---
title: Devices and targets in the app
description: Approve a device, start a thread on its folder, allow its camera and GPU, and manage targets and their approval cards from the desktop app.
---

Two ways to work beyond this computer, both run from the app:

- a **device** is another machine of yours with Ysra installed, such as a
  server or an edge box. The work happens there; you follow it here;
- a **target** is a machine where nothing can be installed. I reach it from
  this computer over your own SSH or command-line sign-in.

This page covers what you do in the app. The full guides are
[Devices](../devices/overview.md) and [Targets](../targets/overview.md) in the
CLI docs.

## Devices

> Diagram: A device signs in with a code you approve, connects out, and does the work on its own folder.

### Approve a device

On the device, run `ysra login --device`. It shows a short code. Then, in the
app, open **Settings → Devices**:

![Approving a device by its code](../assets/screens/desktop/device-approve.webp){ width="1242" height="962" }
/// caption
You see what is asking before you approve it.
///

1. Type the code and choose **Find it**.
2. Check the name and system shown.
3. Choose **Approve**.

A device can't touch your account or your balance, and you can remove it at any
time.

### Start a thread on a device's folder

The device shares folders with `ysra serve --folder <path>`. In **Settings →
Devices**, choose **Folders on edge-01…**, then **New thread** beside a folder.

![A device's shared folders with New thread](../assets/screens/desktop/device-folders.webp){ width="1242" height="718" }
/// caption
Folders the device is sharing.
///

The thread looks like any other, with **on edge-01** in its header: the work
runs on the device, and this computer only shows it.

![A new thread on a device's folder](../assets/screens/desktop/device-thread-header.webp){ width="1440" height="994" }
/// caption
"on edge-01" marks a thread that runs on a device.
///

### Observe or change

Each device has a switch: **Observe** (I only look around and run checks
there) or **Change** (I may also edit there, with your OK). Devices start in
observe.

### Camera and GPU

My commands can't see a device's hardware until you allow it, once per thread:

![The card asking to use the camera and GPU on a device](../assets/screens/desktop/device-thread-hardware-card.webp){ width="1440" height="891" }
/// caption
The card names the impact before you allow it.
///

### If a device shows as offline

| The app says | Do this |
|---|---|
| *edge-01 is offline. Run `ysra serve` there.* | Start `ysra serve` on the device |
| *edge-01 isn't sharing a folder. Run `ysra serve --folder …` there.* | Share a folder from it |

**Remove** signs the device out at once.

## Targets

> Diagram: Every command on a target passes fixed rules and your approval on this computer before it runs.

### Add and manage targets

**Settings → Targets** lists your targets. They are stored only on this
computer.

![Settings, Targets tab with a log open](../assets/screens/desktop/settings-targets.webp){ width="1242" height="870" }
/// caption
A target, its mode, and its log.
///

**Add a target…** asks for a name, a kind and how I reach it. For SSH, choose
**Check its host key**, compare the fingerprint with the server's own, and tick
**Yes, this is my server**.

![Adding a target and checking its host key](../assets/screens/desktop/target-add.webp){ width="1242" height="1686" }
/// caption
Confirm the host key before the target is added.
///

A new target starts in observe mode. Each row has **Observe / Change**,
**Production**, **Log** and **Remove**.

### Approval cards

| Card | When | Answers |
|---|---|---|
| **Look around edge-01?** | The first read in a thread | Allow for this session · Not now |
| **Run this on edge-01?** | Every change | Run it · Skip |
| **This can't be undone on edge-01** | A destructive command | Run it · Skip |

A change card shows **On**, **Runs**, **Why**, **Expect** and **Undo**:

![A change card for a target](../assets/screens/desktop/target-change-card.webp){ width="1440" height="891" }
/// caption
The exact command, why, what to expect, and how to undo it.
///

On a production target, a destructive command also needs its name typed.
**Run it** stays off until it matches exactly:

![A destructive command waiting for the target's name](../assets/screens/desktop/target-destructive-typed-name.webp){ width="1440" height="891" }
/// caption
Type the target's name to run it.
///

Only you can answer these cards; auto mode never does. A card left unanswered
for 15 minutes counts as declined. If you quit the app, every waiting target
question is declined.

### Runbooks

A runbook's plan appears as one card with every step, its check and its
recovery step. **Start** runs the read-only checks first, then asks before each
step and stops at the first check that fails.

![A runbook's plan card](../assets/screens/desktop/runbook-plan.webp){ width="1440" height="891" }
/// caption
The whole plan, before anything runs.
///

More: [Runbooks](../targets/runbooks.md).
