Skip to Content
Admin guidesOverview

Admin guides

These guides cover the day-to-day administration of ELM, in the order content flows through the system:

  • Sources - mirror upstream repositories from HTTP(S), rsync, ISO uploads, or CIQ Depot.
  • Content views - compose curated, versioned repositories with pin/exclude rules, custom uploads, snapshots, and rollback.
  • Hosts and groups - register machines with the agent and organize them into nested groups.
  • Provisioning - network installs with iPXE, kickstarts, and the credentials vault.
  • Authentication - local accounts, LDAP, and SAML 2.0.
  • Users, teams, and permissions - access control and the audit log.
  • Integrations - CIQ Depot catalog, Ascender automation, and Ascender Ledger connection settings.
  • API - the browsable REST API at /api/v1/.
  • Settings and signing - global behavior, retention, provisioning timeouts, and repository metadata keys.
  • MCP server - optional read-only access for AI assistants.

Server settings

Administrators configure global behavior under Settings:

  • General - canonical Base URL, trusted proxies, content-view snapshot retention, the daily source-cleanup time, and the provisioning timeout. See Settings and signing.
  • Integrations - CIQ Depot, Ascender, and Ascender Ledger connection details. See Integrations.
  • Authentication - LDAP and SAML providers, with test actions to validate a configuration before enabling it. See Authentication.
  • Signing - generate or import an OpenPGP key for optional repository metadata signing. See Settings and signing.