CLI examples — Auth and setup
The first stop in the CLI examples cookbook. Run the
shell setup block once per shell, then save a token with auth login
so the rest of the cookbook is paste-ready.
Setup (run once per shell)
$D is referenced in any block that needs a daemon id. If daemon list
is empty when you start, jump to
Daemons, bring one up, then re-run
the D= line.
With LAKESHORE_URL exported, resolveServer() takes that path and
does not read the saved auth file — it sends no bearer token at
all, so any auth login token is ignored. That is correct for an
open-mode local control plane and wrong for a token-enforced
deployment. For the latter, either skip the LAKESHORE_URL export and
rely on the saved login, or unset LAKESHORE_URL after running
lakeshore auth login.
Auth (one-time login)
The auth commands are the only ones that read LAKESHORE_SERVER.
Their server precedence is --server → LAKESHORE_SERVER → the saved
auth file → http://localhost:8080.
auth login — save a token
Prompts for a bearer token on a TTY (omit --token), validates it
against GET <server>/v1/namespaces/<ns>/whoami, then writes
~/.config/lakeshore/auth.yml with mode 600.
Nothing is saved if whoami rejects the token.
auth login — non-interactive (admin-mint via env)
When LAKESHORE_ADMIN_TOKEN is exported and --token is absent, the
CLI mints a fresh per-namespace token on the server and saves that.
--name sets the label base; the CLI appends a timestamp so re-running
doesn't collide with the unique-name constraint.
auth status — show and revalidate
Prints the config path, server, namespace, token prefix and label, last
used timestamp, and authMode, after re-hitting whoami. Exits 1 when
there is no saved auth or the revalidation fails.
authMode is one of admin, token, or open. open means the
control plane is running without token enforcement.
auth logout — drop the saved token
Deletes ~/.config/lakeshore/auth.yml. The next CLI invocation needs
either LAKESHORE_URL set (open mode) or another auth login.
Minting tokens for other people
Only an admin can. lakeshore admin ... hard-fails with exit 1 unless
LAKESHORE_ADMIN_TOKEN is set.
tokens create prints the plaintext once along with a ready-made
lakeshore auth login line for the recipient. None of the admin
subcommands take flags.
Read next
- Installation — install plus the full env-var table.
- Providers + discover — the next step.
- Auth and secrets — the server-side model.