Kilolock Control

Operator notes

- Billing is enforced per workspace.
- Quotas count only managed Terraform resources.
- Archived environments/states do not consume active customer quota.
- Shared-host ownership transfer is supported in-product; dedicated/BYODB migration stays manual in MVP.

Auth

Create Workspace

Creates an organization workspace with an auto-generated ws_... identifier and matching default label.

Control Operators

- Creates a control-login token with a scoped role; the raw token secret is shown only once below.
- Suspended operator tokens stay visible here by default so you can recover them quickly.
- Role guide: support_readonly read only, support_admin recover/archive state and environments, security_admin manage tokens and RBAC, tenant_admin tenant-scoped admin, billing_admin billing only, provisioner provisioning only, platform_admin full access.
- Scope ref: leave blank for global, use workspace_id for tenant scope, or workspace_id/environment_label for environment scope.
Last created operator token (shown once):


Workspace Entitlements

Hard quota is computed as soft + 50%.

Portal Config

- Cloud-only deployment settings consumed by the customer portal.
- Editable here and stored in KLC metadata database.
- Useful for billing visibility and backend.tf snippet generation defaults.



Workspaces

Environments by Workspace

Filters

Lifecycle

Token status deleted performs a hard delete.

Create Environment

Environment Policy


Create Token


Inspect Environment States

Inactive states are shown by default here so support can recover or reactivate them directly from the table.

State Policy


State Lifecycle / Support

Use this for support restore/archive actions. Restoring requires the exact stored state name.

Ownership Transfers


Retention Purge (Archived Tenants)


RBAC Grants