Documentation Administration Maintenance windows
ADMINISTRATION

Maintenance windows

A maintenance window says when scheduled work may act on a computer. This page explains the two kinds of window, how windows set at different levels combine, and what a window never does.

What a maintenance window is

A maintenance window says when scheduled work may touch a computer. It exists so that recurring maintenance happens at times the client can live with, and never at times they cannot.

A window is a limit, not a trigger. It never starts anything. A schedule starts recurring work, and the window decides whether that work may act at that moment.

Allow and exclude

There are two kinds of window.

Kind What it means
Allow Scheduled work acts only inside the window
Exclude A blackout. No scheduled work runs during it, whatever else says otherwise

Use an allow window to keep scheduled maintenance to the evening or the weekend. Use an exclude window to protect a period when nothing should change, such as a client's month-end.

Where a window applies

You declare a window at one of four levels:

  • every client
  • one client
  • a tag
  • one named computer

When more than one window covers a computer, the more specific one wins. A window on one computer beats a window on its tag, which beats one on its client, which beats one set for every client.

An exclude works differently. It is a veto at any level. A blackout on one computer stops scheduled work on that computer even when an allow window for every client says the time is fine.

A window is read in the tenant's time zone where one is set, and in your default time zone otherwise.

What a window does not do

  • It does not schedule anything. A window limits when scheduled work may act. It never causes work to happen.
  • It does not hold back a person. Run maintenance pressed by a person starts immediately, whether or not a window is open. Windows govern scheduled work only.
  • It does not decide restarts. Whether a computer restarts after maintenance is a matter for the restart policy.
Alert windows are separate. If you use Overseer as part of the Overmind suite, the windows that quieten alerting are a different thing with a similar name. Quietening alerts does not stop work, and stopping work does not quieten alerts.

How windows fit with the other controls

Four separate controls shape unattended work. Each decides one thing.

Control What it decides
Schedule When recurring detection and maintenance start
Maintenance window When that scheduled work may act on a computer
Restart policy What may happen about a restart
Standing authorisation What Overseer may do on its own without asking

Who can set a window

Setting a maintenance window requires the capability to act on computers. That is the same capability that covers deployments, schedules and restart policy, so grant it with care.

Next steps

Creating and managing schedulesSet when recurring detection and maintenance run, and for whom. Restart policyThe rules a computer follows when maintenance calls for a restart. Standing authorisationsNamed grants that let Overseer act on its own within a fixed scope.
Was this article helpful?
← Reporting Restart policy →

In development. Launch inquiries welcome.

This documentation describes Overseer as it is being built. If you would like to hear when it launches, get in touch.

Ask about launch