rebase admin

Superadmin view of every workspace — members, quota, and this month's spend — with the quota editable in place.

Synopsis

rebase admin
rebase admin workspaces [--limit <n>] [--json]
rebase admin set <workspace> [--max-memory-mib <mib>] [--max-cpu-milli <milli>]
                             [--max-run-timeout-seconds <s>] [--max-job-timeout-seconds <s>]
                             [--max-concurrent-runs <n>] [--max-instances <n>] [--max-concurrency <n>]
                             [--monthly-credit-cents <cents>] [--json]

Bare rebase admin opens the TUI. The two subcommands are its headless twins, for a shell over SSH or a script.

Who can use it

These commands call the API's /admin/* routes, which are gated by a profile-level superadmin check: the caller's session email must be listed in the API's SUPERADMIN_EMAILS and be under the company domain. Two consequences:

  • It needs a session credential (rebase setup), not an API key — a key is refused.
  • It works on every workspace, including ones you are a member of. That is deliberately unlike rebase workspace compute-policy set, whose principal-level gate refuses a superadmin who is also a member, because a real membership row always wins.

Subcommands

SubcommandArgumentsDescription
nonenoneOpen the admin TUI.
workspacesnoneList every workspace with member count, quota, and credit grant. --json prints the raw listing, members included.
set<workspace>Change a workspace's quota. Capacity flags and --monthly-credit-cents are separate writes on the platform, so passing both makes two requests; either may be refused on its own.

The TUI

One row per workspace: name, id, member count, vCPU and memory ceilings, run timeout, concurrent-run cap, monthly credit, and a defaults flag. The flag marks a workspace that has never run anything: its compute-policy row does not exist yet, so the values shown are the table defaults it would get. The listing does not create the row.

KeyAction
enter, pShow the workspace in the pane beneath the list — members with roles, the quota as a table, and this month's grant, spend, reservations and remaining credit — and move the cursor down into the quota table.
↑ / ↓In the quota table, pick a setting.
e, enterEdit the highlighted setting directly. From the list (nothing highlighted below), e asks which setting first. Fields with a handful of sensible values — memory (Cloud Run's tiers), timeout, concurrent runs, instances, per-instance concurrency — offer a pick-list with the current value highlighted and a Custom… entry for anything else. Genuinely continuous values — vCPU in milli-vCPU, the credit grant in cents — take a typed number.
escape, bClose the pane and return the cursor to the list.
rRefresh now. The screen also refreshes itself every 10 seconds, keeping your place.
qQuit.

The server is the authority on what a value may be. A request above the workspace's max_grantable_* ceiling, or memory that Cloud Run will not pair with the requested vCPU, comes back as a 409 and is shown verbatim — for example max_cloud_run_memory_mib cannot exceed 32768 MiB, the platform maximum.

Editing the credit grant

The monthly grant is copied into the current month's workspace_credit_grants row the first time the month is touched, and usage is computed from that copy. An edit through rebase admin therefore updates both the policy (future months) and this month's row, so it takes effect immediately rather than on the 1st.

Because of that, lowering a grant below what the workspace has already spent this month sets compute_blocked at once — every new run is refused until the next month. The TUI computes this before writing and asks for a second enter; rebase admin set prints a warning after the write.

Billing plan

Which plan a workspace is metered under, and any per-workspace price overrides, live on the same policy row but are written through their own admin routes (API only for now):

GET   /admin/workspaces/{workspace_id}/billing-plan
PATCH /admin/workspaces/{workspace_id}/billing-plan

billing_mode is credits (every run floored to one cent) or passthrough (Cloud Run cost metered 1-to-1, no floor; the grant becomes a spend cap). The optional override fields — service_vcpu_eur_per_second, service_gib_eur_per_second, job_vcpu_eur_per_second, job_gib_eur_per_second, request_fee_eur, min_charge_microcents, price_markup — replace the global price when set; sending an explicit null reverts one to the global. The response's effective block is the plan as it resolves right now, which is what to check after a change.

A run settles at the prices snapshotted when it was admitted, so changing a plan affects runs submitted afterwards, not runs in flight.

Options

OptionTypeDescription
--limit, -lintworkspaces only. Maximum workspaces to list (1–1000). Defaults to 200.
--max-memory-mib, -mintCeiling for a target's memory, in MiB.
--max-cpu-milliintCeiling for a target's vCPU, in milli-vCPU (1000 = 1 vCPU).
--max-run-timeout-secondsintCeiling for a service request (ASGI apps, quick functions, interactive workflows), in seconds (max 3600).
--max-job-timeout-secondsintCeiling for a job workflow run (mode="job"), in seconds (max 86400).
--max-concurrent-runsintCloud Run runs allowed in flight at once.
--max-instancesintCeiling for a service's max instance count.
--max-concurrencyintCeiling for a service's per-instance concurrency.
--monthly-credit-centsintMonthly credit grant, in cents. Applies to this month too.
--json, -jflagMachine-readable output.

Examples

rebase admin workspaces --json | python -m json.tool
rebase admin set agent-work --max-memory-mib 4096
rebase admin set acme --monthly-credit-cents 5000

Enabling superadmin

SUPERADMIN_EMAILS is deployment config only — it is never settable through the API, or superadmin would be self-grantable. It is a list[str] and is parsed as JSON:

gcloud run services update rebase-toolkit-api \
  --region europe-west3 --project rebase-agents \
  --update-env-vars '^##^SUPERADMIN_EMAILS=["name@rebase.energy"]'

A bare address (SUPERADMIN_EMAILS=name@rebase.energy) fails Settings() at import and the container does not start. --update-env-vars merges, so the value survives the deploy script's own redeploys.

On this page