Running Polaris and Bootstrapping a Realm
A realm is a top-level tenant boundary inside one Polaris deployment — catalogs, principals, and roles all live inside exactly one realm. A single-node quickstart typically runs one realm (commonly named default-realm or POLARIS), but production deployments can host many realms behind one Polaris process for multi-tenancy.
clientId:clientSecret pair to the server logs exactly once. If you lose that line before saving it, you re-bootstrap or rotate credentials through an authenticated admin path — there's no way to recover it after the fact.
The root principal is a real Principal (Lesson 2) with the built-in PRINCIPAL_ROLE:ALL scope — enough to do anything, which is why Lesson 6 immediately creates a narrower, purpose-specific principal instead of using root for everyday work.
Exercise: find your bootstrap line
docker compose up -d
docker logs polaris 2>&1 | grep -i "root principal credentials"
realm: default-realm root principal credentials: f103ea289b7df858:<redacted-secret>
Retrieval check
You restart the Polaris container with a fresh (empty) volume. Will last session's root credentials still work?
Correct. Bootstrap credentials are generated per-boot against a given persistence state — a fresh volume means a fresh bootstrap, and the old pair is gone.
Not quite. Credentials aren't baked into the image or tied to the realm name alone — they're generated fresh whenever the underlying state is fresh.
What is a realm's relationship to a catalog?
Correct. Realm sits above Lesson 2's entity tree entirely — it's the tenancy boundary, not a peer of Catalog.
No. A realm is the boundary that contains catalogs, principals, and roles — not interchangeable with "catalog," and a catalog never spans realms.
Practice
- Start your own Polaris container and grep the startup log for the bootstrap line.
- Save the
clientId:clientSecretpair somewhere you can reference for the next three lessons. - State in one sentence what persistence backend your quickstart is using, and whether you'd expect that credential to survive a restart (Lesson 9 covers this properly).