[{"data":1,"prerenderedAt":562},["ShallowReactive",2],{"navigation_docs":3,"-concepts-colony":144,"-concepts-colony-surround":557},[4,35,84,109,124,134,139],{"title":5,"path":6,"stem":7,"children":8,"page":34},"Get Started","\u002Fget-started","1.get-started",[9,14,19,24,29],{"title":10,"path":11,"stem":12,"icon":13},"Introduction","\u002Fget-started\u002Fintroduction","1.get-started\u002F1.introduction","i-lucide-house",{"title":15,"path":16,"stem":17,"icon":18},"Installation","\u002Fget-started\u002Finstallation","1.get-started\u002F2.installation","i-lucide-download",{"title":20,"path":21,"stem":22,"icon":23},"Quick start","\u002Fget-started\u002Fquickstart","1.get-started\u002F3.quickstart","i-lucide-rocket",{"title":25,"path":26,"stem":27,"icon":28},"Project structure","\u002Fget-started\u002Fproject-structure","1.get-started\u002F4.project-structure","i-lucide-folder-tree",{"title":30,"path":31,"stem":32,"icon":33},"Dashboard","\u002Fget-started\u002Fdashboard","1.get-started\u002F5.dashboard","i-lucide-layout-dashboard",false,{"title":36,"path":37,"stem":38,"children":39,"page":34},"Concepts","\u002Fconcepts","2.concepts",[40,45,50,55,60,65,69,74,79],{"title":41,"path":42,"stem":43,"icon":44},"Architecture","\u002Fconcepts\u002Farchitecture","2.concepts\u002F1.architecture","i-lucide-layers",{"title":46,"path":47,"stem":48,"icon":49},"Machines","\u002Fconcepts\u002Fmachines","2.concepts\u002F2.machines","i-lucide-server",{"title":51,"path":52,"stem":53,"icon":54},"Colony & users","\u002Fconcepts\u002Fcolony","2.concepts\u002F3.colony","i-lucide-users",{"title":56,"path":57,"stem":58,"icon":59},"Transport","\u002Fconcepts\u002Ftransport","2.concepts\u002F4.transport","i-lucide-network",{"title":61,"path":62,"stem":63,"icon":64},"Configuration","\u002Fconcepts\u002Fconfiguration","2.concepts\u002F5.configuration","i-lucide-settings",{"title":66,"path":67,"stem":68,"icon":23},"Deploy","\u002Fconcepts\u002Fdeploy","2.concepts\u002F6.deploy",{"title":70,"path":71,"stem":72,"icon":73},"Groups","\u002Fconcepts\u002Fgroups","2.concepts\u002F7.groups","i-lucide-boxes",{"title":75,"path":76,"stem":77,"icon":78},"Templates","\u002Fconcepts\u002Ftemplates","2.concepts\u002F8.templates","i-lucide-package-plus",{"title":80,"path":81,"stem":82,"icon":83},"Existing projects","\u002Fconcepts\u002Fexisting-projects","2.concepts\u002F9.existing-projects","i-lucide-folder-open",{"title":85,"path":86,"stem":87,"children":88,"page":34},"Remote","\u002Fremote","3.remote",[89,94,99,104],{"title":90,"path":91,"stem":92,"icon":93},"Remote machines","\u002Fremote\u002Foverview","3.remote\u002F1.overview","i-lucide-cloud",{"title":95,"path":96,"stem":97,"icon":98},"Remote deploy","\u002Fremote\u002Fdeploy","3.remote\u002F2.deploy","i-lucide-send",{"title":100,"path":101,"stem":102,"icon":103},"CI","\u002Fremote\u002Fci","3.remote\u002F3.ci","i-lucide-workflow",{"title":105,"path":106,"stem":107,"icon":108},"Tunnels","\u002Fremote\u002Ftunnel","3.remote\u002F4.tunnel","i-lucide-cable",{"title":110,"path":111,"stem":112,"children":113,"page":34},"Security","\u002Fsecurity","4.security",[114,119],{"title":115,"path":116,"stem":117,"icon":118},"Security model","\u002Fsecurity\u002Fmodel","4.security\u002F1.model","i-lucide-shield",{"title":120,"path":121,"stem":122,"icon":123},"Known issues","\u002Fsecurity\u002Fknown-issues","4.security\u002F2.known-issues","i-lucide-triangle-alert",{"title":125,"path":126,"stem":127,"children":128,"page":34},"Reference","\u002Freference","5.reference",[129],{"title":130,"path":131,"stem":132,"icon":133},"CLI reference","\u002Freference\u002Fcli","5.reference\u002F1.cli","i-lucide-terminal",{"title":135,"path":136,"stem":137,"icon":138},"Changelog","\u002Fchangelog","changelog","i-lucide-history",{"title":140,"path":141,"stem":142,"icon":143},"Communities","\u002Fcommunities","communities","i-lucide-heart-handshake",{"id":145,"title":51,"body":146,"description":549,"extension":550,"links":551,"meta":552,"navigation":553,"path":52,"seo":554,"stem":53,"__hash__":556},"docs\u002F2.concepts\u002F3.colony.md",{"type":147,"value":148,"toc":543},"minimark",[149,158,163,175,228,236,240,243,313,359,373,415,422,431,449,456,460,475,495,499,514,539],[150,151,152,153,157],"p",{},"The ",[154,155,156],"strong",{},"colony"," is the people: your account, and the users allowed on each\nmachine.",[159,160,162],"h2",{"id":161},"identity","Identity",[150,164,165,166,169,170,174],{},"Every principal holds an ed25519 keypair. The ",[154,167,168],{},"public key is the NodeID",", in\nbase32 without padding. Account keys live at ",[171,172,173],"code",{},"~\u002F.ant\u002Fidentity","; a machine's key\nlives on the machine.",[176,177,182],"pre",{"className":178,"code":179,"language":180,"meta":181,"style":181},"language-sh shiki shiki-themes material-theme-lighter github-light github-dark","ant colony signup             # create an account (--name, --email)\nant colony login              # sign in: --bundle, --identity, --passphrase\nant colony whoami             # print your NodeID and account (--json)\nant colony profile            # edit your own name\u002Femail (--name, --email)\nant colony export --out acct.json    # portable bundle (--passphrase | --no-passphrase)\nant colony import acct.json   # restore a bundle (--passphrase)\nant colony logout\n","sh","",[171,183,184,192,198,204,210,216,222],{"__ignoreMap":181},[185,186,189],"span",{"class":187,"line":188},"line",1,[185,190,191],{},"ant colony signup             # create an account (--name, --email)\n",[185,193,195],{"class":187,"line":194},2,[185,196,197],{},"ant colony login              # sign in: --bundle, --identity, --passphrase\n",[185,199,201],{"class":187,"line":200},3,[185,202,203],{},"ant colony whoami             # print your NodeID and account (--json)\n",[185,205,207],{"class":187,"line":206},4,[185,208,209],{},"ant colony profile            # edit your own name\u002Femail (--name, --email)\n",[185,211,213],{"class":187,"line":212},5,[185,214,215],{},"ant colony export --out acct.json    # portable bundle (--passphrase | --no-passphrase)\n",[185,217,219],{"class":187,"line":218},6,[185,220,221],{},"ant colony import acct.json   # restore a bundle (--passphrase)\n",[185,223,225],{"class":187,"line":224},7,[185,226,227],{},"ant colony logout\n",[150,229,230,231,235],{},"The account's portable credential bundle is passphrase-encrypted by default\n(PBKDF2-HMAC-SHA256, 210k iterations, AES-256-GCM), and load re-checks that the\nkey matches the profile NodeID. Because the NodeID ",[232,233,234],"em",{},"is"," the key, the same\nidentity logs in on any machine.",[159,237,239],{"id":238},"roles","Roles",[150,241,242],{},"Each machine keeps a roster mapping NodeIDs to roles:",[244,245,246,259],"table",{},[247,248,249],"thead",{},[250,251,252,256],"tr",{},[253,254,255],"th",{},"Role",[253,257,258],{},"Capabilities",[260,261,262,273,283,293,303],"tbody",{},[250,263,264,270],{},[265,266,267],"td",{},[171,268,269],{},"owner",[265,271,272],{},"Everything, including ownership transfer",[250,274,275,280],{},[265,276,277],{},[171,278,279],{},"admin",[265,281,282],{},"Everything but ownership transfer",[250,284,285,290],{},[265,286,287],{},[171,288,289],{},"deployer",[265,291,292],{},"Read, deploy, OS-user management",[250,294,295,300],{},[265,296,297],{},[171,298,299],{},"viewer",[265,301,302],{},"Read only",[250,304,305,310],{},[265,306,307],{},[171,308,309],{},"ci",[265,311,312],{},"Read and deploy",[176,314,316],{"className":178,"code":315,"language":180,"meta":181,"style":181},"ant colony users list                              # list the roster (--json, --mirror)\nant colony users add \u003Cnodeid> --role viewer        # add (links ant-\u003Cid> for OS roles)\nant colony users update \u003Cnodeid> --name \"Ada Lovelace\" --email ada@example.com\nant colony users update \u003Cnodeid> --system-user existing_unix_account\nant colony users update \u003Cnodeid> --no-system-user  # detach the linked account\nant colony users update \u003Cnodeid> --role admin      # change the role\nant colony users system-user \u003Cnodeid> --op lock    # print create | lock | unlock | delete\nant colony users remove \u003Cnodeid>                   # remove (--purge deletes the account)\n",[171,317,318,323,328,333,338,343,348,353],{"__ignoreMap":181},[185,319,320],{"class":187,"line":188},[185,321,322],{},"ant colony users list                              # list the roster (--json, --mirror)\n",[185,324,325],{"class":187,"line":194},[185,326,327],{},"ant colony users add \u003Cnodeid> --role viewer        # add (links ant-\u003Cid> for OS roles)\n",[185,329,330],{"class":187,"line":200},[185,331,332],{},"ant colony users update \u003Cnodeid> --name \"Ada Lovelace\" --email ada@example.com\n",[185,334,335],{"class":187,"line":206},[185,336,337],{},"ant colony users update \u003Cnodeid> --system-user existing_unix_account\n",[185,339,340],{"class":187,"line":212},[185,341,342],{},"ant colony users update \u003Cnodeid> --no-system-user  # detach the linked account\n",[185,344,345],{"class":187,"line":218},[185,346,347],{},"ant colony users update \u003Cnodeid> --role admin      # change the role\n",[185,349,350],{"class":187,"line":224},[185,351,352],{},"ant colony users system-user \u003Cnodeid> --op lock    # print create | lock | unlock | delete\n",[185,354,356],{"class":187,"line":355},8,[185,357,358],{},"ant colony users remove \u003Cnodeid>                   # remove (--purge deletes the account)\n",[150,360,361,364,365,368,369,372],{},[171,362,363],{},"users list"," reads the machine daemon; ",[171,366,367],{},"--mirror"," reads the local roster copy\nwithout contacting it. ",[171,370,371],{},"--json"," prints machine-readable output.",[150,374,375,376,378,379,378,381,383,384,387,388,391,392,395,396,399,400,403,404,407,408,403,411,414],{},"Adding a user with an OS-capable role (",[171,377,269],{},", ",[171,380,279],{},[171,382,289],{},") links the\ndeterministic ",[171,385,386],{},"ant-\u003Cid>"," unix account. ",[171,389,390],{},"users update"," can change the role\n(",[171,393,394],{},"--role","), relink a different account (including one that already exists on\nthe machine) or detach it;\n",[171,397,398],{},"users system-user --op"," prints the root-run ",[171,401,402],{},"useradd"," \u002F ",[171,405,406],{},"usermod --lock"," \u002F\n",[171,409,410],{},"usermod --unlock",[171,412,413],{},"userdel"," command for the operator to apply. Ant records a\nlinked account; it does not create, verify, or own an account it did not make.",[150,416,417,418,421],{},"The local machine has one user, your account. Edit it the same way; with no\n",[171,419,420],{},"--machine"," the command targets this host, so you can link your own login:",[176,423,425],{"className":178,"code":424,"language":180,"meta":181,"style":181},"ant colony users update \"$(ant colony whoami --json | jq -r .nodeId)\" --system-user \"$USER\"\n",[171,426,427],{"__ignoreMap":181},[185,428,429],{"class":187,"line":188},[185,430,424],{},[150,432,433,436,437,440,441,444,445,448],{},[154,434,435],{},"User references"," (",[171,438,439],{},"\u003Cnodeid>"," in the commands above) accept a full NodeID, an\nunambiguous ",[154,442,443],{},"prefix"," of one, or an unambiguous display name or email, so\n",[171,446,447],{},"ant colony users update ezyj --name \"Ada\""," works without pasting 52\ncharacters. An ambiguous reference lists the candidates.",[150,450,451,452,455],{},"Your own account's name and email are separate from any roster: change them with\n",[171,453,454],{},"ant colony profile --name \"…\" --email \"…\""," (the NodeID and key are unchanged).",[159,457,459],{"id":458},"invites","Invites",[150,461,462,463,466,467,470,471,474],{},"An invite is signed by the inviter's account key and carries the destination\nmachine NodeID, the role, and an expiry. Redemption is ",[154,464,465],{},"server-side",": the\ndaemon verifies the signature, expiry, that the invite is for ",[232,468,469],{},"this"," machine,\nthe inviter's current role, and the grant matrix, and that the nonce is unused.\nSingle-use is enforced by the daemon, and a leaked token can be ",[154,472,473],{},"revoked","\nbefore it is redeemed.",[176,476,478],{"className":178,"code":477,"language":180,"meta":181,"style":181},"ant colony invite --role deployer --machine prod   # create (--email, --ttl)\nant colony invites                                # list pending (--revoke NONCE)\nant colony join --token ant_inv_… --alias prod     # redeem on the other side\n",[171,479,480,485,490],{"__ignoreMap":181},[185,481,482],{"class":187,"line":188},[185,483,484],{},"ant colony invite --role deployer --machine prod   # create (--email, --ttl)\n",[185,486,487],{"class":187,"line":194},[185,488,489],{},"ant colony invites                                # list pending (--revoke NONCE)\n",[185,491,492],{"class":187,"line":200},[185,493,494],{},"ant colony join --token ant_inv_… --alias prod     # redeem on the other side\n",[159,496,498],{"id":497},"ownership","Ownership",[150,500,501,502,505,506,509,510,513],{},"The first owner is seeded out of band, ",[171,503,504],{},"ant-worker --owner \u003Cnodeid>",", emitted\nby ",[171,507,508],{},"ant nest bootstrap",", or written into the machine's ",[171,511,512],{},"state.json"," as root.\nOwnership can later move by election:",[176,515,517],{"className":178,"code":516,"language":180,"meta":181,"style":181},"ant colony elect-owner \u003Cnodeid>\nant colony election-status\nant colony users update \u003Cnodeid> --role owner\nant colony recover --add-owner \u003Cnodeid>   # break-glass restore if locked out\n",[171,518,519,524,529,534],{"__ignoreMap":181},[185,520,521],{"class":187,"line":188},[185,522,523],{},"ant colony elect-owner \u003Cnodeid>\n",[185,525,526],{"class":187,"line":194},[185,527,528],{},"ant colony election-status\n",[185,530,531],{"class":187,"line":200},[185,532,533],{},"ant colony users update \u003Cnodeid> --role owner\n",[185,535,536],{"class":187,"line":206},[185,537,538],{},"ant colony recover --add-owner \u003Cnodeid>   # break-glass restore if locked out\n",[540,541,542],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":181,"searchDepth":194,"depth":194,"links":544},[545,546,547,548],{"id":161,"depth":194,"text":162},{"id":238,"depth":194,"text":239},{"id":458,"depth":194,"text":459},{"id":497,"depth":194,"text":498},"Your portable identity, the users on a machine, roles, and invites.","md",null,{},{"icon":54},{"title":51,"description":555},"Ant identity is an ed25519 keypair whose public key is your NodeID. Machines keep a roster of users with roles.","RrbzM4SyBqB6AJvt6cPz8F-s-JnPJHMXvrqbC2R7Jpo",[558,560],{"title":46,"path":47,"stem":48,"description":559,"icon":49,"children":-1},"Nests are machines you can deploy to. Register, inspect, and target them.",{"title":56,"path":57,"stem":58,"description":561,"icon":59,"children":-1},"How the CLI talks to a remote machine: iroh, RPC, and blob streaming.",1791494556023]