DocsEnterprise
Licence and set-up
Turn on the Enterprise Edition with a licence key checked offline, read its state, and create the first administrator.
One package, a key
The Enterprise Edition is in the bbm-atlas package you already have. Without a licence key it stays off and BBM-Atlas is the Community Edition; with one, the features the key names turn on. There is nothing else to install.
To buy a licence, or for an evaluation key, write to info@byteblendmatrix.com.
Install your key
export BBM_ATLAS_EE_LICENSE_KEY_FILE=/run/secrets/bbm_atlas_license # or BBM_ATLAS_EE_LICENSE_KEY=BBMA1…bbm-atlas enterprise license # its state, features and seatsbbm-atlas serveThe key is signed and checked offline: nothing phones home, so air-gapped sites work. When both are set, the file wins. bbm-atlas enterprise license exits with 1 when the key isn't active, so scripts can check it.
Its state
| State | What happens |
|---|---|
| valid | The features the key names are on |
| grace | It expired, and the features keep working through the grace period (14 days by default) while the log warns |
| expired | The features switch off and BBM-Atlas runs as the Community Edition. No data is deleted, organisations stay apart, and a renewed key restores everything |
| missing or invalid | The Community Edition, with the reason in the log |
The start-up log reports the state, and so does GET /api/v1/enterprise/license for administrators. Neither ever shows the key.
Features and seats
| Feature | Turns on |
|---|---|
identity | Users, service accounts and their own API keys (People, roles and keys) |
rbac | Roles, checked on every route and tool |
organisations | Several teams on one deployment (Organisations) |
sso | Single sign-on with OIDC or SAML 2.0 (Single sign-on) |
audit | The hash-chained audit log (Audit log) |
ha | Replicas sharing one job queue (High availability) |
Seats are people: each user takes one. Service accounts, for CI and scripts, don't.
The first administrator
With the identity feature every request needs a key, so create the first administrator. On the first start with no principals at all, BBM-Atlas creates them from one setting and prints their API key once:
export BBM_ATLAS_EE_BOOTSTRAP_ADMIN_EMAIL=admin@example.combbm-atlas serve # prints the administrator's key, once# Or, before starting, against the store serve will use:bbm-atlas enterprise bootstrap admin@example.comOnce anyone exists, both do nothing. Keep the key safe: it is never shown again, and is stored only as a hash. The static keys in BBM_ATLAS_API_KEYS keep working: an admin key acts as an Administrator, an ordinary key as an Architect (BBM_ATLAS_EE_API_KEY_ROLE changes that).
Running the Community Edition anyway
BBM_ATLAS_EXTENSIONS_ENABLED=false runs the Community Edition whatever is installed or licensed.