Mojo UpDocs
Nodes

Configuration, files and ports

Where a node keeps its settings and state, how its settings are layered, and the network ports it uses.

A node keeps everything it needs in one state directory, reads an optional settings file an administrator provides, and needs no inbound port unless it is a team hub.

Settings

A node's settings come from two files. The second wins where both set the same key.

LayerFileWho writes it
Administrator/etc/mojoup/node.json on Linux and macOS, %ProgramData%\MojoUp\node.json on Windows. --config or MOJOUP_NODE_CONFIG names another file.An administrator or a machine image. The node only reads it.
The node's ownsettings.json in the state directorymojoup-node config set, the setup wizard, and a person with the right access over the Control API.

Use the administrator's file to provision a fleet: the state directory, tags, and so on. Use config set for one machine:

Terminal
mojoup-node config get node.name
mojoup-node config set node.tags tag:gpu,tag:linux
mojoup-node config set node.autoUpdate install
mojoup-node config set node.home /srv/work --create

config get with no key lists every setting that is set and where its value comes from. A list setting takes a comma-separated list or a JSON array; null removes a setting.

Settings a node uses most

SettingDefaultWhat it does
node.namethe host nameThe name the organisation lists the node under.
node.tagsnoneTags the node asks for when it joins and runs, such as tag:gpu. The approver can change them; assignment happens in the console, never on the node.
node.rolesteamsWhat the node offers to do: teams, inference, dlp, sandbox, computer.
node.homethe user's home folderWhere the node clones repositories and runs agent tools from. It never holds the node's own state.
node.stateDirsee belowWhere the node keeps its state. Read only from the administrator's file.
node.ownerorgWho the node is offered as belonging to: the organisation, the person who joins it (user) or one project. The approver decides.
node.maxConcurrentAgents0 (no limit offered)The most agents the node runs at once. The organisation's quota still applies.
node.acceptsDispatchFromnoneNarrows whom the node accepts work from (project:<id>, group:<name>, user:<id>, tenant). It can narrow, never widen, what the organisation assigns.
node.approvalTimeoutSeconds300How long a tool permission request waits for someone to answer before the node denies it.
node.approvalHoldSeconds1800How long a request is held once it has reached the organisation's inbox (the console and the phone app) before the node denies it.
node.autoUpdatenotifyoff, notify (record and log that an update is available) or install.
node.consent.modelDownloadfalseWhether the node may download the local model runner and a model when asked. Off declines.
node.consent.organisationPolicyreplaceWhen the organisation publishes a policy for a repository that has its own, replace it (replace) or keep the repository's (keep).
node.sandbox.engineoffThe container engine for agent sandboxes: off, docker or podman. See Sandboxed nodes.

Every setting, with its full description, is on the Settings page; the node-only ones start node..

The state directory

The node picks its state directory in this order:

  1. --state-dir (or --state) on the command line.
  2. The MOJOUP_NODE_STATE_DIR environment variable.
  3. node.stateDir in the administrator's settings file.
  4. ~/.mojoup/node, or /var/lib/mojoup/node when run as root on Linux or macOS.

What it holds:

PathWhat it is
settings.jsonThe node's own settings layer.
projects/The projects and repositories the node serves.
state.jsonThe node's install id.
platform.jsonWhich organisation the node joined.
secrets.binEncrypted secrets and tokens.
status.jsonWhat the running node last reported; mojoup-node status prints it.
schedules.jsonRoutines kept on this node.
hosts/Per-repository working storage.
mesh/The mesh agent's key and status.
logs/node.logThe node's log. logs/service.log when it runs as a service or daemon, logs/update.log for updates.
audit/The audit log of every change made through the node.
team-hub/Everything a node that is the team's hub keeps.
control.token, control.sockThe local control connection, present only while the node runs.

Back up the state directory to keep a node's identity and settings. The install folder holds no state: removing it and installing again loses nothing.

The secrets key

The node encrypts its secrets with a key kept in the operating system's store where there is one: DPAPI on Windows, the Keychain on macOS, the Secret Service (secret-tool) or systemd credentials on Linux. Where none is available it falls back to a key file and warns about it in status. Run mojoup-node secrets status to see where the key is and mojoup-node secrets migrate to move a key file into the operating system's store.

The install folder

DefaultAs root
Linux and macOS~/.local/share/mojoup/node/opt/mojoup/node
Windows%LOCALAPPDATA%\MojoUp\Node

Inside it: versions/ (the installed version and the one before it), current (a link to the version in use, which PATH and the service point at) and install.json (where the node was installed from and its channel).

Network and ports

WhatDirectionPort
The organisation's platform, or Mojo Up AI Cloud at https://ai.mojoup.com.auOutbound HTTPSThe platform's HTTPS port
Mesh control listenerLoopback only (127.0.0.1); the mesh agent exposes it on the node's mesh address at the same port7434 by default (platform.mesh.port)
Team hub (mojoup-node hub)Inbound HTTPS on the address it binds (the tailnet by default)7431 by default (--port)
Local control connectionA Unix socket (or a named pipe on Windows), owner-onlyNone

A node that joins an organisation or Mojo Up AI Cloud needs no inbound port: it makes every connection outwards. On a self-hosted organisation that runs a mesh, the console and your other machines reach the node through the encrypted mesh, which also needs no inbound port. Only a node running as a team hub listens for other machines.

mojoup-node doctor checks that the platform is reachable and that the mesh control listener is open.

Behind a proxy

The mesh agent reaches your organisation through the system's proxy by default. platform.mesh.proxy sets it explicitly: direct for none, or a proxy URL.

On this page