Customers
/admin/customers is a support view of every account. Accounts usually come from billing, which keeps the name and email; staff can also Add manually.
A customer’s page
- their servers
- recent activity from the audit log
- sign-in details, sessions and API tokens (an account keeps up to 50 sessions, signing out the least recently used past that, and up to 25 tokens)
- a read-only Networking & DNS card: private networks (with VXLAN IDs), floating IPs and DNS zones
- staff notes
- which reseller they belong to, if any
Actions
| Action | Permission |
|---|---|
| Sign out everywhere | Manage accounts |
| Reset two-factor, after checking who they are | Manage accounts |
| Lock / Unlock. Locked accounts can’t sign in, their teammates lose access to their servers, their scheduled tasks don’t run, and open consoles close within a minute. | Manage accounts |
| Sign in as customer | Sign in as customer |
| Move to a reseller, or make direct again | Manage resellers |
Signing in as a customer
Sign in as customer opens a 30-minute support session with a banner on every page and Back to admin. During it, their password, two-factor, keys, tokens, team, startup scripts, own ISOs and webhooks are read-only (a reseller’s webhooks too). The session appears in their session list, in their Account → Activity (without naming staff), and in the audit log.
- It ends straight away, and you’re back in your own account, if the customer signs it out from their session list, their account is locked, or your role no longer has Sign in as customer.
- Back to admin ends the support session and keeps you signed in. Signing out from it signs you out of the panel altogether.
- A staff member’s own client area can’t be signed in to by anyone else.
Self-service allowance
Give a customer an allowance on their page and they get Deploy server on their Servers page:
| Field | Notes |
|---|---|
| Quota | At most N servers, vCPUs, memory, disk and IPv4 addresses. Empty means no limit. |
| Packages | Which packages they may deploy |
| Locations | Which node groups |
Only servers deployed this way count against the allowance; servers ordered through billing don’t. Customers can destroy their self-service servers (with type-to-confirm), which frees the resources straight away, and change their package to any allowed one that fits. Traffic top-ups, extra IPs and speed limits stay with you.
A billing panel selling resource packs sets the allowance with PUT /api/v1/customers/{id}/allowance. Staff need “See customers” to see an allowance, and “Manage accounts” to change it.
Staff notes on servers
Staff can pin a private note to any server, such as an abuse ticket or “don’t null-route”. It shows at the top of the server’s Overview, and servers with a note are marked in the fleet table. Customers and resellers never see it, and every change is in the audit log.
Creating servers for customers
New server on /admin/servers or a customer’s page opens /admin/servers/new. You pick:
- the customer and a package (hidden packages can be used by staff)
- a location: the group’s placement rule chooses the node, or you choose one from the ranked list, which shows why other nodes are ruled out
- an optional name (what the panel shows, such as Client website)
The server is created Pending setup: the node, disk space and addresses are held, but nothing is installed. The customer is told it’s ready, and its page shows a setup screen instead of the usual tabs, where they pick the image, the hostname (such as web01 or web01.example.com), their SSH keys or a generated root password, and optionally a startup script. Build server starts the install. You can finish the setup for them from the same page; the login choices are then the customer’s SSH keys or a generated password shown to you once.
Until it’s set up, the server can only be suspended, locked, moved to another customer or node, or terminated. Moving it to another node happens at once, since there’s nothing to copy, and works even when its node is down. Terminating it frees what it held without touching the node. Billing can still create a server and build it in one call by sending an image; see the billing API.
You can still create a server in a group that isn’t accepting servers, or with a package that isn’t sold there; the page warns you. It needs the “Create servers” permission.
Moving a server to another customer
Move to another customer in a server’s ⋯ menu hands it to another account, and sends server.owner_changed. Moving it into a reseller’s account is checked against that reseller’s terms.
Nothing of the old account’s comes along: its firewall groups, private networks, floating IPs, its own ISO (one from the shared library stays mounted), alert rules and scheduled tasks are removed from the server, and its activity history starts again so the new owner doesn’t see the old one’s. The full record stays in the audit log.
Its snapshots and backups are deleted, from the node and from backup storage, since they hold the old account’s data; the dialog says so before you confirm, and the audit entry says how many went. It can’t be moved while a snapshot or backup is being taken or restored.