Field report #2252. Operator runs the Darling service on Windows Server 2012, which cannot run the Viewer. They have the web viewer and a Viewer on a remote PC. There is no supported way for them to add a second server.
The three doors are all shut
| path |
why it fails |
darling.json |
seeds config_monitored_servers only when that table is empty; after the first start the store is authoritative and file edits are a silent no-op (#2254) |
| web viewer |
add_servers / remove_server are in DarlingWebEndpoints.ExcludedToolNames, deliberately kept off /api/read/* because they write the registry |
| CLI |
no verb exists. The full list: --backfill-rollups --collapse-legacy-slices --config --configure-firewall --configure-network --disable-mcp --disable-web --dry-run --enable-mcp --enable-web --encrypt-password --export-viewer-config --help --no-vacuum-full --print-viewer-connection --recompress-plan-dim --test-connection --vacuum-full --validate-config --version |
What remains is a GUI on another machine (which then hits the DPAPI credential problem in #2255) or standing up an MCP client. Neither is a reasonable answer for a headless Windows host, and the operator reached the end of the documented surface before asking.
Why "just INSERT the row" is not the workaround
server_id is ServerIdHelper.GetDeterministicHashCode(StorageName) where the storage name is built from host + database + read-only intent. A hand-written INSERT with any other value leaves the collectors writing history under the identity they compute while the registry points elsewhere — the split-history class in #2158. So the identity computation is exactly the part an operator cannot safely do by hand, and exactly what add_servers already does correctly.
Fix shape
An --add-server CLI verb that delegates to the same code path as the add_servers MCP tool — identity computation, per-entry validation, and the in-process connection probe included, so it cannot diverge from the tool. It should also bump config_service.config_version, since the service hot-swaps on that beacon each sweep and therefore needs no restart.
Worth deciding alongside:
Credential handling is the one wrinkle: --encrypt-password already exists, so a verb taking an already-encrypted blob (or integrated auth, which stores nothing) needs no new secret handling.
Field report #2252. Operator runs the Darling service on Windows Server 2012, which cannot run the Viewer. They have the web viewer and a Viewer on a remote PC. There is no supported way for them to add a second server.
The three doors are all shut
darling.jsonconfig_monitored_serversonly when that table is empty; after the first start the store is authoritative and file edits are a silent no-op (#2254)add_servers/remove_serverare inDarlingWebEndpoints.ExcludedToolNames, deliberately kept off/api/read/*because they write the registry--backfill-rollups --collapse-legacy-slices --config --configure-firewall --configure-network --disable-mcp --disable-web --dry-run --enable-mcp --enable-web --encrypt-password --export-viewer-config --help --no-vacuum-full --print-viewer-connection --recompress-plan-dim --test-connection --vacuum-full --validate-config --versionWhat remains is a GUI on another machine (which then hits the DPAPI credential problem in #2255) or standing up an MCP client. Neither is a reasonable answer for a headless Windows host, and the operator reached the end of the documented surface before asking.
Why "just INSERT the row" is not the workaround
server_idisServerIdHelper.GetDeterministicHashCode(StorageName)where the storage name is built from host + database + read-only intent. A hand-written INSERT with any other value leaves the collectors writing history under the identity they compute while the registry points elsewhere — the split-history class in #2158. So the identity computation is exactly the part an operator cannot safely do by hand, and exactly whatadd_serversalready does correctly.Fix shape
An
--add-serverCLI verb that delegates to the same code path as theadd_serversMCP tool — identity computation, per-entry validation, and the in-process connection probe included, so it cannot diverge from the tool. It should also bumpconfig_service.config_version, since the service hot-swaps on that beacon each sweep and therefore needs no restart.Worth deciding alongside:
--remove-server/--list-serversfor symmetry. A verb that can only add leaves the same operator stuck on a rename or a decommission.--test-connectionshould gain the store-vs-file comparison from [BUG] Servers added to darling.json after the first seed are silently ignored, and --test-connection still validates them #2254 while it is being touched — the two issues are the same operator journey.Credential handling is the one wrinkle:
--encrypt-passwordalready exists, so a verb taking an already-encrypted blob (or integrated auth, which stores nothing) needs no new secret handling.