Licence and plugins
What is free, what the licence key unlocks, how to install and activate it, and what happens when it expires.
What is free
The core platform, without any key:
- the operations tree, the service catalogue and every registration field;
- the Kubernetes agent, the shell agent, HTTP probes and the three push endpoints;
- status history, stale detection, storage reports and backup reports with overdue flags;
- CMDB and the dependency graph in both directions;
- users, groups, the four roles, field-level permissions, LDAP sign-in, sessions;
- notifications, global search, saved filters, outgoing webhooks;
- the whole GraphQL and REST API.
What the licence unlocks
Two plugins, both in the premium tier:
| Plugin | Name in the licence | Adds |
|---|---|---|
| SLA measurement | sla |
uptime and error budgets per service and group, incidents, maintenance windows, the daily report, the status page feed |
| Ticketing | ticketing |
the ITIL ticket system, workflows, the catalogue, automatic incident tickets |
A licence can carry either or both. max_users caps the number of active accounts.
The key
The licence is a JWT signed with Ed25519, issued per customer. Decoded, it carries customer, plugins, max_users, iss: itops-license, iat, exp and jti. The verification key is built into the server; the signing key is not in the server binary at all. The server accepts a different verification key through ITOPS_LICENSE_PUBLIC_KEY, which is how a customer-specific issuing key would be used.
Install it as ITOPS_LICENSE_KEY:
secretEnv:
ITOPS_LICENSE_KEY: "eyJhbGciOiJFZERTQSIs…"
# or, GitOps-safely:
secretRefs:
ITOPS_LICENSE_KEY: { name: itops-licence, key: token }
It is validated at startup and the plugins it names start. Without a key, or with an invalid one, the platform runs in base mode and says so in the log and on the Licence page.
Activating without a restart
curl -X POST $API/api/v1/license/activate -H "X-API-Key: $KEY" \
-H "Content-Type: application/json" -d '{"licenseKey": "eyJhbGciOiJFZERTQSIs…"}'
An admin session works too. Every connected client receives a license:updated event and the UI enables the plugin screens without a reload. Put the key in the values file as well, or the next restart loses it.
Switching a plugin off
An admin can disable a licensed plugin at runtime with the togglePlugin mutation or the switch on the Licence page. The setting is stored in the database and survives restarts. A disabled plugin goes quiet: its screens hide, its workers stop, its data stays. Snapshots keep arriving while the SLA plugin is off, and the aggregator backfills them when it is enabled again, so a month is not lost by a week of being switched off.
ITOPS_PLUGINS_SLA_ENABLED=false and ITOPS_PLUGINS_TICKETING_ENABLED=false do the same from the environment. In production these variables can only disable; they never enable a plugin the licence does not carry.
Expiry
The Licence page and licenseInfo in GraphQL show the state:
| Days left | Level |
|---|---|
| more than 30 | ok |
| 30 or fewer | warning, shown in the UI |
| 7 or fewer | critical, shown in the UI |
| expired | expired; the plugins stop, the data stays |
A background checker broadcasts the warning to signed-in admins. Renewal is a new key, installed the same way.
Getting a licence
Write to puskas.balazs@36306800800.hu with the number of users and which plugins you want. The demo licence that powers https://demo.mlops.hu is a product licence for a fictional company and cannot be reused.