🛡️ Platform Admin

Operator-only. Shared admin secret, not a tenant login.

Auto-refreshes every 20s
Edge Nodes
--
Domains (all tenants)
--
Requests (range)
--
Sync Queue Pending
--
Sync Queue Failed
--
Traffic & Bandwidth
Top 10 Client Rates -- requests/min, last 60s window, across every domain
Client IPReq/minEdge Node
Loading…
Edge Node Health
NodeStatusHAProxyCorazaData Plane APIDiskMemoryLoad (1/5/15m)Last Seen
Loading…
Staging Environment -- fully separate deployment (own DB, own secrets), cross-read from this box; see infra/staging-setup.md
Loading…
All Domains
HostnameTenantBackendOwnershipSSLHealthWAFStrict PathsCreated
Loading…
Domain Ownership Verification -- anti-squatting hold: new domains stay off the edge and get no SSL cert until the tenant proves control via DNS TXT or an HTTP token
HostnameTenantStatusMethodRequestedVerified
Loading…
Domain Logs -- WAF events and traffic logs for any domain, any tenant, kept for 14 days

Platform-wide emergency levers. Each applies across every domain, every tenant, the moment it's saved -- layered on top of (never replacing) each domain's own settings. Off by default.

Default Rate Limit
IP Blocklist -- blocks these addresses on every domain, immediately
Bot Challenge
Platform Maintenance Mode -- takes every domain down at once
Tenant Status Banner -- an informational message shown on every tenant's dashboard; the dashboard stays fully usable, nothing is blocked
Per-Domain Rule Limit -- max rows a single domain can have in any one of IP / geo / path / rate-limit / bot-challenge rules; every rule becomes an entry in the shared per-edge-node rule list evaluated on every request, so this bounds how much one tenant can slow down the rest
Tenant DNS Target -- the CNAME value shown to tenants when they register a domain (not wired into the registration flow yet)

Full-platform HAProxy config snapshots, one per edge-agent commit. Rolling back affects every tenant at once.

Recent snapshots
Loading...
Snapshot