A real-time dashboard for monitoring risk server instances — portfolio P&L, system health, alerts, and historical performance across your entire infrastructure.
Application Overview
Centroid Sentinel gives risk operations teams real-time visibility into all risk server instances — portfolio performance, system health, and alerts — from a single browser interface.
Login & Authentication
The dashboard is protected by a shared password. A token is stored in your browser so you don't need to log in on every visit.
How to Sign In
- Open the dashboard URL in your browser.
- The Sign In overlay appears on first visit or after signing out.
- Enter the dashboard password. Use the eye icon to toggle visibility.
- Check "Remember on this browser" to persist your session for 30 days.
- Click Sign in. The dashboard loads immediately after a correct password.
Signing Out
- Click Sign out in the top-right of the header.
- Your stored token is cleared and the login screen reappears.
User Management
Administrators can manage users, roles, and fine-grained permissions via the settings dropdown menu in the top-right corner.
Roles & Permissions
| Role / Permission | Access Level | Description |
|---|---|---|
| Admin | Full Control | Can manage users, delete servers, and access all dashboard settings. |
| Viewer | Read Only | Access to all monitoring views, but cannot manage users or modify server records. |
| can_view_pl | Boolean Flag | When disabled, portfolio P&L values are masked (e.g. ***) for the user. |
Fleet Ops
Fleet Ops lets authorised people group servers and run Ansible against them from the dashboard, without installing anything on the monitored servers. It is switched off by default; open it from the Settings (gear) menu at the top right; if the Fleet Ops item is missing from that menu, either the feature is not enabled on your installation or your account has no Fleet Ops permission.
Who Sees What
Fleet Ops permissions are set in User Management with the Fleet Ops preset list (a shortcut that ticks a set of boxes) or by ticking individual ops.* boxes. The list, the boxes and the Fleet Ops column only appear while Fleet Ops is enabled on your installation.
| Preset | Permissions it ticks | What the user gets today |
|---|---|---|
| viewer (no ops) | none | No Fleet Ops access. |
| operator (view + read-only runs) | ops.view, ops.run_readonly |
The Fleet Ops page with Groups (only groups they were given), Targets, Inventory. Read only. |
| deployer (+ command, files, deploy) | operator plus ops.run_command, ops.push_files, ops.deploy |
Same as operator for now. The run, push and deploy screens arrive in later phases; the permissions are stored and take effect then. |
| ops_admin (everything incl. console) | all ten ops.* permissions |
Everything above, plus managing groups, grants and SSH targets, the full Audit log, and the Console. |
Besides ops.view, three permissions change what you see: ops.manage_groups (create groups, set members and grants), ops.manage_targets (edit SSH targets, flag and unflag servers) and ops.console (the Console tab).
Who May Grant Access
- You can only give or take away an
ops.*permission that you hold yourself. Otherwise the save is refused with You can only grant or remove Fleet Ops keys that you hold yourself. - You cannot change your own Fleet Ops permissions. Another ops admin has to do it.
- Every save that changes an
ops.*box asks for your password first (see the step-up prompt below). So do disabling, deleting, changing the role of, or resetting the password of a user who has anyops.*permission. - The emergency (break-glass) login can never grant Fleet Ops permissions or use Fleet Ops.
- The first ops admin of an installation is created by whoever runs the server, from its command line:
python -m server.ops.grant_admin <username>(with Docker:docker compose exec api python -m server.ops.grant_admin <username>). It gives that existing user the ops_admin preset and records it in the audit log as done bycli.
How to Grant Access
- Open User Management from the settings menu and edit the user.
- Pick a Fleet Ops preset (or tick the
ops.*boxes yourself) and save; confirm your password when asked. Only the boxes you changed are sent, so the user's other permissions are never touched. - Open Fleet Ops → Groups (needs
ops.manage_groups), press Grants on a group and give the user a level:view,runordeploy.
A user without a grant on a group does not see that group at all. Disabling a user cuts all their Fleet Ops access, including an open console, at once. Removing any one of their ops.* permissions (not only ops.console) closes an open console too; after that, what they can see and do follows the permissions they still have — with ops.console left they can reopen the console with their password.
Targets
The Targets tab lists every server with its SSH host, port and user. A server can be managed only when an administrator has entered an SSH host for it here. The address the agent reports is never used, so a server without an SSH host is shown as no ssh_host and is not deployable. A flagged (Shelved or Terminated) server is shown as flagged and is also left out.
- Type the host, check the port (default 22) and user (default
risk), then press Save. - Clear the SSH host to take a server out of every inventory.
- Two servers cannot share one host and port; the second save is refused.
- The Inventory tab shows the exact Ansible inventory that results.
Groups
Groups decide which servers a run may touch. Names are lowercase letters, digits and underscores, starting with a letter; all, ungrouped and all_c24 are reserved.
- Create a group with a name and an optional description.
- Members: tick the servers. Servers marked no ssh can be members but are not deployable until they get an SSH host.
- Grants: choose who may use the group and at which level.
- Require approval / Drop approval stores whether future change jobs need a second person. It has no effect yet. Dropping approval (or creating a group without it) also needs
ops.approve; without it the button is greyed out.
The Step-up Prompt
Every Fleet Ops change (creating a group, saving members, grants or an SSH target, flagging or unflagging a server, changing someone's ops.* permissions, opening the console) first asks you to re-enter your password. After a correct password you are not asked again for 15 minutes. If you cancel the prompt, nothing is changed. A wrong password shows Password not accepted and the change is abandoned — the prompt does not come back; just repeat the action. Too many tries in a minute shows Too many attempts, wait a minute. The prompt is a second check on top of your login, so a stolen session alone cannot touch a server.
ops.manage_targets permission and shows the password prompt like any other Fleet Ops change. With Fleet Ops off, flagging works exactly as before.The Console (Ops Admins Only)
The Console tab embeds the Ansible web interface. It needs ops.console, which only the Ops admin preset includes, and opening it asks for the step-up password. You work in your own account there (named dash- followed by your username) with full rights over the project, so treat it as an administrator tool. The console stays signed in until you close the browser, sign out of the dashboard, or 8 hours pass, whichever comes first; once it is open, changes made inside it do not ask for the password again. If your access is removed while it is open, it disconnects within about 30 seconds.
- Use the project menu on the left of the console: Task Templates, Inventory, Key Store.
- Key Store: add the SSH key used to reach the servers (type SSH key). The key is never kept in the code repository and must not be pasted anywhere else.
- Attach the key to the inventory: open Inventory, edit C24 (generated) and choose the key as its SSH key. The dashboard keeps the inventory's hosts up to date by itself and does not remove the key you attached. Choosing None detaches the key and the next run fails with Permission denied.
- Do not edit the host list in the inventory by hand: it is regenerated from Groups and Targets.
Running Ping with a Limit
- In the console open Task Templates and press run on Ping.
- Fill in the Limit field with a group name (for example
canary) or one server's alias. - Run it. A healthy server answers in a few seconds with its hostname, Python version, disk space and a C24 check.
The limit is mandatory on purpose. Before anything touches a server, an empty limit is refused with This playbook must be run with a host limit, and a limit of all, * or all_c24, or one made only of exclusions (!canary), is refused with This playbook must be run with a limit naming specific groups or hosts; 'all', '*', 'all_c24' or exclusions alone would touch the whole inventory.
The Audit Tab
The Audit tab lists Fleet Ops actions, newest first, with the columns At, Actor, Action, Target and Details. With ops.audit (in the ops_admin preset) you see everyone's actions; with only ops.view you see your own. Recorded actions include permission changes (with the keys added and removed), user disable/delete, group, member, grant, SSH-target and flag changes, duplicate merges and console opens. Press Load older for earlier entries. The log cannot be edited from the dashboard.
Messages You May See
| Message | Meaning |
|---|---|
| not deployable / no ssh_host | The server has no SSH host in Targets (or is flagged). Ask an administrator with ops.manage_targets to set one. |
| No groups have been shared with you. / No grant on this group | You have Fleet Ops access but nobody has given you a grant on any (or that) group. Ask a group manager. |
| Permission ‘ops.…’ required | Your account lacks that permission. Ask an ops admin who holds it to change your preset. Being an Admin does not count. |
| Password not accepted | The password you typed in the prompt was wrong. Nothing was changed and the prompt does not reappear by itself; repeat the action and enter the right password. |
| You can only grant or remove Fleet Ops keys that you hold yourself. | You tried to give or take away an ops.* permission you do not have. Ask an ops admin who has it. |
| Console unavailable | The console engine is still starting or not reachable. Press Retry after a moment. |
| Cannot change your own Fleet Ops permissions | Ask another ops admin to make the change. |
Summary View
The default landing screen — a command-centre showing aggregate stats, health hotspots, and portfolio performance rankings across all instances at a glance.
Core Widgets
| Widget | Description |
|---|---|
| Global Overview | Counters: total instances, live, stale, PropShield-enabled, high CPU/RAM/Disk (Danger/Warning) counts. |
| Instance Types | Instances grouped by type (C24 Live, C24 Backup, Main Server, PropShield Engine) with counts. |
| Top 3 Performers (Today) | 3 instances with the highest today Net P/L, ranked descending. |
| Worst 3 Performers (Today) | 3 instances with the lowest today Net P/L. |
| Top 3 Performers (MTD) | 3 instances with the highest month-to-date Net P/L. |
| Worst 3 Performers (MTD) | 3 instances with the lowest month-to-date Net P/L. |
| High CPU / RAM / Disk | Instances exceeding 90% (Danger) or 70% (Warning) on any resource metric. |
| Stale Instances | All instances not sending data for >2 minutes. |
How to Use
- This is the default screen after login. Return any time via the brand logo or Summary button.
- Scan Global Overview for live vs. stale counts.
- Check High CPU/RAM/Disk widgets to catch infrastructure problems early.
- Review Top/Bottom performers for portfolio profitability insights.
- Click any instance name in any widget to jump to its Detail View.
Cards View
A responsive card grid where every instance is a self-contained card. Ideal for control-room simultaneous surveillance across many servers.
Filter Sidebar
| Filter | Behaviour |
|---|---|
| Search Instances | Case-insensitive real-time filter by instance name or hostname. |
| Public/Internal IP | Filter by IP substring — find servers behind the same public IP. |
| Server Status | Show/hide Live and Stale instances independently. |
| Instance Types | Multi-select checkboxes, populated dynamically from live data. |
| Trading Platforms | Multi-select — show only MT4, MT5, cTrader, etc. |
| PropShield Only | When checked, hides all non-PropShield instances. |
Server Card Anatomy
| Section | Content |
|---|---|
| Card Header | Instance name (click to open Detail View), server time, IPs, PropShield badge, colour-coded status dot. |
| Platform Chips | Coloured badges for each active trading platform. |
| Tab Bar | Switches between: Portfolio, Health, Impact, Stats, Resources. |
| Portfolio Tab | Side-by-side Month and Today values — A-Book, B-Book, C-Book, Fee Rev, Net P/L, Volume. Positive = green, negative = red. |
| Resources Tab | CPU / RAM / Disk gauge bars with percentages and totals. Uptime counter. |
| Card Footer | Push freshness (agent-to-server) and Redis freshness (data source age). |
How to Use
- Click Cards in the view toggle.
- Use the Filters sidebar to narrow results. Collapse it with the arrow for full-width grid.
- Stale servers always appear at the top of the grid.
- Click a different tab on a card (e.g. Resources) to switch its data block.
- Click the instance name on a card to jump to the Detail View.
Detail View
A full deep-dive panel for one selected server — portfolio data with trend charts, system resources, service health, PropShield stats, and a complete alert history.
Left Sidebar (Instance List)
| Feature | Description |
|---|---|
| Instance List | All servers grouped by type with status dots. Stale servers appear first in red. |
| Group Collapse | Click a group header to collapse/expand. Preference is saved per session. |
| Search | Click the search icon to filter sidebar by instance name. |
Detail Panel Cards
| Card | Content |
|---|---|
| This Month | MTD portfolio: A-Book, B-Book, C-Book, Fee Rev, Net P/L, Volume with sparkline trend charts. |
| Today | Daily portfolio same metrics with today's trend sparklines. |
| Service Health | Per-service status rows (RUNNING / failed / ok). Shown only when agent reports health data. |
| Market Impact | Key/value pairs from the market impact block (shown when available). |
| PropShield Stats | PropShield engine metrics (only for PropShield-enabled instances). |
| Resources | CPU, RAM, Disk gauge bars with 24h sparklines. System uptime counter. |
| Alert History | Per-server table: triggered time, type, status, acknowledged by, and comment. |
How to Use
- Click Detail then select a server from the sidebar — or click an instance name from any other view.
- Scroll down in the right panel to see all metric cards and the alert history table.
- Use the Delete button (trash icon) to remove a server record after confirmation.
- Use the Acknowledge button in the alert history to mark an alert with an optional comment.
IP Groups View
A dense row-list that groups servers by public IP. Maximum information density — monitor 30+ instances on a single screen scroll.
IP Groups Row Columns
| Column | Content |
|---|---|
| Status & Name | Freshness dot, instance name (click to open Detail), PropShield PS badge, last update age. |
| Performance | Today P/L + Volume and MTD P/L + Volume. Falls back to service health or status if no portfolio data. |
| Environment details: App URL, Timezone, Feature flags (ABook/GiveUP), Git Date metadata, and Connected Client lists. (C24 only). | |
| Resources | Inline CPU%, RAM%, Disk% colour-coded by threshold. |
How to Use
- Click IP Groups in the view toggle.
- Use the dropdown filters at the top to narrow by Status, Type, or Trading Platform.
- Use the Search box to find a specific server by name, hostname, or IP.
- Servers are grouped by Public IP for easy co-location identification.
- Click any instance name to jump to its Detail View.
Allocation Overview
A physical infrastructure view grouping instances by their public IP address. Designed for operations and hardware planning.
VM Table Column Details
| Column | Description |
|---|---|
| Port | Network port number extracted from the application URL. |
| CPU / MEM / DSK | Total allocated cores and gigabytes. Heat-mapped based on utilization percentage. |
| Description | Instance name with a status dot. Mouseover to reveal the Internal IP. |
Table View
An AG-Grid powered data table with sortable, filterable columns. All instances displayed as rows for structured, cross-column analysis and reporting.
Available Columns
| Group | Columns |
|---|---|
| Identity | Instance Name, Public IP, Hostname, Instance Type, Internal IP, Platforms, PropShield |
| C24 Info | App URL, Client Timezone, ABook, GiveUP, GiveUP Markup, Git Date, C24 Time, Clients |
| Status | Server Status (Live/Stale), Last Updated, Push Age |
| Today Portfolio | A-Book, B-Book, C-Book, Fee Revenue, Net P/L, Volume |
| MTD Portfolio | A-Book, B-Book, C-Book, Fee Revenue, Net P/L, Volume |
| Resources | CPU%, RAM%, Disk%, Uptime |
How to Use
- Click Table in the view toggle. AG-Grid initialises on first access.
- Click any column header to sort ascending or descending.
- Hover a column header and click the filter icon to add per-column text or number filters.
- Click the Reset button in the toolbar to clear all active filters at once.
- Right-click a column header to toggle column visibility.
- The table theme switches automatically to match your selected dark/light theme.
Alerts View
A searchable, filterable audit log of every alert triggered across all servers. Supports inline acknowledgement with comments.
Alert Grid Columns
| Column | Description |
|---|---|
| Server | Instance name of the affected server. |
| Type | Alert type — currently stale (no data >2 min). |
| Triggered At | Timestamp when the alert was first fired. |
| Resolved At | Timestamp when the server recovered and the alert auto-closed. |
| Status | Active, Acked, or Resolved. |
| Acknowledged By | Who acknowledged the alert. |
| Comment | Optional note left when the alert was acknowledged. |
| Actions | Acknowledge button (visible only on active unacknowledged alerts). |
How to Use
- Click Alerts in the view toggle. Grid loads the full history.
- Click Refresh to reload latest alert data from the API.
- Sort by Triggered At to see the most recent outages first.
- Filter by Status column to see only Active alerts.
- Click Acknowledge on an active alert, enter an optional comment, and confirm. Saved to the database.
History View
A time-travel browser that replays the state of all servers at any historical point. Select a datetime and the dashboard renders a frozen snapshot of every instance at that exact moment.
Toolbar Controls
| Control | Description |
|---|---|
| Replay at: (Datetime Picker) | Select the exact date and time to replay. Supports any timestamp with stored snapshot data. |
| ▶ Replay | Fetches the closest snapshot and renders it as a frozen card grid. |
| ⬤ Live | Returns the view to the live real-time data stream. |
| Status Bar | Shows the loaded snapshot timestamp and how many servers had data at that time. |
How to Use
- Click History in the view toggle.
- Use the datetime picker to choose the date and time to inspect.
- Click Replay. The grid loads a frozen snapshot — historical P/L, resources, and status.
- Review the cards. This is historical data, not live.
- Click Live to return to the real-time feed.
Compare View
A side-by-side ranked comparison of all instances by any selected financial metric for Today or Month-to-Date. The fastest way to see who's winning and who needs attention.
Toolbar Controls
| Control | Options | Description |
|---|---|---|
| Period Toggle | Today / Month-to-Date | Switches all data between daily and cumulative month figures. |
| Metric Toggle | Net P/L, A-Book, B-Book, C-Book, Fee Rev, Volume | Selects which metric drives the comparison ranking. |
The table ranks all instances from highest to lowest by the selected metric. Positive values in green, negative in red. A relative bar in each row shows the instance's rank within the group.
How to Use
- Click Compare in the view toggle.
- Select a Period — Today or Month-to-Date.
- Select the Metric (e.g. Net P/L).
- The table instantly re-ranks all instances — highest at top, lowest at bottom.
- Toggle between metrics to compare performance across different book types.
Freshness Indicators
Every server card shows two freshness indicators — Push (agent-to-server latency) and Redis (trading data source age). Both use the same colour system.
| Age | Colour | Card Border | Meaning |
|---|---|---|---|
| <60s | ⬤ Green | None | Healthy — data is current |
| 60–120s | ⬤ Yellow | Subtle yellow glow | Delayed — monitor closely |
| >120s | ⬤ Red | Red glow + alert banner | Stale — alert active |
| Redis >300s | ⬤ Yellow (Redis) | Orange tint | Trading data not updating — possible platform issue |
Themes
Three display modes — selection is saved per browser and persists across sessions.
| Theme | Icon | Description |
|---|---|---|
| Default Mode | 🖶 | Follows the OS/browser preference automatically. |
| Dark Mode | 🌙 | Forces dark theme. Recommended for control rooms and low-light environments. |
| Light Mode | ☀️ | Forces light theme for bright office environments. |
The AG-Grid in Table and Alerts views automatically switches
between ag-theme-alpine-dark and ag-theme-alpine to match your selected theme.
Glossary
Key terms used throughout the application and this guide.
| Term | Definition |
|---|---|
| Instance | A single risk server running the monitoring agent, identified by its instance name. |
| Agent | The Python exporter on each risk server. Reads Redis, pushes snapshots to the central API. |
| Snapshot | A timestamped bundle of all data blocks (portfolio, resources, health) sent by an agent. |
| Stale | A server that has not sent a snapshot for more than 2 minutes. Auto-triggers an alert. |
| A-Book | Straight-through processing positions passed to liquidity providers. |
| B-Book | Internalised positions retained within the broker. |
| C-Book | Hybrid or specialised routing book (e.g. C24 specific). |
| Fee Revenue | Commission and spread revenue collected independently of position P/L. |
| Net P/L | A-Book + B-Book + C-Book + Fee Revenue combined. |
| MTD | Month-to-Date — cumulative from the 1st of the current calendar month. |
| PropShield | Risk management module for prop-trading accounts. Enabled instances show a shield badge. |
| Push Freshness | Time since the agent last delivered a snapshot to the server. |
| Redis Freshness | Time since the trading platform last wrote portfolio data to Redis. |
| Instance Type | Server role: C24 Live, C24 Backup, Main Server, PropShield Engine, Market Impact, Docs. |