Administration overview
What running DataHub involves, the recurring responsibilities, the decisions that are hard to reverse, and where to find each one.
Installing
Standing up a DataHub evaluation stack, what it contains, and what has to change before production.
Organisations and tenants
How multi-tenancy works in DataHub, what isolation you actually get, and how to decide tenant boundaries before you onboard.
Users and access
Where DataHub users come from, how roles reach the platform, and how to manage tokens and service accounts.
Identity providers (OIDC)
How DataHub authenticates users and services, Keycloak as the trusted issuer, and how to bring Microsoft Entra ID identities in through it.
Data set permissions
How organization groups in Keycloak control read and write access to DataHub data, how grants inherit down the data set hierarchy, and what happens when access is denied.
Data lifecycle
Retention, storage cost, housekeeping and backups, keeping a DataHub installation proportionate as it grows.
Monitoring
The Prometheus metrics every DataHub service exposes, which ports to scrape, and what to watch.
Limits and quotas
The request, ingest and connection budgets DataHub enforces per tenant, what a caller sees when one is hit, and how to raise one for a single tenant without a restart.
Enabling the assistant
The three switches that turn the console's Ask AI panel on, the choice between a hosted model and one you run yourself, and the settings that bound what a question may cost.
Architecture, without the jargon
What the moving parts of DataHub are, what each one does, and why there are several, explained for administrators rather than developers.
Security and compliance
DataHub's security posture, the isolation guarantees, and answers to the questions a risk committee will ask.