Skip to main content

Error messages

Every error code DT Edge Platform surfaces, what it means, where to look next. Codes are stable strings — search this page when one shows up.

License gating​

CodeWhere you see itMeansNext
LICENSE_MISSINGToast on every action; landing pageNo license loadedAdmin uploads — see How-to: upload license
LICENSE_INVALIDToast + License page red badgeVerification failed; reason on hoverMatch the reason against License invalid runbook
LICENSE_GRACE_READONLYToast on mutationsLicense expired, in grace; reads pass, mutations 503Renew before grace ends
LICENSE_FINGERPRINT_MISMATCHLicense uploadThe license's --bind doesn't match this clusterGet the new fingerprint, re-issue
LICENSE_WRONG_PRODUCTLicense uploadMinted with --product provisionerRe-issue with --product dtedge
LICENSE_SCHEMA_TOO_NEWLicense uploadNewer schema than this DT Edge Platform build supportsUpgrade DT Edge Platform image first
LICENSE_CLOCK_ROLLBACKServer log + License pageHost clock went backwardsFix timedatectl set-ntp true, restart pods
FLEET_QUOTA_EXCEEDEDToast on install / edge createOperation would push over fleet capHandle fleet quota exceeded

Auth + session​

CodeMeansNext
INVALID_CREDENTIALSWrong email / password (login) or wrong current password (change-password)Try again
2FA_REQUIREDPassword OK; need TOTP codeEnter the 6-digit code
INVALID_2FA_CODETOTP wrongCheck phone clock; try again
TOKEN_EXPIREDJWT past expRe-login
INVALID_TOKENSignature mismatch (JWT_SECRET rotated server-side)Re-login
USER_DEACTIVATEDYour account is is_active=falseAsk admin
USER_NOT_FOUNDAPI key references a user that's been deletedRe-mint the API key
2FA_REQUIRED (post-login)Server policy requires 2FA but you haven't enrolledSetup wizard appears in the login flow

RBAC​

CodeMeansNext
permission deniedCasbin enforce returned falseYour role doesn't grant this; ask admin to update your role or use a different one
not a member of this organizationURL's :org_id not in your membershipsSwitch org via the selector
super admin access requiredThe endpoint is locked to super-adminsAsk a super-admin to do it

Validation​

CodeMeans
INVALID_PAYLOADRequest body didn't parse (typo in YAML, malformed JSON)
INVALID_BASE64_KUBECONFIGThe kubeconfig you pasted isn't valid base64
INVALID_SETTING_KEY / INVALID_SETTING_VALUEAdmin → Settings save: unknown key or invalid value for it
TELEMETRY_ID_REQUIRED / TELEMETRY_ID_TAKENEdge update: telemetry_id empty or already in use by another edge

Edge instance​

CodeMeans
EDGE_INSTANCE_NOT_FOUNDThe edge ID isn't yours or doesn't exist
EDGE_OPERATION_IN_PROGRESSAnother op against this edge is in flight
FAILED_ENCRYPT_KUBECONFIGServer-side encryption error; ENCRYPTION_KEY env may be misconfigured
PUBLIC_RESOURCE_NOT_LICENSEDCalling a public/admin endpoint whose MaxPublic* cap is 0 — feature off in this license

Helm​

CodeMeans
OPERATION_IN_PROGRESSRelease is locked by a running op; wait
RELEASE_OWNERSHIP_FORBIDDENOn a public edge, this release was installed by another org; only that org can upgrade/uninstall
PROTECTED_NAMESPACEYou tried to install into kube-system / cert-manager / DT Edge Platform / etc.
REGISTRY_UNREACHABLE_VERSION_BUMPSmart upgrade tried to pull a new version but registry is down. Pin to the current version (no version change → falls back to stored chart)

Backup locations​

CodeMeansNext
BACKUP_LOCATION_NOT_FOUNDThe backup location was deleted or isn't visible to your orgPick another location; backups already stored there remain restorable
BACKUP_LOCATION_UNAVAILABLEThe S3 target is unreachable from the edgeCheck endpoint, credentials and CA certificate; run the location's Test action (Organizations → Backup Locations)
BACKUP_LOCATION_NOT_VALIDATEDThe location couldn't be validated in time (test can take up to ~90s)Check that Velero is healthy on the edge, then re-test

Alarms​

CodeMeans
GRAFANA_NOT_CONFIGUREDsystem_settings missing the central Grafana URL/creds
NO_EDGES_IN_SCOPEThe active org has no edges to scope the alarm to
INVALID_PROMQLParser error; message includes position
FORBIDDEN_LABEL_<NAME>Your query references a reserved label (telemetry_id, dtedge_org_id, …); strip it — backend injects
ALARM_NOT_FOUNDRule UID isn't yours or doesn't exist
GRAFANA_*_FAILEDUpstream Grafana API call failed (network, 5xx)

Provisioner integration​

CodeMeans
PROVISIONER_NOT_CONFIGUREDAdmin → Settings missing provisioner_url / admin_key
PROVISIONER_UNREACHABLENetwork timeout to upstream Provisioner
NODES_MISSING_SSHDestroying an upstream cluster needs SSH creds the row doesn't have

Operations​

CodeMeans
OPERATION_NOT_FOUNDOperation ID is wrong or it's been deleted
OPERATION_NOT_RETRIABLEYou tried to retry an op that isn't in failed state
FAILED_CREATE_OPERATION / FAILED_ENQUEUE_OPERATIONDB or Redis hiccup; try again, then escalate

Webhooks (incoming)​

CodeMeans
INVALID_SIGNATUREInbound webhook HMAC mismatch (Provisioner → DT Edge Platform); secret out of sync
STALE_TIMESTAMPReplay window exceeded (>5 min)
WEBHOOK_NOT_FOUNDThe webhook config row was deleted

Generic​

CodeMeans
INTERNAL_SERVER_ERRORUnhandled exception; check pod logs
DB_UNAVAILABLEPostgres is down or unreachable
RATE_LIMITEDPer-API-key rate limit hit; back off

See also​