Skip to main content

Configure system settings (admin)

Central observability + Provisioner integration + auth policy. Mutable at runtime — no redeploy needed.

Who can do this​

  • Super-admin only. The page is Admin → Settings.

What lives there​

The settings page is grouped into cards:

Auth​

SettingNotes
Two-factor authentication requiredWhen on, every user must enrol; existing un-enrolled users get walked through enrolment on next login
Public registration enabledWhen off, the /register page returns "registration disabled". Invitations still work.
Token expiry (minutes)JWT validity. Default 1440 (24h). Lower for tighter security; higher for less-frequent re-login.

Central Prometheus​

SettingNotes
prometheus_url / _user / _passCentral Prometheus that edges remote-write to. Used for the metrics tab + alarm evaluation
prometheus_cluster_labelLabel name carrying tenant ID. Empty = no scoping (single-tenant prom only)
prometheus_insecure_skip_verifySkip TLS verification — needed for self-signed cert / internal CA

Central OpenSearch​

Same shape as Prometheus, with _index (default k8s-*) and _cluster_field (the field carrying the tenant ID in log records).

Central Grafana​

Same auth fields as Prometheus. Used for the alarms feature — DT Edge Platform creates Grafana rules against this URL. grafana_insecure_skip_verify defaults true historically; flip off in production with a public-CA cert.

Velero​

SettingNotes
velero_namespaceWhere Velero is installed (default velero)

Provisioner integration​

SettingNotes
provisioner_urlBase URL of the upstream Provisioner
provisioner_admin_keyAdmin API key (encrypted; only super-admin sees *** masked)
provisioner_webhook_secretHMAC secret for incoming webhooks
provisioner_preset_idDefault preset for new clusters (UUID from the Provisioner's preset catalog)

When provisioner_url is set + reachable, DT Edge Platform surfaces provisioning options (provision a new cluster from VMs) in the Edge Instances flow.

Periodics​

SettingDefaultNotes
health_check_interval_minutes30How often DT Edge Platform probes each edge's health
release_sync_interval_minutes1How often DT Edge Platform re-reads helm releases from edges
fleet_aggregation_interval_minutes15How often the license fleet usage snapshot is refreshed

Test a connection​

Cards with URL fields have a Test button. Runs an immediate probe with the saved values (or the values you've typed but not saved yet, depending on implementation):

  • Prometheus — does an up{} query
  • OpenSearch — calls _cluster/health
  • Grafana — calls /api/org
  • Provisioner — fetches /v1/health

Green = reachable + creds work. Red = error message in tooltip.

How changes propagate​

  • Encrypted-value fields (passwords, secrets) are AES-GCM encrypted before they touch the DB. The plaintext never appears in the UI after save (you see ***).
  • All changes are runtime-applied — the next request that needs the setting reads the new value. No pod restart needed.
  • Audit log records every change with the old + new values (encrypted ones show as *** → ***, but the timestamp + actor are recorded).

What's NOT in system settings​

  • License — has its own page (Admin → License). Not a free-form setting.
  • Categories taxonomy — Admin → Categories.
  • Per-edge observability creds — there are no per-edge Prometheus / OpenSearch / Grafana columns. Observability is central across the install.
  • Casbin policy / role catalog — managed via Organizations → Roles.

Common errors​

  • INVALID_SETTING_KEY — typo or attempt to set a key the backend doesn't recognise (e.g. a removed setting from an older docs page)
  • INVALID_SETTING_VALUE — value didn't pass the per-key validator (e.g. cluster_field with whitespace, URL without scheme)
  • Test button red but the setting is correct — the URL is reachable from your browser but not from the DT Edge Platform pod; network policies / DNS differ. Use the edge stale health runbook approach to test from inside the pod.

See also​