# KOPIA server: SERVER\_CONTROL\_USER

**URL:** <https://kopia.discourse.group/t/kopia-server-server-control-user/1033>\
**Category:** General\
**Created:** [April 6, 2022, 11:15pm UTC](https://kopia.discourse.group/t/kopia-server-server-control-user/1033 "2022-04-06T23:15:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![iBackup](https://yyz2.discourse-cdn.com/free1/user_avatar/kopia.discourse.group/ibackup/32/355_2.png) [@iBackup](https://kopia.discourse.group/u/iBackup)\
**Post date:** [April 6, 2022, 11:15pm UTC](https://kopia.discourse.group/t/kopia-server-server-control-user/1033/1 "2022-04-06T23:15:37Z")

</div>

Hi,

What is this user for: `SERVER_CONTROL_USER` ?

A test server:

```auto
repo=/path/2/repo/dir
kopia repository create filesystem --path=${repo}

export KOPIA_SERVER_CONTROL_USER='control-sever'
export KOPIA_SERVER_CONTROL_PASSWORD='SuperP@5w0rd'

kopia server start \
  --ui \
  --tls-cert-file "${repo}/srv.cert" \
  --tls-key-file "${repo}/srv.key" \
  --address 0.0.0.0:51515 \
  --async-repo-connect

```

It accepts credentials and allowed me to bypass basic HTTP authentication as a SERVER\_CONTROL\_USER, but all I got is:

```auto
UI Access denied. See https://github.com/kopia/kopia/issues/880#issuecomment-798421751 for more information.

```

But this link is related more to `KOPIA_SERVER_USERNAME` that works fine and allow to see web UI, the same as with `kopiaUI`. I understand that `KOPIA_SERVER_USERNAME` is a client to particular instance of repository and can be used in the same way as `kopiaUI` with given local repository, but what is `SERVER_CONTROL_USER` is for?

BTW, the mentioned option `--allow-repository-users` referenced in the issue [#880](https://github.com/kopia/kopia/issues/880#issuecomment-798421751) is unknown in recent 0.10.6 version of `kopia`, as well it isn’t present in any source files and as result attempt to login as registered repository user (created with `kopia server user add xxx@zzz`) to the server instance directly (not from remote machine that is subject to back to kopia’s repository server) it failed too and returns link to issue [#880](https://github.com/kopia/kopia/issues/880#issuecomment-798421751)

---

<div class="post-metadata">

**Author:** ![jkowalski](https://yyz2.discourse-cdn.com/free1/user_avatar/kopia.discourse.group/jkowalski/32/3_2.png) [@jkowalski](https://kopia.discourse.group/u/jkowalski)\
**Post date:** [April 7, 2022, 7:08am UTC](https://kopia.discourse.group/t/kopia-server-server-control-user/1033/2 "2022-04-07T07:08:20Z")

</div>

This user is for control operations, it’s primarily used by KopiaUI by can also be used for triggering snapshots:

Here’s the current list of APIs that require this user:

> <https://github.com/kopia/kopia/blob/5d87d817335f6d547e094ab80062113dc3a1fdf4/internal/server/server.go#L169>

---

<div class="post-metadata">

**Author:** ![iBackup](https://yyz2.discourse-cdn.com/free1/user_avatar/kopia.discourse.group/ibackup/32/355_2.png) [@iBackup](https://kopia.discourse.group/u/iBackup)\
**Post date:** [April 7, 2022, 2:46pm UTC](https://kopia.discourse.group/t/kopia-server-server-control-user/1033/3 "2022-04-07T14:46:26Z")

</div>

Thank you very much for response as well for the `kopia` !

---

<div class="post-metadata">

**Author:** ![guerby](https://yyz2.discourse-cdn.com/free1/user_avatar/kopia.discourse.group/guerby/32/222_2.png) [@guerby](https://kopia.discourse.group/u/guerby)\
**Post date:** [April 15, 2022, 7:46am UTC](https://kopia.discourse.group/t/kopia-server-server-control-user/1033/4 "2022-04-15T07:46:38Z")

</div>

> [@iBackup](#):
>
> ```auto
> export KOPIA_SERVER_CONTROL_USER='control-sever'
> export KOPIA_SERVER_CONTROL_PASSWORD='SuperP@5w0rd'
> 
> ```

I’ve been trying to make “kopia server status” work by setting those variables at server launch (kopia repository server with local dir as backend) and in the client but no luck:

```auto
$ kopia server status 
kopia: error: unable to list sources: 400 Bad Request, try --help

```

Any idea what I’m missing?

---

<div class="post-metadata">

**Author:** ![iBackup](https://yyz2.discourse-cdn.com/free1/user_avatar/kopia.discourse.group/ibackup/32/355_2.png) [@iBackup](https://kopia.discourse.group/u/iBackup)\
**Post date:** [April 15, 2022, 2:04pm UTC](https://kopia.discourse.group/t/kopia-server-server-control-user/1033/5 "2022-04-15T14:04:37Z")

</div>

You should run it something like that:

```auto
kopia server status --remote \
--address https://8.8.8.8:51515 \
--server-cert-fingerprint=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx	\ <<SHA2 hash that been generate on certificate creation
--server-control-username=your-ctrl-user \
--server-password=and-here-his-passwd

```
