An unofficial cross-platform TrueNAS dashboard and scoped management client.
The Flutter app connects securely to TrueNAS, presents live inventory and capacity charts, and provides native administration with reviewed changes through a typed Dart API. The target is full applicable WebUI workflow parity; the current implementation is partial. Management writes are covered by fake-transport and widget tests; they have not been exercised on a real appliance. This is not a claim of full TrueNAS compatibility or official endorsement.
TrueNavo replaces the former TrueRAID identity. Android and iOS use the store-registered identifier com.sloki9637.truenavo; macOS and Linux retain com.truenavo.truenavo. This installs as a separate app from earlier mobile identifiers, and existing server profiles, certificate pins and credentials are not migrated automatically. Keep the previous installation until you have reconfigured and verified the new one. The GitLab repository URL has not been renamed.
Privacy policy: www.sloki9637.com/privacy.
- Contribution and dev/main branch flow
- GitHub and store release pipeline
- Store registration and required assets
- Product plan
- Capability parity matrix
- TrueNAS API research
- NASDeck competitor research
- M0 foundation design
- M0 foundation implementation plan
- M0 implementation evidence
- Dashboard and management scope
- Full WebUI parity status — 88 requirements
- Read-only 25.10.1 appliance validation and compatibility fixes
- Native audit retention contract
- Native network transaction contract
- Native performance reporting contract
- Live metric subscriptions and chart semantics
- Dataset property editor and safety checks
- Native application lifecycle, installation and restricted settings contract
- Snapshot workspace and deletion safety contract
- Native Zvol creation, thin growth and dependency checks
- Native POSIX/NFSv4 permission editor
- Native boot environment clone, keep and next-boot management
- Native user/group byte and object quota contract
- Native periodic snapshot schedule and retention contract
- Native SMB share lifecycle and permission boundaries
- Native NFS exports, client restrictions and identity mappings
- Password sign-in and same-channel OTP continuation
- Native system update checks, staging and installation guards
- Native local replication and destination-retention review
- Native Cloud Sync and transfer-effect review
- API-key lifecycle and one-time disclosure
- Write-only cloud credentials and task-reference safeguards
- Native alert center and bounded dismissal contracts
- SSH key pairs and manually trusted connection contracts
- Passive disk inventory and guarded settings contracts
- Native pool scrubs, schedules and owned-job contracts
- Native Rsync transfer and task safety contracts
- Native system power and interruption contracts
- Sensitive configuration backup and protected file-transfer contract
- Configuration restore and automatic-reboot recovery contract
- Factory configuration reset and independent recovery contract
- Timezone and NTP configuration, remote-probe consent and clock-impact contract
- SMTP settings, protected passwords and explicit test-mail contract
- Notification services, private provider projection and reviewed email delivery contract
- Alert-class policies, whole-map preservation and proactive-support disclosure
- Typed external notification providers and write-only credential lifecycle
- Global SMB configuration, identity and restart safeguards
- Stopped-service NFS configuration and export-dependency safeguards
- Protected cron schedules and global scheduler regeneration
- Startup/shutdown command lifecycle and wait-budget limitations
- Product target: TrueNAS 25.10.7
- Compatibility target: TrueNAS 25.04 and later through version/capability adapters
- M0 app targets: Android, iOS, macOS, Windows, Linux, and web
- M0 stack: Flutter app plus the pure-Dart
packages/truenas_apipackage
Native Cron tasks adds configured enablement charts, numeric schedules in the server timezone, verified local-user selection and protected command entry. Creation starts disabled; editing and deletion require prior disable; enablement is reviewed separately. Stored command bodies are never filled into forms or generic inventory. Cron CRUD can regenerate the complete scheduler configuration even for a disabled row. Enabling authorizes future arbitrary commands with the selected account's authority, and output may reach server logs or account email. No manual run, runtime success, exact next-run prediction or command-safety certification is offered.
Native Startup & shutdown tasks adds header-only inventory, phase/configuration charts and a disabled-first COMMAND lifecycle with write-only body replacement. PREINIT, POSTINIT and SHUTDOWN have distinct execution/availability implications. The wait budget does not guarantee command or descendant termination; disabling/deleting cannot cancel work already selected or running. SCRIPT file tasks remain protected. Both new flows use private preservation proofs, single-use reviews, independent saved-configuration readback and shared pending/unknown fences. All verification uses public pinned source, synthetic transports and connector-free previews; no NAS command, scheduler update, boot or shutdown is executed during development.
Native SMB server settings adds standalone server name, workgroup, description, multichannel and non-downgrading transport-encryption changes. Reviews explain restart/client interruption and the additional account-database, cache and discovery effects of name changes. Unrelated settings stay unchanged; directory/HA/security-managed, weak-protocol, unknown-identity and auxiliary-parameter profiles are protected. Share-count charts describe configuration, not connected clients, transfer speed or a security score. Saved-config readback does not attest client connectivity or effective runtime encryption.
Native NFS server settings adds automatic/manual worker counts, protocol selection, verified IPv4 bindings and mount/lock logging changes. Every native update requires the service stopped; protocol/binding edits also require zero enabled exports and preserve all configured export dependencies. Automatic worker counts are interpreted separately from the reported computed count. Kerberos, directory integration, RDMA, port reassignment and other protected settings are not changed. Starting the service remains an independent management workflow; rc generation and logging reload effects are still disclosed. Both new settings pages use single-use reviews, shared pending/unknown fences, independent readback and connector-free previews. No actual NAS or directory server is contacted during development.
Native Alert policies adds per-class severity and notification timing, selected-class reset, configuration charts and eligible proactive-support overrides. It preserves unrelated classes and absent/default fields across the API's whole-map replacement. NEVER also hides standard alert lists; it does not suppress independent mail or proactive support. Reset can restore proactive support, so explicit external-disclosure consent and verified eligibility apply to that transition too. Global support enrollment, contacts and ticket submission are not implemented here.
Native Notification providers adds compiled forms for Slack, Mattermost, Telegram, PagerDuty, OpsGenie, VictorOps, Amazon SNS, InfluxDB and SNMP v2c traps. New rows start disabled; replacement requires fresh complete configuration and write-only credentials while disabled. Enable/disable/delete privately preserve verified attributes, and the update envelope always includes explicit enablement. Stored secrets never populate forms; HTTPS admission and separate unencrypted-transmission consent constrain supported variants. Configuration charts are not delivery statistics. Provider tests, SNMP v3 editing, queue management, delivery events and full notification parity remain unfinished. Verification uses synthetic transports and connector-free previews only: no NAS, external provider or support endpoint is contacted.
Native Notification services adds configured enablement doughnuts and provider/severity-threshold bars, protected provider summaries and the email notification-service lifecycle. New services start disabled; editing and deletion require an explicit prior disable, and enablement has its own recipient/disclosure review. The pinned API requires a complete update envelope with explicit enabled state. This workspace edits verified Mail services; other providers use the separate protected workspace above. Ongoing alert delivery can include sensitive HTML and use server-default queued retries. Disabling/deleting does not recall queued/in-flight mail or silence independent channels. All new tests are synthetic or connector-free; no NAS, SMTP endpoint or external provider was contacted.
Native Email settings adds SMTP sender/server/TLS/authentication editing, separate keep/replace/clear password intents and an explicitly reviewed single-recipient test email. System administration, alert settings and local search open the same protected workspace. Saved passwords never populate forms; updates send changed fields only, and test mail uses saved configuration with new-message queuing disabled. Existing queued mail can still retry using changed settings. TLS/SSL selection does not establish SMTP certificate verification, and server-reported test success is not recipient delivery proof. Uncertain operations retain shared write fences without retries. OAuth enrollment/migration, plaintext SMTP writes, arbitrary messages/attachments, queue management and complete notification-provider settings remain unsupported. All new verification is synthetic or connector-free; no NAS or SMTP endpoint was contacted and no real email was sent.
Native Time settings adds a timezone chooser and configured NTP source creation, editing and deletion, with preference and polling-bound charts. Charts describe configured rows, not live synchronization, measured offset or all effective chrony sources. NTP changes require explicit destination-probe and service-impact review; force stays false. Timezone updates send only the selected timezone, withholding certificate secrets from general configuration. Saved configuration is checked independently; uncertain changes retain a shared write fence and are never retried automatically. Force overrides, private peer diagnostics, HA coordination and other GUI/general settings remain unsupported. Implementation and verification use synthetic transports and connector-free previews, not actual NAS writes.
Read-only appliance validation on 25.10.1 now covers the dashboard parsers, dataset/network inventories, five historical graph families and the realtime event source. It drove fixes for pool byte-total capacity, Netdata boundary alignment and Community Edition network discovery. No real NAS writes were performed; see the bounded evidence linked above.
The current interface includes server profiles, pool/dataset/service/alert/job inventory, per-pool capacity doughnuts, and alert severity distribution. Management adds service start/stop/restart, child filesystem dataset creation, guarded non-recursive dataset deletion and single snapshot creation. Service jobs are polled by their returned ID; writes are never automatically retried.
The Administration workspace now organizes 316 reviewed operation entries in 15 areas, with native schema-driven forms, safe previews, redacted results and session-bound job tracking. Only compiled-policy operations supported by the connected 25.10 server metadata can execute. This is partial coverage of the full WebUI goal, not 316 completed features: topology, recursive ACL/ownership changes, full network recovery, console/file transfer, account-security, unsupported installer semantics and other specialized workflows remain explicitly blocked. The 88-row parity ledger tracks these gaps without narrowing the goal.
Global feature search adds a local command palette for compiled native workspaces, administration areas and the existing 316 policy entries. It matches feature names, selected Korean aliases and API method names; Ctrl/⌘ K works across authenticated pushed pages, with arrow selection, Enter to open and Escape to close. Results navigate to existing guarded screens or unavailable explanations; they do not submit actions or bypass reviews. Search itself makes no appliance query, indexes no NAS content and persists no query in the app. The palette closes and clears on backgrounding. Global shortcuts are disabled during inline authentication, over popups, while an obscured input has focus or while backgrounded; explicit offline administration search remains local navigation. This is feature navigation, not global search of actual server objects or complete Korean localization.
Dedicated network editing now covers standalone non-HA physical interface IPv4/DHCP, description and MTU with before/after review, a temporary 60-second server test, explicit Keep/Revert, shared locks and uncertain-outcome recovery checks. VLAN/bond/bridge, configured IPv6, DNS/gateway and affected app/service-listener migrations remain blocked. TrueNAS network transactions are server-global: do not edit concurrently in the WebUI or another client, and keep console access available.
Native performance reporting discovers CPU, available-memory, disk, interface, temperature, ARC and UPS histories supported by the connected server. It provides 1-hour/24-hour/7-day/30-day/365-day and custom UTC intervals, earlier/later navigation, opaque device selection, line/area/bar views, local zoom, exact sample inspection, individual series controls and a paged timestamp/value table. Zoom does not invent higher-resolution measurements. Units and missing samples are preserved; CPU aggregate/core values are not summed. The server may already zero-fill upstream gaps.
Live dashboard widgets subscribe to the authenticated reporting event source for CPU/core usage, CPU temperature, physical memory, ARC statistics, disk throughput and per-interface traffic. The memory doughnut partitions available versus not-available physical memory; ARC is separate because it overlaps reclaimable memory. Streams stop when hidden, covered, paused or backgrounded and never leave stale values labeled live after failure. Dashboard section visibility/order/reset are saved locally per profile and authenticated endpoint; health stays visible and saved orders survive updates.
The dedicated Dataset properties screen reviews filesystem byte quotas/reservations and supported compression/access-time/read-only settings with inheritance, exact target identity, capacity checks and verified read-back. It shares write locks with the other management workflows. Unknown outcomes are not retried. Pool roots, encrypted/managed datasets, unsupported properties and unverified descendant impacts remain restricted; this is not a complete storage wizard. See its contract for admission details.
The Applications workspace adds installed-state health doughnuts, catalog search/train filters, concrete-version native installation forms, and reviewed start/stop/redeploy/uninstall actions. Installation review preserves ports and paths while hiding secrets. Upgrade review uses server eligibility and release notes, submits no configuration overrides, and lets TrueNAS preserve/migrate existing settings. Own jobs are tracked through completion and independent state read-back. Unsupported installer semantics, configuration editing beyond the restricted scalar flow below, custom YAML, rollback, consoles and complete app resource histories remain gaps. Uninstall can remove Docker-managed volumes even when ixVolume removal is disabled; review its warning and backups first.
The application settings editor supports explicitly selected existing boolean, integer and string leaves with supported constraints. It shows non-secret before/after values, requires the exact app name, and consumes each submitted review so another change requires reloading. The SDK privately reads the installed schema and current configuration, rejects drift, and preserves untouched nested settings and secrets in its submitted payload without filling installer defaults. TrueNAS still validates the entire configuration; unexpected defaults or other read-back differences remain unverified. Completion requires independent private configuration read-back; failed update jobs also remain uncertain because TrueNAS can persist settings before later container work fails. Changed known ports are checked for conflicts, and unsafe numeric precision is rejected. Protected values, lists, storage, permission/device fields, conditional selectors and apps with effectful ACL/volume/GPU normalization remain blocked. Concurrent edits in other clients can race the public API's separate comparison and update calls. This is bounded native editing, not full app-configuration parity. Local suites, static analysis and the Android debug build pass; see the parity ledger for exact evidence. No NAS or credentials were accessed in this continuation.
The Snapshots workspace adds bounded per-filesystem history, exact protection details, creation/deletion, readonly clones, latest-snapshot rollback, TrueNAS hold/release and explicitly listed snapshot sets/bulk deletion. Recovery lists exact targets and dependencies; newer snapshots/bookmarks/clones are never implicitly destroyed. Snapshot sets operate sequentially on visible filesystems, not as an atomic recursive operation. Partial or uncertain changes stop without retries. The public API has no atomic identity-compare/mutate operation: avoid concurrent edits in other clients.
Native Accounts adds user/group creation, profile/shell/SMB/lock settings, password/SSH-key replacement, memberships and guarded deletion, with protected/current/last-administrator checks. Native Virtual machines adds creation/configuration, reviewed lifecycle controls, stopped-only storage-preserving deletion and existing zvol/NIC/ISO/display device controls. Native Activity adds filtered job progress, one-shot exact-job cancellation with terminal-state verification, and a bounded audit metadata viewer with actor/service/result/time filters. These new writes were implemented and tested only with fake transports; no supplied NAS credentials or live writes were used. See Accounts, Virtual machines, Snapshots and Activity for exact boundaries and primary contracts.
Native Zvols adds provisioning-count doughnuts, exact storage accounting, creation, thin-volume growth, selected settings and guarded deletion. Configured VM/iSCSI/NVMe consumers are checked even when disabled; reserved-volume growth remains blocked because server allocation overhead cannot be safely replaced with a client estimate. Native Permissions edits ordered NFSv4 and POSIX ACLs and bounded ordinary mode on existing dataset roots, with identity lookup and owned-job verification. These nonrecursive changes can still affect descendant access. Native Boot environments adds relative used-space bars, reviewed clone/keep/next-boot activation and protected deletion; activation does not reboot. Every workflow has exact-target review, shared mutation locks, session fencing and independent readback. These additions were tested locally only; no NAS connection or write acceptance was performed.
Native User and group quotas adds numeric identity resolution, separate exact byte/object limits, explicit Unlimited and honest known-usage bars on existing unencrypted unmanaged filesystems. Native Snapshot schedules adds creation, changed-field editing, enable/disable, one explicitly queued run and policy deletion, with server-timezone cron controls and bounded existing-snapshot retention-impact manifests. Queued means accepted, not snapshot completion; retention changes can affect existing recovery points. Both use single-use reviews, shared locks, identity/dependency rechecks and independent readback without automatic replay. Project/bulk quotas, replication/VMware coordination, removal-date fixation and exact next-run/expiry simulation remain outside these bounded workflows. Their source-linked contracts describe the remaining races and restrictions; no live write acceptance is claimed.
Native SMB and NFS shares add searchable inventories, configured enablement doughnuts, service state, and reviewed creation, changed-field editing and configuration deletion on admitted existing dataset roots. SMB supports ordinary default-purpose shares with immutable existing names/paths, read-only and enabled settings; NFS adds bounded IPv4 hosts/networks and verified local maproot/mapall identities. Saving can reload protocol configuration and affect existing clients; deleting a share does not delete its dataset or files. Exact-target reviews, shared mutation locks, fresh identity/dependency checks and independent readback guard every operation; ambiguous outcomes are never replayed. Advanced presets, SMB share ACLs/rename/sessions, NFS Kerberos/IPv6/HA and complete protocol-wide settings remain outside this slice. All new verification uses public pinned source, fake transports and connector-free previews; no appliance was contacted or modified.
Password sign-in now uses the same verified TLS path as API keys, with transient secret entry and manual same-channel OTP continuation. Passwords and codes are not saved; redirects and unknown authentication responses fail closed. Two-factor enrollment and recovery are not included. Native System updates provides a local readiness/capacity view, explicitly reviewed upstream checks, selected-release download/install and owned-job monitoring. Local reload never calls update APIs; install forces no resume and no automatic reboot, requires protected recovery environments and retains a fresh-session fence after installation. These workflows were tested only with synthetic transports and connector-free previews.
Native Replication adds local single-source manual PUSH task creation/editing, enablement, reviewed run/deletion and owned-job checks, with destination snapshot identity and retention effects disclosed. Native Cloud Sync adds S3/Dropbox existing-credential references, PUSH/PULL and COPY/SYNC/MOVE, schedules/exclusions and reviewed task lifecycle on admitted leaf datasets. Configuration doughnuts report task counts, not backup integrity or transferred bytes. Both use exact-target confirmation, stale-review rejection and shared pending/unknown fences. Remote replication, restore and additional providers remain missing; no real transfer or server write was tested.
The Data protection overview combines snapshot schedules, replication, Cloud Sync and Rsync inventories with enablement doughnuts, last-recorded-state bars, local search and native-workspace links. Failed sources are excluded and marked unavailable, never shown as successful empty inventories. Unsupported Rsync settings remain withheld summaries; recorded RUNNING/WAITING is not current activity. Opening a workspace from this overview refreshes only that selected inventory. Charts describe loaded policies, not recoverability or a live atomic snapshot; exact next-run prediction, TrueCloud Backup and VMware remain missing.
Native API keys adds own eligible local-account key creation, name/expiry editing, rotation and deletion with current-key protection and explicitly revealed one-time secrets. Stored key hashes are not queried; plaintext never enters controller state and is discarded on close, background or connection change. Rotation/deletion do not terminate existing sessions; expiry edits alone do not guarantee immediate authentication-policy refresh. Native Cloud credentials adds S3/Dropbox write-only creation, name-only rename, complete provider replacement and unreferenced deletion. Existing secrets are not read. Both use single-use reviews, fresh identity/dependency checks and shared uncertainty fences; all errors after mutation dispatch remain unknown without retry. OAuth enrollment, other providers and complete account-security management are still missing. No real NAS connection or credential write was tested for these additions.
Quick management adapters explicitly recognize 25.04, 25.10 and 26.0 release version families and require advertised methods. Schema-driven administration and dedicated network/reporting/dataset/apps/snapshot/accounts/VM/activity/Zvol/permissions/boot/quotas/snapshot-schedule/SMB/NFS/update/disk/pool-maintenance/Rsync/system-power adapters currently admit only the verified 25.10 adapter family. Other versions remain monitoring-only. Account permissions are enforced by TrueNAS. Full WebUI and chart parity is still unfinished: recursive ACL/ownership and account-security flows, consoles, complete topology/device editors, automatic reconnection, manual update uploads and complete restore workflows remain gaps. No billing, advertising or external analytics collection is implemented.
Since M0, explicit trust-on-first-use certificate pinning and opt-in credential storage have been added for the native platforms. Only the Android bridge has been exercised against a real TrueNAS appliance; the iOS, macOS, Windows, and Linux runners remain unverified.
The native Alert center adds safe coded metadata, severity/status/source charts, filtering and reviewed dismiss/restore for 15 source-audited ordinary alert classes. One-shot/custom/HA changes stay blocked. The home dashboard now excludes dismissed alerts from active counts and never displays raw server alert text, HTML or arguments. SSH credentials adds public-only inventory, write-only OpenSSH keypair import, explicit generate-and-store, manual host-key fingerprint review and unreferenced rename/deletion without cascade. No host scan or SSH authentication occurs automatically; private material is not disclosed or retained in app state. The File sharing overview joins SMB/NFS inventories with enablement doughnuts, read-only ratio bars, reported service state and exact-path grouping; it does not prove client access or include block-storage protocols. These additions use synthetic tests only, without NAS contact or real writes.
Native Disks adds bounded passive inventory and reviewed description changes, plus standby/advanced power-management settings for verified non-boot ATA HDDs. Serial identity, boot/ownership state, HA and visible jobs are rechecked; updates send changed fields only. Password/SED/KMIP values are excluded, and temperature remains unknown because this workspace does not probe hardware or run SMART tests. Readback proves stored settings, not physical sleep, power state or health; delayed server power commands can still race external edits or hot-swaps. Wipe, replacement and complete disk diagnostics remain outside this slice. See the disk contract.
Native Pool maintenance adds nullable scan metadata and reported-progress bars, manual scrub START/STOP, and per-pool schedule creation/editing/deletion/enablement with server-timezone cron and an enabled/disabled doughnut. Manual actions own the public non-transient scrub job: accepted work keeps the shared write fence until explicit job verification, without automatic polling. Only a reviewed STOP of the same already-observed scrub can pass an owned START fence; unknown outcomes require original-server inspection and fresh-session recovery. Schedule deletion or disabling does not stop a scan. Pause/resume, resilver control, unhealthy/boot/HA pool changes, topology/expansion/upgrade and full storage parity remain unsupported. These disk and pool additions used pinned TS-25.10.1 source, fake transports and connector-free previews only: no NAS connection, supplied credential use or actual write test occurred. See the pool maintenance contract and current verification ledger.
Native Rsync adds projected task inventory, an enabled/disabled doughnut, explicitly stale last-recorded job-state bars, disabled task creation/editing, separate enable/disable/delete reviews and one explicitly authorized SSH PUSH transfer. Source selection is an admitted leaf ZFS dataset, a verified local non-root account and an existing pinned SSH connection; stored private keys never enter inventory or forms. Native tasks use fixed --one-file-system protection with no custom arguments; existing safe tasks lacking it must be edited before run/enable. Every create/update/enable/disable explicitly disables remote path validation and host-key scanning. Exact-target before/after reviews warn that copying the source directory without an added trailing slash can overwrite destination files even with deletion disabled. Enablement permits future scheduled transfers; disable/delete does not stop a running transfer. Accepted jobs retain shared write locks until explicit issued-job checks, and unknown outcomes are never replayed. Server-reported success is not complete-copy or integrity proof. MODULE/PULL, mirroring, remote setup/probes, cancellation, HA and live acceptance remain missing. All new development and tests are connector-free; no NAS, supplied credential, SSH destination or real write was used. See Rsync contracts and limits.
Native System power adds public host/boot identity and last-read readiness, separate reason drafts and exact-target interruption reviews for standalone reboot/shutdown. It requires READY, an idle healthy boot pool, no visible active/waiting jobs and the same bootable running/next environment. Both methods are jobs: acceptance or disconnection is not proof that the server restarted or powered off. Accepted and uncertain outcomes retain shared write fences; no polling, power retry or automatic reconnect is added. Generic administration cannot bypass this native flow. HA power coordination, changed next-boot environment admission, forced/delayed operations, durable app-restart recovery and live acceptance remain missing. Implementation and verification use pinned public source, fake transports and connector-free samples only; no NAS access or real power action occurred. See system power contracts.
Native Configuration backup adds manual export with separate secret-seed and SSH authorized-key options, full-host confirmation, and explicit sensitive-file consent. The database can contain stored encrypted dataset keys and SSH private keys; including the seed can decrypt stored secrets. This is not a separate or complete encryption-key export, so keep independent recovery material. The SDK verifies a bounded SQLite/TAR envelope and the exact successful export job before releasing a one-use in-memory artifact. Android downloads revalidate the existing connection's exact certificate pin and authority; redirects, arbitrary URLs, automatic retries and external-browser fallback are not supported. A two-phase Android document picker checks the current session again before passing file bytes to the selected provider. The provider can be cloud-backed, and cancellation or failure can leave an empty or partial document; the app does not automatically delete it. Other platforms and unpinned connections remain unavailable for this flow. This is configuration export only, not verified restoration, pool-data backup, configuration upload or factory reset. See backup contract.
Native Configuration restore adds a separate trusted-file import workflow for standalone 25.10 servers with FULL_ADMIN access. Android reads a manually selected SQLite or uncompressed TAR file into bounded memory (10 MiB maximum); only format, size, SHA-256 and actual seed/authorized-key member presence are shown. Envelope inspection does not validate ownership, compatibility, database integrity or recoverability. Explicit recovery-access, independent-backup, trusted-file and replacement/reboot reviews precede an existing-session certificate-pinned upload. TrueNAS configuration upload can replace accounts, addresses and certificates, remove missing seed/key files and automatically reboot. A returned job ID proves acceptance only. Accepted or uncertain submissions retain a shared write fence without automatic polling, retry or reconnect; recovery requires deliberate reconnection and independent original-machine inspection, including separate confirmation if the address changed. HA restoration, other-platform secure import, durable app-restart recovery and real restore acceptance remain unimplemented. All new verification is synthetic or connector-free; no NAS contact or real upload occurred. See restore contract.
Native Factory reset adds a separate standalone FULL_ADMIN recovery review with exact host confirmation, independent-access/backup/key-recovery checks and explicit configuration-loss/reboot consent. Only config.reset [{reboot:true}] is admitted; the no-reboot variant is not a dry run and remains unavailable. TrueNAS replaces the live database before later hooks, so even an error can follow changes. A previously staged configuration restore can supersede factory defaults on restart; the app cannot detect or clear it and requires independent inspection. This is not secure erasure, pool-data backup or verified recovery. Accepted and uncertain requests retain a shared write fence; no automatic polling, reset retry, extra reboot or reconnection occurs. Manual reconnection requires normal TLS/authentication, claimed original-host/readiness verification and independent inspection, with an extra acknowledgment for a changed address. HA reset, initial account setup, durable app-restart recovery and live acceptance are unsupported. No actual reset, NAS contact or supplied-credential use occurred. See factory-reset contract.
TrueNavo is an unofficial third-party project and is not affiliated with, endorsed by, or certified by iXsystems, Inc. TrueNAS is a trademark of iXsystems, Inc.