L3dgr Docker Desktop Extension

Data practices, permissions, updates, and license sync for the L3dgr extension. Authoritative legal PDFs are on L3dgr legal and compliance. For support bundles and contact, see L3dgr Support.

Data Practices Permissions Updates License Sync

Extension data practices

Plain-language summary of extension data practices. Authoritative terms are in the L3dgr legal PDFs on L3dgr legal and compliance.

Local by default

Scan, seal, verify, and staging run in the extension VM. Data stays on host paths and /var/lib/fors33 volumes until outbound sync or connectors are enabled.

Host access

The extension reads and writes Docker-shared /host paths for .f33 sidecars, manifests, receipts, audit JSONL, and staging artifacts from seal, verify, and staging runs.

May leave your machine

OAuth and license checks may contact Fors33 servers. Telemetry is optional, defaults off in Settings, and when enabled reports only event name, platform, timestamp, and status.

Not sent in telemetry

Telemetry never includes file paths, contents, hashes, emails, tokens, connector URLs, bucket names, environment variables, or stack traces from your environment.

Regulated modes

Regulated-mode tooling supports evidence workflows only; it does not certify compliance. You supply timestamp services and bucket policies your organization accepts.

Uninstall

Uninstalling the extension or deleting its Docker volumes removes local extension state. Export identity from Settings before destructive volume or extension removal.

Opt-in telemetry events

When enabled in Settings, the extension may report coarse events only:

scan_run attest_run certificate_download undertaking_pdf_download verification_receipt_download drift_export verification_report_export job_timeout job_resumed_on_mount job_polling_resync_after_sleep_gap

Extension summary · not a substitute for the published policies

Docker Desktop permissions and trust

L3dgr is a Docker Desktop Extension. Installing it grants the extension VM access consistent with Docker’s extension model. Review these points before install in regulated or shared-workstation environments.

Extension VM

L3dgr runs inside Docker Desktop’s extension guest VM, not on the host OS directly. The UI talks to a local backend over Docker’s extension socket API.

Host mount (/host)

Docker mounts your machine under /host in the VM. L3dgr reads and writes only paths you select for seals, manifests, receipts, and staging output.

Named volumes

Settings, identity, stream state, and extension databases live in Docker named volumes under /var/lib/fors33. Uninstalling without export can delete this state.

Network

Outbound HTTPS may contact Fors33 for OAuth, license sync, and optional telemetry. Connectors reach only URLs and credentials you configure in Settings.

Shared workstations

The extension can write artifacts to mounted host paths and run cryptographic operations. Use separate Google accounts and Lab seat roles on shared machines.

Marketplace listing

The Docker Marketplace listing describes required permissions and links here. Compare your installed version in Help & Support → System Information before upgrades.

Operational summary · see L3dgr EULA for license terms

Extension Updates and Continuity

Operational guidance for Docker Desktop extension updates, volume persistence, and Live Ingest continuity. For support, see L3dgr Support.

What persists across an update

  • Settings, identity, profiles, and stream state live in Docker volumes under /var/lib/fors33.
  • Use Manage → Update in Docker Desktop; do not uninstall first.
  • Check Help & Support → System Information after marketplace updates.

Live Ingest continuity

  • Licensed Live Ingest operators can keep network streams running when the L3dgr tab is closed.
  • Free tier operators see only the locked continuity card under Settings → System → Extension Updates.
  • Streams need the Docker engine running; optional host continuity releases streams before you quit Docker Desktop.

Updates with active streams

  • Updating from Docker Desktop while streams run triggers an automatic handoff across the container restart.
  • After update, verify schedules and streams in the Jobs view and Readout tab.

Optional host continuity

  • Enable in Settings → System → Extension Updates, install the host supervisor, then Release Streams to Host before quitting Docker Desktop.
  • Host ingest is opt-in, operator-attributed, and limited to the license window set at release.

Sleep and hibernate

  • Sleep or hibernate may interrupt WebSocket connectors; streams reconnect when the machine wakes.
  • Resource Saver or engine pause stops in-VM ingest unless streams were released to the host supervisor.

Reboot and outages

  • A full shutdown stops in-VM ingest unless streams were released to host first and the license window is still valid.
  • Scheduled jobs can redispatch after Docker and L3dgr start again.

License sync and offline grace

Pro and Lab tiers are described on the L3dgr product page. Billing and seats are managed in Plans and Billing.

  • L3dgr Pro and multiseat licenses refresh through GET /api/licenses/sync when the extension can reach Fors33 (Google OAuth Bearer).
  • Subscription licenses carry a JWT exp claim; renew via sync before expiry when back online.
  • Paid subscriptions include a three-day period-end grace on ledger expires_at after Stripe renewals.
  • During Stripe past_due, access remains until Fors33 revokes on unpaid; update payment in Plans and Billing.
  • Air-gapped (perpetual) licenses use updates_until in the JWT instead of exp; major updates follow your air-gap entitlement terms.