Skip to main content

Upload a license (admin)

DT Edge Platform is license-gated. The API refuses every mutation until a valid license is loaded. This guide is the admin-side upload + renewal flow. For the issuer-side mint flow see the issuer repo's docs.

Who can do this​

  • Super-admin — that's the only role with access to Admin → License

First install​

A fresh DT Edge Platform boots without a license loaded. You'll see the License Required landing page with two pieces of info:

  1. The cluster fingerprint (a sha256 hex string starting with sha256:) — copy it
  2. An Upload license form

Step 1 — Get a license​

Send the fingerprint to whoever issues licenses for your deployment (typically your vendor's licensing operator). They run dtedge-license-issue issue --bind <fingerprint> ... --product dtedge and email back a lic-dtedge-<...>.jwt file.

Step 2 — Upload it​

License Required page → Upload license → drag the .jwt or paste its contents → submit.

The handler:

  1. Verifies the signature against the embedded public key
  2. Checks Product == dtedge, expiry, fingerprint, schema
  3. Saves the row
  4. Publishes a Redis pub/sub event so every API replica refreshes

Within a few seconds the page reloads into the normal dashboard.

Step 3 — (Single-tenancy only) bootstrap​

If your license declares Binding.Tenancy = "single", DT Edge Platform auto-creates:

  • A default org named after the license's customer name
  • The local cluster (the one DT Edge Platform runs on) as that org's edge

Log in again; you're already inside the right org.

For multi-tenancy licenses, you create orgs manually through Organizations → Add organization.

Renewal​

Same path: Admin → License → Upload license → drop the new .jwt. The handler replaces the existing row in place; HA replicas refresh within seconds.

What the License page shows​

Once a license is loaded, Admin → License is your operational dashboard:

  • Status badge — active / grace / missing / invalid, with the reason on hover
  • Customer + tier + expires + grace-until
  • Limits & Usage — current per-org count limits and fleet capacity caps with a delta to the limit
  • Audit history — who uploaded what, when, with full event trail
  • Fleet drilldown — per-edge / per-org breakdown of the fleet capacity snapshot
  • Replace dialog — re-upload over an existing license

Renewal hygiene​

  • Renew before grace starts. While the license is in grace, reads pass but mutations 503 — your users notice.
  • The audit log has every customer's expires_at; build a "renewing in 60 days" report on top of it (no built-in alert yet).

Troubleshooting​

Upload errorWhat to do
invalid signatureJWT was tampered with or signed with a non-matching key. Re-download from the operator.
wrong productLicense was minted with --product provisioner. Re-issue with --product dtedge.
fingerprint mismatchLicense's --bind doesn't match the cluster's current fingerprint. Either the cluster was wiped or the DT Edge Platform DB was reset. Get the new fingerprint, re-issue.
schema too newCustomer-side DT Edge Platform image is older than the schema this license was minted under. Upgrade the image first, then upload.
Status flips active → invalid mid-dayClock rollback detected. Get the host clock right (timedatectl set-ntp true) and restart api/worker pods.

For the deeper diagnosis, see the License invalid runbook in the backend docs.

See also​