Troubleshooting
Problems with signing in, with the edge in front of the console, and with reading the Overview. Each message is quoted from the code, so you can search for it. For other areas see the troubleshooting page of DevEx, DataEx, Intelligence and FORGE.
Console sign-in
“… is not authorized for this console”
Cause. The Google account signed in correctly, but it is not on the console’s allowlist
(emailAllowed in auth.go). When neither CONSOLE_ALLOWED_EMAILS nor CONSOLE_ALLOWED_HD is set,
every Google sign-in is refused. This is deliberate: an unset allowlist used to admit every
Google account on the internet.
Fix. Add the address to CONSOLE_ALLOWED_EMAILS (a list) or set CONSOLE_ALLOWED_HD to your
hosted domain. The name is CONSOLE_ALLOWED_EMAILS, not the apps’ AUTH_ALLOWED_EMAILS.
“Sign-in is unavailable: this console cannot open its session store (appfs core-console/run/sessions). Your credentials were not the problem — tell an operator.”
Cause. Sessions are stored server-side in the console’s encrypted appfs root, and it cannot be
mounted. At boot the console logs 🛑 CONSOLE SIGN-IN DISABLED — a sign-in method is configured but the session store (appfs core-console/run/sessions) cannot be mounted, so every sign-in will be refused. It does not exit, because the same process also reconciles the fleet.
Fix. Check CORE_ENVELOPE_KEK and the OBJECTSTORE_* or CONSOLE_APPFS_DIR wiring of the
core-operator Deployment. The mount is retried on the next sign-in.
“Invalid username or password.”
The password path compares against CONSOLE_ADMIN_USERNAME (default admin) and
CONSOLE_ADMIN_PASSWORD. Every failure is recorded in the audit chain as auth.login denied.
“password sign-in is not configured”
A 404 from /auth/password: CONSOLE_ADMIN_PASSWORD is unset, so the password path is off. Use
Google sign-in, or set the password.
“Captcha verification failed. Please try again.”
reCAPTCHA is configured and the assessment failed. It runs before the credential check, on both sign-in paths.
“csrf check failed”
A 403 from /auth/callback. The Google Identity Services form post must carry the same
g_csrf_token in the cookie and in the body. A request without it is refused. Reload the sign-in page
and try again, and check that nothing between you and the console strips cookies.
“Sign-in failed. Try again.” / {"error": "sign-in failed"}
The Google ID token did not verify: a wrong audience (the console’s GOOGLE_CLIENT_ID), a wrong
issuer (OIDC_ISSUER, default https://accounts.google.com), or an unverified email.
“sign-out could not revoke your session on the server; it expires on its own — tell an operator”
A 503 from /auth/logout: the session store could not be written. The session still expires after
its 12-hour lifetime.
{"error": "unauthorized"} on every request
Your session expired or was revoked (for example with POST /api/sessions/revoke-all). The web app
returns you to the sign-in screen on any 401.
Refused writes
“… is not permitted to … on this console (CONSOLE_AGENT_ADMINS)”
The shape is <identity> is not permitted to <action> on this console (<ALLOWLIST>). You are signed
in, but a privileged write checks a named allowlist and you are not on it. The name in brackets is
the one to change: CONSOLE_AGENT_ADMINS, CORE_CONNECTION_ADMINS, CONSOLE_INSTANCE_ADMINS,
CORE_ATLAS_ADMINS, CORE_RUNNER_ADMINS or CONSOLE_SESSION_ADMINS. DataEx › Trust › Policy &
ReBAC (GET /api/access) shows which lists are live and whether you are on each.
“this console has no sign-in configured, so … would be unattributable”
The console is running open (neither GOOGLE_CLIENT_ID nor CONSOLE_ADMIN_PASSWORD is set). Reads
work, but no privileged write is accepted, because the audit trail could not name anyone. Configure
a sign-in method.
“this console has no sign-in configured, so nobody can be shown the audit trail — …”
Same cause, on DevEx › Audit chain. With sign-in configured, reading the audit trail also needs
CONSOLE_SESSION_ADMINS, and an unset list means nobody.
The edge (devgateway)
These come from grpc/cmd/devgateway/auth.go, in front of every routed host.
| Message | Cause | Fix |
|---|---|---|
auth: <email> is not permitted (403) | the account is not on the edge allowlist | add it to the edge allowlist Secret (edge-auth-secrets/allowed-emails) |
auth: sign-in is unavailable (no session store) — tell an operator (503) | the edge’s session store is not mounted | see the boot log line below |
auth: state expired (400) | the sign-in round trip took too long | start the sign-in again |
auth: token exchange failed (502) | the OIDC token exchange with the identity provider failed | check the edge log line auth: token exchange failed: … |
At boot, the edge logs its configuration errors as ERROR: edge auth is ENABLED but …:
… DEVGW_AUTH_ALLOWED_EMAILS is empty — every sign-in will be REFUSED.Populateedge-auth-secrets/allowed-emails, or setDEVGW_AUTH_ALLOW_ANY_VERIFIED=trueto admit any verified Google account on purpose. (An empty allowlist used to admit everyone; it no longer does.)… DEVGW_SESSION_KEY is unset or shorter than 16 bytes …. Populateedge-auth-secrets/session-key(identical on every edge pod) and roll the DaemonSet.… the session store cannot be mounted …. SetCORE_ENVELOPE_KEKand eitherOBJECTSTORE_*or a writableDEVGW_APPFS_DIR, then roll the DaemonSet.
The edge stays up in every one of these cases and keeps serving /healthz. It terminates TLS for
every routed host, so crash-looping it would turn a sign-in outage into a total one.
Reading the Overview
| What you see | What it means |
|---|---|
A red notice under the header, and the kube-api source marked absent | /api/dashboard could not list a tracked namespace. The notice gives the first error, for example listing deployments in <namespace>: …. An unreadable namespace is never drawn as a healthy one. |
| Agent runs (7d) and Success rate show “—” with “Install the CORE GitHub App to show agent-run status + logs here. …” | the console has no GitHub App credential, so it cannot read Actions runs. It is not zero runs. |
Success rate shows “—” with N ok · M failed | no run in the window has finished yet; running and cancelled runs are not graded |
| Client instances is neutral (not green) | there are no instances: nothing to judge is not a pass |
The pill says 4/5 healthy | one tracked Deployment or DaemonSet has fewer ready replicas than desired. A DaemonSet scheduled onto zero nodes counts as unhealthy. Open DevEx › Cluster › Namespaces. |
Navigation
| Symptom | Cause |
|---|---|
A ?tab= link opens Overview | the name is not a live or retired tab name; see the console map |
| The Admin row is missing | the rail shows it only when the server says you are an admin of the chosen instance. Choose an instance on the landing cards first. |
| The landing cards appear after a reload | the instance remembered in the browser (or named by ?instance=) is no longer in your roster, so it was forgotten |