janusctl reference
Every janusctl command, its arguments and its flags - generated from the command tree janusctl itself runs, completes and prints its help from. How to install it, sign in and reach nodes: janusctl.
Global flags
Section titled “Global flags”They come before the command:
janusctl [-context NAME] [-n NODE[,NODE] | -all] COMMAND ...janusctl -endpoint HOST:PORT -ca FILE -cert FILE -key FILE COMMAND ...| Flag | |
|---|---|
-context NAME | the context to use (default: the current one) |
-n NODE[,NODE] | the node(s) to run the command on - ’?’ to pick |
-all | run the command on every node of the fleet |
-endpoint HOST:PORT | a node’s API, with its own certificate |
-ca FILE | the node’s CA certificate |
-cert FILE | the client certificate |
-key FILE | the client private key |
-as-user NAME | with a Controller certificate: the user the calls are made for |
-as-roles ROLES | with -as-user: that user’s roles, comma-separated |
Sign in
Section titled “Sign in”janusctl login
Section titled “janusctl login”Sign in to a Controller: a certificate of its fleet, and its nodes.
janusctl login [-context NAME] [-controller HOST[:PORT]] [-controller-ca FILE] [-controller-fingerprint SHA256] [-user NAME] [-ssh-key FILE] [-browser] [-no-open] [-device]Runs on this machine: no node is contacted.
| Flag | |
|---|---|
-context NAME | the context to sign in |
-controller HOST[:PORT] | the Controller’s address (the first time) |
-controller-ca FILE | check the Controller against this CA (or certificate) |
-controller-fingerprint SHA256 | trust the Controller’s certificate with this SHA-256 |
-user NAME | your account (with an SSH key) |
-ssh-key FILE | the SSH key: its private key file, or its .pub for ssh-agent |
-browser | sign in on the Controller’s page, in the browser |
-no-open | with -browser: only print the page’s address |
-device | sign in on the Controller’s page from another machine |
janusctl context
Section titled “janusctl context”The Controllers and fleets signed in to.
janusctl context [list | use NAME | delete NAME]Runs on this machine: no node is contacted.
janusctl nodes
Section titled “janusctl nodes”The context’s nodes (refreshed with JANUS_TOKEN).
janusctl nodesRuns on this machine: no node is contacted.
janusctl version
Section titled “janusctl version”Janusctl’s version, and the node’s.
janusctl versionjanusctl system
Section titled “janusctl system”The node: state, logs, files, power.
janusctl system info
Section titled “janusctl system info”Version, kernel, slot, memory, CPU, load, disks.
janusctl system infojanusctl system hostname
Section titled “janusctl system hostname”The node’s hostname.
janusctl system hostnamejanusctl system services
Section titled “janusctl system services”Managed services and their health.
janusctl system servicesjanusctl system service
Section titled “janusctl system service”Control a managed service (janusd: restart only).
janusctl system service start|stop|restart IDjanusctl system logs
Section titled “janusctl system logs”Janusd or haproxy output.
janusctl system logs [-f] [-n LINES] SERVICE| Flag | |
|---|---|
-f | follow |
-n LINES | only the last LINES lines |
janusctl system events
Section titled “janusctl system events”The node’s event log, live.
janusctl system events [-since ID]| Flag | |
|---|---|
-since ID | only events after this ID |
janusctl system dmesg
Section titled “janusctl system dmesg”The kernel’s messages.
janusctl system dmesg [-f]| Flag | |
|---|---|
-f | follow |
janusctl system stats
Section titled “janusctl system stats”CPU and memory of janusd and haproxy.
janusctl system statsjanusctl system systemstat
Section titled “janusctl system systemstat”Boot time, context switches, processes created.
janusctl system systemstatjanusctl system ps
Section titled “janusctl system ps”Every process.
janusctl system psjanusctl system netdev
Section titled “janusctl system netdev”Network interface counters.
janusctl system netdevjanusctl system netstat
Section titled “janusctl system netstat”TCP and UDP sockets.
janusctl system netstatjanusctl system mounts
Section titled “janusctl system mounts”Mounted filesystems.
janusctl system mountsjanusctl system du
Section titled “janusctl system du”Disk usage.
janusctl system du [-r] PATH...| Flag | |
|---|---|
-r | one line per directory |
janusctl system ls
Section titled “janusctl system ls”List a directory.
janusctl system ls [-r] PATH| Flag | |
|---|---|
-r | recursive |
janusctl system cat
Section titled “janusctl system cat”Print a file.
janusctl system cat PATHjanusctl system cp
Section titled “janusctl system cp”A tar archive of PATH (stdout by default).
janusctl system cp [-o FILE] PATH| Flag | |
|---|---|
-o FILE | the archive’s file, - for stdout |
janusctl system pcap
Section titled “janusctl system pcap”Live packet capture, as a pcap file (docs/packet-capture.md).
janusctl system pcap [-i IFACE] [-f FILTER] [-promisc] [-include-own-stream] [-snaplen BYTES] [-duration DURATION] [-o FILE]| Flag | |
|---|---|
-i IFACE | the interface to capture on |
-f FILTER | a tcpdump-style filter |
-promisc | promiscuous mode |
-include-own-stream | capture this capture’s own connection too |
-snaplen BYTES | bytes kept per packet |
-duration DURATION | stop after this long |
-o FILE | the pcap file, - for stdout |
janusctl system metrics
Section titled “janusctl system metrics”The node’s Prometheus exporter: show or change.
janusctl system metrics [-enable] [-disable] [-port PORT]| Flag | |
|---|---|
-enable | turn it on |
-disable | turn it off |
-port PORT | serve on this port |
janusctl system node-exporter
Section titled “janusctl system node-exporter”Prometheus-node-exporter: show or change.
janusctl system node-exporter [-enable] [-disable] [-address IP] [-port PORT] [-collectors A,B]| Flag | |
|---|---|
-enable | run it |
-disable | stop it, and keep it stopped |
-address IP | listen on this address only (* for all) |
-port PORT | listen on this port |
-collectors A,B | the collectors to run |
janusctl system reboot
Section titled “janusctl system reboot”Soft-stop HAProxy, then reboot.
janusctl system reboot [-powercycle]| Flag | |
|---|---|
-powercycle | a power cycle |
janusctl system shutdown
Section titled “janusctl system shutdown”Soft-stop HAProxy, then power off.
janusctl system shutdownjanusctl system restart
Section titled “janusctl system restart”Restart janusd only - HAProxy keeps serving.
janusctl system restartjanusctl system reset
Section titled “janusctl system reset”Wipe the STATE partition and reboot: a new CA on the console.
janusctl system reset [-wipe-state] [-wipe-ephemeral]| Flag | |
|---|---|
-wipe-state | wipe the persistent STATE partition |
-wipe-ephemeral | wipe ephemeral state |
HAProxy
Section titled “HAProxy”janusctl haproxy
Section titled “janusctl haproxy”HAProxy: config, runtime, certificates, files.
janusctl haproxy show-info
Section titled “janusctl haproxy show-info”Version, uptime, connections.
janusctl haproxy show-infojanusctl haproxy stats
Section titled “janusctl haproxy stats”Raw ‘show stat’ CSV.
janusctl haproxy statsjanusctl haproxy backends
Section titled “janusctl haproxy backends”Backends, their servers and states.
janusctl haproxy backendsjanusctl haproxy get-config
Section titled “janusctl haproxy get-config”The running haproxy.cfg.
janusctl haproxy get-configjanusctl haproxy apply-config
Section titled “janusctl haproxy apply-config”Validate, apply and reload seamlessly.
janusctl haproxy apply-config FILEjanusctl haproxy map-list
Section titled “janusctl haproxy map-list”The running config’s file-backed maps.
janusctl haproxy map-listjanusctl haproxy map-get
Section titled “janusctl haproxy map-get”A map’s entries.
janusctl haproxy map-get MAPjanusctl haproxy map-set
Section titled “janusctl haproxy map-set”Set one entry.
janusctl haproxy map-set MAP KEY VALUEjanusctl haproxy map-delete
Section titled “janusctl haproxy map-delete”Delete one entry.
janusctl haproxy map-delete MAP KEYjanusctl haproxy acl-add
Section titled “janusctl haproxy acl-add”Add a pattern to an ACL.
janusctl haproxy acl-add ACL VALUEjanusctl haproxy acl-delete
Section titled “janusctl haproxy acl-delete”Delete a pattern from an ACL.
janusctl haproxy acl-delete ACL VALUEjanusctl haproxy cert-list
Section titled “janusctl haproxy cert-list”Certificates in HAProxy’s store.
janusctl haproxy cert-listjanusctl haproxy cert-upload
Section titled “janusctl haproxy cert-upload”Upload a PEM certificate and key as NAME.
janusctl haproxy cert-upload [-crt-list PATH] [-sni HOST,HOST] NAME FILE| Flag | |
|---|---|
-crt-list PATH | bind it into this crt-list |
-sni HOST,HOST | with -crt-list: the SNI names |
janusctl haproxy cert-delete
Section titled “janusctl haproxy cert-delete”Delete a certificate.
janusctl haproxy cert-delete [-crt-list PATH] NAME| Flag | |
|---|---|
-crt-list PATH | unbind it from this crt-list first |
janusctl haproxy files
Section titled “janusctl haproxy files”HAProxy’s own files (/etc/haproxy/files).
janusctl haproxy filesjanusctl haproxy file-get
Section titled “janusctl haproxy file-get”Print a file.
janusctl haproxy file-get NAMEjanusctl haproxy file-put
Section titled “janusctl haproxy file-put”Write a file.
janusctl haproxy file-put [-reload] NAME FILE| Flag | |
|---|---|
-reload | HAProxy uses it at once |
janusctl haproxy file-delete
Section titled “janusctl haproxy file-delete”Remove a file.
janusctl haproxy file-delete [-reload] NAME| Flag | |
|---|---|
-reload | HAProxy uses it at once |
janusctl haproxy acme
Section titled “janusctl haproxy acme”Let’s Encrypt (letsencrypt extension).
janusctl haproxy acme status
Section titled “janusctl haproxy acme status”The account, each certificate’s state and expiry.
janusctl haproxy acme statusjanusctl haproxy acme get
Section titled “janusctl haproxy acme get”The configuration, as JSON.
janusctl haproxy acme getjanusctl haproxy acme check
Section titled “janusctl haproxy acme check”Check a configuration.
janusctl haproxy acme check [-account-key FILE] FILE| Flag | |
|---|---|
-account-key FILE | an existing account’s private key |
janusctl haproxy acme apply
Section titled “janusctl haproxy acme apply”Save a configuration.
janusctl haproxy acme apply [-account-key FILE] FILE| Flag | |
|---|---|
-account-key FILE | an existing account’s private key |
janusctl haproxy acme renew
Section titled “janusctl haproxy acme renew”Obtain certificates now.
janusctl haproxy acme renew [NAME...]Network
Section titled “Network”janusctl network
Section titled “janusctl network”Addresses, routes, firewall, VRRP, BGP, Consul.
janusctl network status
Section titled “janusctl network status”Interfaces, addresses, routes, DNS, clock.
janusctl network statusjanusctl network get
Section titled “janusctl network get”The network configuration, as JSON.
janusctl network getjanusctl network apply
Section titled “janusctl network apply”Apply a configuration on trial, then confirm it.
janusctl network apply [-timeout DURATION] [-no-confirm] FILE| Flag | |
|---|---|
-timeout DURATION | how long the node waits for the confirmation before reverting |
-no-confirm | apply only - confirm yourself before the timeout |
janusctl network confirm
Section titled “janusctl network confirm”Confirm the configuration on trial.
janusctl network confirmjanusctl network modules
Section titled “janusctl network modules”Optional modules and whether this image has them.
janusctl network modulesjanusctl network firewall
Section titled “janusctl network firewall”Nftables (nftables extension).
janusctl network firewall status
Section titled “janusctl network firewall status”Saved, on trial, live.
janusctl network firewall statusjanusctl network firewall get
Section titled “janusctl network firewall get”The saved ruleset.
janusctl network firewall getjanusctl network firewall check
Section titled “janusctl network firewall check”Validate a ruleset.
janusctl network firewall check FILEjanusctl network firewall apply
Section titled “janusctl network firewall apply”Apply a ruleset on trial, then confirm it.
janusctl network firewall apply [-timeout DURATION] [-no-confirm] FILE| Flag | |
|---|---|
-timeout DURATION | how long the node waits for the confirmation before reverting |
-no-confirm | apply only - confirm yourself before the timeout |
janusctl network firewall confirm
Section titled “janusctl network firewall confirm”Confirm the ruleset on trial.
janusctl network firewall confirmjanusctl network firewall sets
Section titled “janusctl network firewall sets”The live named sets and their elements.
janusctl network firewall setsjanusctl network firewall set-add
Section titled “janusctl network firewall set-add”Add elements live.
janusctl network firewall set-add [-timeout DURATION] FAMILY TABLE SET ELEMENT...| Flag | |
|---|---|
-timeout DURATION | the elements’ timeout |
janusctl network firewall set-del
Section titled “janusctl network firewall set-del”Delete elements.
janusctl network firewall set-del [-timeout DURATION] FAMILY TABLE SET ELEMENT...| Flag | |
|---|---|
-timeout DURATION | unused |
janusctl network vrrp
Section titled “janusctl network vrrp”VRRP (keepalived extension).
janusctl network vrrp status
Section titled “janusctl network vrrp status”Each instance’s state and virtual IPs.
janusctl network vrrp statusjanusctl network vrrp get
Section titled “janusctl network vrrp get”The saved keepalived.conf.
janusctl network vrrp getjanusctl network vrrp check
Section titled “janusctl network vrrp check”Have keepalived check it.
janusctl network vrrp check FILEjanusctl network vrrp apply
Section titled “janusctl network vrrp apply”Check, save and reload it.
janusctl network vrrp apply FILEjanusctl network bgp
Section titled “janusctl network bgp”BGP (bird extension).
janusctl network bgp status
Section titled “janusctl network bgp status”Protocols, sessions, routes.
janusctl network bgp statusjanusctl network bgp get
Section titled “janusctl network bgp get”The saved bird.conf.
janusctl network bgp getjanusctl network bgp check
Section titled “janusctl network bgp check”Have BIRD check it.
janusctl network bgp check FILEjanusctl network bgp apply
Section titled “janusctl network bgp apply”Check, save and reconfigure.
janusctl network bgp apply FILEjanusctl network consul
Section titled “janusctl network consul”Consul agent (consul extension).
janusctl network consul status
Section titled “janusctl network consul status”The service, the node, its cluster.
janusctl network consul statusjanusctl network consul get
Section titled “janusctl network consul get”The saved configuration.
janusctl network consul getjanusctl network consul check
Section titled “janusctl network consul check”Have consul validate it.
janusctl network consul check [-file NAME=PATH] [-only-files] FILE| Flag | |
|---|---|
-file NAME=PATH | a file it names (repeatable) |
-only-files | unused here |
janusctl network consul apply
Section titled “janusctl network consul apply”Check, save and apply (the agent restarts).
janusctl network consul apply [-file NAME=PATH] [-only-files] FILE| Flag | |
|---|---|
-file NAME=PATH | a file it names (repeatable) |
-only-files | drop the saved files not given |
janusctl access
Section titled “janusctl access”The fleet the node trusts, its own CA.
janusctl access trust
Section titled “janusctl access trust”The fleet the node trusts besides its own CA.
janusctl access trustjanusctl access trust-set
Section titled “janusctl access trust-set”Pin the fleet’s root and apply a bundle.
janusctl access trust-set [-root FILE] BUNDLE| Flag | |
|---|---|
-root FILE | the fleet’s root (the first time) |
janusctl access trust-reset
Section titled “janusctl access trust-reset”Forget the fleet (the node’s own CA only).
janusctl access trust-resetjanusctl access rotate-ca
Section titled “janusctl access rotate-ca”Replace the node’s own CA.
janusctl access rotate-ca [-console] DIR| Flag | |
|---|---|
-console | the node prints the admin key on its console |
janusctl pki
Section titled “janusctl pki”Client certificates of the node’s own CA.
janusctl pki generate-client-config
Section titled “janusctl pki generate-client-config”Issue a client certificate into DIR.
janusctl pki generate-client-config [-role ROLE] [-name NAME] [-ttl DURATION] DIR| Flag | |
|---|---|
-role ROLE | os:admin, os:operator or os:reader |
-name NAME | its common name |
-ttl DURATION | how long it’s valid (a year at most) |
janusctl fleet
Section titled “janusctl fleet”A fleet without a Controller (docs/fleet-without-controller.md).
The kit’s passphrase is asked, or read from JANUS_KIT_PASSPHRASE.
janusctl fleet init
Section titled “janusctl fleet init”A new fleet: its root’s key in KIT.
janusctl fleet init [-name FLEET] [-issuer NAME] [-user NAME] [-role ROLE] [-yes] KIT| Flag | |
|---|---|
-name FLEET | the fleet’s name |
-issuer NAME | this machine’s issuing CA’s name |
-user NAME | who this machine’s certificates are for |
-role ROLE | their role |
-yes | don’t ask the passphrase back |
janusctl fleet recover
Section titled “janusctl fleet recover”A fleet from its kit.
janusctl fleet recover [-kit KIT] [-name FLEET] [-issuer NAME] [-user NAME] [-role ROLE]| Flag | |
|---|---|
-kit KIT | the fleet’s recovery kit |
-name FLEET | the fleet’s name |
-issuer NAME | this machine’s issuing CA’s name |
-user NAME | who this machine’s certificates are for |
-role ROLE | their role |
janusctl fleet adopt
Section titled “janusctl fleet adopt”A node into the fleet.
janusctl fleet adopt [-endpoint HOST:PORT] [-ca FILE] [-cert FILE] [-key FILE] [-ca-fingerprint SHA256] [-kit KIT] NAME| Flag | |
|---|---|
-endpoint HOST:PORT | the node’s API |
-ca FILE | its first boot’s CA (ca.crt) |
-cert FILE | admin.crt |
-key FILE | admin.key |
-ca-fingerprint SHA256 | a node already in the fleet: its CA’s SHA-256 |
-kit KIT | the fleet’s recovery kit |
janusctl fleet sync
Section titled “janusctl fleet sync”The newest bundle everywhere.
janusctl fleet sync [-kit KIT]| Flag | |
|---|---|
-kit KIT | the fleet’s recovery kit |
janusctl fleet status
Section titled “janusctl fleet status”Each node’s bundle, this machine’s certificate.
janusctl fleet statusjanusctl fleet export
Section titled “janusctl fleet export”Root.crt, bundle.json, user-data.json.
janusctl fleet export DIRjanusctl fleet forget
Section titled “janusctl fleet forget”A node out of this context.
janusctl fleet forget NAMEjanusctl fleet issuer
Section titled “janusctl fleet issuer”The fleet’s issuing CAs.
janusctl fleet issuer list
Section titled “janusctl fleet issuer list”The issuing CAs of the bundle.
janusctl fleet issuer listjanusctl fleet issuer request
Section titled “janusctl fleet issuer request”A new machine: REQUEST to sign where the kit is.
janusctl fleet issuer request [-issuer NAME] [-user NAME] [-role ROLE] REQUEST| Flag | |
|---|---|
-issuer NAME | this machine’s issuing CA’s name |
-user NAME | who its certificates are for |
-role ROLE | the most they carry |
janusctl fleet issuer sign
Section titled “janusctl fleet issuer sign”Sign a machine’s issuing CA into the bundle.
janusctl fleet issuer sign [-kit KIT] [-replace] [-role ROLE] REQUEST GRANT| Flag | |
|---|---|
-kit KIT | the fleet’s recovery kit |
-replace | replace an issuing CA of that name |
-role ROLE | the most its certificates carry |
janusctl fleet issuer accept
Section titled “janusctl fleet issuer accept”The machine’s issuing CA, the fleet and its nodes.
janusctl fleet issuer accept GRANTjanusctl fleet issuer revoke
Section titled “janusctl fleet issuer revoke”A bundle without NAME’s issuing CA.
janusctl fleet issuer revoke [-kit KIT] NAME| Flag | |
|---|---|
-kit KIT | the fleet’s recovery kit |
Lifecycle
Section titled “Lifecycle”janusctl lifecycle
Section titled “janusctl lifecycle”Install, upgrade, roll back.
janusctl lifecycle install
Section titled “janusctl lifecycle install”Partition a blank disk and write a release (paths on the node).
janusctl lifecycle install [-sha256 HEX] [-controller-address HOST:PORT] [-controller-ca FILE] [-controller-fleet-root FILE] [-network-config FILE] [-fleet-root FILE] [-fleet-bundle FILE] [-registration-token TOKEN] [-insecure-skip-signature-check] DISK BUNDLE_DIR| Flag | |
|---|---|
-sha256 HEX | rootfs.squashfs’s expected SHA-256 |
-controller-address HOST:PORT | a Controller to self-register with |
-controller-ca FILE | the Controller’s CA |
-controller-fleet-root FILE | the Controller’s fleet root |
-network-config FILE | a network configuration (JSON) |
-fleet-root FILE | a fleet to trust from the first boot |
-fleet-bundle FILE | its bundle |
-registration-token TOKEN | a Controller enrollment token |
-insecure-skip-signature-check | accept unsigned UKIs - development only |
janusctl lifecycle upgrade
Section titled “janusctl lifecycle upgrade”Write a release to the inactive slot and reboot into it.
janusctl lifecycle upgrade [-sha256 HEX] [-wait-for-health] [-health-timeout SECONDS] [-insecure-skip-signature-check] [-allow-schematic-change] BUNDLE_DIR|URL| Flag | |
|---|---|
-sha256 HEX | rootfs.squashfs’s expected SHA-256 |
-wait-for-health | revert by itself if the new slot isn’t healthy |
-health-timeout SECONDS | how long it has to be healthy |
-insecure-skip-signature-check | accept unsigned UKIs - development only |
-allow-schematic-change | accept another image schematic |
janusctl lifecycle rollback
Section titled “janusctl lifecycle rollback”Boot the other slot.
janusctl lifecycle rollbackjanusctl lifecycle upload-release
Section titled “janusctl lifecycle upload-release”Stream a local release bundle to the node.
janusctl lifecycle upload-release BUNDLE_DIRjanusctl image
Section titled “janusctl image”Write onto a disk image, offline.
janusctl image seed-controller
Section titled “janusctl image seed-controller”A Controller to self-register with.
janusctl image seed-controller [-controller-address HOST:PORT] [-controller-ca FILE] [-controller-fleet-root FILE] [-registration-token TOKEN] DISK| Flag | |
|---|---|
-controller-address HOST:PORT | the Controller’s registration address |
-controller-ca FILE | its CA |
-controller-fleet-root FILE | its fleet root |
-registration-token TOKEN | an enrollment token |
janusctl image seed-fleet
Section titled “janusctl image seed-fleet”A fleet to trust from the first boot.
janusctl image seed-fleet [-fleet-root FILE] [-fleet-bundle FILE] DISK| Flag | |
|---|---|
-fleet-root FILE | the fleet’s root |
-fleet-bundle FILE | its bundle |
janusctl image seed-network
Section titled “janusctl image seed-network”A network configuration from the first boot.
janusctl image seed-network [-config FILE] DISK| Flag | |
|---|---|
-config FILE | the configuration (JSON) |
janusctl completion
Section titled “janusctl completion”The shell’s completion script (README: Shell completion).
janusctl completion bash|zsh|fishRuns on this machine: no node is contacted.
janusctl help
Section titled “janusctl help”This help, or a command’s.
janusctl help [COMMAND...]Runs on this machine: no node is contacted.