• Concept
  • Version · 6.0
  • Manage

What is License Management?

Last updated: September 29, 2026

License Management is the Secure Server module where an administrator imports license files, reviews what the installation is entitled to run, and serves those terms to Change Automation nodes. Everything it does happens on your own network.

License Management is a single screen in Liquibase Secure server, reached from Administer and titled License Management. It holds every license file the installation has been given, resolves them into one answer about what may run, and exposes that answer to the Change Automation nodes that need it. A Change Automation node is any machine that runs Change Automation, the Liquibase Secure CLI, such as a developer workstation, a CI/CD agent, or a container in a pipeline. Each node needs a license, and a node configured to report usage tells this installation which databases it acts on.

The module is offline by design. License files are signed by Liquibase and verified locally, so an air gapped installation can be licensed, audited, and renewed without reaching the internet. Nothing about your usage is sent to Liquibase.

Two permission templates open License Management by default. Customer Admin has full access. Security Reviewer has read only access to the license files, the effective license, the Signature Trust card, compliance, and alerts. It cannot see utilization figures, and it cannot import, remove, or re-verify files or change thresholds. To learn how templates and groups fit together, see Liquibase Secure Role-Based Access Control.

An account without either template sees no License Management entry under Administer, and opening the page directly shows You do not have access. Permissions apply per workspace, while the license itself applies to the whole installation.

Why use License Management?

An installation that runs Change Automation at scale has to answer three questions, and this module is where all three are answered in one place.

  • What are we entitled to run? The effective license states the tier, support level, term, licensed database types, and database target capacity.

  • Are we inside our contract? The compliance checks compare observed usage against those grants and say plainly when usage has passed a threshold or a term has ended.

  • How do our automation nodes find out? A local endpoint serves the effective license to Change Automation, so nodes do not each need their own license file.

How License Management works

License files and the effective license

You import one or more signed .lic files. Liquibase sends them to you by email when you buy, expand, or renew your license. If you need them sent again, contact Liquibase Support. Four kinds exist:

  • Base establishes the contract and the term.

  • Custom renewal replaces the base license when its own term begins, and its grants then govern. The base it replaced stays in the list as superseded or term expired.

  • Add-on adds capacity or modules on top of a base.

  • Consolidated carries a pre resolved set, generated by Liquibase.

Files are never merged into one another. The module resolves them into a single effective license for the whole installation. One installation has one effective license, not one per workspace or project.

Importing a newer file supersedes an older one rather than replacing it. Superseded files stay in the list read only so an audit can see the whole history, but only the governing file counts toward what the installation may run today.

Signature verification

Only signed files are accepted, and an encrypted file will never verify. The release signing public key ships inside the Liquibase Secure build, so a new installation verifies customer license files with nothing to configure. The Signature Trust card, below the file list on the License Files tab, lists every key the installation trusts. It appears once at least one license file is imported. The key that ships with Liquibase reads Built into binary in the SOURCE column, and a key an operator added reads Property override.

Verification is a property of the installation's key set rather than of one file, so the page offers a single Re-verify action that re-checks every stored file at once.

Usage, compliance, and alerts

Change Automation nodes report the databases they act on. The module counts distinct database targets from those reports and measures them against the licensed capacity.

Compliance turns that comparison into a short checklist covering base license validity, database target capacity, licensed database types, add-on terms, tracking data freshness, and the renewal window. Each row is green, or it states what is wrong and what to do.

Exceeding licensed capacity produces an explicit out of contract state. Nothing stops working. It is a contract term to resolve with your Liquibase account team, not an outage.

Alerts are raised from those same checks against thresholds you control, and appear in the page banner, on the notification bell, and on the Compliance tab.

Key terms

Term

Definition

Effective license

The single resolved answer about what this installation may run, computed from every imported file.

Governing file

The one imported file that currently determines the effective license. Others are superseded or excluded.

DB Target

One distinct database counted against capacity. What counts as one target depends on the database type.

Node

A machine that runs Change Automation, the Liquibase Secure CLI, such as a developer workstation or a CI/CD agent. Nodes that report usage appear in the Reporting Nodes table on the Utilization tab.

Licensed DB Types

The database types the license grants capacity for.

Permission template

A set of permissions that Liquibase ships and an administrator applies to a group. Customer Admin gives full access to License Management, and every workspace applies it to the Administrators group. Security Reviewer gives read only access. See Liquibase Secure Role-Based Access Control. No group has Security Reviewer by default. To give a group read only access, see Grant a group access with a template.

Tier

The commercial tier carried in the license.

Support level

The support tier carried in the license: Standard, Premium, or Signature.

Unlicensed

The state when nothing stored on the installation licenses it.

Out of contract

Usage has passed a licensed limit. Execution continues and the overage is reported.