Admin pages
The Admin sidebar entry only appears for super-admins. It nests every system-wide surface — orgs, users, public resources, taxonomy, the license, audit, and global settings.
Each admin page is gated independently. Super-admin alone isn't
enough — pages that expose public/global resources also require
the matching license cap (MaxPublicEdges, MaxPublicRegistries,
MaxPublicMarketplacePackages) to be > 0.
Admin → Organizations
Sidebar → Admin → Organizations. Lists every org in the system, regardless of who owns it.
| Column | Meaning |
|---|---|
| Name + slug | Display name and URL slug |
| Members | Total member count |
| Edges | Edges owned by this org |
| Created | When the org was created |
| Actions | Edit / Delete |
Add organization in the top-right opens a drawer (name, slug, optional description). Slugs must be unique and URL-safe; the form validates as you type.
Click any row to open the standard Organizations detail view — the same Members / Roles / etc. tabs a regular member sees, but not gated by membership.
Admin → Users
Sidebar → Admin → Users. Every user in the system, across all orgs.
| Column | Meaning |
|---|---|
| Login identity | |
| Name | Display name |
| Active | is_active toggle — flip off to lock out without deleting |
| Super-admin | Shield badge if elevated |
| 2FA | Enrolled / not / required-by-policy |
| Last login | Timestamp |
| Actions | Edit / Set password / Reset 2FA / Toggle super-admin / Toggle active / Delete |
Add user drawer — email, name, password, and optional "Add to org" picker that creates a membership in one shot.
Reset 2FA is the recovery path for users who lost their authenticator device. The next login asks for password only and re-prompts for enrolment. See How-to: set up 2FA.
Deleting a user removes their memberships and audit-log attribution. Generally prefer Toggle active — it preserves audit history.
Admin → Edge Instances
Sidebar → Admin → Edge Instances. Visible only when
MaxPublicEdges > 0.
Same shape as the org-scoped Edge Instances page (see
Edge Instances reference) but operates
on org_id IS NULL rows. Public edges show up to every org
member as install targets; per-release ownership is tracked
separately so two orgs can't manage each other's helm releases.
Admin → Registries
Sidebar → Admin → Registries. Visible only when
MaxPublicRegistries > 0.
Same shape as the per-org Registries page but rows are global — every org sees them as install sources. Use this for shared chart sources (vendor catalogs, internal mirrors).
Admin → Marketplace
Sidebar → Admin → Marketplace. Visible only when
MaxPublicMarketplacePackages > 0.
Cross-org marketplace package catalog. The fields and actions mirror the per-org Marketplace page; the difference is reach — public packages appear in every org's marketplace as install candidates.
Admin → Categories
Sidebar → Admin → Categories. The taxonomy editor.
Categories are the colored badges that show up on edge instances and marketplace packages. They're system-wide (not per-org).
| Field | Meaning |
|---|---|
| Name | Display label |
| Slug | URL-safe identifier (auto-derived from name) |
| Color | Badge background; pick from a palette |
| Description | Free-text |
Deleting a category does not cascade to objects that carry it — those keep the slug as a dangling reference until they're re-tagged. The list page warns you about the count of in-use references before deletion.
Admin → SSH Keys
Sidebar → Admin → SSH Keys. The global SSH key catalog used by the Provisioner integration when DT Edge Platform creates new clusters.
| Field | Meaning |
|---|---|
| Name | Display label |
| Public key | OpenSSH-format ssh-... line |
| Created by | Which super-admin added it |
Adding a key here makes it pickable in the Provision new
cluster flow on the Edge Instances page. Removing one doesn't
affect already-provisioned clusters — the key stays on those
nodes' authorized_keys until you rotate them out manually.
Admin → License
Sidebar → Admin → License. The license dashboard. See also Explanation: license states and How-to: upload a license.
Top-down layout:
- Header strip — status badge, customer name, tier, expiry date at a glance
- Fleet usage — four progress bars (nodes / cpu / mem / gpu) against the license caps. The "View fleet details →" button drills into per-org and per-edge breakdown
- Limits + cluster fingerprint — every numeric cap on the left, the bind fingerprint on the right (copy-to-clipboard)
- Replace license + audit log — bottom row; rare operations
Statuses:
- Active — within
exp, all features available - Grace — past
exp, inside grace window; reads work, mutations fail withLICENSE_GRACE_READONLY - Invalid — verification failed; the whole UI redirects to the License Required landing
- Missing — no license uploaded; same redirect
Admin → License → Fleet
The "View fleet details" drill-down. Two tabs:
- Per-organization rollup — edge count + capacity totals per org. Sortable table with client-side search.
- Per-edge detail — every managed edge with reachability + capacity. Same table behaviour.
Not in the sidebar by design — it's an operator drill-down, not a daily-use surface.
Admin → Audit Logs
Sidebar → Admin → Audit Logs. The cross-org audit view.
Same fields as the per-org Audit Logs page (see Audit Logs reference) but every org's events are visible — useful when you need to trace an action across tenants or correlate with a license event.
Admin → Settings
Sidebar → Admin → Settings. System-wide knobs that affect the whole install.
Major sections:
- Cadence —
health_check_interval_minutes,release_sync_interval_minutes,token_expiry_minutes - Auth policy —
two_factor_required,registration_enabled - Telemetry endpoints — Prometheus, OpenSearch, Grafana (URL + auth + insecure_skip_verify per endpoint)
- Provisioner integration —
provisioner_url,provisioner_admin_key,provisioner_webhook_secret,provisioner_preset_id. The Test connection button validates each before save. - Inbound webhook secret — HMAC for Provisioner → DT Edge Platform callbacks
Each row has its own Save button — changes don't batch.
For day-to-day editing of a single setting, see How-to: configure system settings.