Creating Platform Administrators
An installation needs at least one Platform Administrator. Only a Platform Administrator can create tenants and appoint other administrators, and the chart grants the role to no one. Grant it from the command line with ensure-platform-admins:
- after you enable the Identity Service, to create the first ones;
- whenever no Platform Administrator is left, or none can act.
Once one exists, they appoint others in the Platform Admin Console.
Prerequisites
kubectlaccess to the namespace where the Identity Service runs.- An Identity Service image of 2.0.0 or later; earlier images don't include
ensure-platform-admins. - The
istari-identityanddocker-pull-secretsecrets. If yours have other names, change them in the command. - Each person's account at your identity provider. On Zitadel or Keycloak, it needs a verified email. On Microsoft Entra ID, the command can grant the role only to someone who already has an Istari account (linked or pre-registered by Object ID), because Entra never claims a pre-registration by email.
- The tenant they sign in to: one the chart's Zitadel import created, named by its Zitadel organization's ID (how to find it), or one you created, named by its slug with
-tenant.
Steps
-
Run
ensure-platform-adminsas a one-off pod. Replace<tag>with your Identity Service image tag,<organization id>with the organization's ID, and<email>with the person's address. For a tenant you created, replace"-organization","<organization id>"with"-tenant","<tenant slug>". After a switch to Keycloak, changezitadeltokeycloak. Add-n <namespace>if the Identity Service isn't in your current namespace.kubectl run ensure-platform-admins --rm -i --restart=Never \--image=istaridigital.jfrog.io/customer-docker/identity-service:<tag> \--overrides='{"spec":{"imagePullSecrets":[{"name":"docker-pull-secret"}],"containers":[{"name":"ensure-platform-admins","image":"istaridigital.jfrog.io/customer-docker/identity-service:<tag>","command":["/ensure-platform-admins"],"args":["-database-url-env","ISTARI_DIGITAL_IDENTITY_SERVICE_DATABASE_URL","-organization","<organization id>","-provider","zitadel","-email","<email>"],"envFrom":[{"secretRef":{"name":"istari-identity"}}]}]}}'Flag Meaning -emailA person to make a Platform Administrator. Repeat "-email","<email>"for each person.-organizationThe Zitadel organization whose tenant they sign in through. Anyone the command doesn't know yet is pre-registered there. -tenantThe tenant's slug, in place of -organization.-providerThe identity provider whose sign-in claims a pre-registration: zitadel, orkeycloakafter a switch to Keycloak.Running it again is safe: it never removes the role from anyone.
-
Check the output, one line per address:
Output Meaning <email>: pre-registered and granted the platform administrator role, principal <id>Nobody had this address. Their first sign-in through the organization takes over the new record. <email>: granted the platform administrator role, principal <id>They now hold the role. <email>: principal <id> already holds the platform administrator roleNothing to do. WARNING: <email> skipped: <reason>Nothing granted; the reason says why. - Someone in another organization's tenant is skipped. Run the command once per organization.
- A suspended person is skipped. Reinstate them first.
WARNING: no platform administrator existsat the end means nobody holds the role yet. Fix the skipped addresses and run it again.
-
Verify. Each person signs in at
https://<customer_istari_fqdn>and can open the Platform Admin Console.