Skip to content

Users & Roles

Every person signs in with a username and a password. There is no email address, no self-signup and no password-reset mail: a self-hosted server usually has no outbound mail. An email address still works as a username if you prefer that.

Role May do
user Everything in the application: all tools, tenant and sync settings, the license page, their own password.
admin The same, plus: manage users, install the HTTPS certificate, define new tenants, and decide where a stored credential is sent.

There are no permissions per tenant or per tool.

The last point protects your service keys. A stored secret is never shown, so it must not be possible to have it sent somewhere else either: only an administrator may create a tenant, or use a stored credential for a hostname it was not saved for.

Administrators find Users in the menu: add a user, change a display name or role, reset a password, delete a user. Every user changes their own password under Account.

  • Usernames have 3 to 64 characters: letters, digits, ., _, - and @. Clara and clara are the same user.
  • Passwords have at least 8 characters.
  • There is always at least one administrator: the last one cannot be deleted or demoted, and an administrator cannot delete their own account.
  • Changing a password signs that user out everywhere.

The first administrator is created during installation.

The command line works on the data directory without a running server. With Docker, use the same volume as the server:

Terminal window
# reset a password (asks for the new one)
docker run --rm -it -v pizug_companion:/data pizug/companion:2.0.0 user set-password --username admin
# create another administrator
docker run --rm -it -v pizug_companion:/data pizug/companion:2.0.0 user add --username rescue
# list users and their roles
docker run --rm -v pizug_companion:/data pizug/companion:2.0.0 user list

user add creates an administrator unless you pass --role user. user delete --username NAME removes a user.