Skip to content

Console

Lists every page of the console, its settings panels, and the actions that need a fresh re-authentication.

Every page of the console, the settings panels, and the actions that require a fresh re-authentication.

Page What it shows
Schema The merged schema: namespaces, entities, fields, keys, foreign keys, and the physical table names. Entities with changes waiting for approval carry a marker linking to Approvals.
History Every schema version, newest first, with its change classes, the person or caller behind it, the diff, and the SQL that ran. Unattended applies show the policy tier and rehearsal verdict that authorised them.
Sandbox Isolated test databases holding the organisation’s schema and no production data: seeding, SQL, checkpoints, compare, fork.
Workers Connected job-worker sessions and per-queue summaries, with per-session drain and evict.
Health Live server activity: the most recent log lines, polled about every second.
Callers The repositories enrolled with this organisation: registration, certificate expiry, enrolment, aliases, and each caller’s apply policy and rehearsal grant. Enrolment covers single-use tokens, the developers-may-enrol flag, and CI federation rules.
Approvals Changes waiting on a human. Each shows the proposed .atl source first, then the SQL, the change class, the requester, and any rehearsal verdict. Rehearse, approve, reject and override act from here.
Parked Objects destructive migrations kept instead of dropping, and how long each remains recoverable.
Operations Rollback (preview and execute), the dead-letter queue with per-job retry, and the audit log.
Settings The organisation’s policies and security controls.

An imported database gets its own review page: entities read from the live database, suggested tightenings, and the commit and apply steps that record the baseline. See Adopt an existing database.

Settings panels

Panel Contents
General The organisation’s endpoint and current schema version.
Members Who you are signed in as, the organisation, and your role. Read-only; atlantis support adds members and sets roles.
Security Your password, managed at Cloud, and your other sessions.
Change policy Three panels: the per-class approval rules, protected entities, and freeze windows. See Change approval.
Danger zone Sign out every session. Revoke all caller certificates revokes every caller: all of them stop authenticating and their registered files are removed. Each is restored individually from the Callers page, and its files re-register on the caller’s next apply.

Roles

Role What it can do
viewer Every read.
developer Every read, plus booting sandboxes, triggering rehearsals, and deciding plans for any change class whose policy names developer as the approver.
admin Everything: registration, enrolment, policies, overrides, import plan and apply, rollback, the danger zone.

Actions requiring re-authentication

Reading is open to every signed-in user. The actions below need the role and a fresh re-authentication at Cloud (“sudo”):

  • Approving or overriding a plan
  • Editing the change policy, protected entities, or freeze windows
  • Setting a caller’s apply policy or rehearsal grant
  • Minting an enrolment token; changing enrolment policy or federation rules
  • Restoring a revoked caller
  • Setting caller aliases; draining or evicting a worker
  • Applying a schema import
  • Signing out all sessions; revoking all caller certificates

Rejecting a plan needs the role and no re-authentication.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close