Skip to content

Admin, plugins and themes

A setup wizard runs on first launch and walks through JMAP servers, OAuth/OIDC, the session secret, logging, branding (uploads included) and the admin password. It writes to the admin config dir, so .env.local is left untouched. JSON config can read secrets from files (passwordHashFile, sessionSecretFile, oauthClientSecretFile) for Docker/Kubernetes secret mounts.

The admin dashboard folds its policy sections into one tabbed page. It includes:

  • Policy gates for the Unified Mailbox — turn All mail / Unread / Starred on or off org-wide, and gate the cross-account capability separately (off by default). A gated view still respects the user’s own toggle.
  • Storage split — ADMIN_CONFIG_DIR is operator-authored (can be mounted read-only once setup finishes) and ADMIN_STATE_DIR holds the runtime audit log and login timestamps.
  • An admin toggle for search-engine indexing (robots.txt / noindex).
  • A schema-driven plugin config UI with render and intercept hooks (onAvatarResolve, onBeforeEmailSend), composer-sidebar and email-banner slots, calendar event slots, i18n APIs and an /api/translate proxy. Plugins hot-reload, load from a dev folder, bundle src/ on demand through esbuild, and can request http:fetch scoped by httpOrigins.
  • Themes upload as ZIP bundles; an extension marketplace browses and installs plugins and themes from a configurable directory. Installing and uninstalling stay in the admin dashboard.
  • Bundled plugins include Jitsi Meet for the calendar.
  • PWA: service worker, install prompt, web push for new inbox mail, a dynamic manifest and install screenshots configurable per domain.
  • Update checks run on their own, log new releases server-side and raise a non-dismissible notice. Structured logging (text or JSON) with per-category levels; anonymous telemetry off unless enabled.

Applies to VNClagoon+ 2026.09 and later.

© 2026 VNC - Virtual Network Consult AG. All rights reserved.