Security Settings
Manage your account security, authentication, and account deletion in the Security settings section.
Accessing Security Settings
Navigate to Settings > Security or go directly to /settings/security in your browser.
Authentication
View information about your authentication provider and manage password settings.
Authentication Provider
Your authentication is managed through AWS Cognito, a secure authentication service.
Why External Authentication?
Orkestia uses AWS Cognito for authentication to provide:
- Enterprise Security - Industry-standard security practices
- Multi-Factor Authentication - Support for MFA (if enabled)
- Social Sign-In - Support for Google, GitHub, and other providers
- Password Management - Secure password storage and recovery
- Session Management - Secure session handling
Password Management
Change your password through your authentication provider.
How to Change Your Password
- Go to Settings > Security
- Find the Authentication section
- Click Manage Password button
- You'll be redirected to AWS Cognito's password management page
- Follow the instructions to change your password
Active Sessions
View information about your current session.
Session Information
The Active Sessions section displays:
- Current Session - The device you're currently using
- Session Status - Active or expired
- Session Management - Information about session handling
Session Details
| Property | Value |
|---|---|
| Current Device | Shows you're signed in on this device |
| Status | Active (managed by AWS Cognito) |
| Management | Handled securely by authentication provider |
Managing Sessions
To manage sessions (sign out from all devices):
- Use AWS Cognito's session management (if available)
- Or sign out and sign back in to refresh sessions
- Contact support for advanced session management
Account Deletion
Permanently delete your account and all associated data.
Before Deleting Your Account
- Your user profile and settings
- All organization memberships
- All deployments and configurations
- All connection credentials (AWS, DNS, GitHub, etc.)
- All application data
- All associated data
How to Delete Your Account
Open Deletion Modal
Go to Settings > Security, scroll to Danger Zone, and click Delete Account.
Read Warning
The modal displays a warning about irreversibility and lists what will be deleted.
Confirm Deletion
Type DELETE exactly (case-sensitive) in the confirmation field. The Delete My Account button becomes enabled when correct.
Complete Deletion
Click Delete My Account. You'll be logged out and redirected to the login page.
Confirmation Requirements
- Text:
DELETE(all uppercase) - Case-sensitive:
deleteorDeletewon't work - No spaces or extra characters
- Real-time validation as you type
What Gets Deleted
| Category | Items Deleted |
|---|---|
| User Profile | Display name, profile settings, notification preferences |
| Organization Memberships | All organizations you belong to, your roles |
| Deployments | All applications, sites, deployment configurations, custom domains |
| Connections | AWS, DNS provider, GitHub connections and credentials |
| Associated Data | Activity logs, notification history, all related records |
After Deletion
- Success Message: "Account Deleted" toast notification
- Automatic Logout: Logged out after 2 seconds
- Redirect: Redirected to login page
- Permanent: Account cannot be recovered
Deletion Restrictions
Organization Ownership
If you're the only owner of an organization:
- You may need to transfer ownership first
- Or delete the organization before deleting your account
- Contact support if you need assistance
Security Best Practices
Password Security
- Strong Passwords: Use strong, unique passwords
- Regular Updates: Change password periodically
- Don't Share: Never share your password
- MFA: Enable multi-factor authentication if available
Account Security
- Secure Email: Use a secure email address
- Monitor Access: Review account activity regularly
- Report Issues: Report suspicious activity immediately
Session Security
- Sign Out: Sign out when using shared devices
- Secure Devices: Only sign in on trusted devices
- Browser Security: Use secure, updated browsers
Troubleshooting
Password Management Not Working
Issue: "Manage Password" button doesn't work
Solutions:
- Check if popup blockers are enabled (disable for Orkestia)
- Try a different browser
- Contact support if issue persists
Cannot Delete Account
Issue: Delete button disabled or confirmation not working
Solutions:
- Ensure you typed "DELETE" exactly (case-sensitive)
- Check for extra spaces or characters
- Check if you have organization ownership restrictions
- Contact support if issue persists
Common Questions
Can I recover my account after deletion?
No, account deletion is permanent and irreversible. All data is permanently removed.
What if I'm the only owner of an organization?
You may need to transfer ownership to another member or delete the organization before deleting your account.
Can I change my password in Orkestia?
Password changes are handled by AWS Cognito. Click "Manage Password" to be redirected to Cognito's password management page.
Why do I need to type "DELETE" to confirm?
This confirmation requirement prevents accidental account deletion and ensures you understand the action is permanent.
