Admin operations
Recipes for tasks that only super-admins can perform. Everything on this page requires the super-admin flag on your user account; regular org admins won't see these surfaces in the UI.
If you got here by accident — looking for an everyday task — go back to the How-to landing page.
License + capacity
- Upload a license — first install + renewal
- Handle "fleet quota exceeded" — what the 403 means and how to fix it
- Manage organization limits — per-org caps on nodes / CPU / memory / GPUs
Users
- Manage users system-wide — disable, reset password, reset 2FA, force-logout
- View preset admin passwords — reveal auto-generated Grafana / Harbor / OpenSearch / etc. credentials
SSO
- Configure global SSO — one IdP for the whole install (Admin → Settings → Global SSO)
- Configure per-org SSO — each org brings its own IdP (Organizations → SSO tab)
- Manage global org-role assignments — IdP group → (org, role) mapping for global SSO
System settings
- Configure system settings — central Prometheus / Grafana / OpenSearch / Harbor / Provisioner
- Rotate the provisioner webhook secret — what to do when the shared secret leaks