You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: apps/docs/content/docs/platform/self-hosting/desktop.mdx
+10-1Lines changed: 10 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -25,7 +25,7 @@ Every Sim deployment exposes two public endpoints:
25
25
|`/api/desktop/update/download`| Redirects (302) to the newest installer for this deployment's release channel |
26
26
|`/api/desktop/update/latest-mac.yml`| The update manifest installed apps poll |
27
27
28
-
Both resolve against Sim's public GitHub releases, and the installers themselves are downloaded from GitHub. Nothing is built, signed, or hosted by you: your deployment decides *which* release its clients are offered and serves the manifest, so installed apps poll your server instead of sim.ai — but they cannot be served artifacts of your own from this path. To ship your own build, see [Building your own shell](#building-your-own-shell).
28
+
Both resolve against Sim's public GitHub releases, and the installers themselves are downloaded from GitHub. Nothing is built, signed, or hosted by you: your deployment decides *which* release its clients are offered and serves the manifest, so installed apps poll your server instead of sim.ai — but they cannot be served artifacts of your own from this path, and they fall back to Sim's own feed if yours stops answering (see [What an installed app does when the feed fails](#what-an-installed-app-does-when-the-feed-fails)). To ship your own build, see [Building your own shell](#building-your-own-shell).
29
29
30
30
Both endpoints cache their GitHub lookups for **5 minutes**, and both respond the same way when they cannot answer:
31
31
@@ -37,6 +37,15 @@ Both endpoints cache their GitHub lookups for **5 minutes**, and both respond th
37
37
38
38
The Sim server needs outbound access to `api.github.com` and `github.com` for these to resolve. Unauthenticated GitHub API requests are capped at 60/hour per IP; set `GITHUB_TOKEN` on the Sim server to raise that to 5000/hour.
39
39
40
+
### What an installed app does when the feed fails
41
+
42
+
Those statuses are not equivalent to a client. `404` carries a marker header the shell reads as *no update available*, and the app simply reports that it is up to date. Anything else — a `502`, a timeout, a connection or TLS failure — is treated as the feed being unavailable, and what happens next depends on the build:
43
+
44
+
- A **stable** build falls back to Sim's packaged GitHub feed and keeps updating from the stable channel.
45
+
- A **dev or staging** build skips the check instead. The GitHub fallback only carries stable, production-identity artifacts, which their bundle identity cannot install.
46
+
47
+
So release selection is yours while the feed answers, and reverts to Sim's stable channel when it does not. In the default configuration this is invisible — an unset `APPCONFIG_ENVIRONMENT` resolves the same `latest` release either way — but it does mean a rate-limited or unreachable deployment stops being the authority over what its users are offered, which matters as soon as your deployment serves a channel that disagrees with stable.
48
+
40
49
### Which channel your deployment serves
41
50
42
51
The channel is chosen by `APPCONFIG_ENVIRONMENT`, not by whether you are self-hosting:
0 commit comments