Cenovel / Configure

Configuration & access

Configure console settings, device access, and optional site collectors.

Configuration and secrets

Day-to-day application configuration lives in the console’s Settings. File-based secrets are provisioned separately: the repository setup uses secrets/; the native appliance uses protected credential files under /etc/cenovel/credentials. Native deployment settings are checked in /etc/cenovel/appliance.conf.

cenovelctl config check

Some changes, such as the listener port, take effect after a restart. Follow the instructions shown for the setting.

Device access and polling

As Administrator EX, open Governance → Monitoring → Configuration → Access for credentials and site collectors. Use Schedule to configure how often devices are read.

Cenovel reads switches over SSH using Device CLI profiles. SNMPv3 authPriv can also be used where configured; its profiles require SHA-2 authentication and AES privacy. SNMP does not need to be enabled for SSH polling.

Microsoft sign-in and permissions

Microsoft Entra ID sign-in uses authorization code with PKCE. Configure the tenant, client, secret, redirect URI, and group mappings. Review individual role assignments as well as the default tier; an existing assignment can affect the resolved role.

Optional site collectors

A site collector provides a path to configured management networks. Provision its credentials and allowed networks, and use the enrollment flow in Monitoring. Confirm the collector configuration supplied with your installed release.

Read the operator reference
4. Configuration, device access, and sign-in

Application settings are managed in the console's Settings. File-based
secrets are provisioned separately: the repository setup uses secrets/;
the native appliance uses protected files under /etc/cenovel/credentials.
Native deployment settings are validated in /etc/cenovel/appliance.conf.
Some settings, including the listener port, take effect after a restart.

As Administrator EX, open Governance > Monitoring > Configuration > Access
for device credentials and site collectors. The Schedule section controls
how often devices are read. Monitoring > Networks holds the configured
networks, and Found devices holds discovery results for review.

Cenovel reads switches over SSH with Device CLI profiles. SNMPv3 authPriv
is also available where configured; profiles require SHA-2 authentication
and AES privacy. SSH polling does not require SNMP to be enabled. Device
reads depend on configured credentials, allowed networks, and trust checks.
A site collector provides a path to configured management networks; use the
enrollment and configuration procedure for the installed collector release.

Microsoft Entra ID sign-in uses authorization code with PKCE. Configure the
tenant, client, secret, redirect URI, and group mappings. Review individual
role assignments as well as defaults; an existing assignment can affect the
resolved tier. The local recovery account provides a separate sign-in path.

Reviewed against the current source code. Native appliance administration commands require the appropriate host privileges; validate deployment procedures on your own release before production use.