Skip to content

DocsEnterprise

Licence and set-up

Turn on the Enterprise Edition with a licence key checked offline, read its state, and create the first administrator.

One package, a key

The Enterprise Edition is in the bbm-atlas package you already have. Without a licence key it stays off and BBM-Atlas is the Community Edition; with one, the features the key names turn on. There is nothing else to install.

To buy a licence, or for an evaluation key, write to info@byteblendmatrix.com.

Install your key

terminal
export BBM_ATLAS_EE_LICENSE_KEY_FILE=/run/secrets/bbm_atlas_license   # or BBM_ATLAS_EE_LICENSE_KEY=BBMA1…bbm-atlas enterprise license      # its state, features and seatsbbm-atlas serve

The key is signed and checked offline: nothing phones home, so air-gapped sites work. When both are set, the file wins. bbm-atlas enterprise license exits with 1 when the key isn't active, so scripts can check it.

Its state

StateWhat happens
validThe features the key names are on
graceIt expired, and the features keep working through the grace period (14 days by default) while the log warns
expiredThe features switch off and BBM-Atlas runs as the Community Edition. No data is deleted, organisations stay apart, and a renewed key restores everything
missing or invalidThe Community Edition, with the reason in the log

The start-up log reports the state, and so does GET /api/v1/enterprise/license for administrators. Neither ever shows the key.

Features and seats

FeatureTurns on
identityUsers, service accounts and their own API keys (People, roles and keys)
rbacRoles, checked on every route and tool
organisationsSeveral teams on one deployment (Organisations)
ssoSingle sign-on with OIDC or SAML 2.0 (Single sign-on)
auditThe hash-chained audit log (Audit log)
haReplicas sharing one job queue (High availability)

Seats are people: each user takes one. Service accounts, for CI and scripts, don't.

The first administrator

With the identity feature every request needs a key, so create the first administrator. On the first start with no principals at all, BBM-Atlas creates them from one setting and prints their API key once:

terminal
export BBM_ATLAS_EE_BOOTSTRAP_ADMIN_EMAIL=admin@example.combbm-atlas serve     # prints the administrator's key, once# Or, before starting, against the store serve will use:bbm-atlas enterprise bootstrap admin@example.com

Once anyone exists, both do nothing. Keep the key safe: it is never shown again, and is stored only as a hash. The static keys in BBM_ATLAS_API_KEYS keep working: an admin key acts as an Administrator, an ordinary key as an Architect (BBM_ATLAS_EE_API_KEY_ROLE changes that).

Running the Community Edition anyway

BBM_ATLAS_EXTENSIONS_ENABLED=false runs the Community Edition whatever is installed or licensed.