Counting installations
A security fix matters differently at ten installations than at ten thousand; this count is the only way to know which. The setup wizard asks, with the box unchecked. An installation upgraded to 2.0.0 was never asked and stays off. Switch it under Admin → System at any time, no restart.
What is sent, in full, once a day and nothing else:
GET /v1/openwhistle/count?id=<32 hex characters>&v=<version> HTTP/1.1
Host: telemetry.wdkro.de
Accept: */*
Accept-Encoding: gzip, deflate
Connection: keep-alive
User-Agent: openwhistle/<version>
Over HTTPS; no cookie, no body. The last four headers are what the HTTP library sends with
every request (Accept-Encoding grows if a brotli or zstd package is ever installed).
| Not sent | the hostname, any address, APP_PUBLIC_URL, any count of reports, users or organisations, any setting |
| The identifier | 16 random bytes made on your server when you first agree, and kept in the database. Admin → System shows it and Reset identifier replaces it: the next report is then a new installation as far as anyone can tell |
| Why random | a value derived from the hostname or a machine id could be recomputed by anyone who knows the host, which turns a count into a lookup |
| At the far end | one line: timestamp, identifier, version. Your address is not recorded. Lines are kept 35 days, then only the rolled-up number |
| When | checked every hour, sent when 24 hours passed since the last success; the first attempt waits a random part of an hour after start. With several replicas only one sends (Redis lock) |
| A failure | 10 seconds for the whole request, redirects refused, one debug log line; retried at the next hourly check, never in a loop, never shown on a page |
| Never counted | DEMO_MODE (the public demo) and LOCAL_REVIEW_LOGIN instances |
TELEMETRY_ENABLED overrides the switch: false keeps it off,
true on, and Admin → System shows it as set by the
environment. Unset or empty (the Compose default), the switch decides.
The number is a lower bound and cannot be made tamper-proof: the endpoint is open, so anyone can invent identifiers. It tells ten installations from ten thousand, and shows whether a fix has spread; no more is claimed.