Manage users and credentials
Login and credentials
The login command allows you to log in to a server running in server mode. All users you create within the system have full access to all resources, secrets, and services that the server provides.
First time login
When you run the server for the first time, the system creates a temporary admin account with a temporary password of admin.
Run the following command from the gateway client and enter admin as the password:
The system then prompts you to enter a new password. Follow all remaining proimpts to confirm your password and complete your first login.
Admin login process
To create the admin login:
- Start the gateway server
- The system creates the temporary admin user and password
- Log in with the temporary admin user and password
- Change password
- Authenticate to gateway server
- The server generates an API key that is passed in gRPC calls
User login with temporary password
To create a user with a temporary password flag:
- The user logs in with the temporary password
- The system prompts the user to change the password (required)
- The user changes the password
- The user authenticates to the gateway server
- The server generates an API key that is passed in gRPC calls
Standard login process
Once a user changes their temporary password, their login process resembles the following:
- The user logs in with their password
- The user authenticates to the gateway server
- The server generates an API key that is passed in gRPC calls
Reset admin password
Resetting the admin password requires access to the server instance to perform the reset action.
To reset the password, run:
This command prompts you to enter a new password for the admin user if it’s already set.
Manage users
Create a user account
The create user command creates a new user.
When creating a user account for another user, use the --temp-password flag. This requires the user to change their password the first time they log in to the server.
All users within the system are power users, so ensure that any users you create are trusted.
View users
The get users command displays a list of all users stored within the database.
View user details
The describe user command displays all information about a specific user in the database. It shows when the user was created as well when they last logged in. A login event occurs when the user successfully runs the login command from an iagctl client against the gateway server.
Delete user
The delete user command deletes a user from the database. You cannot undo deletion operations. When you delete a user, the system removes all API keys associated with that user and denies further access.