First-class customer records (#1570). The stable orgId is ours — decoupled from bexio.
Harbor access issues a pull-only Harbor
robot account for this one customer, scoped to a single registry project, so they can
docker login and pull KodeMed images. The secret is shown once, in a dialog,
and can never be retrieved again — not by this portal and not by Harbor. If it is lost, revoke
the access and issue a fresh credential. Revoke Harbor stops them pulling new images
immediately; it does not touch anything they have already installed.
bexio: checking…
orgId
Display name
Legal name
UID
Contact
Status
bexio
Harbor pull
Loading…
One active subscription per (organization, instance id): an org may run several
active subscriptions (e.g. PROD + STAGING), one per instance. Suspended records are dimmed and kept for history.
Organization
Instance
Hostname
Type
Provider
DB
Region
Modules
Year
Users
Expires
Licence
Status
Loading…
A subscription is the commercial record
— who is entitled to what, on which instance, and until when. An issued licence is the
signed file that actually unlocks the software. Creating a subscription here entitles and
documents; it signs nothing and sends nothing to the customer. To give them a working install you
still go to Generate. The control plane reads these records to know what it may
provision.
Drafts are dimmed; published releases carry a publish timestamp and appear in the public changelog.
Version
Release date
State
Published
Notes (langs)
Loading…
Append-only registry of portal-issued licences (metadata only — the signed files
are never stored here). Expired rows carry an amber rule, archived ones a red rule.
The Instance column (#1717) tells same-org / same-type licences apart.
Archive (#1722) takes a wrongly-issued or
leftover test licence out of this list and out of the assign dropdown, and unassigns it from every
SSO user holding it. Nothing is deleted — the audit row stays, tick show archived to see
it again. It is not a kill switch: a licence already deployed at the customer keeps working
until its expiry date, so archiving cannot switch an instance off.
Issued
Organization
Org link
Instance
Type
Modules
Year
Users
Expires
By
Assigned to
Loading…
Keycloak service account not configured on the server
(LICENSE_PORTAL_KC_CLIENT_SECRET) — user management is disabled.
Username
Name
Email
Enabled
Licences (a user can hold several)
Loading…
Every tenant instance the SaaS control plane knows about. The
domain is the primary identity — click a row for the live debug / health panel.
Read-only (lifecycle, firewall, backups & monitoring are later slices of #1716).
Control plane not configured or unreachable on the server
(kodemed.license-portal.control-plane.base-url) — the instance console is
unavailable.
Health
Domain
Organization
State
Version
Provider
Region
Instance id
Actions
Loading…
Loading…
Every tenant at a glance: live cluster health, the deployed version, the
last lifecycle job and the newest verified backup. A tenant whose cluster did not
answer is shown as unreachable — never as healthy.
Control plane not configured or unreachable on the server
(kodemed.license-portal.control-plane.base-url) — the fleet view is
unavailable.
Cluster
Domain
Organization
State
Version
Tier
Last job
Last backup
Cert
Loading…
Audit log
Who did what, to which tenant, when. Append-only: entries cannot be edited
or deleted — from this portal, from the control-plane API, or by the application at
all.
When
Action
Tenant / ref
Who
Detail
Loading…
Harbor pull credential created
Copy the secret NOW. Harbor shows it exactly once — it cannot be retrieved again,
not by this portal and not by Harbor. If it is lost you must revoke this access and
issue a new credential.