# Emergency maintenance

## Enable administrative access

To enable administrative API for your Datalore instance, generate a token by providing [this environment variable](server-configuration.html#server_configuration_admin).

> **Warning:**
> Keep this token secure: it provides access to the access permissions management APIs, which, if exposed, can be used for data leakage by malicious users.
>
>
>
> DO NOT configure this token unless critically necessary and revoke it as soon as the maintenance is complete.

Read further for a few procedures that may help you when Datalore functionality deviates from the expected.

## Set up user access level

Normally, a Datalore instance is operated by its administrators. The first registered user of the instance is automatically assigned a super admin and can then can grant admin roles to other users.

This procedure explains how to reset access to the super admin account if it was accidentally lost.

> **Note:**
> Make sure to enable an admin API token prior to performing the steps below.

Procedure:

1. Identify the ID of the user whose access level you want to alter:

* Open the developer console for the Datalore browser tab.

* Find the entry that contains the `user=....` part. The value that follows the `=` character is the ID of the currently authenticated user. Here is an example of what this line looks like: ``` Client initialized clientId=i9amcJvpqBDoKAWbVc2iOs, user=bKscUiyhbxUNl6a5tTlKq4 ```

2. Execute the following HTTP request by providing your own values as per the table below:

```BASH
curl --request POST \
--url 'https://${host}/api/user_management/v1/admin/user/role?userId=${userId}&role=${role}' \
--header 'Authorization: ${token}'
```

| `${host}` | Your instance FQDN |
| `${role}` |    The role you want to assign to the user.     Allowed values: `REGULAR`, `SUPER_ADMIN`, `ADMIN`     See [User types and roles](manage-users.html#user-type-and-roles) for more details about the user types.    |
| `${token}` | [Value of the administrative API token](#emergency-admin) |

## Workspace full clone

When you export a workspace as described in [this procedure](datalore-workspaces.html#download-your-workspace), the downloaded .zip file will not contain any sensitive information like database connection objects.

However, there can be a situation where you need to copy another user's workspace with all of its contents (including all the attached files and database connections). For example, that user left the company, and you can no longer administer their workspaces.

Procedure:

* Execute the following HTTP request by providing your own values as per the table below:

```BASH
curl --request POST \
--url 'https://${host}/api/admin/vfs/clone_workspace/${ownerId}/${workspaceId}?destinationUserId=${destinationUserId}' \
--header 'Authorization: ${token}'
```

| `${host}` | Your instance FQDN |
| `${ownerId}` | The workspace owner user ID |
| `${workspaceId}` | Workspace ID |
| `${destinationUserId}` | User ID, who this workspace should be cloned to. |
| `${token}` | [Administrative API token](#emergency-admin) |

> **Note:**
> This does not transfer the workspace, but creates its full clone: the original workspace will remain intact.
>
>
>
> To free up the workspace's resources (like storage space), consider deleting the original owner user from Datalore. Make sure to save all associated data first.

## Emergency recovery

Use the emergency recovery procedure if your Datalore instance becomes unavailable due to:

* Database corruption

* Internal storage corruption

* Failed startup with data integrity issues

Procedure: (Recommended) Restore from a backup

If you have [backups](backup-restore.html) that you can try to restore the instance from:

1. Create a new backup of the current state. It may help later if something goes wrong. Even a partial backup can be critical for recovery.

2. Restore the instance from a previous backup.

3. Ensure that your instance is operational. If you notice any issues, contact the [support team](support.html).

Procedure: If no backup is available

If you do not have a backup or restoring from a backup is not possible:

1. [Create a new backup](backup-restore.html) of the current state. It may help later if something goes wrong. Even a partial backup can be critical for recovery.

2. Contact the [support team](support.html).

3. Provide the following:

* System logs

* Deployment details (version, infrastructure)

* Current state of storage and database components

> **Warning:**
> Do not perform destructive operations on the affected database or storage (for example, cleanup, reinitialization, or manual repair) before creating a backup of the current state.
>
>
>
> Even a partial backup can be critical for recovery. Modifying the failed component without a backup may result in permanent data loss.

