Superusers
==========

.. program:: jetstream server

In order to do administrative tasks using the API, JetStream has the concept of superusers. Superusers can be any users specified using the :option:`--superuser` or :option:`--supergroup` command line options, or the user that's running the JetStream process (on Linux and macOS, this defaults to ``root``.

By default, members of the standard administrator group are set as a JetStream :option:`--supergroup`:

+----------+-------------------------+
| Platform | Default Superuser Group |
+==========+=========================+
| Ubuntu   | sudo                    |
+----------+-------------------------+
| Rocky    | wheel                   |
+----------+-------------------------+
| macOS    | admin                   |
+----------+-------------------------+


Once the user is connected to the server via API, they will need to upgrade their privileges using :meth:`~jetstream.serverinterface.ServerInterface.superuser` API call.

Some of the tasks a superuser is allowed to do include:

  * :doc:`Monitoring <jetstream-client:send/send-monitor-location>` all transfers on the server using the JetStream Client application (superusers are :doc:`/using_jetstream/wranglers`)
  * :doc:`Managing </sandboxing/index>` user's sandboxes
  * More detailed :ref:`server configuration <jetstream-api:structure-server-info-configuration>` information
