Users

Installer accounts sign in to the DataMind Installer only. DataMind OS users are separate: see First sign-in to DataMind OS.

The sidebar entry is Register User. The screen heading is User Management: the users list on the left, the Add User form on the right. The first admin is created at the first visit, as Install on a fresh host describes.

Roles and what they can do

ActionAdminUser
Read every screen, watch services, read job and service logsYesYes
Install, start, stop, restart and update DataMind OS, apply configurationYesNo
Edit configuration and the Azure client secretYesNo, read-only, secrets masked
See the users list, create, change or remove accountsYesNo

The users list

Each row shows the account, its role badge and Active or Inactive.

ButtonEffect
Reset passwordSets a new password without the old one. Signs the account out of every session
Deactivate user / Activate userBlocks or allows sign-in. Deactivation signs the account out
Make admin / Make regular userChanges the role at once
Change emailChanges the account's sign-in address
Delete userRemoves the account and signs it out

Each action asks you to confirm. On your own row, Deactivate user, the role button and Delete user are disabled. To change your own address, use Change email in the account menu.

Signing in signs the same account out of other browsers.

Add a user

Enter the person's email address, a password that meets the password rule, the same password in Confirm password, and the Role, User (the default) or Admin, then click Add User. The address is stored in lower case.

Check it worked. The toast User created appears and the new account is highlighted in the list.

Adding an address you deleted earlier brings that account back with the new password and role. An address in use is refused with Email already taken.

The password rule

At least 8 characters, with an uppercase letter, a lowercase letter, a number and a special character. It applies to the first account, to Add User and to Reset password. A password that fails it is refused with Password must be at least 8 characters and contain uppercase, lowercase, number, and special character.

Recover when no admin can sign in

You need shell access to the host.

  1. Open a database shell on the Installer's database:

    bash
    docker exec -it delamain-postgres sh -c 'psql -U "$POSTGRES_USER" -d "$POSTGRES_DB"'
  2. List the accounts:

    sql
    SELECT email, role, is_active, deleted_at FROM users;
  3. Then follow the case that fits.

Another account can still sign in

Promote it. Use its address in lower case:

sql
UPDATE users SET role = 'admin', is_active = true
WHERE email = '<address>' AND deleted_at IS NULL;

Check it worked. The SELECT shows the account with role admin, is_active = t and an empty deleted_at, and you can sign in with it. Then use Reset password on the admin who could not sign in.

No account can sign in

Mark every account deleted:

sql
UPDATE users SET deleted_at = now() WHERE deleted_at IS NULL;

Then open http://<host>:8000. The first-visit form returns: create the admin again.

Check it worked. You can sign in with the new admin account.

Questions, answered

How does a user get a new password?

An admin sets one with Reset password.

I deleted an account by mistake. Can I get it back?

Yes. Add a user with the same address. The account returns with the password and role you enter.

Can an admin lock themselves out?

No. Their own row keeps deactivate, demote and delete disabled. If every admin password is lost, use the database recovery above.