> For the complete documentation index, see [llms.txt](https://docs.portainer.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.portainer.io/portainer-idp/using-portainer-idp/admin/settings.md).

# Settings

Settings holds the configuration that applies to the whole installation and is only available to administrators. Portainer-IDP stores these settings in Portainer's add-on configuration, not in the Helm chart, so installing the add-on asks for no values.

## Edge Admin credential

Portainer-IDP deploys every Edge Stack and Edge Group with one Portainer account that has the Edge Administrator role. This card manages that account's access token. See [Architecture](/portainer-idp/architecture/overview.md#one-credential-checked-access) for why it works this way.

| Action                            | What it does                                                                                                                                                             |
| --------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Set up the Edge Admin account** | Creates a Portainer user named `portainer-idp-edge-admin` with the Edge Administrator role, creates an access token for it, checks the token works, and stores it.       |
| **Rotate credentials**            | Creates and checks a new token before revoking the old one, so deploys keep working throughout.                                                                          |
| **Save pasted key**               | Stores an access token you created yourself, pasted into **Edge Admin API key**, after checking it works. It must belong to an account with the Edge Administrator role. |
| **Create a dedicated account**    | Shown when the stored key belongs to another account. Replaces it with the dedicated `portainer-idp-edge-admin` account.                                                 |
| **Test credential**               | Checks the stored credential again.                                                                                                                                      |

{% hint style="info" %}
When Portainer signs users in with LDAP or OAuth, it can't issue a token to a user created through its API, so the one-click setup isn't available. Create the account and its access token in Portainer, then paste the token.
{% endhint %}

## Orphaned manifests

Lists manifest files in a deploy target's folder that nothing deploys, for example because someone committed them directly or an Edge Stack was deleted in Portainer.

For each one, choose **Register** to deploy it as an application, or **Delete from Git**.

Files found outside every deploy target's folder are listed under **Outside any deploy target**, and can only be deleted.

## System applications in Git

Where system applications, such as the Sealed Secrets controller, are committed: a Git target, branch and folder only administrators write to. Choose **Change** to move it.

System applications already deployed keep their current file. See [Cluster Readiness](/portainer-idp/using-portainer-idp/admin/cluster-readiness.md#where-system-applications-live-in-git).

## Source hosts

The hosts [Source Deploy](/portainer-idp/using-portainer-idp/deploy.md#source-deploy) may read public repositories from, one per line. Only `https` URLs without credentials are accepted.

GitHub, GitLab and Bitbucket are read through their public APIs, and other hosts are treated as GitLab or Gitea compatible. Private and internal addresses are always refused, whatever the list says.

## Where other settings live

| Setting                            | Where it lives                                                                                                                                                                                   |
| ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Encryption key**                 | Generated by the Helm chart on install, and kept across upgrades and uninstalls. It encrypts the personal access tokens users save. You never need to enter it.                                  |
| **Machine credential**             | Mounted into the add-on's pod by Portainer, as the Secret `portainer-idp-token`, whenever it installs, upgrades or repairs the add-on. It can only reach Portainer's add-on configuration store. |
| **Git commit identities**          | Each user's own, in the add-on's database with the token encrypted. See [Git commit identity](/portainer-idp/using-portainer-idp/git-commit-identity.md).                                        |
| **Chart hosts and curated charts** | On the [Helm Charts](/portainer-idp/using-portainer-idp/admin/helm-charts.md) page.                                                                                                              |
| **Audit retention**                | Helm chart values. See [Audit log](/portainer-idp/using-portainer-idp/admin/audit-log.md#retention).                                                                                             |
