Self-hosted edition
Users and sign-in
Roles
| Role | Can |
|---|---|
| viewer | see everything, change nothing |
| operator | also run lifecycle commands (start, stop, restart) |
| admin | also manage instances, agents, settings, users and the license |
Roles are enforced by the server on every request — hiding a button in the browser does not grant access to what it does.
How many users
Your license sets how many admins and operators you can have: Free is a
single user, Starter up to 3, Professional up to 10 and Enterprise 20.
Viewers are unlimited from Starter up. When the limit is reached, adding or
promoting an admin/operator is refused — in the browser and in the
users command — until you add the person as a viewer or upgrade. Need more
Enterprise users? We raise the number on your license key; nothing to reinstall.
Managing users
Admins add, edit and remove users in Settings. From the server's command line you can do the same — useful if every admin is locked out:
sudo runuser -u ords-monitor -- ords-monitor users list
sudo runuser -u ords-monitor -- ords-monitor users add jane 'S3cure-Passw0rd' operator
sudo runuser -u ords-monitor -- ords-monitor users passwd jane 'N3w-Passw0rd'
Sign-in methods
Besides local usernames and passwords, an admin can enable these in Settings (Authentication):
- Duo Universal MFA — per user: set a user's sign-in type to Duo and they
approve every sign-in on their phone. Needs a Duo "Web SDK" application
(client ID, client secret, API hostname) with the redirect URI
https://your-server/auth/duo/callback. - LDAP / Active Directory — users sign in with their directory password; their role comes from directory group membership.
- SAML 2.0 and OpenID Connect — a "Sign in with …" button for your identity provider (Azure AD / Entra ID, Okta, Oracle IDCS, Keycloak, ADFS …). The role comes from the provider's group claim.
Authentication settings and their secrets are stored in /var/lib/ords-monitor,
which only the ords-monitor service account can read.