orchestrator-zero
Orchestrator Zero: mission control for AI agents
Global flags
These work with every command.
| Flag | Type | Default | Description |
|---|---|---|---|
--context | string | $OZ0_CONTEXT or <config dir>/orchestrator-zero/context.json | CLI context file written by server init |
--log-level | string | info | log level: debug, info, warn or error |
apikey
Manage a tenant's API keys, which apps call the runtime API with (ADR 0050)
orchestrator-zero apikey [command]
Subcommands: create, list, revoke
apikey create
Make a key that an app sends as Authorization: Bearer <key> to the runtime API, on the edge's HTTPS port. It has a role in one tenant: reader follows jobs, operator also starts and cancels them and decides approvals. Operators see what jobs read and wrote unless --no-content. The key works nowhere else: not on the admin API, and not on Temporal's ports. It is shown only now; keep it as a secret.
orchestrator-zero apikey create <name> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--expires | string | 90d | how long it lasts, such as 30d or 720h, or never |
--json | bool | print JSON instead of a table | |
--no-content | bool | an operator key that may not see what jobs read and wrote | |
--role | string | operator | reader or operator |
--tenant | string | default | tenant |
apikey list
List a tenant's API keys, never their secrets
orchestrator-zero apikey list [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table | |
--tenant | string | default | tenant |
apikey revoke
Stop an API key from working, within seconds on every edge
orchestrator-zero apikey revoke <id> [flags]
approval
Decide on steps that wait for a person, such as tool calls in requires_approval
orchestrator-zero approval [command]
Subcommands: approve, deny, list
approval approve
Let a waiting step go ahead
orchestrator-zero approval approve JOB APPROVAL [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--comment | string | why; the agent sees it, and so does the job's history | |
--tenant | string | default | tenant |
approval deny
Stop a waiting step; the agent is told why
orchestrator-zero approval deny JOB APPROVAL [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--comment | string | why; the agent sees it, and so does the job's history | |
--tenant | string | default | tenant |
approval list
List what waits for a decision, oldest first
orchestrator-zero approval list [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--job | string | only this job's | |
--json | bool | print JSON instead of a table | |
--tenant | string | default | tenant |
audit
Read the audit log, newest first: who changed what, and what the platform did by itself
orchestrator-zero audit [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--action | string | only this action, or every action under a prefix that ends in a dot, such as node. | |
--json | bool | print JSON instead of a table | |
--limit | int32 | 50 | at most this many entries |
--target | string | only entries about this target, such as a node ID or tenant/plugin |
catalog
List the agents, tools and skills a tenant's plugins offer, and the nodes ready to run them
orchestrator-zero catalog [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table | |
--tenant | string | default | tenant |
cluster
Show the cluster
orchestrator-zero cluster [command]
Subcommands: info
cluster info
Show cluster name, CA hash and servers
orchestrator-zero cluster info [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table |
dev
Start a dev server and a node, install the plugin from its working tree (no commit needed) and reinstall it whenever a file changes. The node's tools (uv, Python, Node.js) are cached between runs; the server starts empty every time.
orchestrator-zero dev [plugin-dir] [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--cache-dir | string | where the dev node keeps uv, Python and Node.js between runs | |
--node-binary | string | next to this binary, else on PATH | orchestrator-zero-node to run |
--runtime-bundle | string | $OZ0_RUNTIME_BUNDLE, else the newest in ./dist/runtime | runtime bundle directory |
job
Follow, cancel and list jobs; start them with run
orchestrator-zero job [command]
Subcommands: cancel, findings, get, list, run, step, trace, watch
job cancel
Cancel a running job and the jobs it delegated to
orchestrator-zero job cancel JOB [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--reason | string | why, for the job's history | |
--tenant | string | default | tenant |
job findings
List the jobs whose traces have warnings, newest first, from the summaries the edge keeps for management (ADR 0039). A job's summary is written when it ends and refreshed while it runs, and it outlives Temporal's retention. --code picks one rule, such as possible_loop or retries; --code all lists every job.
orchestrator-zero job findings [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--agent | string | only this agent's or flow's jobs | |
--code | string | jobs with any warning | only this rule, such as possible_loop, retries or idle; all lists every job |
--json | bool | print JSON instead of a table | |
--limit | int32 | 50 | at most this many jobs |
--since | duration | 24h0m0s | jobs that started this long ago at most |
--tenant | string | default | tenant |
job get
Show a job: status, answer and cost per branch
orchestrator-zero job get JOB [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table | |
--tenant | string | default | tenant |
job list
List recent jobs
orchestrator-zero job list [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table | |
--limit | int | 20 | at most this many jobs |
--tenant | string | default | tenant |
job run
Run a workflow through the edge's Temporal proxy and print its result as JSON. This talks Temporal directly and is meant for debugging nodes and tools; agents are run with orchestrator-zero run.
orchestrator-zero job run [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--address | string | from the context, else 127.0.0.1:7233 | edge Temporal address |
--id | string | random | workflow ID |
--input | stringArray | workflow argument as JSON; repeat for several arguments | |
--namespace | string | from the context, else default | namespace |
--task-queue | string | task queue to run on (required) | |
--timeout | duration | 1m0s | how long to wait for the result |
--workflow | string | workflow type name (required) |
job step
Show one step's input and output, as job trace lists the steps: a model call's messages and response, a tool call's arguments and result, what a person was asked and what they answered. They can hold customer data, so this needs the content permission, and each look is in the audit log.
orchestrator-zero job step JOB STEP [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table | |
--tenant | string | default | tenant |
job trace
Show a job's trace, built by the edge from the job's Temporal history: each step with when it began, how long it took, where it ran and what it cost, and findings about what looks wrong. It shows the shape of the job, not what its steps read and wrote: job step shows one step's input and output.
orchestrator-zero job trace JOB [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table | |
--tenant | string | default | tenant |
job watch
Follow a job live until it ends, then print its answer and cost
orchestrator-zero job watch JOB [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table | |
--tenant | string | default | tenant |
node
Manage nodes: list, accept, reject, block, unblock, purge, delete, upgrade
orchestrator-zero node [command]
Subcommands: accept, block, delete, list, purge, reject, runtimes, show, unblock, upgrade
node accept
Accept pending nodes, like salt-key -a
orchestrator-zero node accept <node-id>... [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--label | stringArray | label for the node, key=value; repeatable | |
--tenant | string | default | tenant the node joins |
node block
Block nodes: the edge refuses their next call on every port
orchestrator-zero node block <node-id>... [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--reason | string | why, for the audit log |
node delete
Forget nodes; their keys may join again as new nodes
orchestrator-zero node delete <node-id>... [flags]
node list
List nodes
orchestrator-zero node list [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table | |
--pending | bool | only nodes waiting for approval (same as --state pending) | |
--state | string | only nodes in this state: pending, accepted, rejected, blocked or purging | |
--tenant | string | only this tenant's nodes |
node purge
Purge nodes (plan §12). Each loses access to work at once. On its next control stream, which a blocked or offline node gets too when it comes back, it receives a command signed with the cluster CA's key, checks the signature, stops its runtimes and plugins, deletes its data directory (keys, plugins, runtimes and tools) and its binary, and is forgotten. The machine must be set up again to rejoin.
orchestrator-zero node purge <node-id>... --yes [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--yes | bool | confirm that the nodes are to delete themselves |
node reject
Reject pending nodes
orchestrator-zero node reject <node-id>... [flags]
node runtimes
List the runtime versions the edge serves, newest first, and how many of a tenant's nodes run each
orchestrator-zero node runtimes [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table | |
--tenant | string | default | count this tenant's nodes |
node show
Show one node
orchestrator-zero node show <node-id> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table |
node unblock
Let blocked nodes back in
orchestrator-zero node unblock <node-id>... [flags]
node upgrade
Tell nodes which runtime version to run (ADR 0028). A node starts the new version next to the one it runs, new jobs move to it once most of the tenant's nodes run it, and the old version stops when no job is pinned to it any more. --runtime "" lets the nodes keep what they run.
--binary tells nodes to replace their own binary with the one the edge serves (ADR 0047): each node checks the release's signature against the keys it trusts, swaps the binary, and restarts its runtimes.
orchestrator-zero node upgrade [node-id...] [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--all-in | string | every accepted node of this tenant | |
--binary | bool | replace the node binary with the one the edge serves, signed (ADR 0047) | |
--json | bool | print JSON instead of a table | |
--runtime | string | the runtime version to run: one the edge serves |
operator
Manage this operator's certificate
orchestrator-zero operator [command]
Subcommands: renew
operator renew
Make a new key, have the cluster sign a certificate for it, and put both in place of the ones in the CLI context. The certificate in use must still be valid. Once it has expired, issue new credentials on a server with orchestrator-zero server operator issue.
orchestrator-zero operator renew [flags]
plugin
Build, check and install plugins
orchestrator-zero plugin [command]
Subcommands: approve-tools, install, lint, list, new, remove, test, update
plugin approve-tools
A plugin's tools are snapshotted when the first node lists them (ADR 0049). A node that later lists a function differently, such as a remote MCP server that changed a description or a schema, makes the change pending, and nodes refuse to call the functions that changed. plugin list shows the change; look at it (orchestrator-zero catalog --json has the listings) before you approve it.
orchestrator-zero plugin approve-tools <name> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--tenant | string | default | tenant |
plugin install
Install a plugin from a Git repository. The edge resolves the ref (default: the latest release tag, or the default branch) to a commit and locks it, checks the plugin like plugin lint, and packs it; nodes download it from the edge, never from Git. Installing an installed plugin updates it: a version with evals runs them on a test node first, and a new version of a plugin that runs on two or more nodes rolls out to canaries first, step by step through health and quality gates (rollout show).
orchestrator-zero plugin install <git-url> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--all-at-once | bool | give a new version to every node at once, instead of rolling it out to canaries first | |
--batch | int32 | half of the rest | nodes in each later step of a rollout |
--canary | int32 | 1 | nodes in a rollout's first step |
--json | bool | print JSON instead of a table | |
--no-gate | bool | install a version with evals at once, without running them on a test node first | |
--path | string | the plugin's folder in the repository, for repositories that hold several | |
--ref | string | latest release tag, else the default branch | branch, tag or full commit SHA |
--secret | string | tenant secret with a token for a private repository over HTTPS (the token, or user:token) | |
--select | stringArray | only nodes with this label, key=value; repeatable | |
--soak | duration | 1m | how long each step of a rollout is watched before its gates |
--start-timeout | duration | 5m | how long a step's nodes may take to run the new version |
--tenant | string | default | tenant to install into |
plugin lint
Check a plugin the way the edge does before it installs one: oz0-plugin.yaml (unknown fields are errors), the agents it lists, its skills and the files they refer to. Exits non-zero on errors.
orchestrator-zero plugin lint [dir] [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print the checked bundle and problems as JSON |
plugin list
List installed plugins and how each node is doing with them
orchestrator-zero plugin list [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table | |
--tenant | string | only this tenant's plugins |
plugin new
Create a plugin from a template
orchestrator-zero plugin new <dir> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--description | string | one line about what the plugin does | |
--name | string | the directory's name | plugin name |
--template | string | python-tool | template: python-agent, python-tool |
plugin remove
Uninstall a plugin; nodes stop it and delete it
orchestrator-zero plugin remove <name> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--tenant | string | default | tenant |
plugin test
Start a dev server and a node with the plugin from its working tree, run every case of its evals as a job, one at a time, and grade the answers. A case with a recording (evals/cassettes/<eval>/<case>.jsonl) is answered from it, without calling a model; others call the real API with ANTHROPIC_API_KEY or OPENAI_API_KEY from the environment. --record calls the real API for every case and keeps the answers. Exits non-zero when an eval passes fewer cases than its threshold.
orchestrator-zero plugin test [plugin-dir] [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--cache-dir | string | where the test node keeps uv, Python and Node.js between runs | |
--cassettes | string | <plugin>/evals/cassettes | where the recordings live |
--eval | string | run only this eval | |
--json | bool | print JSON instead of a table | |
--live | bool | call the real API for every case, ignoring recordings | |
--llm-anthropic-url | string | https://api.anthropic.com | Anthropic API address for live calls |
--llm-openai-url | string | https://api.openai.com | OpenAI API address for live calls |
--node-binary | string | next to this binary, else on PATH | orchestrator-zero-node to run |
--record | bool | call the real API for every case and keep the answers as the cases' recordings | |
--runtime-bundle | string | $OZ0_RUNTIME_BUNDLE, else the newest in ./dist/runtime | runtime bundle directory |
plugin update
Resolve an installed plugin's ref again. A new commit runs its evals on a test node first, when it has any, and rolls out to canaries first when the plugin runs on two or more nodes (ADR 0052).
orchestrator-zero plugin update <name> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--all-at-once | bool | give a new version to every node at once, instead of rolling it out to canaries first | |
--batch | int32 | half of the rest | nodes in each later step of a rollout |
--canary | int32 | 1 | nodes in a rollout's first step |
--json | bool | print JSON instead of a table | |
--no-gate | bool | roll out a version with evals at once, without running them on a test node first | |
--soak | duration | 1m | how long each step of a rollout is watched before its gates |
--start-timeout | duration | 5m | how long a step's nodes may take to run the new version |
--tenant | string | default | tenant |
rollout
Rollouts move a tenant's nodes to a new version in steps, the canary first, through health and quality gates, and roll back by themselves. rollout start rolls out a runtime version; a new version of an installed plugin rolls out when plugin install installs it, once its quality gate passes if it has one. A tenant runs one rollout at a time; plugin rollouts wait for their turn.
orchestrator-zero rollout [command]
Subcommands: abort, list, show, start
rollout abort
Roll a running rollout back, or drop a waiting one
orchestrator-zero rollout abort <rollout-id> [flags]
rollout list
List rollouts, newest first
orchestrator-zero rollout list [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table | |
--tenant | string | only this tenant's rollouts |
rollout show
Show a rollout's steps and verdicts
orchestrator-zero rollout show <rollout-id> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table |
rollout start
Start a rollout of a runtime version to a tenant's online nodes. Each step assigns the version to its nodes, waits until they run it, sends them their share of new jobs, and watches them for --soak. A step passes when its nodes stay healthy and jobs on the new version fail no more than on the old one; a step that fails rolls the upgraded nodes back by itself.
orchestrator-zero rollout start --runtime <version> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--batch | int32 | half of the rest | nodes in each later step |
--canary | int32 | 1 | nodes in the first step |
--json | bool | print JSON instead of a table | |
--runtime | string | the runtime version to move to: one the edge serves | |
--soak | duration | 1m | how long each step is watched before its gates |
--start-timeout | duration | 5m | how long a step's nodes may take to run the new version |
--tenant | string | default | tenant |
run
Start a job for an agent and wait for its answer. INPUT is text, or JSON for agents with an input schema; "-" reads it from stdin. What the job and each agent it delegated to cost goes to stderr.
While the job runs, what its agents write and the tools they call stream to stderr (--quiet stops that). Jobs are durable: if you stop waiting, the job keeps running; follow it with job watch or job get.
orchestrator-zero run AGENT [INPUT] [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--budget | float | the agent's limits.max_cost_usd | most the job and the jobs it delegates to may spend on LLM calls, in US dollars |
--detach | bool | print the job ID and return without waiting | |
--id | string | job ID (default: a new random one); a job with this ID that still runs is followed instead | |
--json | bool | print JSON instead of a table | |
--quiet (-q) | bool | do not stream what the agents do; print only the answer and the cost | |
--tenant | string | default | tenant to run in |
--timeout | duration | longest the job may run, on top of the agent's own limits | |
--wait | duration | until the job ends | longest to wait for the answer |
secret
Manage tenant secrets, such as LLM API keys
orchestrator-zero secret [command]
Subcommands: delete, list, set
| Flag | Type | Default | Description |
|---|---|---|---|
--tenant | string | default | tenant |
secret delete
Delete a secret
orchestrator-zero secret delete <NAME> [flags]
secret list
List secret names (never values)
orchestrator-zero secret list [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table |
secret set
Store a secret; the value comes from stdin, --from-env or --from-file, never from the command line
orchestrator-zero secret set <NAME> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--from-env | string | read the value from this environment variable | |
--from-file | string | read the value from this file |
server
Run an orchestrator-zero server
orchestrator-zero server [command]
Subcommands: backup, dist, init, operator, restore, start
server backup
Write one archive of every management table, read in one snapshot while servers keep running, and for a dev server its Temporal database too. The master key is not in it: keep that apart, and give it to server restore. The archive holds job content and sealed secrets, so store it as you store the database. A cluster's Temporal databases are backed up with PostgreSQL's own tools.
orchestrator-zero server backup --out FILE [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--data-dir | string | ~/.local/share/orchestrator-zero | server data directory |
--db | string | PostgreSQL URL of the management database (or set OZ0_DB) | |
--dev | bool | a dev server's data directory (--data-dir) instead of a cluster's database | |
--out (-o) | string | the archive to write, such as oz0-backup.tar.gz |
server dist
Manage what the edge serves to nodes: node binaries and runtimes
orchestrator-zero server dist [command]
Subcommands: pull
server dist pull
Mirror a release into the dist directory the edge serves (ADR 0047). URL is where a release's dist folder is served: manifest.json, manifest.json.sig and the files they name. The release's signature must be by a key this server binary trusts, and every file must match its digest; the manifest goes in place last, so nodes see the new release whole or not at all. Then node upgrade --binary moves nodes to it.
orchestrator-zero server dist pull URL [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--dist-dir | string | the dist folder next to this binary's folder | the edge's dist directory |
server init
Create a cluster once, before its first server starts. It creates the PostgreSQL databases and schemas, writes the master key, creates the cluster's CAs, the first tenant and the first operator, whose credentials go to --operator-dir.
orchestrator-zero server init [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--advertise | string | 127.0.0.1 | server address to put in the operator's CLI context |
--cluster-name | string | oz0 | cluster name (lowercase letters, digits, dashes) |
--data-dir | string | ~/.local/share/orchestrator-zero | server data directory |
--db | string | PostgreSQL URL of the management database, e.g. postgres://oz0@db:5432/oz0 (or set OZ0_DB) | |
--history-shards | int | 1024 | Temporal history shards; can never change |
--master-key-out | string | <data-dir>/master.key | where to write the master key |
--operator | string | admin | first operator |
--operator-dir | string | <config dir>/orchestrator-zero/<cluster> | where to write the operator's credentials |
--tenant | string | default | first tenant; its Temporal namespace has the same name |
server operator
Issue operator credentials on a server's own machine
orchestrator-zero server operator [command]
Subcommands: issue
server operator issue
Issue a key, a certificate and a CLI context for an operator (default admin), and add the operator if the cluster has none of that name. It runs on a server's machine: it reads the database and the master key, so whoever can run it is trusted like a server. A context already in --operator-dir keeps its addresses. An operator whose certificate still works renews it with orchestrator-zero operator renew.
orchestrator-zero server operator issue [NAME] [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--advertise | string | 127.0.0.1 | server address for a new CLI context |
--data-dir | string | ~/.local/share/orchestrator-zero | server data directory |
--db | string | PostgreSQL URL of the management database (or set OZ0_DB) | |
--dev | bool | a dev server's data directory (--data-dir): its database and master key, and its operator directory | |
--master-key-file | string | <data-dir>/master.key | master key file |
--namespace | string | default | namespace for a new CLI context |
--operator-dir | string | <config dir>/orchestrator-zero/<name> | where to write the credentials |
server restore
Restore an archive from server backup into an empty database: --db for a cluster, or a new dev data directory with --dev --data-dir. It checks every file's digest, and that the master key unseals the backup's CAs, before it writes anything. Then it inserts every row in one transaction and migrates to this binary's schema. Nodes keep their certificates and reconnect; operators get new credentials with server operator issue, which a dev server does by itself when it starts.
orchestrator-zero server restore FILE --master-key-file KEY [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--data-dir | string | ~/.local/share/orchestrator-zero | server data directory |
--db | string | PostgreSQL URL of the management database (or set OZ0_DB) | |
--dev | bool | a dev server's data directory (--data-dir) instead of a cluster's database | |
--master-key-file | string | the master key of the cluster the backup is from |
server start
Start the server. With --dev, management, edge and an embedded Temporal run in one process on SQLite, which is meant for development and tests. Without it the server joins the cluster that server init created in PostgreSQL.
orchestrator-zero server start [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--advertise | string | first non-loopback IPv4 | address other servers and nodes reach this server on |
--data-dir | string | ~/.local/share/orchestrator-zero | server data directory (with --dev: keep dev state here instead of a temporary directory) |
--db | string | PostgreSQL URL of the management database (or set OZ0_DB) | |
--dev | bool | run in dev mode: one process, embedded Temporal on SQLite | |
--dist-dir | string | the dist folder next to this binary's folder | what make dist built, which the edge serves to new nodes |
--edge-api-port | int | 7443 | edge HTTPS port for join, renew and the control stream |
--edge-temporal-port | int | 7233 | port where nodes reach Temporal through the edge |
--ip | string | 127.0.0.1 with --dev, else 0.0.0.0 | IP address to bind listeners to |
--llm-anthropic-url | string | https://api.anthropic.com | Anthropic API address for the LLM gateway |
--llm-openai-url | string | https://api.openai.com | OpenAI-compatible API address for the LLM gateway |
--management-port | int | 8443 | management HTTPS port for the admin API |
--master-key-file | string | <data-dir>/master.key | master key file written by server init |
--metrics-listen | string | serve /metrics for Prometheus on this address over plain HTTP, such as 127.0.0.1:9464 (not authenticated: keep it private) | |
--name | string | host name | server name in the cluster |
--otlp-endpoint | string | send traces over OTLP/HTTP to this URL, such as http://collector:4318: the server's own, and the nodes', which the edge relays | |
--otlp-header | stringToString | [] | a header for every trace export, such as Authorization=Bearer ...; repeatable |
--san | strings | extra host name or IP for the edge certificate, such as a load balancer; repeatable | |
--temporal-frontend-membership-port | int | 6933 | Temporal frontend membership port |
--temporal-frontend-port | int | 7234 | Temporal frontend gRPC port |
--temporal-history-membership-port | int | 6934 | Temporal history membership port |
--temporal-history-port | int | 7235 | Temporal history gRPC port |
--temporal-log-level | string | WARN | log level for Temporal's own logs |
--temporal-matching-membership-port | int | 6935 | Temporal matching membership port |
--temporal-matching-port | int | 7236 | Temporal matching gRPC port |
--temporal-port | int | 7234 | dev mode: port of the embedded Temporal frontend |
--temporal-ui-port | int | 8233 | dev mode: port of the Temporal web UI (0 disables it) |
--temporal-worker-membership-port | int | 6939 | Temporal worker membership port |
--temporal-worker-port | int | 7239 | Temporal worker gRPC port |
tenant
Manage tenants
orchestrator-zero tenant [command]
Subcommands: budget, create, list
tenant budget
Set the most a tenant may spend in a calendar month (UTC) on model calls and on what plugins report. Once it is spent, the gateway refuses the tenant's model calls until the month ends or the budget is raised.
orchestrator-zero tenant budget <tenant> <usd> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table |
tenant create
Create a tenant and its Temporal namespace
orchestrator-zero tenant create <id> [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--display-name | string | human-readable name | |
--json | bool | print JSON instead of a table |
tenant list
List tenants
orchestrator-zero tenant list [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table |
token
Manage join tokens
orchestrator-zero token [command]
Subcommands: create, list, revoke
token create
Create a join token; nodes that use it are accepted without approval
orchestrator-zero token create [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--description | string | what the token is for | |
--json | bool | print JSON instead of a table | |
--label | stringArray | label for joining nodes, key=value; repeatable | |
--max-uses | uint32 | how many nodes may join with it (0: unlimited) | |
--tenant | string | default | tenant the nodes join |
--ttl | duration | 24h0m0s | how long the token is valid (0: forever) |
token list
List join tokens
orchestrator-zero token list [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table | |
--tenant | string | only this tenant's tokens |
token revoke
Revoke a join token; nodes that joined with it stay
orchestrator-zero token revoke <token-id> [flags]
usage
Show LLM tokens and cost by job, agent and model
orchestrator-zero usage [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--job | string | only this job (workflow id) | |
--json | bool | print JSON instead of a table | |
--since | duration | 24h0m0s | how far back |
--tenant | string | default | tenant |
user
Manage web UI accounts and their roles in tenants
orchestrator-zero user [command]
Subcommands: add, grant, list, password, remove, revoke
user add
Add a web UI account; without --password-stdin a password is generated and printed once
orchestrator-zero user add NAME [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--password-stdin | bool | read the password from stdin instead of generating one | |
--role | string | reader | admin (every tenant, and the cluster), reader (reads every tenant) or member (only its tenants: see user grant) |
user grant
Give an account a role in a tenant (ADR 0046), replacing the one it had there. Readers look; operators also start and cancel jobs and decide approvals; admins also change the tenant's nodes, plugins, secrets, tokens and budget; owners also decide who is a member. --content says whether the account may see what the tenant's jobs read and wrote; without it, operators and above may and readers may not.
orchestrator-zero user grant NAME [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--content | bool | operators and above | whether the account may see what the tenant's jobs read and wrote |
--role | string | reader, operator, admin or owner | |
--tenant | string | default | tenant |
user list
List web UI accounts
orchestrator-zero user list [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--json | bool | print JSON instead of a table |
user password
Set a new password and sign the user out everywhere; without --password-stdin one is generated
orchestrator-zero user password NAME [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--password-stdin | bool | read the password from stdin instead of generating one |
user remove
Remove a web UI account and sign it out
orchestrator-zero user remove NAME [flags]
user revoke
Take an account's role in a tenant away
orchestrator-zero user revoke NAME [flags]
| Flag | Type | Default | Description |
|---|---|---|---|
--tenant | string | default | tenant |
version
Print the version
orchestrator-zero version [flags]