Botique

Botique Central

Platform Control Plane & Cloud Orchestrator

Sign In with Microsoft Config Required
Or with password

Restricted to authorized Botique platform operators (@botique.cloud, @botique.be).

Botique
Single-Use Activation

Activate Operator Account

Set your secure password to enter Botique Central

Operator: user@botique.cloud
Role Assigned: PLATFORM_SUPERADMIN
Botique Central Control
RS256 JWKS Active
W
wietse@botique.cloud

Customer Cloud Instances

Orchestrate, publish, and provide JIT support to dedicated enterprise Botique-Cloud instances.

View JWKS

Total Clouds

0

Active Deployments

0

Official Release

v1.0.0

Control Plane DB

PostgreSQL (botique_central)

Published Customer Tenants

Tenant / Name Cloud URL Tier Version Status Container Runtime Actions
Loading published customer clouds...

Platform User Management

Manage Central Platform SuperAdmins, Support Operators, and Tenant Owners.

Registered Users & Operators

Name Email Role Status Actions
Loading users...

Platform Settings

Configure Microsoft Entra ID (Graph API) email automation and Hetzner Cloud DNS automated routing.

Hetzner Cloud DNS Integration

Automates DNS A-record registration for new customer cloud subdomains (e.g. slug.botique.cloud).

DNS Status

Operational
Active Zone: botique.cloud
Target IP: -
Token Configured: Yes
Last Tested: -

Microsoft Entra ID / Graph Email

Authenticates via Microsoft Graph Client Credentials (OAuth 2.0).

Email Status

Operational
Sender: agent@botique.cloud
Secret: Configured
Last Tested: -

Send Test Preview Email

Resend Email Delivery resend-go/v2

High-deliverability transactional mailing service for invites, security alerts, and system notifications.

Found in your Resend Dashboard → API Keys. Encrypted and never exposed in cleartext.

Service Status

Not Configured
Active Sender: -
API Key Status: Not Set
Last Verified: -

Send Live Test Email

Microsoft Entra ID (Azure AD) SSO ISO 27001 / CRA

Configure Single Sign-On credentials for corporate operator authentication with MFA and zero password storage.

Copy and paste this into Azure Portal → App Registration → Authentication → Redirect URIs (Web).

SSO Status

Not Configured
Active Directory: common
App Client ID: Not Set
Secret Status: Not Set
Last Tested: -

Domain Restriction Active

Only authenticated users with corporate emails ending in @botique.cloud or @botique.be are allowed operator console access.

GitLab & Private Container Registry Server 2 (Ops)

Configure sovereign CI/CD repository connection, container registry credentials, and operator SSH deployment keys.

Add this key in GitLab → Edit Profile → SSH Keys to enable passwordless terminal pushes to port 2222.

GitLab CI/CD Runner Dev Runner

Register and connect this server's runner container with GitLab to execute sovereign CI/CD builds.

Checking...
Runner Container: botique-dev-runner
Dispatches pipeline jobs tagged for this node (Development Environment).

Container running on this host (e.g. botique-dev-runner or botique-prod-runner).

Must match the tags specified in .gitlab-ci.yml jobs.

Obtain from GitLab: Project / Group Settings → CI/CD → Runners → New project runner. Copy the token starting with glrt-.


              
Executes automated registration inside container via Docker socket.

Cluster Infrastructure

Not Tested
GitLab Web: gitlab.botique.cloud
Registry: registry.botique.cloud
Git SSH: Port 2222
Deploy Token: Not Set
Runner Status: Checking...
Runner Tags: -
Last Tested: -

Sovereign CI/CD Architecture

GitLab CI/CD builds container images directly into registry.botique.cloud. Jobs with tag hetzner-dev deploy to Dev, while jobs with tag production deploy to Central.

Platform Audit Trail

Chronological record of cloud publishes, upgrades, and administrative actions.

Loading audit trail...
>_

Live Container Logs & Telemetry

Dozzle Stream

Real-time log streaming, CPU/RAM utilization gauges, and container events from Docker daemon.

URL:
Open in New Tab

Dozzle Service Not Responding

Ensure the botique-dozzle container is running on port 8888 (docker compose up -d botique-dozzle).

Try Opening Directly

Publish New Botique-Cloud

.botique.cloud

JIT Support Token Minted

RS256 cryptographically signed Just-In-Time support token recognized by the customer's @botique/auth module.

Launch Support Session →

Invite Operator / Admin

Enter operator details. A single-use secure activation link will be automatically generated and sent via Resend.

Invitation Generated

Invitation email successfully dispatched via Resend!
Single-use token

Delete Customer Tenant

This action will permanently delete Acme Corp (acme) and stop/remove its container.

Warning: This action cannot be undone. To prevent accidental deletion, please type DELETE in capitals below.

Delete Operator Account

Are you sure you want to permanently delete operator User (user@botique.cloud)?

Access Revocation: This will revoke access immediately and purge any pending invitation tokens.

Upgrade Customer Cloud Version

Roll out a verified release package to tenant instance

Tenant Instance Acme Corp acme.botique.cloud
Current Version v1.0.0
Select target version
Loading release catalog...
Advanced: Specify custom release tag or commit SHA

Overrides selection above. Ensure this image exists in registry.botique.cloud.