Admin setup
Operator tasks: minting tokens for users, managing the token lifecycle, and grouping namespaces into an organization. This page is hidden from the public sidebar and excluded from search engines.
Toggle dev-mode pages with Cmd+Shift+D (macOS) or Ctrl+Shift+D.
Prerequisites
| Requirement | Why |
|---|---|
CLI installed (npm i -g @dreamlake/lakeshore) | The admin command group lives here. |
LAKESHORE_ADMIN_TOKEN exported | Every lakeshore admin subcommand exits 1 without it. |
| A resolvable control plane | Either LAKESHORE_URL (+ LAKESHORE_NAMESPACE) or a saved lakeshore auth login. |
The admin token is the control plane's LAKESHORE_ADMIN_TOKEN config
var — the same value the server boots with:
admin tokens create mints into the namespace the CLI resolved, not a
namespace you name on the command line. That is LAKESHORE_NAMESPACE
when LAKESHORE_URL is set, otherwise the namespace: in
~/.config/lakeshore/auth.yml, defaulting to default. Set
LAKESHORE_NAMESPACE before minting for someone else.
Onboarding a user
The command mints the token, prints it once, and hands you a ready-to-paste setup line for the recipient:
Omit the name and the label defaults to <$USER>-<YYYY-MM-DD>. Labels
must match ^[a-zA-Z0-9][a-zA-Z0-9_-]{0,63}$.
Only the SHA-256 hash of the plaintext is stored, plus the first 8 characters as a display prefix. There is no recovery path — if the recipient loses it, mint a new one and revoke the old.
A recipient who only uses the Python SDK can skip auth login and write
the credential file by hand:
lakeshore auth login writes this file with mode 600; do the same if
you create it manually.
Listing and revoking
list prints NAME, PREFIX, CREATED, LAST USED, STATUS.
LAST USED reads never until the token authenticates once.
Revocation is a soft delete: the row stays listable with
revoked <date> in STATUS, and the auth hook answers 403 for every
subsequent request carrying it.
Batch onboarding
Deliver the plaintexts over a channel you trust — a shared password vault, not chat. They are shown exactly once.
Namespaces and organizations
None of these take flags. Slugs must match
^[a-z0-9][a-z0-9-]{0,63}$.
An organization is just a shared orgId string on two or more
namespaces. The effects are concrete:
- A token scoped to one member namespace authenticates against any
sibling that shares the
orgId— the auth hook stops returning 403 on the namespace mismatch. - Provider and queue listings are scoped to the org's namespaces, so every member sees the same set. Provider names must be unique across the org, not just within one namespace.
The CLI has no flag for orgId yet, so set it over the API:
PATCH accepts only orgId; send null to remove a namespace from its
org, and any other body shape returns 400.
A namespace with a null orgId gets an unscoped provider listing — it
sees every provider on the control plane, not just its own. Give every
tenant namespace an orgId if you want provider isolation between
teams.
To act as a different namespace from the CLI, point the environment at
it rather than looking for a flag — there is no global --namespace
option:
Daemon enrollment tokens
Daemons do not use dlk_ tokens. A daemon enrolls with a one-shot
enroll token — plaintext prefix dle_, single-use, namespace-scoped,
default TTL one hour and a hard cap of 30 days. These are minted through
POST /v1/namespaces/:ns/enroll-tokens (admin-only) and are not yet
exposed as a lakeshore admin subcommand.
Control plane surfaces
| Surface | URL |
|---|---|
| API (control plane) | https://api.lakeshore.dreamlake.ai |
| Dashboard | https://demo.lakeshore.dreamlake.ai |
| Liveness | GET /healthz — { ok: true }, no I/O |
| Readiness | GET /readyz — pings Mongo + Redis, 503 when either is down |
See also
- Quick start — the flow you hand to a new user.
- Auth and secrets — the auth tiers and the secret store.
- Deployment — standing the control plane up in the first place.