Skip to content

Commit 184b817

Browse files
committed
docs(self-hosting): document the client feed fallback
1 parent 69e1e83 commit 184b817

1 file changed

Lines changed: 10 additions & 1 deletion

File tree

  • apps/docs/content/docs/platform/self-hosting

‎apps/docs/content/docs/platform/self-hosting/desktop.mdx‎

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ Every Sim deployment exposes two public endpoints:
2525
| `/api/desktop/update/download` | Redirects (302) to the newest installer for this deployment's release channel |
2626
| `/api/desktop/update/latest-mac.yml` | The update manifest installed apps poll |
2727

28-
Both resolve against Sim's public GitHub releases, and the installers themselves are downloaded from GitHub. Nothing is built, signed, or hosted by you: your deployment decides *which* release its clients are offered and serves the manifest, so installed apps poll your server instead of sim.ai — but they cannot be served artifacts of your own from this path. To ship your own build, see [Building your own shell](#building-your-own-shell).
28+
Both resolve against Sim's public GitHub releases, and the installers themselves are downloaded from GitHub. Nothing is built, signed, or hosted by you: your deployment decides *which* release its clients are offered and serves the manifest, so installed apps poll your server instead of sim.ai — but they cannot be served artifacts of your own from this path, and they fall back to Sim's own feed if yours stops answering (see [What an installed app does when the feed fails](#what-an-installed-app-does-when-the-feed-fails)). To ship your own build, see [Building your own shell](#building-your-own-shell).
2929

3030
Both endpoints cache their GitHub lookups for **5 minutes**, and both respond the same way when they cannot answer:
3131

@@ -37,6 +37,15 @@ Both endpoints cache their GitHub lookups for **5 minutes**, and both respond th
3737

3838
The Sim server needs outbound access to `api.github.com` and `github.com` for these to resolve. Unauthenticated GitHub API requests are capped at 60/hour per IP; set `GITHUB_TOKEN` on the Sim server to raise that to 5000/hour.
3939

40+
### What an installed app does when the feed fails
41+
42+
Those statuses are not equivalent to a client. `404` carries a marker header the shell reads as *no update available*, and the app simply reports that it is up to date. Anything else — a `502`, a timeout, a connection or TLS failure — is treated as the feed being unavailable, and what happens next depends on the build:
43+
44+
- A **stable** build falls back to Sim's packaged GitHub feed and keeps updating from the stable channel.
45+
- A **dev or staging** build skips the check instead. The GitHub fallback only carries stable, production-identity artifacts, which their bundle identity cannot install.
46+
47+
So release selection is yours while the feed answers, and reverts to Sim's stable channel when it does not. In the default configuration this is invisible — an unset `APPCONFIG_ENVIRONMENT` resolves the same `latest` release either way — but it does mean a rate-limited or unreachable deployment stops being the authority over what its users are offered, which matters as soon as your deployment serves a channel that disagrees with stable.
48+
4049
### Which channel your deployment serves
4150

4251
The channel is chosen by `APPCONFIG_ENVIRONMENT`, not by whether you are self-hosting:

0 commit comments

Comments
 (0)