CLI

orchestrator-zero-node

The node binary: join a cluster and run agents on this machine.

Orchestrator Zero node: runs agents on this machine

Global flags

These work with every command.

FlagTypeDefaultDescription
--data-dirstring~/.local/share/orchestrator-zero-nodewhere the node keeps its identity, uv, Python, runtimes and state
--log-levelstringinfolog level: debug, info, warn or error

join

Join a cluster. The node creates its key locally (it never leaves the machine) and checks the server against the CA hash in the join token or --ca-hash before it sends anything. With a valid token it is accepted at once; without one it waits until an operator runs orchestrator-zero node accept.

orchestrator-zero-node join [flags]
FlagTypeDefaultDescription
--ca-hashstringcluster CA hash (sha256:...) to join without a token and wait for approval
--namestringhost namedisplay name
--serverstringedge address, for example https://edge.example.com:7443 (required)
--tokenstringjoin token from orchestrator-zero token create (or set OZ0_JOIN_TOKEN)

run

Run the node in the foreground. It installs uv, Python and the runtime bundle if they are missing, opens the control stream to the edge, and runs the runtime on the task queues the edge assigns, behind a local proxy that holds the node's certificate. Certificates are renewed in place; a blocked node stops its runtime and waits.

orchestrator-zero-node run [flags]
FlagTypeDefaultDescription
--runtime-bundlestringdownload the edge's, which make dist buildsruntime bundle directory

version

Print the version

orchestrator-zero-node version [flags]
Copyright © 2026