Subshell Docs

Registration

Control who can create accounts and enroll execution machines.

Account registration

Registration is configured per sign-in provider. The email provider controls email-based account creation; OIDC providers have their own registration and approval settings.

  1. In the server dashboard's sidebar, open Server Settings → Auth.
  2. Review registration for each enabled provider.
  3. Enable it only where you intend to admit new users.
  4. Require approval if new accounts should wait for administrator review.

Pending or rejected accounts do not receive ordinary access to the instance. Review approvals under Server Settings → Users in the dashboard sidebar.

Administrative account creation

In the server dashboard's sidebar, open Server Settings → Users to create an account directly. Do not open registration just to create a test or automation account.

The first-account setup window is different from ongoing registration: an unconfigured instance permits its first admin to be created. Protect that window with network access controls.

Node enrollment

Node enrollment has a separate instance policy. A permitted user generates a single-use setup key and enrolls a machine under their ownership.

A setup key authorizes enrollment, not a new human account. A node credential issued by enrollment authenticates the machine afterward.

Next steps

Read Users and roles, Enroll a node with the CLI, and Access model.

Edit on GitHub

Last updated on

On this page