stops a bundle being redeemed, and frees its subdomain label if it was for a new site |
| Connect | Connects to the selected site, opening its admin console in a new browser tab via the per-site proxy subdomain (see HTTP Proxy). A row double-click does the same. An offline site shows a message instead, since there is no live tunnel to reach. While the Hub is over its licensed site count the button stays clickable and reports the limit |
| View Details | Opens the read-only Site Details dialog for the selected site |
| Manage Access | Opens the per-site ACL dialog for the selected site |
| Disable / Enable | Toggles hub_site.enabled. Disabled sites do not accept tunnels and are not reachable via the proxy. Button label flips based on selection state |
| Delete | Permanently removes the site row. Clickable whenever a row is selected. A site must be disabled first, with no exception while over the licensed site count: disabling is never refused. Clicking Delete on an enabled site names that and stops; disable it with the Disable button, then click Delete again |
| Counters | N online · M offline · K with errors · T total, recalculated on every poll |
| Filter | Free-text filter applied client-side against display name, subdomain, and tags. Escape clears the filter |
Warning
Disabling a site stops the tunnel but does not revoke the cert. The site retains valid credentials and the next time it is enabled the tunnel reconnects automatically. To prevent reconnection, also revoke the cert from the SSL & PKI page.
Delete is irreversible
Delete removes the hub_site row, the per-site ACL entries (both
user and role grants), and the historic association with the bundle
that produced it. The
cert serial remains revoked (if revoked) but the site row is gone.
The remote QIE still has its registration locally and retries connecting; if you do not also unregister on the QIE side, you see takeover-rejected log entries on the Hub.
Grid columns¶
| Column | Source | Notes |
|---|---|---|
| (status icon) | enabled + connected |
Green signal = enabled and connected; red signal-slash = enabled and disconnected; grey power = disabled. Disabled supersedes connected: a disabled site whose tunnel happens to still be open reads as Disabled |
| Site | display name | Falls back to the site identifier UUID when display name is null |
| Subdomain | subdomain label | The DNS label used for the per-site proxy URL |
| Status | computed | Online / Offline / Disabled |
| Tags | tags CSV | Operator-supplied during enrollment; mutable |
| Version | qieVersion | Reported by the remote QIE in every heartbeat |
| Running, Paused, Stopped, Errored | channel counts | Per-site channel state summary reported by the heartbeat |
| CA | CA-rotation readiness | Shown only during a CA rotation (see Rotating the internal CA). Green = the site trusts the new CA and is on a new-CA client cert (ready to retire); red = connected but not yet ready, or errored; grey = offline and not ready. The column appears when a rotation is staged and disappears once the old CA is retired |
Columns are sortable except the status-icon column.
Filter and counters¶
The filter field at the top right matches free text against display name, subdomain, and tags. Filtering is client-side. The Hub already has every row in memory after the most recent poll, so it responds on every keystroke without round-tripping the server.
The counters strip in the middle of the toolbar (N online · M offline
· K with errors · T total) is computed against the full result set,
not the filtered view. Filtering does not change the totals.
For 1000-site deployments, expect a typical workflow to be: filter to a
tag (east-coast, radiology, etc.), scan for red icons or channels-errored
counts, then open the interesting rows via View Details (a row
double-click connects straight to the site's console).
Status semantics¶
A site is considered Online while:
enabledis true; AND- the Hub has an open tunnel
Serverupgrade for the site's identifier; AND - the last heartbeat is more recent than the heartbeat-loss threshold (a few missed 15-second heartbeats).
Anything else is Offline (red signal-slash) or Disabled (grey power icon). Operationally:
- Brief offline flashes during the heartbeat-loss window are normal. network glitches, brief WAN reconfigurations, or main Jetty restarts on the remote site.
- Persistent offline (more than a few minutes) usually means the remote QIE is down, the tunnel cert is invalid, or the Hub hostname does not match the server cert's SAN/CN (the engine verifies the hostname against the cert). See Troubleshooting.
- Repeated rapid online → offline → online cycling can indicate a cert-takeover storm (two QIE installations presenting the same client cert and alternately taking over the tunnel). This is a flagged security signal. See Security Guidance.
Refresh cadence¶
The Sites Dashboard polls every 3 seconds, so a site connecting or disconnecting shows up quickly without navigating away and back. The Site Details dialog polls every 15 seconds while open. The polls run independently, so opening a dialog does not pause the parent grid's polling.
Manual Refresh on the Site Details dialog issues an immediate re-pull and resets the 15-second timer.
The Site Details dialog's 15-second interval is intentionally aligned with the remote-side heartbeat cadence: a fresh poll is at most one heartbeat behind reality in steady state.
