View preset admin passwords
Each provisioner preset auto-generates random admin passwords for the services it installs (Grafana, Harbor, OpenSearch, Prometheus / Alertmanager basic-auth, fluent-bit local OpenSearch). The dtedge UI exposes these passwords on demand through a reveal dialog.
Who can do this
Super-admins. The reveal endpoint is gated server-side; org members never see the action.
Open the dialog
- Admin → Settings (sidebar in admin section).
- Scroll to the Provisioner Integration card.
- Below the Default preset dropdown, click the Manage presets & view admin passwords link.
- The dialog opens with a card per preset.
What you see
Each preset card shows:
- The preset name + a profile badge (
edgeblue,prodpurple) andsharedif it's visible to all org users. - A Show / Hide toggle on the right.
- A short description.
Clicking Show for a preset reveals every sensitive admin
password as a copyable <Code> block, e.g.:
kube-prometheus-stack.kps_grafana_admin_password
Xy7!kQm2#pLr9@Ns4eR8tBa
A clipboard button next to each value copies it. Toast confirms the copy.
Clicking Hide removes the values from the dialog immediately.
Memory hygiene
Revealed values are kept in component state only — closing the dialog (Cancel button or click outside) clears every revealed preset. Reopening the dialog requires re-clicking Show for each preset you want to inspect again.
The browser tab's memory holds the plaintext only while the dialog is open. Refreshing the page or navigating away discards it.
What's behind the values
Every sensitive password is auto-generated at preset create
time (24-char shell-safe random) and stored encrypted in the
provisioner's presets.secret_vars column. The dtedge backend
proxies the reveal call through a server-to-server admin
endpoint; both layers verify the super-admin role.
The audit log records that the reveal happened (user, time, target preset) but the response body is masked — auditors see that someone accessed the secrets, not the secret values.
Coupled passwords
opensearch.opensearch_admin_password and
fluent-bit.fb_local_opensearch_password always carry the
same value — fluent-bit's local output authenticates
against OpenSearch with that password. Rotating the OpenSearch
admin password automatically rotates the fluent-bit one.