Web UI
Every server serves the web UI on its management port, 8443: the same address the CLI's context points at. It uses the same APIs as the CLI, so everything it shows, the CLI can show too.
Sign in
Open https://<server>:8443 and sign in as admin:
- A cluster:
orchestrator-zero server initprints the first password once, under Web UI. - Dev mode: the password is in
admin-passwordin the data directory, and the server logs the address and the file when it starts.
The browser warns about the certificate: the server's certificate comes from the cluster's own CA. Trust the CA on your machine (ca.crt in the operator context's folder), or accept the warning on a dev machine.
What you can do
The sidebar groups the pages by what you do: Operate (Overview, Jobs, Approvals), Build (Agents, Tools and skills, Plugins), Quality (Findings), Fleet (Nodes), Spend (Cost) and Admin (Settings).
Lists filter at the top and open a row in a drawer beside them, so you can look at one thing without losing your place. A page's address keeps its filters, its open tab, the row in the drawer and the step you opened, so a link shows what you saw. Hover over a job's ID anywhere to see what the job is.
| Page | What it shows and does |
|---|---|
| Overview | Nodes online and waiting, agents, jobs running, the last day's cost, recent jobs, the servers; each number links to its page |
| Nodes | Every node with its state, health, runtime, labels and last heartbeat, filtered by status or by ID, name, label or host; a node's drawer adds its machine, certificate and health penalties. Accept, reject, block, unblock and delete. Add nodes creates a join token and shows the two commands to run on the machine, ready to copy. Upgrade rolls a runtime out to every node, a canary first, and a panel above the nodes follows each step to its verdict, with Roll back while it runs |
| Agents | The agents of the tenant's plugins and where they can run, filtered by name or plugin, and a Run button that starts a job with an input and a budget; an agent's drawer links to its jobs |
| Tools and skills | The tenant's tools with their functions and the nodes that run them, and its skills |
| Plugins | Installed plugins with their version, commit, nodes and quality gate; a plugin's drawer has its source, tools, agents, the gate's report and its status on each node. Install from a Git URL, update, remove |
| Approvals | What waits for a person across the tenant's jobs; open one in the drawer to approve or deny it, with a comment |
| Jobs | Recent jobs, filtered by status, agent or ID; click a row to peek at a job without leaving the list. A job's page has a tab for its steps, a waterfall with findings and an inspector for each step; its live stream while it runs, child jobs on other nodes included; its answer; and its cost per branch. Beside them are the job's facts, its child jobs, and a link to its history in Temporal's own UI, which admins reach at /temporal/ |
| Findings | Jobs whose steps look wrong: loops, retries, idle time, waits for a node, budgets, workflow failures, filtered by rule, agent and period; a job's drawer has all its findings, its cost and a link to its steps |
| Cost | Cost and model calls over the last day, week or month, and this month against the tenant's budget; then by agent, model, node and job, each with a bar for its share |
| Audit log | Under Admin, for the tenant's admins: who changed what, and what the platform did by itself, filtered by action and target; an entry's drawer has its detail |
| Settings | Tenants, join tokens, secrets (set and delete; values are never shown) and API keys (shown once) for admins, people and their roles for owners, and your own password |
Accounts and roles
orchestrator-zero user add kim --role member # prints a generated password, once
orchestrator-zero user grant kim --role operator # kim's role in the default tenant
orchestrator-zero user grant kim --role reader --tenant acme --content
orchestrator-zero user add sam --role admin --password-stdin < password.txt
orchestrator-zero user list
orchestrator-zero user revoke kim --tenant acme
orchestrator-zero user password kim # a new password; signs kim out everywhere
orchestrator-zero user remove kim
An account has a role in each tenant it is a member of. Each role can do what the ones before it can:
| Role | May |
|---|---|
| reader | Look: nodes, agents, plugins, jobs and their steps, cost, findings |
| operator | Also start and cancel jobs, and decide approvals |
| admin | Also change the tenant: nodes and rollouts, plugins, secrets, join tokens, the budget; and read its audit log |
| owner | Also decide who is a member, under Settings, People, or with user grant |
Seeing what jobs read and wrote, such as prompts, answers, tool arguments and results, and each step's input and output, is a permission of its own. Operators, admins and owners have it unless an owner takes it away (--content=false), and readers do not unless an owner gives it (--content). Without it, the job page shows the shape of each job: which tools it called and when, its steps and their cost, but not their content.
The account itself has a cluster role: admin (the owner of every tenant, who also adds tenants and accounts), reader (reads every tenant) or member (only its tenants). server init and dev mode create one admin. Everyone can change their own password under Settings.
- Sessions last seven days and end when the password changes. Five wrong passwords for one name from one address within 15 minutes cost a minute's wait.
- The session cookie only works for requests from the app itself: other sites cannot use it, and the app loads nothing from anywhere else, so it works without internet access.
- The CLI keeps using its operator certificate; accounts are for people in a browser.
default tenant. A tenant switcher and sign-in with OIDC come later.