Reference

Files and directories

Where servers, nodes and operators keep their state.

Server

PathWhat
~/.local/share/orchestrator-zeroThe default data directory (--data-dir)
<data-dir>/master.keyThe master key, unless --master-key-file points elsewhere. Back it up.

In dev mode with --data-dir, the directory also holds oz0.db (the management database), temporal.db (the embedded Temporal's), operator/ (the operator's credentials and context.json), join-token (a reusable token for dev nodes) and admin-password. Without --data-dir, dev mode uses a temporary directory removed at exit. server backup --dev copies both databases while the server runs; see backups.

Operator

server init writes the first operator's credentials to --operator-dir, by default ~/.config/orchestrator-zero/<cluster>/. server operator issue writes new ones the same way, and operator renew replaces the certificate and key in place:

FileWhat
context.jsonThe cluster's name, the edge and management addresses, the namespace, and the paths below
ca.crtThe cluster's CA certificate
operator.crt, operator.keyThe operator's certificate and private key. Keep them private.

Point the CLI at it with export OZ0_CONTEXT=.../context.json or --context. Without either, the CLI looks for ~/.config/orchestrator-zero/context.json.

Node

PathWhat
~/.local/share/orchestrator-zero-nodeThe default data directory (--data-dir): the node's identity and key, uv, Python, Node.js, runtimes and state
<data-dir>/node.jsonThe node's state, including the list of edges it can fail over to
<data-dir>/plugins/<name>/<commit>/Each installed plugin, with its environments

Nothing on a node needs a backup: its plugins come from the edge, and a lost node can join again.

Copyright © 2026