Configure system settings (admin)
Central observability + Provisioner integration + auth policy. Mutable at runtime — no redeploy needed.
Who can do this
- Super-admin only. The page is Admin → Settings.
What lives there
The settings page is grouped into cards:
Auth
| Setting | Notes |
|---|---|
| Two-factor authentication required | When on, every user must enrol; existing un-enrolled users get walked through enrolment on next login |
| Public registration enabled | When off, the /register page returns "registration disabled". Invitations still work. |
| Token expiry (minutes) | JWT validity. Default 1440 (24h). Lower for tighter security; higher for less-frequent re-login. |
Central Prometheus
| Setting | Notes |
|---|---|
prometheus_url / _user / _pass | Central Prometheus that edges remote-write to. Used for the metrics tab + alarm evaluation |
prometheus_cluster_label | Label name carrying tenant ID. Empty = no scoping (single-tenant prom only) |
prometheus_insecure_skip_verify | Skip TLS verification — needed for self-signed cert / internal CA |
Central OpenSearch
Same shape as Prometheus, with _index (default k8s-*) and
_cluster_field (the field carrying the tenant ID in log
records).
Central Grafana
Same auth fields as Prometheus. Used for the alarms feature —
DT Edge Platform creates Grafana rules against this URL.
grafana_insecure_skip_verify defaults true historically; flip
off in production with a public-CA cert.
Velero
| Setting | Notes |
|---|---|
velero_namespace | Where Velero is installed (default velero) |
Provisioner integration
| Setting | Notes |
|---|---|
provisioner_url | Base URL of the upstream Provisioner |
provisioner_admin_key | Admin API key (encrypted; only super-admin sees *** masked) |
provisioner_webhook_secret | HMAC secret for incoming webhooks |
provisioner_preset_id | Default preset for new clusters (UUID from the Provisioner's preset catalog) |
When provisioner_url is set + reachable, DT Edge Platform surfaces
provisioning options (provision a new cluster from VMs) in the
Edge Instances flow.
Periodics
| Setting | Default | Notes |
|---|---|---|
health_check_interval_minutes | 30 | How often DT Edge Platform probes each edge's health |
release_sync_interval_minutes | 1 | How often DT Edge Platform re-reads helm releases from edges |
fleet_aggregation_interval_minutes | 15 | How often the license fleet usage snapshot is refreshed |
Test a connection
Cards with URL fields have a Test button. Runs an immediate probe with the saved values (or the values you've typed but not saved yet, depending on implementation):
- Prometheus — does an
up{}query - OpenSearch — calls
_cluster/health - Grafana — calls
/api/org - Provisioner — fetches
/v1/health
Green = reachable + creds work. Red = error message in tooltip.
How changes propagate
- Encrypted-value fields (passwords, secrets) are AES-GCM
encrypted before they touch the DB. The plaintext never
appears in the UI after save (you see
***). - All changes are runtime-applied — the next request that needs the setting reads the new value. No pod restart needed.
- Audit log records every change with the old + new values
(encrypted ones show as
***→***, but the timestamp + actor are recorded).
What's NOT in system settings
- License — has its own page (Admin → License). Not a free-form setting.
- Categories taxonomy — Admin → Categories.
- Per-edge observability creds — there are no per-edge Prometheus / OpenSearch / Grafana columns. Observability is central across the install.
- Casbin policy / role catalog — managed via Organizations → Roles.
Common errors
INVALID_SETTING_KEY— typo or attempt to set a key the backend doesn't recognise (e.g. a removed setting from an older docs page)INVALID_SETTING_VALUE— value didn't pass the per-key validator (e.g. cluster_field with whitespace, URL without scheme)- Test button red but the setting is correct — the URL is reachable from your browser but not from the DT Edge Platform pod; network policies / DNS differ. Use the edge stale health runbook approach to test from inside the pod.
See also
- Reference: Admin pages
- Backend docs: Operations → Configuration