Ballast 0.4.0-beta · Windows · invited beta
Ballast operations runbook
Use the installed Start Ballast shortcut or launcher to open the app. One hidden supervisor owns the managed dashboard and its scheduler. The default address is http://127.0.0.1:8600. Opening the app again attaches to that installation; it must not start another trading scheduler.
Closing, quitting and restarting
Closing the browser/app window leaves the background engine running. Use the app's Quit Ballast or Restart Ballast controls for managed shutdown. The confirmation explains what will stop. Shutdown waits for an active trading cycle and update maintenance to finish; Cancel is available while waiting. Local protective exits cannot run while the program is stopped.
Intentional Quit is remembered in TERMINAL_STOP. Background recovery and logon startup respect it. An explicit launch reopens the app and clears that quit intent. This marker is separate from the trading STOP file.
Do not force-kill a process merely because it owns port 8600. Identify the exact installation and use managed shutdown. Do not launch an additional raw server against an active ledger. An unresponsive process needs diagnosis of its active order/cycle and maintenance state before exceptional recovery.
Trading controls and circuit breakers
- Stop trading disables scheduled trading, including local exits. Existing
broker orders or broker-side instructions may still act independently.
- The installation's STOP file is the explicit total local trading halt.
Review why it exists before using the corresponding System control.
- A loss circuit breaker blocks new entries while exit evaluation continues.
Releasing STOP does not release a circuit breaker. Review the recorded cause and use the separate breaker-release action when appropriate.
- Incomplete account/price data must be shown as unavailable or partial, not a
zero balance. A partial portfolio does not establish drawdown or free cash. Use the decision log and diagnostics; never delete ledger rows to make an unexplained loss or reconciliation warning disappear.
Starting trading or requesting a manual cycle requires review of the current capital plan. The review is bound to settings, account and mode; changes can invalidate it. Existing active settings are retained by a program update. A separate review may be required for changed crypto risk semantics before new crypto entries, while exits continue to be evaluated.
Uncertain orders and legacy ledger diagnostics
A submitted order is not a confirmed fill. Pending or ambiguous execution keeps a durable hold to prevent duplicate submission. Check the exact account, broker order/client reference, cumulative executions and local records. Do not clear a hold just to retry. Some cases require manual reconciliation; a blocked symbol can also prevent a subsequent exit until the ambiguity is resolved.
Ledger readiness is a diagnostic, not automatic repair or proof that historical records belong to the selected account. Preserve records and backups. Account selection, owned quantities and protected long-term holdings remain explicit.
After a confirmed crypto stop, the per-coin cooldown defaults to 48 hours and survives restart. Other exit management continues. The captured stop policy and its historical/recent/fixed basis are displayed for review.
Storage, backups and startup
System shows the effective private-data directory. New installations use the local Windows profile. Existing installations keep their ledger until an explicit verified migration; changing folders without migration can create an empty-looking account. See PRIVATE-STORAGE.md.
Use SQLite's backup facility or back up after a fully drained shutdown; do not copy an active database as an ordinary file and ignore its journal. Keep backups private and outside release folders. Credential protection uses Windows DPAPI; financial records are not an encrypted database. Restoring on another Windows identity may require reconnecting providers. Old plaintext/cloud versions may still need removal or key rotation after a migration.
Automatic Windows logon startup is an optional System preference. Save a choice to replace/remove legacy startup registrations. No normal first launch enables it. If Windows prevents removal of an old scheduled task, System reports that condition for explicit repair. The normal supervisor performs background recovery without a recurring visible terminal.
Updates and diagnostics
The title and System tab show the running version. Eligible signed updates offer Update now and Update later; System retains the update action. Read UPDATING.md before manual maintenance of older clients.
Finance presents account panels independently from options-research availability. Options execution remains disabled. Markets uses the provider's actual named crypto lists; topic news and article images remain research information. Map and Events are retired from navigation. AI text and historical backtests are not evidence of verified facts or guaranteed returns.
Report a problem with the version, relevant control/decision, time and a redacted error. Do not share keys, account numbers, credential files, database backups or complete logs without reviewing their private content.