[{"data":1,"prerenderedAt":605},["ShallowReactive",2],{"navigation_docs":3,"-get-started-dashboard":144,"-get-started-dashboard-surround":600},[4,35,84,109,124,134,139],{"title":5,"path":6,"stem":7,"children":8,"page":34},"Get Started","\u002Fget-started","1.get-started",[9,14,19,24,29],{"title":10,"path":11,"stem":12,"icon":13},"Introduction","\u002Fget-started\u002Fintroduction","1.get-started\u002F1.introduction","i-lucide-house",{"title":15,"path":16,"stem":17,"icon":18},"Installation","\u002Fget-started\u002Finstallation","1.get-started\u002F2.installation","i-lucide-download",{"title":20,"path":21,"stem":22,"icon":23},"Quick start","\u002Fget-started\u002Fquickstart","1.get-started\u002F3.quickstart","i-lucide-rocket",{"title":25,"path":26,"stem":27,"icon":28},"Project structure","\u002Fget-started\u002Fproject-structure","1.get-started\u002F4.project-structure","i-lucide-folder-tree",{"title":30,"path":31,"stem":32,"icon":33},"Dashboard","\u002Fget-started\u002Fdashboard","1.get-started\u002F5.dashboard","i-lucide-layout-dashboard",false,{"title":36,"path":37,"stem":38,"children":39,"page":34},"Concepts","\u002Fconcepts","2.concepts",[40,45,50,55,60,65,69,74,79],{"title":41,"path":42,"stem":43,"icon":44},"Architecture","\u002Fconcepts\u002Farchitecture","2.concepts\u002F1.architecture","i-lucide-layers",{"title":46,"path":47,"stem":48,"icon":49},"Machines","\u002Fconcepts\u002Fmachines","2.concepts\u002F2.machines","i-lucide-server",{"title":51,"path":52,"stem":53,"icon":54},"Colony & users","\u002Fconcepts\u002Fcolony","2.concepts\u002F3.colony","i-lucide-users",{"title":56,"path":57,"stem":58,"icon":59},"Transport","\u002Fconcepts\u002Ftransport","2.concepts\u002F4.transport","i-lucide-network",{"title":61,"path":62,"stem":63,"icon":64},"Configuration","\u002Fconcepts\u002Fconfiguration","2.concepts\u002F5.configuration","i-lucide-settings",{"title":66,"path":67,"stem":68,"icon":23},"Deploy","\u002Fconcepts\u002Fdeploy","2.concepts\u002F6.deploy",{"title":70,"path":71,"stem":72,"icon":73},"Groups","\u002Fconcepts\u002Fgroups","2.concepts\u002F7.groups","i-lucide-boxes",{"title":75,"path":76,"stem":77,"icon":78},"Templates","\u002Fconcepts\u002Ftemplates","2.concepts\u002F8.templates","i-lucide-package-plus",{"title":80,"path":81,"stem":82,"icon":83},"Existing projects","\u002Fconcepts\u002Fexisting-projects","2.concepts\u002F9.existing-projects","i-lucide-folder-open",{"title":85,"path":86,"stem":87,"children":88,"page":34},"Remote","\u002Fremote","3.remote",[89,94,99,104],{"title":90,"path":91,"stem":92,"icon":93},"Remote machines","\u002Fremote\u002Foverview","3.remote\u002F1.overview","i-lucide-cloud",{"title":95,"path":96,"stem":97,"icon":98},"Remote deploy","\u002Fremote\u002Fdeploy","3.remote\u002F2.deploy","i-lucide-send",{"title":100,"path":101,"stem":102,"icon":103},"CI","\u002Fremote\u002Fci","3.remote\u002F3.ci","i-lucide-workflow",{"title":105,"path":106,"stem":107,"icon":108},"Tunnels","\u002Fremote\u002Ftunnel","3.remote\u002F4.tunnel","i-lucide-cable",{"title":110,"path":111,"stem":112,"children":113,"page":34},"Security","\u002Fsecurity","4.security",[114,119],{"title":115,"path":116,"stem":117,"icon":118},"Security model","\u002Fsecurity\u002Fmodel","4.security\u002F1.model","i-lucide-shield",{"title":120,"path":121,"stem":122,"icon":123},"Known issues","\u002Fsecurity\u002Fknown-issues","4.security\u002F2.known-issues","i-lucide-triangle-alert",{"title":125,"path":126,"stem":127,"children":128,"page":34},"Reference","\u002Freference","5.reference",[129],{"title":130,"path":131,"stem":132,"icon":133},"CLI reference","\u002Freference\u002Fcli","5.reference\u002F1.cli","i-lucide-terminal",{"title":135,"path":136,"stem":137,"icon":138},"Changelog","\u002Fchangelog","changelog","i-lucide-history",{"title":140,"path":141,"stem":142,"icon":143},"Communities","\u002Fcommunities","communities","i-lucide-heart-handshake",{"id":145,"title":30,"body":146,"description":592,"extension":593,"links":594,"meta":595,"navigation":596,"path":31,"seo":597,"stem":32,"__hash__":599},"docs\u002F1.get-started\u002F5.dashboard.md",{"type":147,"value":148,"toc":584},"minimark",[149,165,170,199,214,217,255,282,286,448,452,469,472,486,490,497,562,565,580],[150,151,152,156,157,160,161,164],"p",{},[153,154,155],"code",{},"ant ui"," serves a local web console over the same ",[153,158,159],{},"ant.yaml"," files and client\nconfig the CLI uses. Every edit it makes writes the file with comments\npreserved, so the two stay on the same page, a domain you add in the dashboard\nis a ",[153,162,163],{},"domains:"," entry the CLI sees, and vice versa.",[166,167,169],"h2",{"id":168},"run-it","Run it",[171,172,177],"pre",{"className":173,"code":174,"language":175,"meta":176,"style":176},"language-sh shiki shiki-themes material-theme-lighter github-light github-dark","ant ui                      # serve in the foreground until interrupted\nant ui run                  # the same, as an explicit subcommand\nant ui passwd               # set a password before leaving loopback (--clear, --password-stdin)\n","sh","",[153,178,179,187,193],{"__ignoreMap":176},[180,181,184],"span",{"class":182,"line":183},"line",1,[180,185,186],{},"ant ui                      # serve in the foreground until interrupted\n",[180,188,190],{"class":182,"line":189},2,[180,191,192],{},"ant ui run                  # the same, as an explicit subcommand\n",[180,194,196],{"class":182,"line":195},3,[180,197,198],{},"ant ui passwd               # set a password before leaving loopback (--clear, --password-stdin)\n",[150,200,201,202,206,207,210,211,213],{},"The dashboard is ",[203,204,205],"strong",{},"local-only by design",": one dashboard per operator, on their\nown laptop, reading their own ",[153,208,209],{},"~\u002F.ant"," and ",[153,212,159],{}," files. It is not meant to\nbe hosted on a server or shared between users. The machines it manages are\nreached through your account and each machine's colony roles, so your dashboard\nshows exactly the machines your account can access and nothing else.",[150,215,216],{},"As a background service (a systemd user unit on Linux, a launchd agent on\nmacOS):",[171,218,220],{"className":173,"code":219,"language":175,"meta":176,"style":176},"ant ui install              # install, enable, and start the service (--host, --port, --force)\nant ui status               # installed \u002F enabled \u002F running? (--json)\nant ui logs -f              # follow its logs (--lines N)\nant ui stop | start | restart\nant ui recreate             # reinstall (picks up a new host\u002Fport) and restart\nant ui uninstall            # stop and remove it\n",[153,221,222,227,232,237,243,249],{"__ignoreMap":176},[180,223,224],{"class":182,"line":183},[180,225,226],{},"ant ui install              # install, enable, and start the service (--host, --port, --force)\n",[180,228,229],{"class":182,"line":189},[180,230,231],{},"ant ui status               # installed \u002F enabled \u002F running? (--json)\n",[180,233,234],{"class":182,"line":195},[180,235,236],{},"ant ui logs -f              # follow its logs (--lines N)\n",[180,238,240],{"class":182,"line":239},4,[180,241,242],{},"ant ui stop | start | restart\n",[180,244,246],{"class":182,"line":245},5,[180,247,248],{},"ant ui recreate             # reinstall (picks up a new host\u002Fport) and restart\n",[180,250,252],{"class":182,"line":251},6,[180,253,254],{},"ant ui uninstall            # stop and remove it\n",[150,256,257,258,261,262,265,266,269,270,273,274,277,278,281],{},"It binds where ",[153,259,260],{},"ui.host"," \u002F ",[153,263,264],{},"ui.port"," in ",[153,267,268],{},"~\u002F.ant\u002Fconfig.json"," say, loopback by\ndefault, and that is the supported mode. Binding to a non-loopback address\n(for example, to open your own dashboard from another device on your LAN) is\n",[203,271,272],{},"refused unless a password is set"," (",[153,275,276],{},"ant ui passwd","), and is then wrapped in\nHTTP Basic auth behind a signed session cookie; put TLS in front. That is a\nsafety net for your own access, not a multi-user hosting mode. See\n",[279,280,110],"a",{"href":116},".",[166,283,285],{"id":284},"pages","Pages",[287,288,289,302],"table",{},[290,291,292],"thead",{},[293,294,295,299],"tr",{},[296,297,298],"th",{},"Page",[296,300,301],{},"What it shows",[303,304,305,315,347,365,378,388,428,438],"tbody",{},[293,306,307,312],{},[308,309,310],"td",{},[203,311,30],{},[308,313,314],{},"A fleet overview: project and machine counts, recent activity, and machine metrics.",[293,316,317,322],{},[308,318,319],{},[203,320,321],{},"Projects",[308,323,324,325,328,329,328,332,328,335,328,338,328,341,328,344,281],{},"Every discovered project. A project page has tabs: ",[203,326,327],{},"General",", ",[203,330,331],{},"Environments",[203,333,334],{},"Domains",[203,336,337],{},"Deployments",[203,339,340],{},"Monitoring",[203,342,343],{},"Volumes",[203,345,346],{},"Advanced",[293,348,349,353],{},[308,350,351],{},[203,352,70],{},[308,354,355,356,328,358,360,361,364],{},"A group page with tabs: ",[203,357,321],{},[203,359,331],{}," (shared env and secrets), ",[203,362,363],{},"Network & domains"," (the shared docker network and the group's base domains).",[293,366,367,371],{},[308,368,369],{},[203,370,337],{},[308,372,373,374,377],{},"The deploy history shared with ",[153,375,376],{},"ant trail history",", filterable by project and machine.",[293,379,380,385],{},[308,381,382],{},[203,383,384],{},"Activity",[308,386,387],{},"The operations log across the fleet.",[293,389,390,395],{},[308,391,392],{},[203,393,394],{},"Nest",[308,396,397,398,400,401,404,405,408,409,412,413,416,417,420,421,273,424,427],{},"The machines ant knows about. A machine page has tabs: ",[203,399,327],{}," (host facts, the opt-in machine-wide network, and the ",[203,402,403],{},"colony users"," on that machine, roles, linked system accounts, and ownership election), ",[203,406,407],{},"Docker"," (containers with a log tail, volumes, and a prune dialog), ",[203,410,411],{},"Tools"," (inspect and install Caddy, builders, and their versions; per-tool detail), ",[203,414,415],{},"Audit"," (the tamper-evident action log), and ",[203,418,419],{},"Setup"," (the NodeID, bootstrap plan, re-provision, and state backup\u002Frestore) on a remote machine. A remote machine also offers ",[203,422,423],{},"Run image",[153,425,426],{},"ant trail deploy --image",").",[293,429,430,435],{},[308,431,432],{},[203,433,434],{},"Logs",[308,436,437],{},"Live container and build logs.",[293,439,440,445],{},[308,441,442],{},[203,443,444],{},"Settings",[308,446,447],{},"The dashboard service, your account, notifications, project directories, the config file, and this machine.",[449,450,331],"h3",{"id":451},"environments",[150,453,454,455,457,458,460,461,464,465,468],{},"The environment picker on a project page scopes the whole page to the selected\ndeployment: the run-state badge, the run\u002Fbuild\u002Fmachine badges, the image the\n",[203,456,327],{}," tab reports, and the ",[203,459,340],{}," tab (containers, logs, and the\ndisk usage of that environment's machine). A ",[153,462,463],{},"server:","\u002F",[153,466,467],{},"machine:"," deployment\nreads its containers from that machine over iroh, so a remote environment never\nborrows the local one's \"running\" state. Live log streaming is local-only; for a\nremote environment the container picker fetches the last 500 lines instead.",[449,470,334],{"id":471},"domains",[150,473,474,475,477,478,481,482,485],{},"Adding a domain on a project's ",[203,476,334],{}," tab mirrors ",[153,479,480],{},"ant nest edit domain add",". Pick a subdomain (plus a path, or a group base domain) and the port it\nroutes to; the base defaults to ",[153,483,484],{},"localhost"," for a local project, or to the\ngroup's base domains when the project belongs to a group. Domains are opt-in:\nant never adds a hostname for you.",[166,487,489],{"id":488},"cli-vs-dashboard","CLI vs. dashboard",[150,491,492,493,496],{},"The dashboard is a convenience over the CLI, not a separate control plane.\nCreate your Ant account and restore it from a bundle on ",[203,494,495],{},"Settings → Ant\naccount",". Lifecycle work is on both surfaces: deploy, build, stop, restart,\nrollback, destroy, prune, run a prebuilt image, container logs, domains, the\nmachine's audit log, and its state backup. A few actions are still CLI-only:",[498,499,500,510,523,539,556],"ul",{},[501,502,503,273,506,509],"li",{},[203,504,505],{},"Swarm",[153,507,508],{},"ant nest swarm …",") has no dashboard surface yet.",[501,511,512,515,516,519,520,281],{},[203,513,514],{},"Teardown and identity",": ",[153,517,518],{},"ant nest machines decommission"," and\n",[153,521,522],{},"ant nest identity generate",[501,524,525,515,528,328,531,534,535,538],{},[203,526,527],{},"Account portability",[153,529,530],{},"ant colony export",[153,532,533],{},"colony join",", and\n",[153,536,537],{},"colony recover"," (signup, login, profile, and logout are in Settings).",[501,540,541,544,545,547,548,551,552,555],{},[203,542,543],{},"Installing a tool"," from the ",[203,546,411],{}," tab works, but ",[153,549,550],{},"--dry-run"," and the\ngeneric ",[153,553,554],{},"ant nest tools allow-ports"," (for tools other than Caddy) stay in the\nCLI, since they need host package managers and sudo.",[501,557,558,559,561],{},"The dashboard service itself is managed with ",[153,560,155],{}," (install, passwd, logs,\nrecreate, uninstall).",[150,563,564],{},"For everything else, either surface works, and both write the same files.",[150,566,567,569,570,573,574,577,578,281],{},[203,568,105],{}," are on both surfaces: ",[153,571,572],{},"ant nest tunnel",", or the ",[203,575,576],{},"Tunnel"," action on\na running container's row on a remote machine's page. Either way the forwarding\nlistener is created on the host running it, so the local URL only resolves from\nthat machine; the dashboard deliberately does not expose the port to other\ndevices. See ",[279,579,105],{"href":106},[581,582,583],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":176,"searchDepth":189,"depth":189,"links":585},[586,587,591],{"id":168,"depth":189,"text":169},{"id":284,"depth":189,"text":285,"children":588},[589,590],{"id":451,"depth":195,"text":331},{"id":471,"depth":195,"text":334},{"id":488,"depth":189,"text":489},"The local web console: how to serve it, and what each page does.","md",null,{},{"icon":33},{"title":30,"description":598},"Ant's local web dashboard: projects, groups, nests, deployments, domains, and logs.","DCZIUM9K39EFojnQPlIOkigLVv8fbeiYTvCDp2WAKws",[601,603],{"title":25,"path":26,"stem":27,"description":602,"icon":28,"children":-1},"ant.yaml, the state under ~\u002F.ant, and what Ant writes where.",{"title":41,"path":42,"stem":43,"description":604,"icon":44,"children":-1},"The pillars, the process model, and what runs where.",1791494555767]