Licensing
An Infrared license is a signed token from darkshift that says who the install is licensed to and on which plan. Infrared runs fully in every license state: no feature is locked, and nothing stops when a license expires or is missing. The license tells you and darkshift where an install stands.
License states
| State | When | What Infrared does |
|---|---|---|
evaluation | No license is installed. | Runs fully. Settings says to contact darkshift for a license. |
licensed | A valid license is installed. | Runs fully and shows the customer, plan, limits and expiry. |
expired | The license's expiry date has passed. | Keeps running. Settings shows the date it expired. |
invalid | The installed license is malformed or its signature doesn't verify. | Keeps running. Settings shows why. |
A license may name limits on the number of orgs and workload clusters. Today they're informational: Infrared shows them and doesn't enforce them.
What a license contains
A license is one line that starts with irl1.: base64url JSON claims, then darkshift's Ed25519 signature over them. Infrared verifies the signature with a public key built into infrared-api, so it works offline.
| Claim | Meaning |
|---|---|
id | The license's ID, for support. |
customer | Who it's for. |
plan | The plan, such as team or enterprise. |
orgs, clusters | Limits on orgs and workload clusters; absent means no limit. |
iat, exp | When it was issued and when it expires; no exp means it never expires. |
skeleton | A skeleton key: no limits and no expiry. darkshift uses these for its own installs. |
Install a license
As the platform admin, signed in with email and password, open Settings → License, paste the license into Install a license and install it. Settings then shows the new state.
Through the API, with a platform admin session (API tokens and GitHub sessions can't install a license):
curl -X PUT https://<host>/api/v1/license \
-b cookies.txt -H 'Content-Type: application/json' \
-d "{\"license\": \"$(cat infrared.license)\"}"
Infrared verifies the license first and refuses a malformed one or one whose signature doesn't verify (HTTP 422). An expired license is accepted, so you can install a renewal early or late in any order. It's stored in the Secret infrared-license, key license, in Infrared's namespace (infrared by convention). You can also create that Secret yourself:
kubectl -n infrared create secret generic infrared-license --from-file=license=infrared.license
Read the state with GET /v1/license, which any signed-in user can call. It returns the state and what the license grants, never the license itself:
{"state": "licensed", "id": "acme-20261001", "customer": "acme", "plan": "team",
"expiresAt": "2027-10-01T00:00:00Z", "message": "Licensed to acme (team)."}
Renew or replace
Install the new license the same way; it replaces the old one. To go back to evaluation, delete the Secret infrared-license.