# Web Portal

> Cordium documentation. Canonical page: <https://octelium.com/docs/cordium/latest/use/web-portal>.

The Cordium web portal is a browser-based console for creating, configuring and using *Workspaces*, *Spaces* and *Templates* without installing any software. It is available at `https://cordium.<DOMAIN>` and it is served as the Octelium `WEB` *Service* `default.cordium`. Everything you can do with the `cordium` CLI can also be done from the portal, from following a *Workspace*'s initialization live to opening terminals, editing specs in a form or in YAML, managing the *Members* of a *Space*, and chatting with the [Cordium Agent](https://octelium.com/docs/cordium/latest/use/agent.md).

## Signing In

Open `https://cordium.<DOMAIN>` in your browser. If you are not logged in yet, you are redirected to the *Cluster*'s login page where you can authenticate via any of its identity providers (e.g. GitHub, Google, Okta, Entra ID or any OpenID Connect or SAML 2.0 provider) or via a passkey (read more [here](https://octelium.com/docs/octelium/latest/management/core/identity-providers.md)). Your *User* must be authorized to access the `default.cordium` *Service* by an Octelium *Policy* (read more [here](https://octelium.com/docs/cordium/latest/management/access-control.md)).

The dashboard shows your running *Workspaces* and the *Spaces* that you belong to:

*Screenshot: The Cordium web portal dashboard showing two running Workspaces and three Spaces.*

The sidebar gives you access to the **Agent**, your **Spaces**, all your **Workspaces** across *Spaces*, your **Snapshots**, the Octelium **Services** that you can access, **Your Secrets** (i.e. *UserSecrets*) and your **Settings** (i.e. your *UserConfig*).

## Creating Workspaces

Click **New workspace** from anywhere in the portal, choose the *Space*, and optionally override the repository and the container image of the *Space*'s `default` *Template*. You can also create *Workspaces* from a specific *Template* via the **Launch a workspace** section of the *Template*'s page. **Ephemeral storage** creates an ephemeral *Workspace* whose storage is discarded on every stop, while **Full configuration** opens the complete spec editor (see [below](#configuring-workspaces)).

Once created, the *Workspace*'s state progresses live as it is initialized (e.g. `Start requested`, `Initializing`, `Pulling image`, `Preparing` and finally `Running`), and its **Logs** tab streams the image pull, the repository clone and the output of the lifecycle tasks in real time:

*Screenshot: Creating a Workspace from the web portal and following its initialization logs until it is running.*

You can list all your *Workspaces*, filtered by *Space*, from the **Workspaces** page:

*Screenshot: The list of Workspaces with their state, repository, Space and Template.*

## Using Workspaces

Every *Workspace* has its own page with the following tabs:

**Overview:** The overview of a running Workspace with its details and actions. The details of the *Workspace* (e.g. its URL, repository, storage, effective resources, *Volumes* and *Region*) and its actions.

**Terminals:** Running tests, querying a PostgreSQL Service and calling an HTTP Service without any credentials from a browser terminal. Browser terminals with multiple tabs. Octelium *Services* are reachable by name without any credentials.

**Logs:** The startup and task logs of a Workspace. The image pull, repository clone and lifecycle task logs of the current run.

**Snapshots:** The snapshots of a Workspace with their consistency and size. The *WorkspaceSnapshots* of the *Workspace*, which can be restored into new *Workspaces*.

**Config:** The configuration form of a Workspace. The spec editor of the *Workspace*.

The page header shows the *Workspace*'s state and lets you **Start** and **Stop** it, **Open** its default application in a new tab, and **View YAML** of the complete resource. The **Actions** panel lets you take a snapshot, jump to the *Workspace*'s *Template* and, for stopped *Workspaces* whose *Template* uses a *GitProvider*, **Sign in to Git provider** (read more [here](https://octelium.com/docs/cordium/latest/workspaces/secrets.md#using-gitproviders)).

### Terminals

The **Terminals** tab opens fully interactive shells inside running *Workspaces*, as the *Workspace* user. You can open as many terminals as you want, each in its own tab, and adjust the font size or switch to full screen. Terminal input counts as activity for the inactivity timeout (read more [here](https://octelium.com/docs/cordium/latest/workspaces/resources.md#inactivity-timeout)).

*Screenshot: Running tests, querying a PostgreSQL Service and calling an HTTP Service without any credentials from a browser terminal.* Inside the Workspace, the PostgreSQL and HTTP Services are accessed via secretless access, with no credentials in the environment.

### Applications

The **Applications** panel of the **Overview** tab lists the applications of a running *Workspace* and their HTTPS URLs. It also lets you share each application with the members of the *Workspace*'s *Space* or with all the *Users* of the *Cluster*, and stop sharing it at any time (read more [here](https://octelium.com/docs/cordium/latest/workspaces/applications.md#sharing-applications)):

*Screenshot: The Applications panel of a Workspace with the sharing menu open.*

### Configuring Workspaces

The **Config** tab lets you edit the display name, description and the complete spec of the *Workspace*, either via a form organized in sections (i.e. **Source**, **Image**, **Runtime**, **Volumes**, **Network**, **Applications**, **Resources** and **Variables**) or directly in YAML. The spec only contains what the *Workspace* overrides on top of its *Template* (read more about configuration levels [here](https://octelium.com/docs/cordium/latest/workspaces/overview.md#configuration-levels)), and changes take effect the next time the *Workspace* starts.

**Form:** The spec editor form with the repository clone options. The form editor, here with the primary repository and its clone options.

**YAML:** The YAML editor of a Workspace. The YAML editor, which is equivalent to the files used by `cordium run --file`.

## Spaces

The **Spaces** page lists your personal and organization *Spaces*. **New Space** creates a personal (`USER`) or an organization (`ORGANIZATION`) *Space*, provided that you are allowed to own *Spaces* (read more [here](https://octelium.com/docs/cordium/latest/workspaces/spaces.md#creating-spaces)):

*Screenshot: Creating an organization Space from the web portal.*

Every *Space* has its own page with tabs for its *Workspaces*, *Templates*, *Secrets*, *Volumes*, *GitProviders*, *Members* and settings. Managing *Templates*, *Secrets*, *Volumes*, *GitProviders* and *Members* requires the `ADMIN` or `OWNER` role (read more [here](https://octelium.com/docs/cordium/latest/workspaces/spaces.md#members-and-roles)):

**Overview:** The overview of an organization Space. The *Space*'s recent *Workspaces*, counters and default limits.

**Template:** The overview of a Template with its blueprint and runtime summary. A *Template* with its blueprint, runtime summary and pre-build status.

**Pre-builds:** The pre-builds of a Template with their states. The pre-builds of a *Template*. **Build** triggers a new one.

**Secrets:** The Secrets of a Space. The write-only *Secrets* of the *Space*.

**Volumes:** The Volumes of a Space with their access mode, size and capacity. The *Volumes* of the *Space*, which can be resized and deleted.

**Members:** The Members of a Space with their roles. The *Members* of the *Space* and their roles.

## Snapshots

The **Snapshots** page lists all your *WorkspaceSnapshots* across *Spaces* with their state, consistency, size and source *Workspace*. **Restore** creates a new *Workspace* out of a snapshot (read more [here](https://octelium.com/docs/cordium/latest/workspaces/snapshots.md)):

*Screenshot: The list of WorkspaceSnapshots.*

## Your Secrets

The **Your Secrets** page manages your personal *UserSecrets*. **New Secret** creates a secret from a value, a multi-line value or a file, or asks the *Cluster* to generate an SSH key pair whose public key you can register at your git hosting service (read more [here](https://octelium.com/docs/cordium/latest/workspaces/user-config.md#ssh-keys)):

*Screenshot: Creating an SSH key UserSecret and getting its public key.*

## Settings

The **Settings** page edits your *UserConfig*, i.e. your dotfiles repository, the environment variables and lifecycle tasks that apply to all your *Workspaces*, and your preferred *Region* when the *Cluster* has several *Regions* (read more [here](https://octelium.com/docs/cordium/latest/workspaces/user-config.md)). It also holds your portal preferences:

*Screenshot: The Settings page with the dotfiles and environment variables of the UserConfig.*

## Services

The **Services** page lists the Octelium *Services* that you are authorized to access, i.e. the *Services* that your *Workspaces* can reach by name via secretless access, along with their mode, *Namespace* and port (read more [here](https://octelium.com/docs/cordium/latest/workspaces/secretless.md)):

*Screenshot: The list of Octelium Services available to the User.*
