Skip to main content

View preset admin passwords

Each provisioner preset auto-generates random admin passwords for the services it installs (Grafana, Harbor, OpenSearch, Prometheus / Alertmanager basic-auth, fluent-bit local OpenSearch). The dtedge UI exposes these passwords on demand through a reveal dialog.

Who can do this​

Super-admins. The reveal endpoint is gated server-side; org members never see the action.

Open the dialog​

  1. Admin → Settings (sidebar in admin section).
  2. Scroll to the Provisioner Integration card.
  3. Below the Default preset dropdown, click the Manage presets & view admin passwords link.
  4. The dialog opens with a card per preset.

What you see​

Each preset card shows:

  • The preset name + a profile badge (edge blue, prod purple) and shared if it's visible to all org users.
  • A Show / Hide toggle on the right.
  • A short description.

Clicking Show for a preset reveals every sensitive admin password as a copyable <Code> block, e.g.:

kube-prometheus-stack.kps_grafana_admin_password
Xy7!kQm2#pLr9@Ns4eR8tBa

A clipboard button next to each value copies it. Toast confirms the copy.

Clicking Hide removes the values from the dialog immediately.

Memory hygiene​

Revealed values are kept in component state only — closing the dialog (Cancel button or click outside) clears every revealed preset. Reopening the dialog requires re-clicking Show for each preset you want to inspect again.

The browser tab's memory holds the plaintext only while the dialog is open. Refreshing the page or navigating away discards it.

What's behind the values​

Every sensitive password is auto-generated at preset create time (24-char shell-safe random) and stored encrypted in the provisioner's presets.secret_vars column. The dtedge backend proxies the reveal call through a server-to-server admin endpoint; both layers verify the super-admin role.

The audit log records that the reveal happened (user, time, target preset) but the response body is masked — auditors see that someone accessed the secrets, not the secret values.

Coupled passwords​

opensearch.opensearch_admin_password and fluent-bit.fb_local_opensearch_password always carry the same value — fluent-bit's local output authenticates against OpenSearch with that password. Rotating the OpenSearch admin password automatically rotates the fluent-bit one.

See also​