First sign-in requires a superadmin account. Create it in a terminal as described below, then open the admin address and sign in with the chosen username and password. These credentials belong to the generated application; Generator UI runs separately.
First browser sign-in
- Wait for the application backend and interface to start.
- Open the admin sign-in page.
- Enter the credentials created during bootstrap.
- After sign-in, open the required module and create your first record.
Required operator bootstrap
An empty application has no administrator. The operator creates one in the terminal. There is no public first-owner registration form: a random website visitor cannot acquire those privileges.
With make dev, account creation is offered during bootstrap. For Docker deployments, run the command in the running backend container. Set and repeat a password of 12–128 UTF-8 bytes; input is hidden. You cannot create the first account in the browser or use a default password.
On your local machine, run these commands from the project root for environment local. They find the backend container, check there is exactly one and start creating the owner account:
project_name=$(bash deploy/generated/runtime/environment.sh "$PWD" local | jq -er .project)
backend_container=$(docker ps -q \
--filter "label=com.docker.compose.project=$project_name-local" \
--filter "label=com.docker.compose.service=backend")
test "$(printf '%s\n' "$backend_container" | awk 'NF { n++ } END { print n+0 }')" -eq 1 || {
echo 'Ожидался ровно один работающий backend-контейнер' >&2
exit 1
}
docker exec -it "$backend_container" admin bootstrap-superadmin --if-needed --login owner
--if-needed makes repeating the command safe: if the first account already exists, no new account is created.
For a server environment, sign in to the backend server and run the command there. Replace $project_name-local with Compose project <project>-<environment>. Before running, verify the selected container and environment. Database connection settings, secrets and TLS come from the container configuration. For automation, use --password-file pointing to a private file inside the container. Do not put the password in arguments or shell history, or create the first account in a regular CI deployment job.
After first sign-in
Continue with the generated admin. Entity access settings are in Generator UI → Access. Other maintenance tasks are covered in generated application commands.