Fabric → Proxies
A proxy is a public-facing component — like a worker or sensor — that lets external session guests reach a shared session without exposing your core server. Admins declare which proxies are legitimate; each proxy authenticates with its own token and reports live status. Operating proxies requires the Session Proxy add-on; anyone with the read permission can always see the proxies that exist.
Proxies are viewed and managed on the Fabric page’s Estate tab, alongside your Workers and Sensors. Filter the Estate to Proxies to focus on them.
What you can do
- See every declared proxy and its live status.
- Register a proxy and obtain its deployment token.
- Edit a proxy.
- Regenerate a proxy’s token.
- Enable or disable a proxy.
- Delete a proxy.
Table columns
On the Estate tab, proxy rows show:
| Column | Notes |
|---|---|
| Name | Proxy display name. |
| Type | Proxy. |
| Status | pending (awaiting connection admission), online (connected and ready), offline (disconnected), or error. |
| Location | The location the proxy is assigned to. |
| Version | The proxy agent version. Blank until the proxy connects. |
| Activity | Live count of guest sessions the proxy is relaying. |
| Last Heartbeat | Timestamp of the most recent check-in, or Never until the first connect. |
| Actions | View details / Edit / Regenerate Token / Delete. |
Open View details to see the proxy’s live guest sessions. A Live badge above the table indicates that these values update in real time as proxies check in.
Fields
| Field | Meaning |
|---|---|
| Name | Required. A descriptive label, unique across proxies. |
| Description | Optional notes. |
| Location | Required. The location this proxy serves. |
| Enabled | Edit only. An administrative marker recording that the proxy is meant to be out of service; it does not currently interrupt the proxy’s traffic. |
Common tasks
Register a proxy
- On the Fabric Estate tab, click Create and choose Proxy.
- Fill the form: Name, optional Description, and Location.
- Click Create.
- A dialog shows the deployment token. Copy it — the full token is only shown once.
Deploy the proxy agent
The proxy agent is the mistershell/proxy container, run on a public-facing host that external guests can reach. MisterShell does not install it for you.
- Set the core’s public URL as
MISTERSHELL_URL(your load balancer / GSLB hostname) — the proxy connects out to it. - Set the deployment token from the previous step as
PROXY_TOKEN. - Publish the proxy’s port (
:8000by default) behind your own TLS-terminating load balancer, then start the container.
Both MISTERSHELL_URL and PROXY_TOKEN are required — the agent exits immediately if either is missing. It authenticates to core and moves from pending to online. See Deployment → Docker Compose examples for a complete run example.
Regenerate a proxy’s token
Use this when a token has been exposed or on a rotation schedule.
- Click the Regenerate Token action on the row.
- Confirm in the dialog.
- A dialog shows the new token. Update the proxy’s configuration and restart it with the new value — the old token stops working immediately.
Edit a proxy
- Click the Edit action on the row.
- Update name, description, location, or enabled state.
- Click Update.
Delete a proxy
- Click the Delete action on the row.
- Confirm.
The proxy’s entry is removed; if the proxy is still running on its host, it can no longer authenticate. Stop and uninstall the proxy process on the host to complete decommissioning.
Readiness
A proxy only serves guests once it is online — that is, it has connected and authenticated to core. A pending or offline proxy refuses guest traffic. Declare and start the proxy before sending out guest invites, so guests have a working path in.
Licensing
Proxies are gated by the Session Proxy add-on; its licensed capacity is the maximum number of proxies. A usage indicator shows used / licensed, colored green, orange when only one slot remains, and red at the limit. Creating a proxy beyond capacity is rejected; existing proxies keep working and deleting one is never blocked. Without the add-on, existing proxies stay visible, but Create, Edit, and Regenerate Token are locked with a padlock explaining what is missing.
Permissions
- Read:
app.fabric.read. - Create / edit / regenerate token:
app.fabric.write. - Delete:
app.fabric.delete.