Manage Access

Management authentication, access to the appliance cluster, and ERS application accounts are separate. Use the identity appropriate to the task.

Access Meaning

Management session

A browser sign-in backed by Gitea. The signed-in Gitea administrator status determines Management administrator access.

Cluster access lease

The limited period during which Management retains the appliance artifact bundle and can use its credentials. Signing in does not create this connection.

ERS accounts

Users and administrators of the installed applications and their identity service. Their credentials differ from the Management sign-in.

Sign in and check your Role

  1. Open the configured Management HTTPS address and verify its certificate.

  2. Select Sign in with Gitea and sign in with the account created for you. Initial administrator setup is described in Initialize Management.

  3. Open Profile and check the displayed username. Management administrators see Administrator.

  4. If your task requires cluster access, check the connected appliance and reconnect if necessary.

Management operations require a Gitea administrator session, including installation, reconnection, registry settings and secrets. Headlamp, Grafana and Terminal also require administrator access. A Gitea login without administrator status does not grant operational access.

When an account’s Gitea administrator status changes, sign out and sign in again before relying on the role shown by the current Management session. Manage account permissions through the organization’s Gitea administration process; do not grant administrator access merely to resolve a missing-tool link.

Use ERS Accounts

After bootstrap, open ERS > Overview. The ERS access card links to CLM, CARA and Keycloak. Use Reveal generated administrator credentials to retrieve the generated initial credentials through the secrets editor.

Manage ERS users and access in the appropriate application or identity service and follow the matching product manual. A Management account change does not change ERS users.

End a Session

Choose Profile > Sign out when finished. Signing out does not end the appliance connection. Management also loses its retained artifact bundle when the cluster access lease expires or Management restarts. Keep the artifact archive outside Management for the next connection.

Headlamp uses shared Kubernetes credentials for admitted administrators. Grafana does not attribute actions to individual Management users. Do not treat either tool as a per-user Kubernetes authorization or audit system.

If Management administrator access is lost, the ISO does not provide a password-reset action. Follow Management recovery for the recovery procedure.