Skip to main content
Version: 0.1 (next)

Licensing

An Infrared license is a signed token from darkshift that says who the install is licensed to and on which plan. Infrared runs fully in every license state: no feature is locked, and nothing stops when a license expires or is missing. The license tells you and darkshift where an install stands.

License states​

StateWhenWhat Infrared does
evaluationNo license is installed.Runs fully. Settings says to contact darkshift for a license.
licensedA valid license is installed.Runs fully and shows the customer, plan, limits and expiry.
expiredThe license's expiry date has passed.Keeps running. Settings shows the date it expired.
invalidThe installed license is malformed or its signature doesn't verify.Keeps running. Settings shows why.

A license may name limits on the number of orgs and workload clusters. Today they're informational: Infrared shows them and doesn't enforce them.

What a license contains​

A license is one line that starts with irl1.: base64url JSON claims, then darkshift's Ed25519 signature over them. Infrared verifies the signature with a public key built into infrared-api, so it works offline.

ClaimMeaning
idThe license's ID, for support.
customerWho it's for.
planThe plan, such as team or enterprise.
orgs, clustersLimits on orgs and workload clusters; absent means no limit.
iat, expWhen it was issued and when it expires; no exp means it never expires.
skeletonA skeleton key: no limits and no expiry. darkshift uses these for its own installs.

Install a license​

As the platform admin, signed in with email and password, open Settings → License, paste the license into Install a license and install it. Settings then shows the new state.

Through the API, with a platform admin session (API tokens and GitHub sessions can't install a license):

curl -X PUT https://<host>/api/v1/license \
-b cookies.txt -H 'Content-Type: application/json' \
-d "{\"license\": \"$(cat infrared.license)\"}"

Infrared verifies the license first and refuses a malformed one or one whose signature doesn't verify (HTTP 422). An expired license is accepted, so you can install a renewal early or late in any order. It's stored in the Secret infrared-license, key license, in Infrared's namespace (infrared by convention). You can also create that Secret yourself:

kubectl -n infrared create secret generic infrared-license --from-file=license=infrared.license

Read the state with GET /v1/license, which any signed-in user can call. It returns the state and what the license grants, never the license itself:

{"state": "licensed", "id": "acme-20261001", "customer": "acme", "plan": "team",
"expiresAt": "2027-10-01T00:00:00Z", "message": "Licensed to acme (team)."}

Renew or replace​

Install the new license the same way; it replaces the old one. To go back to evaluation, delete the Secret infrared-license.