02 · Hello, hosted control plane
Two commands prove the CLI can authenticate against a real control plane, send a bearer token, and read its namespace back. Run this when you've just installed the CLI and want to confirm the wire works before anything else. Takes under a minute.
Before you begin
- Network access to a control plane. The hosted one lives at
https://api.lakeshore.dreamlake.ai. - A valid client token (
dlk_...) scoped to at least one namespace. If you don't have one yet, see 15 · Token lifecycle. LAKESHORE_URLunset. If it's exported, every non-authcommand will use it and send no token at all, which defeats the point of this test.
Step 1: Log in
login validates by calling GET /v1/namespaces/<ns>/whoami with the
Bearer header before it writes anything. On success it saves
~/.config/lakeshore/auth.yml with mode 600 and prints:
Step 2: Check status
This reloads the file and re-validates it against the same whoami
endpoint.
What success looks like
authMode: token plus your namespace means the full auth path — TLS,
Bearer header, token-hash lookup, namespace scoping — works end to end.
If something goes wrong
| Symptom | Likely cause |
|---|---|
whoami failed (401) | Token typo or revoked. Re-mint via 15 · Token lifecycle. |
whoami failed (403) | Token valid but scoped to a different namespace. Check --namespace. |
ENOTFOUND / DNS error | Server URL typo, or no internet. |
No saved auth. from status | login never completed — it does not save when whoami rejects the token. |
authMode: open | You hit a control plane running without token enforcement. Fine for local dev, not what you want against the hosted CP. |
You're done
The CLI can talk to the hosted control plane. Next, run the same exercise against a local stack: 03 · Hello, local stack.