EDON / FIELD NOTES

Citadel

Use the subscription service: activation, roles, connections and remote access.

Managing your own instances directly

An end-customer business can use Citadel to administer its own Atlas and Argos instances at one site or across multiple locations. Its internal IT team gains a central point for system status, remote access and operator responsibilities. MSPs and integrators use the same capabilities for customer installations, with separate scopes and grants.

Direct business administration and delegated access for a customer user are distinct permission configurations: a customer user sees only instances shared with them and needs an explicit grant for remote administration. In either case, the organizational structure, groups and instance enrollment must be configured.

Activating Citadel

Citadel is a service provided by EDON to partners and customers on a subscription basis. It is not distributed for self-hosting: you do not install the console on your own server. Atlas and Argos remain the instances connected to the service, retaining their local consoles and functions.

Contact EDON for activation and subscription terms. Once service access is available, organize operators and permissions, then connect the instances to manage. The ISOs available on this site are dedicated to Atlas and Argos respectively; the downloadable Citadel overview describes the service.

Identity and responsibilities

Access requires a password and TOTP second factor. A user’s first sign-in uses an activation code followed by credential setup. Sensitive operations require recent second-factor verification: an open session should not be treated as permanent authorization.

Partner groups grant distinct permissions for instance viewing, enrollment approval, management and remote access. Customer users receive access to instances shared with them; remote administration needs a specific grant. Restrict management grants to operators who need them and to the scope defined for your organization.

Registering Atlas or Argos

  1. Activate service access and configure your organization’s operators.
  2. Verify that instances are registered and can reach the service.
  3. Enter the URL provided for your organization in the appliance’s Citadel settings.
  4. Approve the request by comparing its code, or use an authorized enrollment key for automatic approval.
  5. Assign the customer and grant rights to the appropriate users or groups.
  6. Test access, session closure and revocation before taking the installation into service.

The daily registry check can report a registration that is no longer valid; the notification is not automatic revocation. An operator must assess the case and act. Enrollment keys are secrets to share only with authorized operators.

Connections and remote sessions

Instances use a VPN tunnel to Citadel, with TCP/443 fallback when UDP is unavailable. The management network isolates instances from one another. Operators open the product console on a session-specific name; this is not a general-purpose VPN to the customer’s entire network.

Remote sessions have a maximum lifetime of four hours and a maximum idle period of thirty minutes. The proxy checks each request, with a ten-second authorization cache. Checks cover session validity, operator permissions and instance state. Revocation should therefore not be interpreted as guaranteed instantaneous propagation to every request already in progress.

A remote grant provides administrative access to the appliance. It is not limited to read-only access or to the functions a technician normally uses. For work involving customer data, establish scope and responsibilities before opening a session.

Status, updates and audit

Reachability information depends on periodic instance messages. Comparing versions with the repository identifies outdated installations, but does not document coordinated update distribution across every appliance.

The audit log can be filtered and exported as CSV. It tracks administrative events and the remote-access lifecycle; it is not a video recording and does not guarantee detail of every operation performed inside an instance console. Configure notifications and recipients, and define who may read or export user, customer and connection information.

Responsibilities and continuity

The business or partner manages authorized operators and its Atlas and Argos instances. The Citadel console is provided as a service; installing and administering the Citadel server are not customer tasks.

Connectivity to the service is required for remote management. Local Atlas and Argos functions continue to run on their respective instances. Agree service terms and also organize local access and appliance recovery procedures according to operational needs.

Citadel overview

LET’S TALK INFRASTRUCTURE

Control starts with a conversation.

Tell us about your infrastructure. Let’s start with what you actually need.

Talk to an engineer