Skip to main content

Administration

Two kinds of people administer Ouroboros, and this section is for both. You may be one, the other, or both at once:

  • The deployment administrator runs the installation — the machines, the containers, the database and the configuration every workspace on it shares.
  • A workspace administrator runs one workspace — who is in it, what may merge on its own, which trackers and models it uses and where its record lives.

They hold their power in different places. Deployment administration happens on the host: whoever can edit the services' environment and restart them administers the deployment. Nothing in the app makes you one, and the app has no screen for it. Workspace administration happens in the app, under Settings, and needs the Owner or Maintainer role in that workspace — see Roles & capabilities.

What the deployment administrator looks after​

You set up and keep running everything the workspaces stand on:

You look afterWhat it meansRead
The servicesThe UI, REST and engine containers, which of them are public, the database and its migrationsDeploying Ouroboros
ConfigurationThe OURO_* variables each service reads at start-up — the addresses services reach each other on, secrets, mail and limitsConfiguration reference
Sign-inThe GitHub OAuth app every person signs in throughSign-in & workspace settings
The farm gatewayThe address build runners reach the installation on, over mutual TLSThe farm gateway
MailThe mail server that sends decision mail, digests and invitationsNotifications, email & webhooks
Upgrades and backupsApplying new versions, migrating the database and keeping backups you can restoreOperations

A setting made here applies to every workspace on the installation, and a service reads it when it starts — change one and restart that service. Before anyone signs in for the first time, work through the Go-live checklist.

What a workspace administrator looks after​

Anyone who signs in gets a personal workspace of their own and can create more. Whoever creates a workspace is its first Owner. From then on the workspace's Owners and Maintainers run it from Settings, reached from the sidebar's Settings entry or the account menu's Workspace settings.

Workspace settings: the tab row across the top, then one card per part of the workspace you administer.
The Workspace settings page for Acme Robotics, headed Who can do what, what merges on its own, and where the record lives., with Export audit CSV and Save changes, and the tab row Workspace, Members, Policies, Integrations, Audit and Danger zone, then Sources, Providers, Farm tokens and Knowledge / env. Below it the Workspace card shows the workspace name, the tenant domain acme-robotics.dev, the self-hosted data region, 30 days of data retention and training switched off; the Members & roles card, marked applies instantly, lists Ken Suenobu as Owner and Maya Chen as Maintainer, both able to approve loops, Jorge Reyes as Viewer, the devops-bot service account and a pending Maintainer invitation for priya@acme.dev, above the footer Owner > Maintainer (approve/merge) > Viewer (read-only); the Appearance card begins underneath.The Workspace settings page for Acme Robotics, headed Who can do what, what merges on its own, and where the record lives., with Export audit CSV and Save changes, and the tab row Workspace, Members, Policies, Integrations, Audit and Danger zone, then Sources, Providers, Farm tokens and Knowledge / env. Below it the Workspace card shows the workspace name, the tenant domain acme-robotics.dev, the self-hosted data region, 30 days of data retention and training switched off; the Members & roles card, marked applies instantly, lists Ken Suenobu as Owner and Maya Chen as Maintainer, both able to approve loops, Jorge Reyes as Viewer, the devops-bot service account and a pending Maintainer invitation for priya@acme.dev, above the footer Owner > Maintainer (approve/merge) > Viewer (read-only); the Appearance card begins underneath.

The page is headed Workspace settings — Who can do what, what merges on its own, and where the record lives. Its tab row leads to each part:

TabWhat you do thereRead
WorkspaceThe workspace's name, its tenant domain, its data region and how long its data is keptSign-in & workspace settings
MembersInvite people, change their roles, decide who may approve loops, and issue service-account tokensMembers, invites, roles & API tokens
PoliciesWhat may merge without a person, protected paths, the spend guard and dry-runPolicies & guardrails
IntegrationsWhether each connected system is working, and the webhook endpoints the workspace reports toNotifications, email & webhooks
AuditThe workspace's audit trail, and Export audit CSVData retention, audit & lifecycle
Danger zonePausing the workspace, disconnecting it, and deleting itData retention, audit & lifecycle
SourcesThe trackers and repositories the workspace takes issues fromTicket sources & repositories
ProvidersThe model providers and keys loops run onModel providers & keys
Farm tokensThe pools of build runners and the tokens that enroll themBuild farm administration
Knowledge / envEach repository's environment recipe, on the Knowledge pageKnowledge

The hub also holds two cards with no tab of their own — scroll to them: Appearance, your own theme and font size, which only you see; and Notifications, the workspace's daily digest time and who receives the weekly insights mail.

Fields you edit on the hub wait for Save changes. A control marked applies instantly — everything on Members and Danger zone — acts as soon as you confirm it.

What can go wrong​

  • Every field is read-only. You are a Viewer in this workspace. The page says so under the tab row — Viewing workspace settings as a viewer. Every setting on this page can be read. Changing one takes an owner or an admin. Ask one of the workspace's Owners or Maintainers. ("Admin" is the stored name of the Maintainer role.)
  • A setting you need is not on the page. It is probably a deployment setting, made in the services' environment rather than in the app — look it up in the Configuration reference and ask whoever runs the installation.
  • A section says it could not be read. The hub shows the rest of the page and a Retry button above it; press it once the service is reachable again.
  • You cannot delete the workspace. Deleting is for Owners only, and so is making someone an Owner. See Roles & capabilities.