Skip to content

Administration (tenant, provisioning, org setup, secrets)

The VNCdirectory+ sidebar has three admin areas: Tenant administration, Org Setup and Secrets & Keys.

Tenant → Administration for the selected tenant (the tenant picker is top left).

  • Seats — Seats licensed, Seats used and Retained (the headline numbers, and a meter at the top right, for example 9 / 30).
  • Seats & domains — set Seats licensed, and manage the tenant’s Domains (add one to claim it).
  • OIDC / JWKS — the tenant’s OIDC issuer and JWKS URI, with a /tenants/resolve test (enter a domain or tenant id and Resolve).
  • Save settings applies the changes; the badge shows live · API.

Tenant administration: seats, domains, OIDC/JWKS and user provisioning

Below the tenant settings, Tenant → User provisioning provisions an account:

  1. AI-assisted fill — describe the user (for example “Andrea Demo, full access, ABC Holdings”) and select AI fill. It gathers context from the directory and Keycloak (units, roles) — review before submitting.
  2. Fill or confirm the Identity & access form (name, unit, roles).
  3. Submit to provision the user.

Org Setup models the organisation: the Organisation tree and its Effect, a Runbook, and profile actions. Save applies, and a runbook can be generated/archived. → Units and entitlement

The God-Key registry — store, manage, recover — the suite’s root of trust. It has three tabs:

  • Key-chain pyramid — how the keys derive from one another.
  • DR restore flow — the disaster-recovery order.
  • Key registry — every key, filtered by Layer and Criticality.

Each key shows its criticality — GOD-KEY · root, Admin or Service — and what it unlocks. Examples: the Hetzner Robot login + 2FA (the break-glass to every server), the Paper recovery set (GOD-KEYS.txt) (the printable set that survives a full disaster), the sealed-secrets master key, the admin SSH / WireGuard / Proxmox / Kubernetes keys, and the service keys (Keycloak, Infisical, Gitea).

The Secrets & Keys registry: the God-Key pyramid, DR restore flow and the key list

Treat this registry as break-glass material: it is the highest-privilege surface in the suite. Access is audited.

Applies to VNClagoon+ 2026.09 and later.

© 2026 VNC - Virtual Network Consult AG. All rights reserved.