Mesh StorageManage
Manage
Fleet operations — API keys, dashboard signals, and edge redaction
Day-to-day fleet operations after a device is connected:
- API key rotation — issue, roll, and revoke device API keys without re-provisioning.
- Dashboard signals — see device status, last contact, and upload activity.
- Redact — strip or hash sensitive fields before recordings leave the device.
API key rotation
Every device gets its own API key on approval. You can rotate it from Mesh Storage without re-provisioning or connecting to the device over SSH.
A rotation may be needed when a device is decommissioned, a key may have been exposed, or your security policy requires periodic credential rotation.
How key rotation works
Key rotation is designed to avoid upload downtime:
- Request a roll from the device actions menu under
devices/. The old key remains valid. - On its next sync, the device receives and persists a new key.
- Alloy revokes the old key after the device confirms the replacement.
You can cancel a pending roll before the device syncs.
Dashboard signals
The devices/ folder shows fleet status at a glance:
| Column | What it tells you |
|---|---|
| Device | Edge ID and device ID |
| Info | Hostname or machine identifier |
| Status | Pending, Approved, or Rejected |
| Last Seen | When the device last contacted Alloy |
| Last Upload | When the device last uploaded a file |
| Files/Size | Total files uploaded and their cumulative size |
