Manages the lifecycle of a Kademi account (organisation): creation, admin domain and URL resolution, and moving an account between parent organisations. Also captures an account's apps and settings as an AccountConfigSnapshot, diffs two snapshots into a ConfigDiff, and applies that diff to bring one account's configuration into line with another - used when deploying configuration between environments such as development and production. Stores per-tenant environment variables and secrets read by scripts and apps, and keeps a list of config items to ignore when diffing. Reached from server-side scripts as AccountManager.THIS(). May overlap with OrganisationManager, since account management responsibilities are being moved here over time.

Group: Managers


Properties

PropertyReturnsDescription
autoApplySupportedTypeIdsList<String>Config item type ids, such as 'settings', that at least one currently active app declares support for automatically applying during a configuration deployment.
defaultAdminMenuStringThe default admin menu identifier configured for the whole server, used when an organisation has not customised its own admin menu.
environmentVarsPathStringRelative content-storage path where this tenant's environment variables are persisted.
envVariablesPropertiesThe current tenant's environment variables, loaded from content storage and cached briefly to avoid repeated reads under load.
secretNamesList<String>Names of the secret properties stored for the current tenant, without their values.
secretsPropertiesThe current tenant's secret values, loaded from content storage and cached briefly to avoid repeated reads under load. Secret property names are always prefixed with 'secret.'.
thisAdminDomainStringFull external admin domain, including the '.admin.' segment and primary domain, for the current tenant organisation.
xstreamXStream

Methods

newAccountBuilder() · createAccount(NewAccountBuilder b) · createStandardAdminGroup() · createAccount(String company, Profile profile) · findAdminDomain(String adminDomain) · moveAccountParent(String newParentOrgId) · currentAdminUrl(String path, Profile loginProfile) · fullAdminDomain(String adminDomain) · getThisAdminDomain() · adminUrl(String adminDomain, String path, Profile loginProfile) · adminUrl(Organisation adminOrg, String path, Profile loginProfile) · createAccountConfigSnapshot() · getAutoApplySupportedTypeIds() · applyAccountConfigConfiguration(ConfigDiff config, RemoteServerCredentials creds, Consumer<String> statusCb, AtomicBoolean cancelled, Map<String,List<String>> selectedTypesByAppIdsMap) · listSnapshots() · loadSnapshot(String name) · deleteSnapshot(String fileName) · hideSnapshot(String fileName, Profile hiddenBy) · unhideSnapshot(String fileName) · saveSnapshot(String fileName, AccountConfigSnapshot acs) · enqueueDeploymentItem(String importConfigId, Map<String,List<String>> selectedTypesByAppIdsMap) · diffConfigSnapshots(AccountConfigSnapshot source, AccountConfigSnapshot dest) · applyIgnoredToDiff(ConfigDiff originalDiff) · configDiffToXml(ConfigDiff configDiff) · xmlToConfigDiff(String xml) · accountConfigToJson(AccountConfigSnapshot acs) · jsonToAccountConfigSnapshot(String json) · getDefaultAdminMenu() · getEnvironmentVarsPath() · putEnvVariable(String name, String value) · removeEnvVariable(String name) · getEnvVariables() · putSecret(String name, String value) · removeSecret(String name) · getSecrets() · getSecretNames() · addIgnore(String appId, String type, String portableId) · removeIgnore(String ignoreId) · findIgnoredItems()

newAccountBuilder()

Returns: NewAccountBuilder

Starts a fluent builder for creating a new Kademi account (organisation), optionally with a new administrator profile.

createAccount(NewAccountBuilder b)

Returns: Organisation

Creates a new account as a child organisation of the current admin org, using the settings collected on the given builder. If the builder has no profile, a new administrator profile is created for it and set back onto the builder. Also obtains a licence, initialises the admin domain, installs the builder's recipe app and starts a new project from it asynchronously.

ParameterDescription
bthe builder holding the company title, admin domain, recipe and either an existing profile or new-user details

createStandardAdminGroup()

Returns: Group

Gets or creates the standard Administrators group for the current tenant organisation, granting it the admin role. Idempotent: returns the existing group if one has already been created.

createAccount(String company, Profile profile)

Returns: Organisation

Creates a new account as a child organisation of the current admin org, named after the given company (or the profile's nickname if no company is given), and adds the given profile to its Administrators group. Unlike the builder-based createAccount, this does not obtain a licence, install a recipe or start a project.

ParameterDescription
companydisplay name to derive the new organisation's name from; falls back to the profile's nickname if blank
profilethe profile to add to the new account's Administrators group, or null to create the account without one

findAdminDomain(String adminDomain)

Returns: String

Derives a unique, URL-safe admin domain from the given name by lower-casing it, stripping unsafe characters, and appending an incrementing numeric suffix until no existing organisation already uses it.

ParameterDescription
adminDomaincandidate name to base the admin domain on, typically a company or nickname

moveAccountParent(String newParentOrgId)

Returns: void

Moves the current tenant account to be a child of a different parent organisation, identified by its admin domain. Requires the current user to hold the admin role on both the current parent and the destination parent, and the destination parent must have a valid licence.

ParameterDescription
newParentOrgIdadmin domain of the organisation to become the new parent

currentAdminUrl(String path, Profile loginProfile)

Returns: String

Builds an absolute admin URL for the current tenant organisation, optionally with an auto-login token for the given profile.

ParameterDescription
pathpath within the admin site to link to; a leading slash is added if missing
loginProfileprofile to generate auto-login parameters for, or null for a plain URL; must have admin or admin-viewer access to the organisation

fullAdminDomain(String adminDomain)

Returns: String

Builds the full external admin domain for the given short admin domain, by appending '.admin.' and the server's primary domain.

ParameterDescription
adminDomainthe organisation's short admin domain, as returned by findAdminDomain

getThisAdminDomain()

Returns: String

Full external admin domain, including the '.admin.' segment and primary domain, for the current tenant organisation.

adminUrl(String adminDomain, String path, Profile loginProfile)

Returns: String

Builds an absolute admin URL for the organisation with the given admin domain, optionally with an auto-login token for the given profile.

ParameterDescription
adminDomainadmin domain of the organisation to look up
pathpath within the admin site to link to; a leading slash is added if missing
loginProfileprofile to generate auto-login parameters for, or null for a plain URL; must have admin or admin-viewer access to the organisation

adminUrl(Organisation adminOrg, String path, Profile loginProfile)

Returns: String

Builds an absolute admin URL for the given organisation, optionally with an auto-login token for the given profile.

ParameterDescription
adminOrgorganisation to build the admin URL for
pathpath within the admin site to link to; a leading slash is added if missing
loginProfileprofile to generate auto-login parameters for, or null for a plain URL; must have admin or admin-viewer access to the organisation

createAccountConfigSnapshot()

Returns: AccountConfigSnapshot

Captures the current tenant account's configuration, the settings and other config items of every active app, as a portable AccountConfigSnapshot that can later be compared against another snapshot. Apps whose settings are considered non-portable, such as admin-lib and aws, are excluded, and non-marketplace apps have their content hash recorded so they can be reinstalled directly.

getAutoApplySupportedTypeIds()

Returns: List<String>

Config item type ids, such as 'settings', that at least one currently active app declares support for automatically applying during a configuration deployment.

applyAccountConfigConfiguration(ConfigDiff config, RemoteServerCredentials creds, Consumer<String> statusCb, AtomicBoolean cancelled, Map<String,List<String>> selectedTypesByAppIdsMap)

Returns: Map<String,List<String>>

Applies a previously computed configuration diff to the current tenant account: installing and enabling apps, switching app versions and updating app settings as needed. Runs inside a single transaction and can be cancelled part-way through, in which case the transaction is rolled back.

ParameterDescription
configthe diff describing which apps and config item types to apply, produced by diffConfigSnapshots
credscredentials used to fetch app content from the remote server when installing or updating an app
statusCbcallback invoked with human-readable progress messages as each app is processed
cancelledflag checked between apps; when set, processing stops and the transaction is rolled back
selectedTypesByAppIdsMapthe config item types to apply for each app id, restricting processing to only the selected apps and types

listSnapshots()

Returns: List<ConfigSnapshotInfo>

Lists the account configuration snapshots previously saved for the current tenant, including each one's file size, creation date and, if it has been hidden, who hid it and when.

loadSnapshot(String name)

Returns: AccountConfigSnapshot

Loads a previously saved account configuration snapshot by its file name.

ParameterDescription
namefile name of the snapshot to load, as returned by listSnapshots

deleteSnapshot(String fileName)

Returns: void

Deletes a previously saved account configuration snapshot. Does nothing if no snapshot with that file name exists.

ParameterDescription
fileNamefile name of the snapshot to delete, as returned by listSnapshots

hideSnapshot(String fileName, Profile hiddenBy)

Returns: void

Marks a saved account configuration snapshot as hidden, recording who hid it and when. Hiding does not delete the snapshot file.

ParameterDescription
fileNamefile name of the snapshot to hide
hiddenBythe profile hiding the snapshot

unhideSnapshot(String fileName)

Returns: void

Clears the hidden flag previously set on a saved account configuration snapshot by hideSnapshot.

ParameterDescription
fileNamefile name of the snapshot to unhide

saveSnapshot(String fileName, AccountConfigSnapshot acs)

Returns: void

Serialises an account configuration snapshot to XML and saves it to the current tenant's content storage under the given file name.

ParameterDescription
fileNamefile name to save the snapshot as; must not already exist
acsthe snapshot to save

enqueueDeploymentItem(String importConfigId, Map<String,List<String>> selectedTypesByAppIdsMap)

Returns: AsyncJob

Queues a background job that applies a previously imported deployment configuration to the current tenant account.

ParameterDescription
importConfigIdthe UUID of the imported config file to process
selectedTypesByAppIdsMapapps and their config item types to process, keyed by app id

diffConfigSnapshots(AccountConfigSnapshot source, AccountConfigSnapshot dest)

Returns: ConfigDiff

Compares two account configuration snapshots and builds a ConfigDiff describing every config item that was added, removed or changed between them, skipping items on the account's ignore list. For the admin website's app type, also adds warnings when app versions are inconsistent between the account and website level, or when a website has an unpublished change.

ParameterDescription
sourcethe earlier snapshot to compare from, or null to treat every item in dest as newly added
destthe later snapshot to compare to; must not be null

applyIgnoredToDiff(ConfigDiff originalDiff)

Returns: ConfigDiff

Filters a config diff by removing any deltas that match an entry in the account's ignore list, leaving the original diff untouched.

ParameterDescription
originalDiffthe diff to filter; must not be null

configDiffToXml(ConfigDiff configDiff)

Returns: String

Serialises a config diff to XML using this account manager's XStream configuration.

ParameterDescription
configDiffthe diff to serialise, or null

xmlToConfigDiff(String xml)

Returns: ConfigDiff

Deserialises XML previously produced by configDiffToXml back into a ConfigDiff.

ParameterDescription
xmlthe XML representation of a config diff

accountConfigToJson(AccountConfigSnapshot acs)

Returns: String

Serialises an account configuration snapshot to JSON using AccountManagerSerializer.

ParameterDescription
acsthe snapshot to serialise

jsonToAccountConfigSnapshot(String json)

Returns: AccountConfigSnapshot

Deserialises JSON previously produced by accountConfigToJson back into an AccountConfigSnapshot.

ParameterDescription
jsonthe JSON representation of a snapshot, or blank

getDefaultAdminMenu()

Returns: String

The default admin menu identifier configured for the whole server, used when an organisation has not customised its own admin menu.

getEnvironmentVarsPath()

Returns: String

Relative content-storage path where this tenant's environment variables are persisted.

putEnvVariable(String name, String value)

Returns: void

Sets an environment variable for the current tenant, persisting it to content storage and invalidating the short-lived read cache.

ParameterDescription
namethe environment variable name
valuethe value to set

removeEnvVariable(String name)

Returns: void

Removes an environment variable for the current tenant, persisting the change to content storage and invalidating the short-lived read cache.

ParameterDescription
namethe environment variable name to remove

getEnvVariables()

Returns: Properties

The current tenant's environment variables, loaded from content storage and cached briefly to avoid repeated reads under load.

putSecret(String name, String value)

Returns: void

Sets a secret value for the current tenant, persisting it to content storage and invalidating the short-lived read cache.

ParameterDescription
namethe secret name; must start with 'secret.'
valuethe value to set; stored as an empty string if null

removeSecret(String name)

Returns: void

Removes a secret value for the current tenant, persisting the change to content storage and invalidating the short-lived read cache.

ParameterDescription
namethe secret name to remove

getSecrets()

Returns: Properties

The current tenant's secret values, loaded from content storage and cached briefly to avoid repeated reads under load. Secret property names are always prefixed with 'secret.'.

getSecretNames()

Returns: List<String>

Names of the secret properties stored for the current tenant, without their values.

addIgnore(String appId, String type, String portableId)

Returns: void

Adds a config item to the account's ignore list, so future diffs and deployments skip it. Records the current user and timestamp against the new ignore entry.

ParameterDescription
appIdid of the app the ignored item belongs to
typeconfig item type of the ignored item, for example a website or app settings type
portableIdportable id of the config item to ignore

removeIgnore(String ignoreId)

Returns: void

Removes a single entry from the account's ignore list by its id.

ParameterDescription
ignoreIdid of the ignore entry to remove

findIgnoredItems()

Returns: IgnoredConfigItemList

The current tenant's list of config items excluded from configuration diffs and deployments.

To get full access to the Kademi Hub existing customers can login here, or new customers can register here.