Skip to main content
Version: v3.9.0

Reach the console

The Controller embeds EdgeOps Console. You do not run a separate console container. At startup the Controller writes controller-config.js into the embedded static build. The console reads window.controllerConfig from that file. You do not edit controller-config.js by hand.

This page is how you reach the console. The Config sidebar group is Configuration.

Public URL and listen port​

You set the public URL and the listen port on the Controller.

SettingYAML keyEnvironment variableDefault
Listen portconsole.portCONSOLE_PORT8008
Public URLconsole.urlCONSOLE_URLDerived from CONTROLLER_PUBLIC_URL if unset
console:
port: 8008
url: "https://console.example.com:8008"

Set CONSOLE_URL to the scheme, host, and port users type in the browser. OAuth redirect URIs depend on this value.

After the control plane is up, open that URL. You can also run potctl view for the connected cluster.

The Controller sets consoleUrl from CONSOLE_URL, then falls back to CONTROLLER_PUBLIC_URL, then http://localhost:{CONSOLE_PORT}.

Full Controller settings: Controller configuration.

Runtime controller-config.js​

At startup the Controller injects a script like this into the embedded console build:

window.controllerConfig = {
apiPort: 51121,
publicUrl: "https://controller.example.com:51121",
consoleUrl: "https://console.example.com:8008",
auth: {
mode: "embedded",
loginUrl: "/api/v3/user/login",
refreshUrl: "/api/v3/user/refresh",
logoutUrl: "/api/v3/user/logout",
profileUrl: "/api/v3/user/profile",
changePasswordUrl: "/api/v3/user/change-password",
oauthAuthorizeUrl: "/api/v3/user/oauth/authorize",
oauthInteractionUrl: "/login/oauth",
},
controlPlane: "Remote",
}

Fields the console reads​

FieldPurpose
publicUrlScheme, host, and port for Controller REST and WebSocket calls
consoleUrlPublic console URL for OAuth redirects and same-origin checks
auth.modeembedded (default) or external
auth.*UrlLogin, refresh, logout, profile, password, and OAuth paths, relative to publicUrl
controlPlaneOptional. Remote, Kubernetes, or Local for UI hints

The console does not read viewerUrl. Use consoleUrl and the auth block above.

Authentication​

Console OAuth uses a dedicated client on the Controller.

Environment variableYAML keyDescription
OIDC_CONSOLE_CLIENT_IDauth.consoleClientSPA client ID for EdgeOps Console
AUTH_CONSOLE_CLIENT_ENABLEDauth.consoleClient.enabledRegister and enable the console OAuth client

Embedded mode is the default. The issuer is {CONTROLLER_PUBLIC_URL}/oidc. Bootstrap the first admin with OIDC_BOOTSTRAP_ADMIN_USERNAME and OIDC_BOOTSTRAP_ADMIN_PASSWORD. Walkthrough: Embedded OIDC.

External identity: set AUTH_MODE=external and OIDC_ISSUER_URL. Walkthrough: External OIDC.

Sign-in screens are in Identity and sign-in.

TLS and reverse proxies​

The console and the API can both use TLS. Set CONTROLLER_PUBLIC_URL and CONSOLE_URL to the external HTTPS URLs. Behind a reverse proxy, enable TRUST_PROXY on the Controller so redirect URIs and CORS origins match what clients send.

Listener certificates use the TLS_* variables. Details: Controller configuration.

Console source: edgeops-console. Production images embed the static build/ output via EDGEOPS_CONSOLE_PATH at Controller build time.

Group 3See anything wrong with the document? Help us improve it!