If the default administrator account has been deleted, if its password has been changed and lost, or if any other action has resulted in the inability to log in under any account, a recovery procedure is provided. It restores the admin account with the default password admin and the Super Admin role. As part of the process, the Super Admin role is also restored with all maximum-level privileges. If the "Required for All" two-factor authentication policy was configured in the system, the policy will be switched to "Optional for All", and the second-factor settings (TOTP/Email OTP/Backup Codes) for the admin user will be reset.

The recovery is performed using the restore-default-admin.yml playbook from the installation playbook archive (see v1.2_1.5 Stable versions).

The restoration process connects to the database and creates or updates the administrator account. By default, the database connection uses the address specified in the hosts.yml file under the common_host section.

During the first run, the playbook will require installation of the python3-psycopg2 library, which requires Internet access from the target host.

Stand-alone installation

Run the playbook using the following command:

ansible-playbook restore-default-admin.yml

High-availability installation

If a high-availability setup is used, in which the PostgreSQL database runs as a cluster, the playbook must be executed on the node that currently holds the Primary role. By default, this is the node specified in the node_primary section of the hosts-cluster.yml.

Specify the address of the Primary node in the inventory/hosts.yml file and run the playbook:

ansible-playbook restore-default-admin.yml

Running the playbook on a node in Standby (read-only) state will result in an error because the database does not allow write operations. This will not affect the database cluster’s functionality or state.