rebase admin
Superadmin view of every workspace — members, quota, and this month's spend — with the quota editable in place.
Synopsis
rebase admin
rebase admin workspaces [--limit <n>] [--json]
rebase admin set <workspace> [--max-memory-mib <mib>] [--max-cpu-milli <milli>]
[--max-run-timeout-seconds <s>] [--max-job-timeout-seconds <s>]
[--max-concurrent-runs <n>] [--max-instances <n>] [--max-concurrency <n>]
[--monthly-credit-cents <cents>] [--json]Bare rebase admin opens the TUI. The two subcommands are its headless twins, for a
shell over SSH or a script.
Who can use it
These commands call the API's /admin/* routes, which are gated by a profile-level
superadmin check: the caller's session email must be listed in the API's
SUPERADMIN_EMAILS and be under the company domain. Two consequences:
- It needs a session credential (
rebase setup), not an API key — a key is refused. - It works on every workspace, including ones you are a member of. That is deliberately
unlike
rebase workspace compute-policy set, whose principal-level gate refuses a superadmin who is also a member, because a real membership row always wins.
Subcommands
| Subcommand | Arguments | Description |
|---|---|---|
| none | none | Open the admin TUI. |
workspaces | none | List every workspace with member count, quota, and credit grant. --json prints the raw listing, members included. |
set | <workspace> | Change a workspace's quota. Capacity flags and --monthly-credit-cents are separate writes on the platform, so passing both makes two requests; either may be refused on its own. |
The TUI
One row per workspace: name, id, member count, vCPU and memory ceilings, run timeout, concurrent-run cap, monthly credit, and a defaults flag. The flag marks a workspace that has never run anything: its compute-policy row does not exist yet, so the values shown are the table defaults it would get. The listing does not create the row.
| Key | Action |
|---|---|
enter, p | Show the workspace in the pane beneath the list — members with roles, the quota as a table, and this month's grant, spend, reservations and remaining credit — and move the cursor down into the quota table. |
↑ / ↓ | In the quota table, pick a setting. |
e, enter | Edit the highlighted setting directly. From the list (nothing highlighted below), e asks which setting first. Fields with a handful of sensible values — memory (Cloud Run's tiers), timeout, concurrent runs, instances, per-instance concurrency — offer a pick-list with the current value highlighted and a Custom… entry for anything else. Genuinely continuous values — vCPU in milli-vCPU, the credit grant in cents — take a typed number. |
escape, b | Close the pane and return the cursor to the list. |
r | Refresh now. The screen also refreshes itself every 10 seconds, keeping your place. |
q | Quit. |
The server is the authority on what a value may be. A request above the workspace's
max_grantable_* ceiling, or memory that Cloud Run will not pair with the requested vCPU,
comes back as a 409 and is shown verbatim — for example
max_cloud_run_memory_mib cannot exceed 32768 MiB, the platform maximum.
Editing the credit grant
The monthly grant is copied into the current month's workspace_credit_grants row the
first time the month is touched, and usage is computed from that copy. An edit through
rebase admin therefore updates both the policy (future months) and this month's row,
so it takes effect immediately rather than on the 1st.
Because of that, lowering a grant below what the workspace has already spent this month
sets compute_blocked at once — every new run is refused until the next month. The TUI
computes this before writing and asks for a second enter; rebase admin set prints a
warning after the write.
Billing plan
Which plan a workspace is metered under, and any per-workspace price overrides, live on the same policy row but are written through their own admin routes (API only for now):
GET /admin/workspaces/{workspace_id}/billing-plan
PATCH /admin/workspaces/{workspace_id}/billing-planbilling_mode is credits (every run floored to one cent) or passthrough (Cloud Run
cost metered 1-to-1, no floor; the grant becomes a spend cap). The optional override
fields — service_vcpu_eur_per_second, service_gib_eur_per_second,
job_vcpu_eur_per_second, job_gib_eur_per_second, request_fee_eur,
min_charge_microcents, price_markup — replace the global price when set; sending an
explicit null reverts one to the global. The response's effective block is the plan
as it resolves right now, which is what to check after a change.
A run settles at the prices snapshotted when it was admitted, so changing a plan affects runs submitted afterwards, not runs in flight.
Options
| Option | Type | Description |
|---|---|---|
--limit, -l | int | workspaces only. Maximum workspaces to list (1–1000). Defaults to 200. |
--max-memory-mib, -m | int | Ceiling for a target's memory, in MiB. |
--max-cpu-milli | int | Ceiling for a target's vCPU, in milli-vCPU (1000 = 1 vCPU). |
--max-run-timeout-seconds | int | Ceiling for a service request (ASGI apps, quick functions, interactive workflows), in seconds (max 3600). |
--max-job-timeout-seconds | int | Ceiling for a job workflow run (mode="job"), in seconds (max 86400). |
--max-concurrent-runs | int | Cloud Run runs allowed in flight at once. |
--max-instances | int | Ceiling for a service's max instance count. |
--max-concurrency | int | Ceiling for a service's per-instance concurrency. |
--monthly-credit-cents | int | Monthly credit grant, in cents. Applies to this month too. |
--json, -j | flag | Machine-readable output. |
Examples
rebase admin workspaces --json | python -m json.tool
rebase admin set agent-work --max-memory-mib 4096
rebase admin set acme --monthly-credit-cents 5000Enabling superadmin
SUPERADMIN_EMAILS is deployment config only — it is never settable through the API, or
superadmin would be self-grantable. It is a list[str] and is parsed as JSON:
gcloud run services update rebase-toolkit-api \
--region europe-west3 --project rebase-agents \
--update-env-vars '^##^SUPERADMIN_EMAILS=["name@rebase.energy"]'A bare address (SUPERADMIN_EMAILS=name@rebase.energy) fails Settings() at import and
the container does not start. --update-env-vars merges, so the value survives the
deploy script's own redeploys.

