Admin console

The Admin app is an authenticated operations client for the Manager operations API. It provides job and Worker summaries, detail screens, health status, lifecycle actions, telemetry, and grouped Worker capabilities. Its server handles OIDC login and proxies REST and SSE requests with the user's access token.

Connectivity

The Admin app loads and validates configuration at runtime. Local development defaults to Admin on http://localhost:4500 and Manager on http://localhost:4400. Configure a separate Admin OIDC public client whose access token has the dedicated encode-flow-admin audience. Restrict issuance of that audience to authorized operators in the identity provider. Set the Manager's OIDC_OPERATIONS_ADMIN_AUDIENCE to the same value.

PORT=4500
STAGE=local
ADMIN_PUBLIC_URL=http://localhost:4500
CONTROL_PLANE_URL=http://localhost:4400
OIDC_ISSUER=https://account.example.com
OIDC_CLIENT_ID=encode-flow-admin
OIDC_AUDIENCE=encode-flow-admin
AUTH_ENCRYPTION_KEYS=replace-with-at-least-32-random-characters
yarn nx run @encode-flow/admin:dev

The browser connects to the Admin server's same-origin GET /api/events endpoint with EventSource. The server forwards it to the Manager's protected operations stream. While connected, job.progress, job.updated, and worker.updated invalidate or patch the relevant views. If SSE disconnects, React Query polls the Admin REST proxy every 10 seconds until the stream recovers.

Operations

  • Cancel queued or active jobs from the job detail screen.
  • Drain a Worker without interrupting its active attempts.
  • Inspect state, connectivity, capacity, CPU, memory, GPU, disk, and counts.
  • Expand capability groups for GPU, hardware acceleration, encoders, decoders, and filters.
  • Use health status to distinguish a reachable process from ready dependencies.

Security and deployment

The Admin server reads its Manager origin at runtime and does not expose it to browser components. It stores OIDC sessions encrypted, attaches the access token to Manager requests, restricts the proxy to operations and readiness routes, and checks the request origin for mutations. It does not hold NATS or PostgreSQL credentials.