Skip to main content

Admin panel

The Django admin at /admin/ includes an upload statistics dashboard for operators.

Security: Admin is cross-tenant — it lists all companies' buckets, objects, and quotas. For production:

  • Set DJANGO_ADMIN_ENABLED=false on public API pods and run admin on a separate internal deployment.
  • Restrict admin to a private network, VPN, or IP allowlist.
  • Enforce MFA on operator accounts via your identity provider.
  • Prefer manage.py createsuperuser over the home-page bootstrap when DEBUG=false.

See Production security for the full hardening checklist.

Access​

  1. Create the first superuser:
uv run python manage.py createsuperuser

With DEBUG=true (local default), the home page also shows a one-time web form on first visit. In production (DEBUG=false), the form is hidden unless you set SETUP_TOKEN and open /?setup_token=<token> once.

  1. Open http://localhost:8001/admin/ and sign in.
  2. Full report: http://localhost:8001/admin/statistics/

What you see​

SectionContents
Overview cardsTotal objects, document count/size, buckets, uploads (24h / 7d)
Daily chartUploads over the last 14–30 days
MIME familiesImages, Text/Markdown, Office/PDF, Video, …
Top MIME typesExact content types
By company / bucketUsage breakdown
QuotasUsed vs limit with usage meters
Recent uploadsLatest files (documents tagged)

Model changelists (buckets, objects, quotas) remain available below the dashboard on the admin index.