Registration
Control who can create accounts and enroll execution machines.
Account registration
Registration is configured per sign-in provider. The email provider controls email-based account creation; OIDC providers have their own registration and approval settings.
- In the server dashboard's sidebar, open Server Settings → Auth.
- Review registration for each enabled provider.
- Enable it only where you intend to admit new users.
- Require approval if new accounts should wait for administrator review.
Pending or rejected accounts do not receive ordinary access to the instance. Review approvals under Server Settings → Users in the dashboard sidebar.
Administrative account creation
In the server dashboard's sidebar, open Server Settings → Users to create an account directly. Do not open registration just to create a test or automation account.
The first-account setup window is different from ongoing registration: an unconfigured instance permits its first admin to be created. Protect that window with network access controls.
Node enrollment
Node enrollment has a separate instance policy. A permitted user generates a single-use setup key and enrolls a machine under their ownership.
A setup key authorizes enrollment, not a new human account. A node credential issued by enrollment authenticates the machine afterward.
Next steps
Read Users and roles, Enroll a node with the CLI, and Access model.
Edit on GitHubLast updated on
