Skip to main content
Version: 2026.09

Creating Platform Administrators

An installation needs at least one Platform Administrator. Only a Platform Administrator can create tenants and appoint other administrators, and the chart grants the role to no one. Grant it from the command line with ensure-platform-admins:

  • after you enable the Identity Service, to create the first ones;
  • whenever no Platform Administrator is left, or none can act.

Once one exists, they appoint others in the Platform Admin Console.

Prerequisites​

  • kubectl access to the namespace where the Identity Service runs.
  • An Identity Service image of 2.0.0 or later; earlier images don't include ensure-platform-admins.
  • The istari-identity and docker-pull-secret secrets. If yours have other names, change them in the command.
  • Each person's account at your identity provider. On Zitadel or Keycloak, it needs a verified email. On Microsoft Entra ID, the command can grant the role only to someone who already has an Istari account (linked or pre-registered by Object ID), because Entra never claims a pre-registration by email.
  • The tenant they sign in to: one the chart's Zitadel import created, named by its Zitadel organization's ID (how to find it), or one you created, named by its slug with -tenant.

Steps​

  1. Run ensure-platform-admins as a one-off pod. Replace <tag> with your Identity Service image tag, <organization id> with the organization's ID, and <email> with the person's address. For a tenant you created, replace "-organization","<organization id>" with "-tenant","<tenant slug>". After a switch to Keycloak, change zitadel to keycloak. Add -n <namespace> if the Identity Service isn't in your current namespace.

    kubectl run ensure-platform-admins --rm -i --restart=Never \
    --image=istaridigital.jfrog.io/customer-docker/identity-service:<tag> \
    --overrides='{
    "spec":{
    "imagePullSecrets":[{"name":"docker-pull-secret"}],
    "containers":[{
    "name":"ensure-platform-admins",
    "image":"istaridigital.jfrog.io/customer-docker/identity-service:<tag>",
    "command":["/ensure-platform-admins"],
    "args":["-database-url-env","ISTARI_DIGITAL_IDENTITY_SERVICE_DATABASE_URL",
    "-organization","<organization id>",
    "-provider","zitadel",
    "-email","<email>"],
    "envFrom":[{"secretRef":{"name":"istari-identity"}}]
    }]}
    }'
    FlagMeaning
    -emailA person to make a Platform Administrator. Repeat "-email","<email>" for each person.
    -organizationThe Zitadel organization whose tenant they sign in through. Anyone the command doesn't know yet is pre-registered there.
    -tenantThe tenant's slug, in place of -organization.
    -providerThe identity provider whose sign-in claims a pre-registration: zitadel, or keycloak after a switch to Keycloak.

    Running it again is safe: it never removes the role from anyone.

  2. Check the output, one line per address:

    OutputMeaning
    <email>: pre-registered and granted the platform administrator role, principal <id>Nobody had this address. Their first sign-in through the organization takes over the new record.
    <email>: granted the platform administrator role, principal <id>They now hold the role.
    <email>: principal <id> already holds the platform administrator roleNothing to do.
    WARNING: <email> skipped: <reason>Nothing granted; the reason says why.
    • Someone in another organization's tenant is skipped. Run the command once per organization.
    • A suspended person is skipped. Reinstate them first.
    • WARNING: no platform administrator exists at the end means nobody holds the role yet. Fix the skipped addresses and run it again.
  3. Verify. Each person signs in at https://<customer_istari_fqdn> and can open the Platform Admin Console.