Administer

Configure public addresses and organisation sign in

Map frontend and API origins, register OIDC callbacks, and allow intended browser integrations.

Before you start

Prepare DNS, trusted HTTPS certificates, and gateway routes for every browser address. An origin is a scheme, hostname, and optional port without a path.

Configure the addresses

  1. As System Owner, open System Configuration, then Public addresses and CORS.
  2. Add each frontend origin and its browser facing API origin. Multiple frontend addresses may map to the same installation.
  3. Open Authentication connections and edit each OpenID Connect profile.
  4. Add the matching frontend and callback mappings. Register each exact callback with the identity provider as a confidential Web application redirect URI.
  5. Under Additional browser API access (CORS), add only approved integration origins. Leave session cookies off for bearer token clients.
  6. Save and reload each frontend.

Check the result

Test sign in from every public address and confirm the returned browser stays on its intended frontend. A private cluster address must not become the public sign in destination.

The API still checks authentication, tenant access, and exact resource actions. Allowing an origin does not grant Product permission.

If sign in returns to the wrong place

Compare the browser origin, mapped API origin, proxy route, and registered callback exactly. Check HTTPS trust on the browser and servers. Do not use a wildcard to hide a mapping error.

Next step

Read Authentication and access and Add and manage nodes.

Pūnaha Docs

Search the guides

Enter at least two characters.

    Product screen

    View the full screenshot