[ Switch to styled version → ]


← Docs index

Enterprise

Early access. Enterprise controls are available in assisted deployments and may evolve during rollout. Validate requirements and deployment details with the Pilot team.

Enterprise features add controls for production networks, including role-based access control, identity provider integration, policies, audit logging, and declarative provisioning.

Overview

Enterprise features extend standard networks with controls for production deployments: role-based access control (RBAC), identity provider integration, membership policies, structured audit logging, and declarative provisioning through blueprints.

Standard networks treat membership as a binary boundary. Enterprise networks add layers for access control (RBAC), identity and directory synchronization, traffic permissions (port policies), event logging (audit), and configuration (blueprints).

Enable enterprise

Enterprise features are enabled on a per-network basis at creation time.

pilotctl network create --name prod-fleet --enterprise

Enabling enterprise on a network promotes the creator to the owner role and unlocks enterprise features for that network.

Feature summary

Enterprise gating

Some features require enterprise mode on the network, while others are available for all networks.

Features that require enterprise mode:

Features available to all networks:

Attempting an enterprise operation on a non-enterprise network returns an error. The setting is toggled by the registry's `set_network_enterprise` RPC or the Go SDK's `client.Client.SetNetworkEnterprise`. Membership is preserved when toggling.

Per-network admin tokens and blueprint provisioning are gated by an admin token, not by enterprise mode. Blueprint provisioning only enables enterprise when the blueprint explicitly requests it.

What’s next

Documentation for specific enterprise features:

Related