Skip to main content
Applies to:
Cockpit v2Host tenant & guardHost settings · dashboard · monitoring

The host tier​

The host is a system tenant that sits above every ordinary tenant. It owns cross-tenant operations — creating tenants, defining editions, setting platform-wide defaults, and monitoring the instance.

Host access control (defense in depth)

Host operations are protected by layered checks that require all of: an authenticated user, membership in the host tenant, and an explicit host-level permission. Access is granted on permissions rather than role names. The host tenant is itself never feature-gated.

Host settings​

Host settings define platform-wide defaults. They are grouped into four areas:

GroupContains
GeneralPlatform name, default language and available languages, default timezone, date format
SecurityPassword policy (minimum length, character classes), lockout threshold and duration, session and token lifetimes, require-2FA, session timeout
EmailSMTP host / port / credentials / TLS, default from-address and name
BillingEnable flag, default currency, tax rate, company details and tax id

The host can also edit an individual tenant's settings — security and general overrides, logo and theme — through per-tenant settings.

Dashboard and monitoring​

The host tier exposes an operational view across all tenants — a platform-wide summary plus operational KPIs, both across all tenants and per individual tenant.

API reference
Detailed API endpoints are documented separately in the Developer Docs → Platform Administration API.

Instance & environment configuration​

Some configuration is set at the instance level (operator-managed environment settings) rather than through the application — for example the database connection and TLS material. One host-relevant switch:

VariablePurpose
DKE_UNLICENSED_ALL_FEATURES_OKFor self-hosted installs: synthesize an open "all features" edition. An explicit opt-in — the platform is otherwise fail-closed, not fail-open.
Deployment model is orthogonal to editions

Whether the platform runs as managed SaaS or self-hosted is a deployment choice, not an edition. Self-hosted installs use the environment switch above rather than a special "on-premise" edition — deployment and editions are independent (see Editions).

API reference​

The host tier exposes operations to read and update host and per-tenant settings and to retrieve dashboard and monitoring data, each governed by host-level permissions on top of the host access controls described above.

API reference
Detailed API endpoints are documented separately in the Developer Docs → Platform Administration API.