Configuration & access
Configure console settings, device access, and optional site collectors.
Configuration and secrets
Day-to-day application configuration lives in the console’s Settings. File-based secrets are provisioned separately: the repository setup uses secrets/; the native appliance uses protected credential files under /etc/cenovel/credentials. Native deployment settings are checked in /etc/cenovel/appliance.conf.
cenovelctl config checkSome changes, such as the listener port, take effect after a restart. Follow the instructions shown for the setting.
Device access and polling
As Administrator EX, open Governance → Monitoring → Configuration → Access for credentials and site collectors. Use Schedule to configure how often devices are read.
Cenovel reads switches over SSH using Device CLI profiles. SNMPv3 authPriv can also be used where configured; its profiles require SHA-2 authentication and AES privacy. SNMP does not need to be enabled for SSH polling.
Microsoft sign-in and permissions
Microsoft Entra ID sign-in uses authorization code with PKCE. Configure the tenant, client, secret, redirect URI, and group mappings. Review individual role assignments as well as the default tier; an existing assignment can affect the resolved role.
Optional site collectors
A site collector provides a path to configured management networks. Provision its credentials and allowed networks, and use the enrollment flow in Monitoring. Confirm the collector configuration supplied with your installed release.
Read the operator reference
4. Configuration, device access, and sign-in Application settings are managed in the console's Settings. File-based secrets are provisioned separately: the repository setup uses secrets/; the native appliance uses protected files under /etc/cenovel/credentials. Native deployment settings are validated in /etc/cenovel/appliance.conf. Some settings, including the listener port, take effect after a restart. As Administrator EX, open Governance > Monitoring > Configuration > Access for device credentials and site collectors. The Schedule section controls how often devices are read. Monitoring > Networks holds the configured networks, and Found devices holds discovery results for review. Cenovel reads switches over SSH with Device CLI profiles. SNMPv3 authPriv is also available where configured; profiles require SHA-2 authentication and AES privacy. SSH polling does not require SNMP to be enabled. Device reads depend on configured credentials, allowed networks, and trust checks. A site collector provides a path to configured management networks; use the enrollment and configuration procedure for the installed collector release. Microsoft Entra ID sign-in uses authorization code with PKCE. Configure the tenant, client, secret, redirect URI, and group mappings. Review individual role assignments as well as defaults; an existing assignment can affect the resolved tier. The local recovery account provides a separate sign-in path.
Reviewed against the current source code. Native appliance administration commands require the appropriate host privileges; validate deployment procedures on your own release before production use.