Files and directories
Server
| Path | What |
|---|---|
~/.local/share/orchestrator-zero | The default data directory (--data-dir) |
<data-dir>/master.key | The master key, unless --master-key-file points elsewhere. Back it up. |
In dev mode with --data-dir, the directory also holds oz0.db (the management database), temporal.db (the embedded Temporal's), operator/ (the operator's credentials and context.json), join-token (a reusable token for dev nodes) and admin-password. Without --data-dir, dev mode uses a temporary directory removed at exit. server backup --dev copies both databases while the server runs; see backups.
Operator
server init writes the first operator's credentials to --operator-dir, by default ~/.config/orchestrator-zero/<cluster>/. server operator issue writes new ones the same way, and operator renew replaces the certificate and key in place:
| File | What |
|---|---|
context.json | The cluster's name, the edge and management addresses, the namespace, and the paths below |
ca.crt | The cluster's CA certificate |
operator.crt, operator.key | The operator's certificate and private key. Keep them private. |
Point the CLI at it with export OZ0_CONTEXT=.../context.json or --context. Without either, the CLI looks for ~/.config/orchestrator-zero/context.json.
Node
| Path | What |
|---|---|
~/.local/share/orchestrator-zero-node | The default data directory (--data-dir): the node's identity and key, uv, Python, Node.js, runtimes and state |
<data-dir>/node.json | The node's state, including the list of edges it can fail over to |
<data-dir>/plugins/<name>/<commit>/ | Each installed plugin, with its environments |
Nothing on a node needs a backup: its plugins come from the edge, and a lost node can join again.