Upload a license (admin)
DT Edge Platform is license-gated. The API refuses every mutation until a valid license is loaded. This guide is the admin-side upload + renewal flow. For the issuer-side mint flow see the issuer repo's docs.
Who can do this
- Super-admin — that's the only role with access to Admin → License
First install
A fresh DT Edge Platform boots without a license loaded. You'll see the License Required landing page with two pieces of info:
- The cluster fingerprint (a sha256 hex string starting with
sha256:) — copy it - An Upload license form
Step 1 — Get a license
Send the fingerprint to whoever issues licenses for your
deployment (typically your vendor's licensing operator). They run
dtedge-license-issue issue --bind <fingerprint> ... --product dtedge
and email back a lic-dtedge-<...>.jwt file.
Step 2 — Upload it
License Required page → Upload license → drag the .jwt or
paste its contents → submit.
The handler:
- Verifies the signature against the embedded public key
- Checks
Product == dtedge, expiry, fingerprint, schema - Saves the row
- Publishes a Redis pub/sub event so every API replica refreshes
Within a few seconds the page reloads into the normal dashboard.
Step 3 — (Single-tenancy only) bootstrap
If your license declares Binding.Tenancy = "single", DT Edge Platform
auto-creates:
- A default org named after the license's customer name
- The local cluster (the one DT Edge Platform runs on) as that org's edge
Log in again; you're already inside the right org.
For multi-tenancy licenses, you create orgs manually through Organizations → Add organization.
Renewal
Same path: Admin → License → Upload license → drop the
new .jwt. The handler replaces the existing row in place; HA
replicas refresh within seconds.
What the License page shows
Once a license is loaded, Admin → License is your operational dashboard:
- Status badge —
active/grace/missing/invalid, with the reason on hover - Customer + tier + expires + grace-until
- Limits & Usage — current per-org count limits and fleet capacity caps with a delta to the limit
- Audit history — who uploaded what, when, with full event trail
- Fleet drilldown — per-edge / per-org breakdown of the fleet capacity snapshot
- Replace dialog — re-upload over an existing license
Renewal hygiene
- Renew before grace starts. While the license is in
grace, reads pass but mutations 503 — your users notice. - The audit log has every customer's
expires_at; build a "renewing in 60 days" report on top of it (no built-in alert yet).
Troubleshooting
| Upload error | What to do |
|---|---|
invalid signature | JWT was tampered with or signed with a non-matching key. Re-download from the operator. |
wrong product | License was minted with --product provisioner. Re-issue with --product dtedge. |
fingerprint mismatch | License's --bind doesn't match the cluster's current fingerprint. Either the cluster was wiped or the DT Edge Platform DB was reset. Get the new fingerprint, re-issue. |
schema too new | Customer-side DT Edge Platform image is older than the schema this license was minted under. Upgrade the image first, then upload. |
| Status flips active → invalid mid-day | Clock rollback detected. Get the host clock right (timedatectl set-ntp true) and restart api/worker pods. |
For the deeper diagnosis, see the License invalid runbook in the backend docs.
See also
- Explanation: license states
- Handle fleet quota exceeded
- Backend docs: Concept → License