Skip to main content

Admin API Configuration

The [admin] section controls PRISM's administrative API, which provides health checks, metrics, cache management, and cache warming endpoints.

TOML Example​

[admin]
enabled = true
address = "127.0.0.1:4001"
bearer_token = "your-secret-token"

Parameters​

ParameterTypeDefaultDescription
enabledBooleantrueEnable or disable the admin API
addressString"127.0.0.1:4001"Socket address for the admin API
bearer_tokenString or nullnullOptional bearer token for authentication

Detailed Explanation​

enabled​

When false, PRISM does not start the admin API listener. You lose access to health checks, metrics, and cache management endpoints.

address​

The admin API listens on a separate port from the main server. By default it binds to 127.0.0.1:4001, restricting access to localhost. In containerized deployments, you may want 0.0.0.0:4001 for health check probes from the orchestrator.

bearer_token​

When set, all admin API endpoints except GET /health require an Authorization: Bearer <token> header. This secures cache purge, warmup, and other mutating operations.

When null (default), PRISM generates a token for the run and logs it at startup — the API is never served unauthenticated. The generated one changes on every restart, so set this to keep it stable.

Using peers requires it: a generated token cannot be shared, so each replica would sign forwarded purges with its own and every peer would reject them. Startup refuses peers without a configured token rather than letting the fan-out fail silently.

GET /health, /ready and /startup never require a credential, so orchestrator probes work either way.

To run with no authentication at all, set insecure_no_auth = true.

metrics_bearer_token​

A read-only credential accepted only for GET /metrics. Give this one to Prometheus so the scrape credential cannot purge the fleet; every other path answers 401 to it. The full bearer_token keeps working on /metrics too.

[admin]
bearer_token = "admin-secret" # full control
metrics_bearer_token = "scrape-only" # GET /metrics and nothing else

Audit events​

Every mutating admin call (/purge/*, /render, /warmup) emits a structured info-level event on the audit tracing target: endpoint, caller IP, parameters, entries removed, and peer fan-out results. Route or retain them separately with an EnvFilter directive such as audit=info.

Licence visibility​

GET /status reports version, license (valid / trial / expired / no_license / invalid) and licensed; /metrics exposes prism_license_valid (alert when 0) and prism_license_info{status=...}.

Example Use Cases​

Kubernetes deployment with health checks​

[admin]
enabled = true
address = "0.0.0.0:4001"
bearer_token = "k8s-admin-secret-42"

The liveness/readiness probe hits GET /health (no auth required), while cache management operations require the bearer token.

Disabled admin API​

[admin]
enabled = false

Local development​

[admin]
enabled = true
address = "127.0.0.1:4001"
# No token needed for local dev