Skip to content

Forgeplane admin dashboard

Forgeplane’s admin dashboard is permission-gated. Use it to operate installation-wide resources and recovery controls; the navigation and actions shown to you depend on system permissions, organization membership, and team scope.

Surface Use it for
Identities Local users, system roles, and service-account ownership
Workers and tools Registration, capabilities, pools, maintenance, and tool-version selection
Quotas and usage Governance limits and recorded consumption
Settings and feature gates Runtime coordinator settings and staged behavior
State recovery Explicit recovery for managed-state instances in recovery_required
Notifications and audit Operator events, filters, retention, and bounded export

Administrators manage local users and the system roles defined in Permissions and roles. Service accounts provide separately owned, non-interactive identities for automation; each key is shown once and can be revoked independently.

Use Service accounts for ownership and key rotation. API keys authenticate through X-API-Key, not the session-JWT Bearer scheme.

The workers view reports registration state, advertised capabilities, version, pool, current work, and last heartbeat. Operators can drain workers before maintenance, reactivate drained workers, and remove disconnected records.

A reported capability only describes scheduling eligibility. Production worker images must explicitly include the corresponding tool binary and runtime dependencies.

The tool catalog controls which tool versions may be selected. Named worker pools control routing and placement. Keep the catalog aligned with binaries actually installed in each tool-capable image.

Terraform and OpenTofu support preview/apply/teardown and managed state. Ansible supports execute and streaming; do not configure a Terraform-style preview or teardown workflow for it.

/admin/quotas manages governance limits. The usage view shows recorded consumption against those limits. Quotas supplement authorization; they do not grant permission to create or operate a resource.

/admin/settings changes runtime-tunable coordinator settings stored in PostgreSQL. System settings is the key-by-key reference.

Feature gates control staged behavior and target-specific overrides. Use Feature gates for current keys and precedence rather than copying defaults into deployment automation.

/admin/state-recovery is the operator surface for Terraform/OpenTofu instances that fail closed as recovery_required. Recovery is an explicit administrative action with audit records; Forgeplane does not silently create an empty state when a required layer is missing.

Back up PostgreSQL, encrypted state objects, and the exact encryption keys as one recovery set. See Managed state for the production contract.

The notifications view reports operator-relevant events and respects retention. The audit view supports filters and bounded export. See Audit logging for event and export behavior.

Before changing a production control, confirm the required permission, record the reason, and verify the resulting state and audit record.