Exit Nodes

In Settings the section is named Exit Nodes. The same product capability is edge tracking nodes (Edge Tracking Nodes): separate servers closer to the audience. The admin SPA stays on the mother tracker only — the node has no SPA and no /admin. An EDGE campaign’s clicks are handled on the node; campaigns, offers, landings, and Track Paths arrive from the mother as releases (configuration snapshots).

Purpose. Install a node over SSH, bind a tracking domain (DNS to the node IP), switch the campaign to EDGE, assign a node+domain pair, build a flow, and confirm the assignment is ready before putting the URL into ads.

Exit Nodes list
Settings → Tracker → Exit Nodes. The shot shows Degraded — for live ads aim for Online and a fresh heartbeat; Degraded usually means config or connectivity is not healthy yet.

How this fits normal tracking

An Exit Node is a VM you install from Settings → Tracker → Exit Nodes. A Domain with Ingress target = Exit Node must resolve to that node’s IP, not the mother tracker’s CNAME/IP (otherwise Check DNS fails). DNS/SSL detail: Domains.

A Campaign uses mode EDGE (Exit Node): failure policy plus assignments (node → domain). Offers and Landings are created as usual and placed in Flows — there is no separate “edge copy”; the node gets a snapshot of the same entities. Ordinary edits sync automatically; if a snapshot stalls, Issue release on the node list force-pushes the current config.

When EDGE helps (and when it does not)

Use EDGE when you need tracking closer to the audience geo (your own IP/server in-region) or the tracking domain must point at the node IP. On EDGE you cannot rely on cloaking action curl or browser / t.js fingerprint; redirect fingerprint is computed on the node. Frequency cap and uniqueness are first applied per node, then reconciled on the mother after clicks are ingested — do not expect a global uniqueness view from one node alone.

If one tracker server is enough — keep DIRECT (main tracker) and Ingress = Main tracker. EDGE is optional for ordinary campaigns.

Prerequisites

Admin rights (or access to Settings, Domains, and Campaigns), a clean VM with a public IP and SSH (login/password only for the install job; the password is not stored in the DB or logs), a domain/subdomain you control, plus offer/source (and landing if needed) as in a normal launch — see Campaigns, Offers, Landing Pages.

How to open

  1. Sidebar → Settings → Tracker group → Exit Nodes (/settings?tab=exit-nodes).
  2. Domains: Domains (/domains) → domain form → Ingress target.
  3. Campaigns: Campaigns → campaign → Settings tab → Edge tracking block.

Install an Exit Node — step by step

Add Exit Node
Add Exit Node modal: name, IP, SSH port/login/password, OS package-update consent.
  1. Click Add Exit Node.
  2. Fill Name, Server IP, SSH port (usually 22), SSH login, and SSH password if needed.
  3. Enable Allow OS package update only if you consent to package updates during install. Without consent, the OS is left alone.
  4. Click Install and wait for the modal progress to finish (connecting → preflight → host_key_confirmation → server_updating → installing_dependencies → deploying_edge_runtime → bootstrapping_edge → registering_node → health_check → completed).
  5. If install stops on host key confirmation — verify the fingerprint against the server you expect, then confirm in the UI.
  6. On failure open the install log in the modal, fix SSH/network/firewall, and retry.

After success the node appears with a status and a release generation number. Watch heartbeat: connectivity, config freshness, event backlog. A parked conversions banner means a postback arrived before the Edge click — confirm ads hit the EDGE domain.

Node list: statuses and actions without button-hunting

Online is the healthy state for traffic. Provisioning / Confirming host means install is still running. Degraded means the node responds but something is wrong (often a stale snapshot or freshness issue) — do not send ads until you clear it. Draining stops new assignments while in-flight clicks finish. Offline / Failed — not ready for traffic on that node.

Issue release when you edited a campaign/offer/flow but readiness or heartbeat still shows a stale config. Drain is the planned take-out. Revoke invalidates credentials immediately: heartbeat and clicks from the node stop; the disk is not wiped. Wipe is a destructive VM clean-up that also removes the node row; the UI asks for its own confirmation. Do not revoke/wipe while DNS and campaign assignments still point at that node IP.

Domain: Ingress to Exit Node

Domains list
Domains list. The Server IPv4 banner is the mother tracker IP — for Ingress = Exit Node, DNS must use the node IP, not that banner address.
Domain bound to Exit Node
Domain form: Ingress target = Exit Node, node picker; UI hint that A/CNAME must point at the node IP.
  1. Domains → New Domain / Edit — domain name, status active.
  2. Ingress target → Exit Node (not Main tracker).
  3. In Exit Node pick the node. At the registrar, A/CNAME must point at this node IP; CNAME to the mother’s system tracker CNAME fails Check DNS.
  4. SSL (Let's Encrypt / Cloudflare / Manual) as in the Domains article; wait for DNS Verified and SSL active.
  5. Save and open https://your-edge-domain/ with no browser warning.

One domain, one ingress: Main tracker or Exit Node. Switching ingress changes where DNS must point; update live ads deliberately.

Campaign: EDGE mode and assignments

Campaign Edge tracking
Campaigns → Settings → Edge tracking: EDGE mode, limitation warnings, failure policy.
  1. Create or open a campaign and select a tracking domain already bound to an Exit Node (or bind it in parallel).
  2. In Edge tracking set Tracking mode = EDGE (Exit Node) and read the UI warnings: turn browser / t.js fingerprint off on EDGE; cloaking curl is not available on EDGE.
  3. Choose Failure policy: Fail closed — on node problems traffic does not fall through to the main tracker; Fallback URL — your spare address in Fallback destination; Direct fallback (disclosed main URL) — put the main tracker URL in Fallback destination and check the disclosure (“I understand traffic may go to the main tracker URL”); without disclosure it will not redirect.
  4. Save the campaign (new ones — Save first), then assign Exit Node + Domain and click Save assignments. The mother’s system tracker CNAME is not a valid assignment domain.
  5. Wait for readiness: DNS+SSL+release ready. While Not ready (DNS, SSL, or artifacts missing), do not send ads. If assignments saved but the release did not arrive — Issue release on the node under Settings → Exit Nodes.

Offers, Landings, and Flows on EDGE

EDGE campaign Flows
Flows tab on an EDGE campaign: same landings and offers; edits reach the node via release.

Same scheme as DIRECT: offer (and optional landing) → campaign flow. The difference is where the click is handled (the node) and that the snapshot must arrive first. Create the offer with {clickid} and network/postback per the Offers article; landing per Landing Pages; build the path on the campaign Flows tab. Copy the URL from URL & Postback (edge-domain host), open it in a private window, then check the click and a test conversion in Logs. After changing an offer URL or flow step, wait for a successful release and a fresh heartbeat — otherwise the node still serves the old path.

Typical scenarios

First EDGE launch. Node Online → Domain with Ingress = Exit Node, DNS to node IP, Verified + SSL → EDGE campaign with a ready assignment → flow with offer → test click → ads.

Offer change on a live EDGE campaign. Edit Offers / Flows → wait for automatic release (or Issue release) → check heartbeat / readiness → test click → only then mass-replace links in ad cabinets if the public URL changed.

Take a node out of rotation. Drain → let clicks finish → Revoke if needed. Move DNS and assignments off the node IP before destructive actions.

Fall back to DIRECT. Campaign mode → DIRECT, domain Ingress → Main tracker (and DNS to the mother), save, verify the URL. Update ads that still use the edge domain separately.

Checklist before sending ads

  1. Node is not Offline/Failed; heartbeat is not stuck on a long-stale config.
  2. Domain: Ingress = Exit Node, DNS Verified, SSL active, A/CNAME → node IP (not the mother tracker IP).
  3. Campaign: EDGE mode, assignment Ready.
  4. Flow has the intended offer/landing; a test click on the HTTPS edge domain runs the path.
  5. Logs show the click; a test conversion matches.

Common mistakes

  • DNS points at the mother’s CNAME/IP while Ingress = Exit Node — Check DNS fails.
  • EDGE mode without an assignment or with Not ready (DNS, SSL, or artifacts missing) — not ready for ads.
  • Browser / t.js fingerprint left on, or relying on cloaking curl on EDGE — the UI warns; the setup will not behave like DIRECT.
  • Expecting clicks on a mother URL while the campaign is EDGE — wrong host.
  • Revoke/Wipe while assignments and DNS still target the node IP — tracking outage.
  • Ignoring Degraded and a stale config in heartbeat — the node serves an old flow/offer.