Forgeplane admin dashboard
Forgeplane’s admin dashboard is permission-gated. Use it to operate installation-wide resources and recovery controls; the navigation and actions shown to you depend on system permissions, organization membership, and team scope.
Choose the admin surface
Section titled “Choose the admin surface”| Surface | Use it for |
|---|---|
| Identities | Local users, system roles, and service-account ownership |
| Workers and tools | Registration, capabilities, pools, maintenance, and tool-version selection |
| Quotas and usage | Governance limits and recorded consumption |
| Settings and feature gates | Runtime coordinator settings and staged behavior |
| State recovery | Explicit recovery for managed-state instances in recovery_required |
| Notifications and audit | Operator events, filters, retention, and bounded export |
Identities
Section titled “Identities”Administrators manage local users and the system roles defined in Permissions and roles. Service accounts provide separately owned, non-interactive identities for automation; each key is shown once and can be revoked independently.
Use Service accounts for ownership and key rotation. API keys authenticate through X-API-Key, not the session-JWT Bearer scheme.
Workers and worker pools
Section titled “Workers and worker pools”The workers view reports registration state, advertised capabilities, version, pool, current work, and last heartbeat. Operators can drain workers before maintenance, reactivate drained workers, and remove disconnected records.
A reported capability only describes scheduling eligibility. Production worker images must explicitly include the corresponding tool binary and runtime dependencies.
The tool catalog controls which tool versions may be selected. Named worker pools control routing and placement. Keep the catalog aligned with binaries actually installed in each tool-capable image.
Terraform and OpenTofu support preview/apply/teardown and managed state. Ansible supports execute and streaming; do not configure a Terraform-style preview or teardown workflow for it.
Quotas, settings, and feature gates
Section titled “Quotas, settings, and feature gates”/admin/quotas manages governance limits. The usage view shows recorded consumption against those limits. Quotas supplement authorization; they do not grant permission to create or operate a resource.
/admin/settings changes runtime-tunable coordinator settings stored in PostgreSQL. System settings is the key-by-key reference.
Feature gates control staged behavior and target-specific overrides. Use Feature gates for current keys and precedence rather than copying defaults into deployment automation.
Managed-state recovery
Section titled “Managed-state recovery”/admin/state-recovery is the operator surface for Terraform/OpenTofu instances that fail closed as recovery_required. Recovery is an explicit administrative action with audit records; Forgeplane does not silently create an empty state when a required layer is missing.
Back up PostgreSQL, encrypted state objects, and the exact encryption keys as one recovery set. See Managed state for the production contract.
Notifications and audit
Section titled “Notifications and audit”The notifications view reports operator-relevant events and respects retention. The audit view supports filters and bounded export. See Audit logging for event and export behavior.
Before changing a production control, confirm the required permission, record the reason, and verify the resulting state and audit record.