[{"data":1,"prerenderedAt":490},["ShallowReactive",2],{"navigation_docs":3,"-concepts-machines":144,"-concepts-machines-surround":485},[4,35,84,109,124,134,139],{"title":5,"path":6,"stem":7,"children":8,"page":34},"Get Started","\u002Fget-started","1.get-started",[9,14,19,24,29],{"title":10,"path":11,"stem":12,"icon":13},"Introduction","\u002Fget-started\u002Fintroduction","1.get-started\u002F1.introduction","i-lucide-house",{"title":15,"path":16,"stem":17,"icon":18},"Installation","\u002Fget-started\u002Finstallation","1.get-started\u002F2.installation","i-lucide-download",{"title":20,"path":21,"stem":22,"icon":23},"Quick start","\u002Fget-started\u002Fquickstart","1.get-started\u002F3.quickstart","i-lucide-rocket",{"title":25,"path":26,"stem":27,"icon":28},"Project structure","\u002Fget-started\u002Fproject-structure","1.get-started\u002F4.project-structure","i-lucide-folder-tree",{"title":30,"path":31,"stem":32,"icon":33},"Dashboard","\u002Fget-started\u002Fdashboard","1.get-started\u002F5.dashboard","i-lucide-layout-dashboard",false,{"title":36,"path":37,"stem":38,"children":39,"page":34},"Concepts","\u002Fconcepts","2.concepts",[40,45,50,55,60,65,69,74,79],{"title":41,"path":42,"stem":43,"icon":44},"Architecture","\u002Fconcepts\u002Farchitecture","2.concepts\u002F1.architecture","i-lucide-layers",{"title":46,"path":47,"stem":48,"icon":49},"Machines","\u002Fconcepts\u002Fmachines","2.concepts\u002F2.machines","i-lucide-server",{"title":51,"path":52,"stem":53,"icon":54},"Colony & users","\u002Fconcepts\u002Fcolony","2.concepts\u002F3.colony","i-lucide-users",{"title":56,"path":57,"stem":58,"icon":59},"Transport","\u002Fconcepts\u002Ftransport","2.concepts\u002F4.transport","i-lucide-network",{"title":61,"path":62,"stem":63,"icon":64},"Configuration","\u002Fconcepts\u002Fconfiguration","2.concepts\u002F5.configuration","i-lucide-settings",{"title":66,"path":67,"stem":68,"icon":23},"Deploy","\u002Fconcepts\u002Fdeploy","2.concepts\u002F6.deploy",{"title":70,"path":71,"stem":72,"icon":73},"Groups","\u002Fconcepts\u002Fgroups","2.concepts\u002F7.groups","i-lucide-boxes",{"title":75,"path":76,"stem":77,"icon":78},"Templates","\u002Fconcepts\u002Ftemplates","2.concepts\u002F8.templates","i-lucide-package-plus",{"title":80,"path":81,"stem":82,"icon":83},"Existing projects","\u002Fconcepts\u002Fexisting-projects","2.concepts\u002F9.existing-projects","i-lucide-folder-open",{"title":85,"path":86,"stem":87,"children":88,"page":34},"Remote","\u002Fremote","3.remote",[89,94,99,104],{"title":90,"path":91,"stem":92,"icon":93},"Remote machines","\u002Fremote\u002Foverview","3.remote\u002F1.overview","i-lucide-cloud",{"title":95,"path":96,"stem":97,"icon":98},"Remote deploy","\u002Fremote\u002Fdeploy","3.remote\u002F2.deploy","i-lucide-send",{"title":100,"path":101,"stem":102,"icon":103},"CI","\u002Fremote\u002Fci","3.remote\u002F3.ci","i-lucide-workflow",{"title":105,"path":106,"stem":107,"icon":108},"Tunnels","\u002Fremote\u002Ftunnel","3.remote\u002F4.tunnel","i-lucide-cable",{"title":110,"path":111,"stem":112,"children":113,"page":34},"Security","\u002Fsecurity","4.security",[114,119],{"title":115,"path":116,"stem":117,"icon":118},"Security model","\u002Fsecurity\u002Fmodel","4.security\u002F1.model","i-lucide-shield",{"title":120,"path":121,"stem":122,"icon":123},"Known issues","\u002Fsecurity\u002Fknown-issues","4.security\u002F2.known-issues","i-lucide-triangle-alert",{"title":125,"path":126,"stem":127,"children":128,"page":34},"Reference","\u002Freference","5.reference",[129],{"title":130,"path":131,"stem":132,"icon":133},"CLI reference","\u002Freference\u002Fcli","5.reference\u002F1.cli","i-lucide-terminal",{"title":135,"path":136,"stem":137,"icon":138},"Changelog","\u002Fchangelog","changelog","i-lucide-history",{"title":140,"path":141,"stem":142,"icon":143},"Communities","\u002Fcommunities","communities","i-lucide-heart-handshake",{"id":145,"title":46,"body":146,"description":477,"extension":478,"links":479,"meta":480,"navigation":481,"path":47,"seo":482,"stem":48,"__hash__":484},"docs\u002F2.concepts\u002F2.machines.md",{"type":147,"value":148,"toc":471},"minimark",[149,163,168,221,282,298,302,305,313,321,345,349,407,429,433,447,462,467],[150,151,152,153,157,158,162],"p",{},"A ",[154,155,156],"strong",{},"nest"," is a machine you deploy to. Your own machine is the first nest,\ncalled ",[159,160,161],"code",{},"local",". Registering a remote machine makes it a target that projects can\nname.",[164,165,167],"h2",{"id":166},"the-registry","The registry",[169,170,175],"pre",{"className":171,"code":172,"language":173,"meta":174,"style":174},"language-sh shiki shiki-themes material-theme-lighter github-light github-dark","ant nest machines list            # list registered machines\nant nest machines add prod --hostname prod.example.com\nant nest machines add prod --node-id 7f2e…            # already-running worker\nant nest machines add prod --host ADDR --ssh-key ~\u002F.ssh\u002Fid_ed25519   # provision over SSH\nant nest machines remove prod\nant nest machines decommission prod --host ADDR --ssh-key ~\u002F.ssh\u002Fid_ed25519 --yes\nant nest machines network prod --name ant-prod --driver bridge\n","sh","",[159,176,177,185,191,197,203,209,215],{"__ignoreMap":174},[178,179,182],"span",{"class":180,"line":181},"line",1,[178,183,184],{},"ant nest machines list            # list registered machines\n",[178,186,188],{"class":180,"line":187},2,[178,189,190],{},"ant nest machines add prod --hostname prod.example.com\n",[178,192,194],{"class":180,"line":193},3,[178,195,196],{},"ant nest machines add prod --node-id 7f2e…            # already-running worker\n",[178,198,200],{"class":180,"line":199},4,[178,201,202],{},"ant nest machines add prod --host ADDR --ssh-key ~\u002F.ssh\u002Fid_ed25519   # provision over SSH\n",[178,204,206],{"class":180,"line":205},5,[178,207,208],{},"ant nest machines remove prod\n",[178,210,212],{"class":180,"line":211},6,[178,213,214],{},"ant nest machines decommission prod --host ADDR --ssh-key ~\u002F.ssh\u002Fid_ed25519 --yes\n",[178,216,218],{"class":180,"line":217},7,[178,219,220],{},"ant nest machines network prod --name ant-prod --driver bridge\n",[150,222,223,226,227,230,231,234,235,234,238,234,241,244,245,234,248,234,251,234,254,257,258,261,262,265,266,269,270,273,274,277,278,281],{},[159,224,225],{},"add"," registers a machine by NodeID, or provisions it over SSH when ",[159,228,229],{},"--host"," is\ngiven (",[159,232,233],{},"--ssh-user",", ",[159,236,237],{},"--ssh-port",[159,239,240],{},"--ssh-key",[159,242,243],{},"--ssh-password"," \u002F\n",[159,246,247],{},"--ssh-password-stdin",[159,249,250],{},"--docker-mode",[159,252,253],{},"--no-caddy",[159,255,256],{},"--no-caddy-check",", and\n",[159,259,260],{},"--id","). ",[159,263,264],{},"decommission"," reverses provisioning on the machine over SSH\n(",[159,267,268],{},"--purge"," also removes the worker user, state, containers, images, and\nnetworks; ",[159,271,272],{},"--keep-record"," keeps the local entry). ",[159,275,276],{},"network"," shows or sets the\nmachine-wide network. See ",[279,280,90],"a",{"href":91},".",[150,283,284,285,234,287,290,291,294,295,281],{},"Each machine has a stable key (",[159,286,161],{},[159,288,289],{},"prod",", …) and the machine it points at.\nA project targets one by name via ",[159,292,293],{},"machine:"," in ",[159,296,297],{},"ant.yaml",[164,299,301],{"id":300},"everything-nests-under-a-machine","Everything nests under a machine",[150,303,304],{},"In schema v2, groups, projects, and Caddy settings belong to a machine:",[169,306,311],{"className":307,"code":309,"language":310},[308],"language-text","machines\n└── local\n    ├── caddy        { auto_start: true }\n    ├── docker       { mode: rootless }\n    ├── network      { name: ant-local }\n    ├── groups       { backend: { network: {…}, domains: [example.com] } }\n    └── project_dirs [ \u002Fhome\u002Fme\u002Fcode\u002Fapi, \u002Fhome\u002Fme\u002Fcode\u002Fworker ]\n","text",[159,312,309],{"__ignoreMap":174},[150,314,315,316,320],{},"This is what makes remote deploys coherent: a group and its project directories\nare facts about ",[317,318,319],"em",{},"a machine",", not about your laptop in the abstract. When a\nproject joins a group, its directory moves to the group.",[150,322,323,324,326,327,330,331,334,335,334,338,341,342,344],{},"v1 configs migrate on load; a top-level ",[159,325,161],{}," object folds into\n",[159,328,329],{},"machines.local",", flat ",[159,332,333],{},"groups","\u002F",[159,336,337],{},"project_dirs",[159,339,340],{},"caddy"," are nested, and a legacy\ngroup carrying a ",[159,343,293],{}," field nests under that machine.",[164,346,348],{"id":347},"inspecting-a-machine","Inspecting a machine",[169,350,352],{"className":171,"code":351,"language":173,"meta":174,"style":174},"ant nest                      # overview of the local machine (--json)\nant nest ping [machine]       # is the worker reachable? is iroh available? (--timeout)\nant nest doctor               # Docker, Caddy, docker mode, tools (--machine M for a nest)\nant nest identity show        # a machine's NodeID\nant nest identity generate    # create a machine identity (--force)\nant nest audit                # tamper-evident action log (--limit, --json)\nant nest state export --out state.json   # back up roster and invites\nant nest state import --file state.json  # restore (owner-only; --force)\nant nest tools                # inspect tools (also install | allow-ports)\nant nest tunnel --container app --port 8080   # forward a local port over iroh\n",[159,353,354,359,364,369,374,379,384,389,395,401],{"__ignoreMap":174},[178,355,356],{"class":180,"line":181},[178,357,358],{},"ant nest                      # overview of the local machine (--json)\n",[178,360,361],{"class":180,"line":187},[178,362,363],{},"ant nest ping [machine]       # is the worker reachable? is iroh available? (--timeout)\n",[178,365,366],{"class":180,"line":193},[178,367,368],{},"ant nest doctor               # Docker, Caddy, docker mode, tools (--machine M for a nest)\n",[178,370,371],{"class":180,"line":199},[178,372,373],{},"ant nest identity show        # a machine's NodeID\n",[178,375,376],{"class":180,"line":205},[178,377,378],{},"ant nest identity generate    # create a machine identity (--force)\n",[178,380,381],{"class":180,"line":211},[178,382,383],{},"ant nest audit                # tamper-evident action log (--limit, --json)\n",[178,385,386],{"class":180,"line":217},[178,387,388],{},"ant nest state export --out state.json   # back up roster and invites\n",[178,390,392],{"class":180,"line":391},8,[178,393,394],{},"ant nest state import --file state.json  # restore (owner-only; --force)\n",[178,396,398],{"class":180,"line":397},9,[178,399,400],{},"ant nest tools                # inspect tools (also install | allow-ports)\n",[178,402,404],{"class":180,"line":403},10,[178,405,406],{},"ant nest tunnel --container app --port 8080   # forward a local port over iroh\n",[150,408,409,412,413,261,415,418,419,422,423,426,427,281],{},[159,410,411],{},"ant nest ping"," reports that iroh is unavailable on platforms built without the\ntransport (see ",[279,414,15],{"href":16},[159,416,417],{},"ant nest doctor","\nchecks the Docker daemon, Caddy, the docker mode, and tools; locally, or over\nthe worker RPCs with ",[159,420,421],{},"--machine M"," (host-level port grants are reported as not\napplicable remotely). ",[159,424,425],{},"ant nest tunnel"," reaches a published container port from\nyour machine without opening one on the nest; see ",[279,428,105],{"href":106},[164,430,432],{"id":431},"privileged-work-is-operator-run","Privileged work is operator-run",[150,434,435,436,439,440,443,444,446],{},"Ant's worker never invokes ",[159,437,438],{},"sudo",". Provisioning a machine (installing the\nworker, opening ports) is an operator action; ",[159,441,442],{},"ant nest bootstrap --host"," runs\nthe same steps over SSH through the SSH user's ",[159,445,438],{},":",[169,448,450],{"className":171,"code":449,"language":173,"meta":174,"style":174},"ant nest bootstrap            # print the root-run steps for a machine\nant nest reconcile --apply    # run them (root)\n",[159,451,452,457],{"__ignoreMap":174},[178,453,454],{"class":180,"line":181},[178,455,456],{},"ant nest bootstrap            # print the root-run steps for a machine\n",[178,458,459],{"class":180,"line":187},[178,460,461],{},"ant nest reconcile --apply    # run them (root)\n",[150,463,464,465,281],{},"The worker itself runs unprivileged. See ",[279,466,115],{"href":116},[468,469,470],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":174,"searchDepth":187,"depth":187,"links":472},[473,474,475,476],{"id":166,"depth":187,"text":167},{"id":300,"depth":187,"text":301},{"id":347,"depth":187,"text":348},{"id":431,"depth":187,"text":432},"Nests are machines you can deploy to. Register, inspect, and target them.","md",null,{},{"icon":49},{"title":46,"description":483},"How Ant registers deploy-target machines, and how groups, projects, and Caddy nest under each one.","Nwwx-GvfS9CmOkogP59kyoKlH1j49A80lX3c53Pu8X0",[486,488],{"title":41,"path":42,"stem":43,"description":487,"icon":44,"children":-1},"The pillars, the process model, and what runs where.",{"title":51,"path":52,"stem":53,"description":489,"icon":54,"children":-1},"Your portable identity, the users on a machine, roles, and invites.",1791494555825]