CREATE USER
OPERATIONS ACCESS
GoldSec sign in
Trading, intelligence, and infrastructure. Sign in to oversee your GoldSec fleet.
Use your GoldSec account. Workspace visibility and controls are determined by assigned privileges; admin is the dashboard superuser; Linux/system accounts are separate.
ACCOUNT SECURITY
Change password
Use a unique password or passphrase of at least 14 characters. Other sessions for your account will be signed out.
OPERATIONS / OVERVIEW
Fleet overview
Health, deployment progress and the next action for every system.
One view. Every system.
Live observations, planned downtime and installation progress stay separate.
Fleet inventory
NEXT ACTIONS
Needs your attention
PLANNED SYSTEM WORKFLOW
Bootstrap once. Fleet continues remotely.
Run one command on a fresh system. Its authenticated outbound Fleet agent continues the reviewed role plan over HTTPS; Remote Desktop pairing is optional for inspection and later administration.
Fresh-node enrollment is active: create the node, run the one-time bootstrap, and Fleet continues the reviewed role plan over authenticated HTTPS. Production trading remains explicitly gated after staged readiness.
- 01Pending nodeChoose a system type
- 02BootstrapNode.js + Remote Desktop
- 03Verified handoffConfirm machine identity
- 04Manager installationRole plan + health checks
FLEET CONTROL
Selected machine
Choose a VM. Review its current state before making a change.
Terminal observations & infrastructure
Bottle management
Create a fresh Bottle, clone an existing working Bottle, or permanently delete a stopped Bottle on the selected VM.
Clones preserve the source Wine prefix, installed libraries and applications. A clone is not launched automatically. Active Bottles cannot be deleted.
Management VM diagnostics
Power & terminal
Actions affect only the selected VM. Reboots and stops interrupt running applications.
Stopping a terminal does not close existing broker positions. A VM reboot restores enabled startup services.
Managed services
Start, stop, restart, inspect startup status, or read recent logs.
Service journal
Last 120 entries within two hours. Credential-bearing entries and long identifiers are omitted.
Process manager
Application process controls. Protected system and management processes use service controls.
CPU is the process lifetime average, not an instantaneous sample. Killing MT5 may trigger automatic recovery.
System inventory
Filesystems
Network counters
Action history
Accepted requests and host results. A submitted request alone does not confirm recovery.
Authentication history
UNIVERSAL NODE MANAGEMENT
Node inventory
Register a fresh machine or inspect an existing fleet member.
Node configuration & registration
Backup & recovery status: verified full-system recovery sets are available in Backups & recovery with authenticated downloads. Application-role capture is active; only two-copy-verified role snapshots become deployable/downloadable. Full boot certification remains pending an isolated recovery rehearsal.
Advanced: register an already-paired device
The selected device ID is the execution target. The hardware catalog is inventory, not a compatibility guarantee. A fresh system must have an operating system and a paired Remote Desktop agent before software installation.
NODE OPERATIONS / VISUAL TELEMETRY
Worker, tester & AI Unit telemetry
Screenshots and performance history stay with compute nodes; the management server remains out of this visual wall.
AI LAB → FLEET FEEDBACK LOOP
Model lifecycle & learning status
OBSERVED CHANGES
Operations event tape
Polling observations, not a complete audit trail. Short outages between samples may be missed. Historical restart totals alone do not create new alerts.
INSTALLATION CONTROL
Deployment queue
Bootstrap progress, connector handoffs and manager-owned plans.
Enrollment history & connection controls
Registered deployment jobs
DATA PROTECTION
Backups & recovery
AGX Orin is the primary repository. The external HDD is its recovery mirror.
Loading market-aware backup policy…
Only two-copy-verified recovery/application artifacts are downloadable. Archives stay encrypted and the recovery keys remain separate. Full-system restore still requires an isolated boot rehearsal before it can be called boot-certified.
CONTROL PLANE
Remote Desktop connections
Remote Desktop has two independent layers: each machine runs a sharing agent, and GoldSec Fleet separately authorizes a controller session to discover and manage those paired devices.
Two approvals, one clear handoff
Device sharing / pairing is what desktop-commander remote does on each machine. Fleet controller authorization is a separate OAuth approval that lets this manager list and operate those already-paired devices.
A manually running sharing agent can therefore be online while Fleet still reports the controller as unauthorized. Neither approval copies broker logins or starts live trading.
IDENTITY & ACCESS MANAGEMENT
Users, sub-accounts, roles, groups & fleet scope
admin is the immutable dashboard superuser; Linux/system accounts are separate. Create dashboard sub-accounts for teams or operators; effective access is the union of role, groups and direct grants, with Fleet/Site or node scope enforced by the APIs.
Use roles for a person's base job, groups for department/team access, and direct grants only for exceptions. Fleet and trading permissions can be restricted to specific machines.
ROLE TEMPLATES
ACCESS GROUPS