mojoup-node command line
Every mojoup-node command, its options and its exit codes.
mojoup-node is the headless node's only interface. Run mojoup-node --help on the machine to see the same list for the version you have installed.
mojoup-node <command> [options]Options every command takes
| Option | What it does |
|---|---|
--state-dir <dir> (or --state <dir>) | Where the node keeps its state. Default ~/.mojoup/node, or /var/lib/mojoup/node when run as root on Linux or macOS. Give one of the two spellings, not both. |
--config <file> | The administrator's settings file. Default /etc/mojoup/node.json, or %ProgramData%\MojoUp\node.json on Windows. |
-h, --help | Print the command list. |
-v, --version | Print the version. |
The state directory can also come from the MOJOUP_NODE_STATE_DIR environment variable or from node.stateDir in the administrator's settings file. The command-line option wins. See Configuration, files and ports.
Interactive commands
| Command | What it does |
|---|---|
mojoup-node | With no command, it works out what you need. On a machine that has not joined, it runs the setup wizard. On a running node, it opens the node's console (the REPL). On a node that has joined but is stopped, it offers to start it in the background, run it here, show its last status, check the machine or change its setup. |
setup | The first-run wizard: how to find your organisation, the approval, name, tags and roles, the home folder, the repositories to serve, and whether to start at boot. On a node that has already joined, it asks what you would like to change. |
dashboard [--once] | The live view: hosts, agents, spend and approvals to answer. --once prints it once as plain text and exits. |
doctor | Checks this machine: runtimes, mesh, platform, ports, service and disk. One pass, warning or failure line for each, with the fix. |
logs [-f] [-n <lines>] | Prints the node's log. -f (--follow) keeps following it; -n (--lines) sets how many lines. |
chat [--root <root>] [--specialist <id>] | Talk to a repository's agent on the running node. --root takes a root's id, name or path. --specialist names the specialist that answers; without it, the repository's default chat agent answers. |
setup options
When there is no terminal, the wizard takes its answers from options and names the option it is missing.
| Option | What it answers |
|---|---|
--email <address> | Find your organisation from your work email. |
--url <platform> | Find your organisation from its platform address. |
--cloud | Use Mojo Up AI Cloud. Give it alone, not with --url or --email. |
--token <join key> | Join with a join key instead of waiting for an approval. |
--name <name> | The node's name. |
--tags <a,b> | Tags, comma-separated (for example tag:gpu,tag:linux). |
--roles <a,b> | What the node is for: any of teams, inference, dlp, sandbox, computer. |
--root <path> | A repository folder to serve. Repeat for several. |
--home <folder> | The node's home folder, where it clones repositories and runs agent tools from. Created if it does not exist. |
--startup yes|no | Whether to install the service so the node starts with the machine. |
--email and --url cannot be used together.
Joining
| Command | What it does |
|---|---|
join --cloud [--name <name>] [--tags <a,b>] | Join Mojo Up AI Cloud. The node goes to the organisation that is active in the Cloud console when you approve the code: your personal one or a team. It serves only that one. |
join --email <address> [--name] [--tags] [--token <join key>] | Find your organisation from your work email and ask to join it as a node. |
join --url <platform> [--name] [--tags] [--token <join key>] | The same, from the platform's address. |
join --hub <invitation | https://address:port> [--code <code>] [--fingerprint <sha256:…>] [--yes] [--name] [--tags] | Join a team hub instead of an organisation. |
How join behaves:
- Without
--token, it prints a code and a page to open, then waits until a person allowed to approve nodes signs the node in. A node's code is valid for up to 24 hours. - With
--token, it joins with a join key an administrator made. There is no code and no wait. --urland--emailcannot be used together, and--cloudcannot be combined with--url,--emailor--hub.- With
--hub, the invitation line (it startsmojoup-hub:) carries the hub's address, its certificate fingerprint and a code. Given an address instead, the node prints the hub's certificate fingerprint and asks you to compare it with the one on the hub's Settings → Team page;--yesaccepts it without asking, and--fingerprintsupplies it. Without--code, the hub's owner approves the node under Waiting to join. join --hubdoes not take--url,--emailor--token.--code,--fingerprintand--yesonly work with--hub.
Step by step: Join a node.
Running
| Command | What it does |
|---|---|
run [--root <path>]... [--project <name>] | Run the node in the foreground: its repositories' hosts, the Control API, the relay, fleet reporting and the mesh. --root adds a folder on this machine to the project first (safe to repeat); --project names that project, otherwise it takes the node's name. On a terminal, the node's console opens once it has started; on a pipe, it prints its log. Stops on Ctrl+C or a stop request. |
run --daemon | Run the node in the background without a service manager. |
status [--json] | What the running node last reported, plus the team hub, routines, service and update lines. --json prints the raw status. |
version | Print the version. |
Running as a service
| Command | What it does |
|---|---|
service install [--system] [--tray] | Run the node at logon, restarted if it crashes. --system runs it at boot instead and needs an administrator or root. --tray adds the tray icon (Windows). |
service uninstall | Stop it and remove what install wrote. The node's state is kept. |
service start | stop | restart | status | Control the installed service. |
start | stop | restart | The same. With no service installed, start runs the node in the background. |
install, uninstall | Short for service install and service uninstall. |
tray [start | stop | status] | The tray icon (Windows only). |
Details per operating system: Run a node as a service.
Settings
| Command | What it does |
|---|---|
config get [key] | Show the node's settings and where each comes from. |
config set <key> <value> | Change a setting. null removes it. config set node.home <folder> --create makes the folder as well. |
The keys are the same as the workbench's settings; the node-only ones start node.. See Settings.
Updates
| Command | What it does |
|---|---|
update | Update this install from where it was installed from. The new version is tried first; if it does not start, the node stays on the current version and its settings are put back. |
update --check | Only report whether a newer version is available. |
update --source <base> | Update from a different source (remembered for next time). |
update --channel stable|preview | Switch the install's channel (remembered). |
update --background | Run the update as its own process and return at once. Cannot be combined with --check. |
A node running in someone's terminal is left alone: stop it first, or run it as a service or in the background.
Secrets
| Command | What it does |
|---|---|
secrets list [--project <id>] | The node's own secrets: names, scope, use and age. Never a value. |
secrets set <NAME> [--project <id>] [--repository <rootId>] [--use tools,agent,provider] [--provider <id>] [--description <text>] | Keep a secret. The value is read from standard input (pipe it in) or asked for without echo, never from the command line. Setting a name that already exists at that scope replaces it. A repository's secret needs --project too. |
secrets remove <NAME> [--project <id>] [--repository <rootId>] | Remove a secret. |
secrets status | Which store holds the node's secrets key, and how many secrets the node keeps. |
secrets migrate | Move a key file into the operating system's store (DPAPI on Windows, the Keychain on macOS, secret-tool on Linux). |
list, set and remove need the node to be running. Without --project, a secret is for every project on the node.
Routines
| Command | What it does |
|---|---|
routines list | The routines kept on this node, numbered: where each runs, when next, the last result and its id. |
routines run <n|id> | Start a routine now. |
routines remove <n|id> | Remove a routine. |
A routine is made on a person's workbench, on its Routines page, and saved on the node. A routine can be named by its number, its id or the start of its id.
Being a team hub
| Command | What it does |
|---|---|
hub [--name <team>] [--owner <person>] [--bind tailnet|<interface>|<address>] [--port <n>] | Run the team's hub in the foreground. --bind defaults to tailnet; --port defaults to 7431 (0 picks a free port). Prints the address, the certificate fingerprint and, with --name, the owner's first invitation. Ctrl+C stops it. |
hub invite [--name <person> --role contributor|viewer] [--kind desktop|node|phone] | Make an invitation line. Without --name, it is another invitation for the owner. --role needs --name and defaults to contributor. |
hub devices [--json] | The team's people, their devices and who is waiting to join. |
hub revoke <deviceId> | Revoke a device: its token no longer opens the hub. |
hub approve <request> --as <name> [--role contributor|viewer] | Approve a device that is waiting to join, as the person named. |
hub deny <request> | Refuse a device that is waiting to join. |
hub policy import <repository> | Take the team's policy from a repository's .mojoup/policy.json. |
hub policy publish | unpublish | Publish the team's policy so every member applies it, or withdraw it. |
The hub subcommands talk to the hub running on the same machine. A node that has joined a team hub cannot also be one. See Run a team hub.
Git credential helper
| Command | What it does |
|---|---|
git-credential get|store|erase | Git's credential helper for the node's repositories in an organisation's project. The node sets it in each such repository's local git config; you do not run it yourself. get asks the running node for a credential for the person the work is for; store and erase do nothing. |
Exit codes
| Code | Meaning |
|---|---|
0 | Success. join was approved. git-credential always exits 0. |
1 | Anything else went wrong. status exits 1 when the node has never reported a status. |
2 | A usage error: an unknown command or option, or options that do not go together. run also exits 2 when the organisation refuses this machine as a node, for example because it holds a workbench's sign-in rather than a node's. |
3 | Refused: the approver said no, a join key was refused, or a team hub refused the code. |
Environment variables
| Variable | What it does |
|---|---|
MOJOUP_NODE_STATE_DIR | The state directory, when --state-dir is not given. |
MOJOUP_NODE_CONFIG | The administrator's settings file, in place of the default path. |
MOJOUP_DISABLE_AUTO_UPDATE=1 | Turns off the node's automatic update check, whatever node.autoUpdate says. |
NO_COLOR | Draws the banner and screens without colour. |
The install scripts read their own variables; see Install a node.