[{"data":1,"prerenderedAt":3318},["ShallowReactive",2],{"navigation_docs":3,"-reference-cli":144,"-reference-cli-surround":3313},[4,35,84,109,124,134,139],{"title":5,"path":6,"stem":7,"children":8,"page":34},"Get Started","\u002Fget-started","1.get-started",[9,14,19,24,29],{"title":10,"path":11,"stem":12,"icon":13},"Introduction","\u002Fget-started\u002Fintroduction","1.get-started\u002F1.introduction","i-lucide-house",{"title":15,"path":16,"stem":17,"icon":18},"Installation","\u002Fget-started\u002Finstallation","1.get-started\u002F2.installation","i-lucide-download",{"title":20,"path":21,"stem":22,"icon":23},"Quick start","\u002Fget-started\u002Fquickstart","1.get-started\u002F3.quickstart","i-lucide-rocket",{"title":25,"path":26,"stem":27,"icon":28},"Project structure","\u002Fget-started\u002Fproject-structure","1.get-started\u002F4.project-structure","i-lucide-folder-tree",{"title":30,"path":31,"stem":32,"icon":33},"Dashboard","\u002Fget-started\u002Fdashboard","1.get-started\u002F5.dashboard","i-lucide-layout-dashboard",false,{"title":36,"path":37,"stem":38,"children":39,"page":34},"Concepts","\u002Fconcepts","2.concepts",[40,45,50,55,60,65,69,74,79],{"title":41,"path":42,"stem":43,"icon":44},"Architecture","\u002Fconcepts\u002Farchitecture","2.concepts\u002F1.architecture","i-lucide-layers",{"title":46,"path":47,"stem":48,"icon":49},"Machines","\u002Fconcepts\u002Fmachines","2.concepts\u002F2.machines","i-lucide-server",{"title":51,"path":52,"stem":53,"icon":54},"Colony & users","\u002Fconcepts\u002Fcolony","2.concepts\u002F3.colony","i-lucide-users",{"title":56,"path":57,"stem":58,"icon":59},"Transport","\u002Fconcepts\u002Ftransport","2.concepts\u002F4.transport","i-lucide-network",{"title":61,"path":62,"stem":63,"icon":64},"Configuration","\u002Fconcepts\u002Fconfiguration","2.concepts\u002F5.configuration","i-lucide-settings",{"title":66,"path":67,"stem":68,"icon":23},"Deploy","\u002Fconcepts\u002Fdeploy","2.concepts\u002F6.deploy",{"title":70,"path":71,"stem":72,"icon":73},"Groups","\u002Fconcepts\u002Fgroups","2.concepts\u002F7.groups","i-lucide-boxes",{"title":75,"path":76,"stem":77,"icon":78},"Templates","\u002Fconcepts\u002Ftemplates","2.concepts\u002F8.templates","i-lucide-package-plus",{"title":80,"path":81,"stem":82,"icon":83},"Existing projects","\u002Fconcepts\u002Fexisting-projects","2.concepts\u002F9.existing-projects","i-lucide-folder-open",{"title":85,"path":86,"stem":87,"children":88,"page":34},"Remote","\u002Fremote","3.remote",[89,94,99,104],{"title":90,"path":91,"stem":92,"icon":93},"Remote machines","\u002Fremote\u002Foverview","3.remote\u002F1.overview","i-lucide-cloud",{"title":95,"path":96,"stem":97,"icon":98},"Remote deploy","\u002Fremote\u002Fdeploy","3.remote\u002F2.deploy","i-lucide-send",{"title":100,"path":101,"stem":102,"icon":103},"CI","\u002Fremote\u002Fci","3.remote\u002F3.ci","i-lucide-workflow",{"title":105,"path":106,"stem":107,"icon":108},"Tunnels","\u002Fremote\u002Ftunnel","3.remote\u002F4.tunnel","i-lucide-cable",{"title":110,"path":111,"stem":112,"children":113,"page":34},"Security","\u002Fsecurity","4.security",[114,119],{"title":115,"path":116,"stem":117,"icon":118},"Security model","\u002Fsecurity\u002Fmodel","4.security\u002F1.model","i-lucide-shield",{"title":120,"path":121,"stem":122,"icon":123},"Known issues","\u002Fsecurity\u002Fknown-issues","4.security\u002F2.known-issues","i-lucide-triangle-alert",{"title":125,"path":126,"stem":127,"children":128,"page":34},"Reference","\u002Freference","5.reference",[129],{"title":130,"path":131,"stem":132,"icon":133},"CLI reference","\u002Freference\u002Fcli","5.reference\u002F1.cli","i-lucide-terminal",{"title":135,"path":136,"stem":137,"icon":138},"Changelog","\u002Fchangelog","changelog","i-lucide-history",{"title":140,"path":141,"stem":142,"icon":143},"Communities","\u002Fcommunities","communities","i-lucide-heart-handshake",{"id":145,"title":130,"body":146,"description":3305,"extension":3306,"links":3307,"meta":3308,"navigation":3309,"path":131,"seo":3310,"stem":132,"__hash__":3312},"docs\u002F5.reference\u002F1.cli.md",{"type":147,"value":148,"toc":3274},"minimark",[149,195,230,233,262,267,278,390,404,410,430,447,457,463,549,552,799,836,896,902,913,952,958,967,1041,1158,1160,1560,1570,1575,1620,1638,1647,1653,1665,1667,1673,1698,1715,1777,1790,1805,1820,1822,1897,1924,1976,1978,2003,2048,2052,2074,2077,2081,2090,2105,2132,2140,2160,2186,2217,2237,2239,2248,2451,2454,2494,2519,2522,2537,2563,2598,2601,2625,2627,2667,2684,2707,2709,2739,2749,2753,2778,2802,2804,2813,2853,2878,2884,2944,3002,3044,3054,3061,3076,3080,3091,3115,3120,3165,3185,3189,3192,3263,3267,3270],[150,151,152,153,157,158,162,163,166,167,169,170,173,174,169,177,180,181,169,184,187,188,169,191,194],"p",{},"The CLI is a single binary, ",[154,155,156],"code",{},"ant",". Five groups cover the surface: ",[159,160,161],"strong",{},"Build","\n(",[154,164,165],{},"ant haul","), ",[159,168,66],{}," (",[154,171,172],{},"ant trail","), the ",[159,175,176],{},"machine layer",[154,178,179],{},"ant nest","),\n",[159,182,183],{},"Collab",[154,185,186],{},"ant colony","), and the ",[159,189,190],{},"dashboard service",[154,192,193],{},"ant ui",").",[150,196,197,198,201,202,205,206,209,210,205,212,215,216,205,219,209,222,205,224,209,227,229],{},"The obvious verbs are aliases for the group paths, so a first guess works:\n",[154,199,200],{},"ant deploy|logs|status|down|restart|destroy|rollback|history|prune"," →\n",[154,203,204],{},"ant trail …","; ",[154,207,208],{},"ant build"," → ",[154,211,165],{},[154,213,214],{},"ant init|new|edit|machines|tools|templates|identity|groups","\n→ ",[154,217,218],{},"ant nest …",[154,220,221],{},"ant account",[154,223,186],{},[154,225,226],{},"ant dashboard",[154,228,193],{},".",[150,231,232],{},"Shell completion is available for every shell Cobra supports:",[234,235,240],"pre",{"className":236,"code":237,"language":238,"meta":239,"style":239},"language-sh shiki shiki-themes material-theme-lighter github-light github-dark","ant completion bash > \u002Fetc\u002Fbash_completion.d\u002Fant\nant completion zsh  > \"${fpath[1]}\u002F_ant\"\nant completion fish > ~\u002F.config\u002Ffish\u002Fcompletions\u002Fant.fish\n","sh","",[154,241,242,250,256],{"__ignoreMap":239},[243,244,247],"span",{"class":245,"line":246},"line",1,[243,248,249],{},"ant completion bash > \u002Fetc\u002Fbash_completion.d\u002Fant\n",[243,251,253],{"class":245,"line":252},2,[243,254,255],{},"ant completion zsh  > \"${fpath[1]}\u002F_ant\"\n",[243,257,259],{"class":245,"line":258},3,[243,260,261],{},"ant completion fish > ~\u002F.config\u002Ffish\u002Fcompletions\u002Fant.fish\n",[263,264,266],"h2",{"id":265},"global-flags","Global flags",[150,268,269,270,273,274,277],{},"These are accepted by every command (persistent flags on the root; ",[154,271,272],{},"--config","\nis added to each command that reads ",[154,275,276],{},"ant.yaml","):",[279,280,281,294],"table",{},[282,283,284],"thead",{},[285,286,287,291],"tr",{},[288,289,290],"th",{},"Flag",[288,292,293],{},"Effect",[295,296,297,316,332,346,360,373],"tbody",{},[285,298,299,305],{},[300,301,302],"td",{},[154,303,304],{},"--machine \u003Cid>",[300,306,307,308,311,312,315],{},"Operate on another machine (default ",[154,309,310],{},"local","). Honoured by machine-scoped commands; commands that only act on this host fail fast when it targets a remote, and the machine registry ignores it. ",[154,313,314],{},"ANT_MACHINE"," is the environment fallback, so a CI pipeline can set the target once.",[285,317,318,323],{},[300,319,320],{},[154,321,322],{},"--config \u003Cpath>",[300,324,325,326,328,329,331],{},"Path to ",[154,327,276],{}," (default ",[154,330,276],{},"). On commands that read a project config.",[285,333,334,339],{},[300,335,336],{},[154,337,338],{},"--verbose",[300,340,341,342,345],{},"Echo each child command (",[154,343,344],{},"$ docker compose … build",") before running it",[285,347,348,357],{},[300,349,350,353,354],{},[154,351,352],{},"-q",", ",[154,355,356],{},"--quiet",[300,358,359],{},"Suppress progress and build output; only results print",[285,361,362,370],{},[300,363,364,353,367],{},[154,365,366],{},"-h",[154,368,369],{},"--help",[300,371,372],{},"Help for the command",[285,374,375,387],{},[300,376,377,353,380,383,384],{},[154,378,379],{},"-v",[154,381,382],{},"--version"," (root) or ",[154,385,386],{},"ant version",[300,388,389],{},"Print the CLI version",[150,391,392,393,396,397,400,401,403],{},"Commands that report data also take ",[154,394,395],{},"--json",". Build output streams to\n",[159,398,399],{},"stderr",", so ",[154,402,395],{}," output on stdout stays machine-readable.",[263,405,407,409],{"id":406},"ant-haul-build",[154,408,165],{},", build",[234,411,413],{"className":236,"code":412,"language":238,"meta":239,"style":239},"ant haul                          # build for deployment \"local\"\nant haul dev\nant haul --release 20260101T120000Z\n",[154,414,415,420,425],{"__ignoreMap":239},[243,416,417],{"class":245,"line":246},[243,418,419],{},"ant haul                          # build for deployment \"local\"\n",[243,421,422],{"class":245,"line":252},[243,423,424],{},"ant haul dev\n",[243,426,427],{"class":245,"line":258},[243,428,429],{},"ant haul --release 20260101T120000Z\n",[150,431,432,433,436,437,440,441,444,445,229],{},"Flags: ",[154,434,435],{},"--release \u003Cid>"," (build tag, default a UTC timestamp), ",[154,438,439],{},"--push"," (build here and push to ",[154,442,443],{},"deploy.registry"," without deploying, the split-pipeline form for CI), ",[154,446,272],{},[150,448,449,450,453,454,456],{},"Builds the image without running it (",[154,451,452],{},"build: none"," is rejected). A project that\nnames a machine builds on that machine; compose projects build here, where the\nsource is. ",[154,455,439],{}," always builds here and supports container projects only.",[263,458,460,462],{"id":459},"ant-trail-deploy-and-manage",[154,461,172],{},", deploy and manage",[234,464,466],{"className":236,"code":465,"language":238,"meta":239,"style":239},"ant trail deploy                  [deployment] [--no-caddy] [--release ID]\nant trail deploy --image REF      [--from-tar F | --pull] [--port P] [--domain D]... [--machine M]\nant trail logs                    [deployment] [service] [-f] [--tail N]\nant trail status                  [deployment] [--json] [--machine M]\nant trail restart                 [deployment]\nant trail down                    [deployment]\nant trail destroy                 [deployment] --yes [--keep-images] [--machine M]\nant trail exec                    [deployment] -- \u003Ccommand> [args...]   [--service NAME]\nant trail env                     [deployment]\nant trail doctor                  [deployment]\nant trail prune                   [--all] [--images] [--dangling] [--cache] [--volumes] [--stopped] [--dry-run] [--yes]\nant trail history                 [--project P] [--machine M] [--limit N] [--json]\nant trail history --clear         [--project P] [--yes]\nant trail rollback                [deployment] [--to RELEASE] [--steps N]\n",[154,467,468,473,478,483,489,495,501,507,513,519,525,531,537,543],{"__ignoreMap":239},[243,469,470],{"class":245,"line":246},[243,471,472],{},"ant trail deploy                  [deployment] [--no-caddy] [--release ID]\n",[243,474,475],{"class":245,"line":252},[243,476,477],{},"ant trail deploy --image REF      [--from-tar F | --pull] [--port P] [--domain D]... [--machine M]\n",[243,479,480],{"class":245,"line":258},[243,481,482],{},"ant trail logs                    [deployment] [service] [-f] [--tail N]\n",[243,484,486],{"class":245,"line":485},4,[243,487,488],{},"ant trail status                  [deployment] [--json] [--machine M]\n",[243,490,492],{"class":245,"line":491},5,[243,493,494],{},"ant trail restart                 [deployment]\n",[243,496,498],{"class":245,"line":497},6,[243,499,500],{},"ant trail down                    [deployment]\n",[243,502,504],{"class":245,"line":503},7,[243,505,506],{},"ant trail destroy                 [deployment] --yes [--keep-images] [--machine M]\n",[243,508,510],{"class":245,"line":509},8,[243,511,512],{},"ant trail exec                    [deployment] -- \u003Ccommand> [args...]   [--service NAME]\n",[243,514,516],{"class":245,"line":515},9,[243,517,518],{},"ant trail env                     [deployment]\n",[243,520,522],{"class":245,"line":521},10,[243,523,524],{},"ant trail doctor                  [deployment]\n",[243,526,528],{"class":245,"line":527},11,[243,529,530],{},"ant trail prune                   [--all] [--images] [--dangling] [--cache] [--volumes] [--stopped] [--dry-run] [--yes]\n",[243,532,534],{"class":245,"line":533},12,[243,535,536],{},"ant trail history                 [--project P] [--machine M] [--limit N] [--json]\n",[243,538,540],{"class":245,"line":539},13,[243,541,542],{},"ant trail history --clear         [--project P] [--yes]\n",[243,544,546],{"class":245,"line":545},14,[243,547,548],{},"ant trail rollback                [deployment] [--to RELEASE] [--steps N]\n",[150,550,551],{},"Flags by command:",[279,553,554,564],{},[282,555,556],{},[285,557,558,561],{},[288,559,560],{},"Command",[288,562,563],{},"Flags",[295,565,566,585,638,657,668,681,697,755,781],{},[285,567,568,573],{},[300,569,570],{},[154,571,572],{},"deploy [deployment]",[300,574,575,353,578,353,580,353,583],{},[154,576,577],{},"--no-caddy",[154,579,435],{},[154,581,582],{},"--deploy-timeout \u003Cd>",[154,584,395],{},[285,586,587,592],{},[300,588,589],{},[154,590,591],{},"deploy --image REF",[300,593,594,353,597,353,600,353,603,353,606,353,609,353,612,615,616,615,619,353,622,328,625,166,628,353,631,328,634,637],{},[154,595,596],{},"--image",[154,598,599],{},"--app",[154,601,602],{},"--name",[154,604,605],{},"--from-tar \u003Cfile>",[154,607,608],{},"--pull",[154,610,611],{},"--port \u003Cn>",[154,613,614],{},"--env KEY=VALUE"," (repeatable), ",[154,617,618],{},"--domain D",[154,620,621],{},"--network",[154,623,624],{},"--restart",[154,626,627],{},"unless-stopped",[154,629,630],{},"--publish-all",[154,632,633],{},"--timeout",[154,635,636],{},"5m",")",[285,639,640,645],{},[300,641,642],{},[154,643,644],{},"logs [deployment] [service]",[300,646,647,650,651,353,654],{},[154,648,649],{},"-f","\u002F",[154,652,653],{},"--follow",[154,655,656],{},"--tail \u003Cn>",[285,658,659,664],{},[300,660,661],{},[154,662,663],{},"status [deployment]",[300,665,666],{},[154,667,395],{},[285,669,670,675],{},[300,671,672],{},[154,673,674],{},"exec [deployment] -- cmd",[300,676,677,680],{},[154,678,679],{},"--service \u003Cname>"," (compose only); local deployments only",[285,682,683,688],{},[300,684,685],{},[154,686,687],{},"destroy [deployment]",[300,689,690,353,693,696],{},[154,691,692],{},"--yes",[154,694,695],{},"--keep-images","; on a machine it removes the workload (container\u002Fcompose\u002Fstack) and its domains, leaving the machine's images for cache",[285,698,699,704],{},[300,700,701],{},[154,702,703],{},"prune",[300,705,706,709,710,650,713,353,716,650,719,353,722,650,725,353,728,650,731,353,734,650,737,205,740,353,742,328,745,166,747,353,750,353,753],{},[154,707,708],{},"--all","; per-category ",[154,711,712],{},"--images",[154,714,715],{},"--skip-images",[154,717,718],{},"--dangling",[154,720,721],{},"--skip-dangling",[154,723,724],{},"--cache",[154,726,727],{},"--skip-cache",[154,729,730],{},"--volumes",[154,732,733],{},"--skip-volumes",[154,735,736],{},"--stopped",[154,738,739],{},"--skip-stopped",[154,741,599],{},[154,743,744],{},"--deployment",[154,746,310],{},[154,748,749],{},"--keep-images \u003Cn>",[154,751,752],{},"--dry-run",[154,754,692],{},[285,756,757,762],{},[300,758,759],{},[154,760,761],{},"history",[300,763,764,353,767,353,770,773,774,353,776,353,779],{},[154,765,766],{},"--project",[154,768,769],{},"--machine",[154,771,772],{},"--limit"," (default 20), ",[154,775,395],{},[154,777,778],{},"--clear",[154,780,692],{},[285,782,783,788],{},[300,784,785],{},[154,786,787],{},"rollback [deployment]",[300,789,790,353,793,796,797],{},[154,791,792],{},"--to \u003Crelease-or-image>",[154,794,795],{},"--steps \u003Cn>"," (default 1), ",[154,798,395],{},[150,800,801,802,805,806,808,809,812,813,816,817,820,821,824,825,828,829,832,833,835],{},"A ",[154,803,804],{},"machine:"," field in ",[154,807,276],{}," makes ",[154,810,811],{},"deploy"," remote: the client packages the\nbuild context (honouring ",[154,814,815],{},".dockerignore","), the machine builds the image there,\nruns it, and programs the machine's Caddy, which is ",[159,818,819],{},"required"," on a remote\nnest. No image is transferred for a project deploy; ",[154,822,823],{},"ant trail deploy --image"," is\nthe low-level form for running a pre-built image (",[154,826,827],{},"--from-tar"," uploads a\n",[154,830,831],{},"docker save"," archive, ",[154,834,608],{}," fetches from a registry).",[150,837,838,839,842,843,846,847,850,851,854,855,858,859,353,862,865,866,868,869,872,873,876,877,880,881,883,884,887,888,891,892,895],{},"On a machine, a deploy stages the new container (ephemeral ports, read-only\nmounts only), waits for the configured ",[154,840,841],{},"health_check",", and only then swaps: a bad\nbuild does not take the running container down. A deploy whose mounts are\nwritable (a live data volume or a bind the app needs to boot) cannot be staged\nsafely and is replaced in place instead. Remote deploys default to\n",[154,844,845],{},"restart: unless-stopped",", apply log rotation and resource limits even when\nunset, and prune superseded image tags to ",[154,848,849],{},"deploy.keep_images"," (or\n",[154,852,853],{},"rollback.keep_releases","). Concurrent deploys on a machine are serialized.\n",[154,856,857],{},"ant trail logs"," fetches a tail snapshot from the machine (",[154,860,861],{},"--tail N",[154,863,864],{},"all",");\n",[154,867,649],{}," is local-only. Compose projects build each ",[154,870,871],{},"build:"," service on the machine\nand run the rest from images. ",[154,874,875],{},"run: stack"," deploys the raw stack file on a Swarm\nmanager, routes domains at each service's published port, and maps\n",[154,878,879],{},"zero_downtime"," to a Swarm start-first rolling update; its services need\npullable images (",[154,882,871],{}," is refused). Stack tasks carry ant's managed\u002Fapp\nlabels, so they appear in ",[154,885,886],{},"ant nest containers list"," and ",[154,889,890],{},"ant trail status",", and\n",[154,893,894],{},"ant trail logs \u003Cdeployment> [service]"," reads one task's logs (name the service\nwhen the stack has several).",[150,897,898,901],{},[154,899,900],{},"ant trail destroy --machine M"," stops and removes the deployment's workload on\nthe machine and clears its Caddy routes; the machine's images are left in place.",[150,903,904,905,908,909,912],{},"Running this from a CI pipeline? See ",[906,907,100],"a",{"href":101}," for a ",[154,910,911],{},"ci","-role setup and\nready-made GitHub Actions\u002FGitLab jobs.",[150,914,915,918,919,922,923,926,927,930,931,926,934,937,938,941,942,945,946,948,949,951],{},[154,916,917],{},"ant trail history"," reads the deploy log shared by the CLI and the dashboard.\n",[154,920,921],{},"ant trail rollback"," redeploys a previously released image without rebuilding\n(the previous release by default, or ",[154,924,925],{},"--to RELEASE"," \u002F ",[154,928,929],{},"--steps N","), running the\noptional ",[154,932,933],{},"rollback.pre_hook",[154,935,936],{},"rollback.post_hook",". It records a ",[154,939,940],{},"rollback","\nentry (which does not shift the deploy sequence) and refuses compose and stack\nprojects, their release is several images (compose) or a file that names them\n(stack), so redeploy those with an explicit ",[154,943,944],{},"--release"," or a pinned image. The\nrelease's image tag must still exist on the target, which ",[154,947,849],{},"\n\u002F ",[154,950,853],{}," control.",[263,953,955,957],{"id":954},"ant-nest-machines-tools-scaffolding",[154,956,179],{},", machines, tools, scaffolding",[150,959,960,961,963,964,966],{},"Bare ",[154,962,179],{}," reports this machine's host facts, live usage, containers, and\ndisk (",[154,965,395],{}," for machine-readable output). Its subcommands are grouped by\npillar:",[968,969,970,989,996],"ul",{},[971,972,973,976,977,353,980,353,983,353,986],"li",{},[159,974,975],{},"Project",": ",[154,978,979],{},"init",[154,981,982],{},"new",[154,984,985],{},"edit",[154,987,988],{},"templates",[971,990,991,976,993],{},[159,992,70],{},[154,994,995],{},"groups",[971,997,998,976,1001,353,1004,353,1007,353,1010,353,1013,1016,1017,353,1020,353,1023,353,1026,353,1029,353,1032,353,1035,1016,1038],{},[159,999,1000],{},"Machine",[154,1002,1003],{},"machines",[154,1005,1006],{},"identity",[154,1008,1009],{},"tools",[154,1011,1012],{},"swarm",[154,1014,1015],{},"bootstrap",",\n",[154,1018,1019],{},"reconcile",[154,1021,1022],{},"doctor",[154,1024,1025],{},"ping",[154,1027,1028],{},"tunnel",[154,1030,1031],{},"audit",[154,1033,1034],{},"state",[154,1036,1037],{},"containers",[154,1039,1040],{},"volume",[234,1042,1044],{"className":236,"code":1043,"language":238,"meta":239,"style":239},"ant nest init                     [--port N] [--build X] [--run X] [--file F] [--target-machine M]\nant nest new                      TEMPLATE [DIR] [--app A] [--var K=V]... [--group G] [--target-machine M]\nant nest templates                list | search [QUERY] | show TEMPLATE [--json] | add ID | sync\nant nest edit                     file | env | secret | domain | deploy | deployment | volume | network | group\nant nest machines                 list | add NAME [--host H --ssh…] | remove NAME | decommission NAME --host H [--purge] [--handover] --yes | network M\nant nest identity                 show | generate [--force]\nant nest swarm                    status | init [--advertise-addr A] | leave [--force]\nant nest tools                    [--json] | install [tool...] [--dry-run] [--yes] | allow-ports [tool...] [--yes]\nant nest tools TOOL               status [--json]\n                                  # TOOL: docker, caddy, nixpacks, pack, railpack\nant nest tools caddy              status [--json] | restart | stop\nant nest bootstrap                [--machine M] [--docker-mode MODE] [--host H --ssh… | --cloud-init --worker-url URL]\nant nest reconcile                [--apply --state F --yes]\nant nest doctor                   [--machine M] [--cleanup]\nant nest ping                     [machine] [--timeout 20s]\nant nest tunnel                   --machine M --container NAME --port P [--local L]\nant nest audit                    [--limit N] [--json]\nant nest state                    export [--out F] | import [--file F] [--force]\nant nest containers               list [--json] | start NAME | stop NAME | restart NAME | rm NAME --yes\nant nest volume                   list [--json] [--all] | rm NAME [--force] [--all] [--yes]\nant nest groups                   list | create | domains | network | add | remove | rename | delete\n",[154,1045,1046,1051,1056,1061,1066,1071,1076,1081,1086,1091,1096,1101,1106,1111,1116,1122,1128,1134,1140,1146,1152],{"__ignoreMap":239},[243,1047,1048],{"class":245,"line":246},[243,1049,1050],{},"ant nest init                     [--port N] [--build X] [--run X] [--file F] [--target-machine M]\n",[243,1052,1053],{"class":245,"line":252},[243,1054,1055],{},"ant nest new                      TEMPLATE [DIR] [--app A] [--var K=V]... [--group G] [--target-machine M]\n",[243,1057,1058],{"class":245,"line":258},[243,1059,1060],{},"ant nest templates                list | search [QUERY] | show TEMPLATE [--json] | add ID | sync\n",[243,1062,1063],{"class":245,"line":485},[243,1064,1065],{},"ant nest edit                     file | env | secret | domain | deploy | deployment | volume | network | group\n",[243,1067,1068],{"class":245,"line":491},[243,1069,1070],{},"ant nest machines                 list | add NAME [--host H --ssh…] | remove NAME | decommission NAME --host H [--purge] [--handover] --yes | network M\n",[243,1072,1073],{"class":245,"line":497},[243,1074,1075],{},"ant nest identity                 show | generate [--force]\n",[243,1077,1078],{"class":245,"line":503},[243,1079,1080],{},"ant nest swarm                    status | init [--advertise-addr A] | leave [--force]\n",[243,1082,1083],{"class":245,"line":509},[243,1084,1085],{},"ant nest tools                    [--json] | install [tool...] [--dry-run] [--yes] | allow-ports [tool...] [--yes]\n",[243,1087,1088],{"class":245,"line":515},[243,1089,1090],{},"ant nest tools TOOL               status [--json]\n",[243,1092,1093],{"class":245,"line":521},[243,1094,1095],{},"                                  # TOOL: docker, caddy, nixpacks, pack, railpack\n",[243,1097,1098],{"class":245,"line":527},[243,1099,1100],{},"ant nest tools caddy              status [--json] | restart | stop\n",[243,1102,1103],{"class":245,"line":533},[243,1104,1105],{},"ant nest bootstrap                [--machine M] [--docker-mode MODE] [--host H --ssh… | --cloud-init --worker-url URL]\n",[243,1107,1108],{"class":245,"line":539},[243,1109,1110],{},"ant nest reconcile                [--apply --state F --yes]\n",[243,1112,1113],{"class":245,"line":545},[243,1114,1115],{},"ant nest doctor                   [--machine M] [--cleanup]\n",[243,1117,1119],{"class":245,"line":1118},15,[243,1120,1121],{},"ant nest ping                     [machine] [--timeout 20s]\n",[243,1123,1125],{"class":245,"line":1124},16,[243,1126,1127],{},"ant nest tunnel                   --machine M --container NAME --port P [--local L]\n",[243,1129,1131],{"class":245,"line":1130},17,[243,1132,1133],{},"ant nest audit                    [--limit N] [--json]\n",[243,1135,1137],{"class":245,"line":1136},18,[243,1138,1139],{},"ant nest state                    export [--out F] | import [--file F] [--force]\n",[243,1141,1143],{"class":245,"line":1142},19,[243,1144,1145],{},"ant nest containers               list [--json] | start NAME | stop NAME | restart NAME | rm NAME --yes\n",[243,1147,1149],{"class":245,"line":1148},20,[243,1150,1151],{},"ant nest volume                   list [--json] [--all] | rm NAME [--force] [--all] [--yes]\n",[243,1153,1155],{"class":245,"line":1154},21,[243,1156,1157],{},"ant nest groups                   list | create | domains | network | add | remove | rename | delete\n",[150,1159,551],{},[279,1161,1162,1170],{},[282,1163,1164],{},[285,1165,1166,1168],{},[288,1167,560],{},[288,1169,563],{},[295,1171,1172,1206,1228,1239,1260,1271,1281,1302,1349,1377,1399,1410,1423,1434,1445,1457,1492,1504,1521,1534,1546],{},[285,1173,1174,1178],{},[300,1175,1176],{},[154,1177,979],{},[300,1179,1180,353,1182,353,1185,353,1188,353,1191,353,1194,353,1197,353,1200,353,1203],{},[154,1181,599],{},[154,1183,1184],{},"--build",[154,1186,1187],{},"--run",[154,1189,1190],{},"--file",[154,1192,1193],{},"--port",[154,1195,1196],{},"--group",[154,1198,1199],{},"--target-machine",[154,1201,1202],{},"--output",[154,1204,1205],{},"--force",[285,1207,1208,1213],{},[300,1209,1210],{},[154,1211,1212],{},"new TEMPLATE [DIR]",[300,1214,1215,353,1217,615,1220,353,1222,353,1224,353,1226],{},[154,1216,599],{},[154,1218,1219],{},"--var KEY=VALUE",[154,1221,1196],{},[154,1223,1199],{},[154,1225,1205],{},[154,1227,395],{},[285,1229,1230,1235],{},[300,1231,1232],{},[154,1233,1234],{},"templates list",[300,1236,1237],{},[154,1238,395],{},[285,1240,1241,1246],{},[300,1242,1243],{},[154,1244,1245],{},"templates search [QUERY]",[300,1247,1248,615,1251,353,1254,1257,1258],{},[154,1249,1250],{},"--tag T",[154,1252,1253],{},"--refresh",[154,1255,1256],{},"--limit N"," (default 25), ",[154,1259,395],{},[285,1261,1262,1267],{},[300,1263,1264],{},[154,1265,1266],{},"templates show TEMPLATE",[300,1268,1269],{},[154,1270,395],{},[285,1272,1273,1278],{},[300,1274,1275],{},[154,1276,1277],{},"templates add ID",[300,1279,1280],{},"-",[285,1282,1283,1288],{},[300,1284,1285],{},[154,1286,1287],{},"templates sync",[300,1289,1290,353,1293,328,1296,166,1299],{},[154,1291,1292],{},"--repo URL",[154,1294,1295],{},"--ref R",[154,1297,1298],{},"canary",[154,1300,1301],{},"--dir D",[285,1303,1304,1309],{},[300,1305,1306],{},[154,1307,1308],{},"machines add NAME",[300,1310,1311,353,1314,353,1317,353,1320,353,1323,353,1326,353,1329,353,1332,650,1335,353,1338,353,1341,353,1344,353,1346],{},[154,1312,1313],{},"--id",[154,1315,1316],{},"--hostname",[154,1318,1319],{},"--node-id",[154,1321,1322],{},"--host",[154,1324,1325],{},"--ssh-user",[154,1327,1328],{},"--ssh-port",[154,1330,1331],{},"--ssh-key",[154,1333,1334],{},"--ssh-password",[154,1336,1337],{},"--ssh-password-stdin",[154,1339,1340],{},"--worker-bin",[154,1342,1343],{},"--docker-mode",[154,1345,577],{},[154,1347,1348],{},"--no-caddy-check",[285,1350,1351,1356],{},[300,1352,1353],{},[154,1354,1355],{},"machines decommission NAME",[300,1357,1358,353,1360,353,1363,353,1366,353,1369,353,1372,353,1375],{},[154,1359,1322],{},[154,1361,1362],{},"--ssh-*",[154,1364,1365],{},"--purge",[154,1367,1368],{},"--handover",[154,1370,1371],{},"--keep-record",[154,1373,1374],{},"--keep-identity",[154,1376,692],{},[285,1378,1379,1384],{},[300,1380,1381],{},[154,1382,1383],{},"machines network MACHINE",[300,1385,1386,353,1388,353,1391,353,1394,353,1397],{},[154,1387,602],{},[154,1389,1390],{},"--driver",[154,1392,1393],{},"--subnet",[154,1395,1396],{},"--external",[154,1398,778],{},[285,1400,1401,1406],{},[300,1402,1403],{},[154,1404,1405],{},"identity generate",[300,1407,1408],{},[154,1409,1205],{},[285,1411,1412,1417],{},[300,1413,1414],{},[154,1415,1416],{},"tools install",[300,1418,1419,353,1421],{},[154,1420,752],{},[154,1422,692],{},[285,1424,1425,1430],{},[300,1426,1427],{},[154,1428,1429],{},"tools allow-ports",[300,1431,1432],{},[154,1433,692],{},[285,1435,1436,1441],{},[300,1437,1438],{},[154,1439,1440],{},"tools \u003Ctool> status",[300,1442,1443],{},[154,1444,395],{},[285,1446,1447,1455],{},[300,1448,1449,926,1452],{},[154,1450,1451],{},"tools caddy restart",[154,1453,1454],{},"stop",[300,1456,1280],{},[285,1458,1459,1463],{},[300,1460,1461],{},[154,1462,1015],{},[300,1464,1465,353,1467,353,1469,353,1471,353,1473,353,1475,650,1477,353,1479,353,1481,353,1484,1487,1488,166,1490],{},[154,1466,1343],{},[154,1468,1322],{},[154,1470,1325],{},[154,1472,1328],{},[154,1474,1331],{},[154,1476,1334],{},[154,1478,1337],{},[154,1480,1340],{},[154,1482,1483],{},"--cloud-init",[154,1485,1486],{},"--worker-url"," (required with ",[154,1489,1483],{},[154,1491,577],{},[285,1493,1494,1499],{},[300,1495,1496],{},[154,1497,1498],{},"ping [machine]",[300,1500,1501,1503],{},[154,1502,633],{}," (default 20s)",[285,1505,1506,1510],{},[300,1507,1508],{},[154,1509,1028],{},[300,1511,1512,1515,1516,1515,1518],{},[154,1513,1514],{},"--container"," (required), ",[154,1517,1193],{},[154,1519,1520],{},"--local",[285,1522,1523,1527],{},[300,1524,1525],{},[154,1526,1031],{},[300,1528,1529,1531,1532],{},[154,1530,1256],{}," (default 50), ",[154,1533,395],{},[285,1535,1536,1541],{},[300,1537,1538],{},[154,1539,1540],{},"state export",[300,1542,1543],{},[154,1544,1545],{},"--out F",[285,1547,1548,1553],{},[300,1549,1550],{},[154,1551,1552],{},"state import",[300,1554,1555,353,1558],{},[154,1556,1557],{},"--file F",[154,1559,1205],{},[150,1561,1562,1565,1566,1569],{},[154,1563,1564],{},"ant nest tools"," is the tool surface (",[154,1567,1568],{},"ant forage"," was retired).",[1571,1572,1574],"h3",{"id":1573},"project-templates","Project templates",[150,1576,1577,1580,1581,1584,1585,1588,1589,1592,1593,169,1596,1599,1600,1603,1604,1606,1607,1610,1611,205,1614,1617,1618,229],{},[154,1578,1579],{},"ant nest new TEMPLATE [DIR]"," creates a project from the catalog: it renders\nthe template's files, writes generated secrets to ",[154,1582,1583],{},".env"," (0600, gitignored),\nwrites ",[154,1586,1587],{},"kind: database"," for database templates, and registers the project for\ndiscovery. Without ",[154,1590,1591],{},"DIR"," it uses ",[154,1594,1595],{},"~\u002F.ant-apps\u002F\u003Capp>",[154,1597,1598],{},"\u002Fetc\u002Fant\u002Fapps\u002F\u003Capp>"," as\nroot; override with ",[154,1601,1602],{},"ANT_APPS_DIR","). ",[154,1605,1219],{}," sets a template variable,\nshown by ",[154,1608,1609],{},"ant nest templates show",". The catalog is the Dokploy blueprints\nimported by ",[154,1612,1613],{},"ant nest templates sync",[154,1615,1616],{},"~\u002F.ant\u002Ftemplates\u002F\u003Cid>"," overrides an\nimported template with the same id. See ",[906,1619,75],{"href":76},[150,1621,1622,1625,1626,1628,1629,1632,1633,1635,1636,229],{},[154,1623,1624],{},"ant nest identity"," manages a machine's iroh NodeID (the key it is dialed by).\n",[154,1627,823],{}," is the low-level form for running one image on a\nmachine; for a project-driven deploy that builds first, use ",[154,1630,1631],{},"ant trail deploy","\nwith ",[154,1634,804],{}," set in ",[154,1637,276],{},[150,1639,1640,1643,1644,1646],{},[154,1641,1642],{},"ant nest tunnel"," forwards a local TCP port to a container port on a machine\nover iroh, so a loopback-bound service can be reached with no inbound port on\neither side. The worker only reaches ports ant published on the machine's\nloopback for a container it manages, see ",[906,1645,105],{"href":106}," for the\ndirection, the dashboard's equivalent, and troubleshooting.",[150,1648,1649,1652],{},[154,1650,1651],{},"ant nest audit"," shows the machine's tamper-evident action log: every privileged\nRPC (deploy, route, roster, volume, tunnel) is recorded with a hash chain, so a\nremoved or edited line fails verification. The log rotates at 8 MiB and reading\nit requires the admin role.",[150,1654,1655,1658,1659,1661,1662,229],{},[154,1656,1657],{},"ant nest state export|import"," backs up and restores a machine's daemon state\n(the roster and invites). Import is owner-only, refuses a document with no users\nunless ",[154,1660,1205],{}," is given, and keeps the previous file as\n",[154,1663,1664],{},"agent-state.json.bak",[1571,1666,1003],{"id":1003},[150,1668,1669,1672],{},[154,1670,1671],{},"ant nest machines add"," registers a nest. A machine is dialed by NodeID, so if\nyou only have an address, provision it over SSH in one step:",[234,1674,1676],{"className":236,"code":1675,"language":238,"meta":239,"style":239},"ant nest machines add prod --host 173.87.3.89 --ssh-key ~\u002F.ssh\u002Fid_ed25519\nant nest machines add prod --host 173.87.3.89 --ssh-password-stdin\nant nest machines add prod --hostname prod.example.com --node-id 7f2e…\nant nest machines network prod --name ant-prod --driver bridge\n",[154,1677,1678,1683,1688,1693],{"__ignoreMap":239},[243,1679,1680],{"class":245,"line":246},[243,1681,1682],{},"ant nest machines add prod --host 173.87.3.89 --ssh-key ~\u002F.ssh\u002Fid_ed25519\n",[243,1684,1685],{"class":245,"line":252},[243,1686,1687],{},"ant nest machines add prod --host 173.87.3.89 --ssh-password-stdin\n",[243,1689,1690],{"class":245,"line":258},[243,1691,1692],{},"ant nest machines add prod --hostname prod.example.com --node-id 7f2e…\n",[243,1694,1695],{"class":245,"line":485},[243,1696,1697],{},"ant nest machines network prod --name ant-prod --driver bridge\n",[150,1699,1700,1703,1704,1706,1707,1710,1711,1714],{},[154,1701,1702],{},"ant nest doctor"," checks the active machine; locally, or over the worker RPCs\nwith ",[154,1705,769],{}," (host-level port grants are reported as not applicable\nremotely). It reports the docker daemon, Caddy reachability, the docker mode,\nand tool status. ",[154,1708,1709],{},"--cleanup"," also removes leftovers: on this host the pre-v2\nconfig backup, world-readable deploy logs, and empty ",[154,1712,1713],{},"~\u002F.ant\u002Flocal"," trees; on a\nmachine the stored compose\u002Fstack projects whose workload is gone.",[150,1716,1717,1718,1721,1722,1725,1726,1729,1730,1732,1733,1736,1737,1739,1740,1742,1743,1746,1747,353,1749,353,1751,353,1753,1016,1755,353,1757,353,1759,926,1761,1016,1763,353,1765,353,1767,1769,1770,1773,1774,1776],{},"Provisioning needs a signed-in account (",[154,1719,1720],{},"ant colony signup","): its NodeID seeds\nthe daemon's first owner, and ant ships the machine identity it generates. The\ndocker compose and buildx plugins are installed when the distro ships them\nseparately. The\nworker binary is ",[159,1723,1724],{},"pushed over SSH"," when provisioning that way (build it with\n",[154,1727,1728],{},"task build:agent"," for the machine's architecture); ",[154,1731,1483],{}," instead\ndownloads the published ",[154,1734,1735],{},"ant-worker-linux-\u003Carch>"," release asset. When the SSH\nuser is not root, the bootstrap runs through sudo; a passwordless sudo is used\nwhen available, and otherwise the SSH password (from ",[154,1738,1334],{}," \u002F\n",[154,1741,1337],{},") is fed to ",[154,1744,1745],{},"sudo -S","; the password never appears in argv\nor the environment. Flags: ",[154,1748,1313],{},[154,1750,1316],{},[154,1752,1319],{},[154,1754,1325],{},[154,1756,1328],{},[154,1758,1331],{},[154,1760,1334],{},[154,1762,1337],{},[154,1764,1343],{},[154,1766,577],{},[154,1768,1348],{},". The host may embed the port\n(",[154,1771,1772],{},"--host 203.0.113.7:2222","); an explicit ",[154,1775,1328],{}," wins over it.",[150,1778,1779,1782,1783,1786,1787,1789],{},[154,1780,1781],{},"ant nest machines remove"," only unregisters the machine locally. It deletes the\nlocal identity copy (",[154,1784,1785],{},"~\u002F.ant\u002Fmachines\u002F\u003Cid>",") with the record; pass\n",[154,1788,1374],{}," to keep the key for a later re-provision. To remove ant\nfrom the machine itself (stop and delete the worker, its unit, binary, and the\nCaddy admin drop-in, then unregister), use decommission over SSH:",[234,1791,1793],{"className":236,"code":1792,"language":238,"meta":239,"style":239},"ant nest machines decommission prod --host 173.87.3.89 --ssh-key ~\u002F.ssh\u002Fid_ed25519 --yes\nant nest machines decommission prod --host 173.87.3.89 --ssh-password-stdin --purge --yes\n",[154,1794,1795,1800],{"__ignoreMap":239},[243,1796,1797],{"class":245,"line":246},[243,1798,1799],{},"ant nest machines decommission prod --host 173.87.3.89 --ssh-key ~\u002F.ssh\u002Fid_ed25519 --yes\n",[243,1801,1802],{"class":245,"line":252},[243,1803,1804],{},"ant nest machines decommission prod --host 173.87.3.89 --ssh-password-stdin --purge --yes\n",[150,1806,1807,1809,1810,1812,1813,1816,1817,1819],{},[154,1808,1365],{}," additionally removes the worker user and its state (the machine\nidentity and roster), every ant-managed container and image, and the docker\nnetworks ant created for it. Without ",[154,1811,1365],{}," the machine keeps ",[154,1814,1815],{},"\u002Fhome\u002Fant",", so\nre-provisioning reuses the same NodeID and roster. ",[154,1818,1371],{}," leaves the\nlocal entry in place.",[1571,1821,1012],{"id":1012},[234,1823,1825],{"className":236,"code":1824,"language":238,"meta":239,"style":239},"ant nest swarm status --machine prod\nant nest swarm init --machine prod [--advertise-addr A]\nant nest swarm leave --machine prod --force\nant nest swarm nodes --machine prod\nant nest swarm node promote|demote|drain|activate|pause NODE --machine prod\nant nest swarm node rm NODE [--force] [--yes] --machine prod\nant nest swarm join-token [worker|manager] [--rotate] --machine prod\nant nest swarm services --machine prod\nant nest swarm service ps SERVICE --machine prod\nant nest swarm service logs SERVICE [--tail N] --machine prod\nant nest swarm service scale SERVICE REPLICAS --machine prod\nant nest swarm service restart SERVICE --machine prod\nant nest swarm service update SERVICE [--image REF] [--force] [--rollback] [--with-registry-auth] --machine prod\nant nest swarm service rm SERVICE [--yes] --machine prod\n",[154,1826,1827,1832,1837,1842,1847,1852,1857,1862,1867,1872,1877,1882,1887,1892],{"__ignoreMap":239},[243,1828,1829],{"class":245,"line":246},[243,1830,1831],{},"ant nest swarm status --machine prod\n",[243,1833,1834],{"class":245,"line":252},[243,1835,1836],{},"ant nest swarm init --machine prod [--advertise-addr A]\n",[243,1838,1839],{"class":245,"line":258},[243,1840,1841],{},"ant nest swarm leave --machine prod --force\n",[243,1843,1844],{"class":245,"line":485},[243,1845,1846],{},"ant nest swarm nodes --machine prod\n",[243,1848,1849],{"class":245,"line":491},[243,1850,1851],{},"ant nest swarm node promote|demote|drain|activate|pause NODE --machine prod\n",[243,1853,1854],{"class":245,"line":497},[243,1855,1856],{},"ant nest swarm node rm NODE [--force] [--yes] --machine prod\n",[243,1858,1859],{"class":245,"line":503},[243,1860,1861],{},"ant nest swarm join-token [worker|manager] [--rotate] --machine prod\n",[243,1863,1864],{"class":245,"line":509},[243,1865,1866],{},"ant nest swarm services --machine prod\n",[243,1868,1869],{"class":245,"line":515},[243,1870,1871],{},"ant nest swarm service ps SERVICE --machine prod\n",[243,1873,1874],{"class":245,"line":521},[243,1875,1876],{},"ant nest swarm service logs SERVICE [--tail N] --machine prod\n",[243,1878,1879],{"class":245,"line":527},[243,1880,1881],{},"ant nest swarm service scale SERVICE REPLICAS --machine prod\n",[243,1883,1884],{"class":245,"line":533},[243,1885,1886],{},"ant nest swarm service restart SERVICE --machine prod\n",[243,1888,1889],{"class":245,"line":539},[243,1890,1891],{},"ant nest swarm service update SERVICE [--image REF] [--force] [--rollback] [--with-registry-auth] --machine prod\n",[243,1893,1894],{"class":245,"line":545},[243,1895,1896],{},"ant nest swarm service rm SERVICE [--yes] --machine prod\n",[150,1898,1899,1900,1903,1904,1906,1907,1909,1910,1912,1913,1916,1917,1920,1921,1923],{},"Swarm is a ",[159,1901,1902],{},"server"," feature: every subcommand requires a remote machine\n(",[154,1905,769],{}," or ",[154,1908,314],{},"), and ant never initializes a swarm on this host.\n",[154,1911,979],{}," makes the machine a single-node manager (",[154,1914,1915],{},"--advertise-addr"," is only\nneeded when docker cannot choose among its addresses); ",[154,1918,1919],{},"leave"," needs ",[154,1922,1205],{},"\non a manager that still runs services.",[150,1925,1926,1927,353,1930,353,1933,353,1936,353,1939,1942,1943,1946,1947,353,1949,353,1951,353,1954,1957,1958,1961,1962,1965,1966,1968,1969,1971,1972,1975],{},"Reads (",[154,1928,1929],{},"status",[154,1931,1932],{},"nodes",[154,1934,1935],{},"services",[154,1937,1938],{},"service ps",[154,1940,1941],{},"service logs",") need the\n",[154,1944,1945],{},"read"," capability; node operations (",[154,1948,979],{},[154,1950,1919],{},[154,1952,1953],{},"node …",[154,1955,1956],{},"join-token",")\nneed an admin or owner role on the machine; service mutations (",[154,1959,1960],{},"service scale|restart|update|rm",") need deploy. ",[154,1963,1964],{},"service update"," is for hotfixes; for\nlasting changes edit the stack file and redeploy, which is the zero-downtime\npath. ",[154,1967,1941],{}," aggregates every replica's output, while ",[154,1970,857],{},"\nreads one task. Anything beyond these commands (overlay\u002Fnetwork admin, swarm\nconfigs and secrets, the rest of ",[154,1973,1974],{},"docker service update",") stays docker on the\nmachine.",[1571,1977,1015],{"id":1015},[234,1979,1981],{"className":236,"code":1980,"language":238,"meta":239,"style":239},"ant nest bootstrap --machine prod                       # print the root plan\nant nest bootstrap --machine prod --host 173.87.3.89 --ssh-key ~\u002F.ssh\u002Fid_ed25519\nant nest bootstrap --machine prod --cloud-init --worker-url https:\u002F\u002Fhost\u002Fant-worker-linux-amd64\nant nest bootstrap --machine prod --host 173.87.3.89 --worker-bin .\u002Fbin\u002Fant-worker\n",[154,1982,1983,1988,1993,1998],{"__ignoreMap":239},[243,1984,1985],{"class":245,"line":246},[243,1986,1987],{},"ant nest bootstrap --machine prod                       # print the root plan\n",[243,1989,1990],{"class":245,"line":252},[243,1991,1992],{},"ant nest bootstrap --machine prod --host 173.87.3.89 --ssh-key ~\u002F.ssh\u002Fid_ed25519\n",[243,1994,1995],{"class":245,"line":258},[243,1996,1997],{},"ant nest bootstrap --machine prod --cloud-init --worker-url https:\u002F\u002Fhost\u002Fant-worker-linux-amd64\n",[243,1999,2000],{"class":245,"line":485},[243,2001,2002],{},"ant nest bootstrap --machine prod --host 173.87.3.89 --worker-bin .\u002Fbin\u002Fant-worker\n",[150,2004,2005,2006,2008,2009,2012,2013,353,2015,353,2018,2021,2022,2025,2026,2028,2029,2032,2033,2035,2036,1603,2039,2041,2042,2044,2045,2047],{},"With ",[154,2007,1322],{},", ant runs the plan over SSH, uploading the local ",[154,2010,2011],{},"ant-worker","\n(default: next to ",[154,2014,156],{},[154,2016,2017],{},".\u002Fbin\u002Fant-worker",[154,2019,2020],{},"$PATH",", or ",[154,2023,2024],{},"ANT_WORKER_BIN",";\noverride with ",[154,2027,1340],{},") and the machine identity; re-running it is also\nthe ",[159,2030,2031],{},"upgrade path",", and preserves the machine identity and roster. The\ndocker mode is the recorded one unless ",[154,2034,1343],{}," is given, which\nre-provisions into that mode and updates the registry. It refuses\na worker that is not a Linux ELF matching the target's architecture\n(",[154,2037,2038],{},"uname -m",[154,2040,1483],{}," prints a user-data script that installs the worker\nfrom ",[154,2043,1486],{}," (required, because the target must fetch the binary\ndirectly; use the ",[154,2046,1735],{}," URL from the release's download\ndirectory) and reports its NodeID when you cannot SSH. With neither, it prints\nthe steps for an operator to run as root.",[1571,2049,2051],{"id":2050},"caddys-admin-api","Caddy's admin API",[150,2053,2054,2055,2058,2059,2062,2063,2066,2067,2070,2071,2073],{},"Ant programs routes through the machine's Caddy. The upstream packages expose\nthat API on a root-only unix socket whose permissions vary across restarts, so\nthe bootstrap points it at ",[154,2056,2057],{},"127.0.0.1:2019"," instead; it rewrites only the\n",[154,2060,2061],{},"admin"," directive in ",[154,2064,2065],{},"\u002Fetc\u002Fcaddy\u002FCaddyfile"," (backup kept at\n",[154,2068,2069],{},"\u002Fetc\u002Fcaddy\u002FCaddyfile.ant.bak",") and restarts Caddy. A host already serving TCP\non ",[154,2072,2057],{}," is left alone. If the Caddyfile cannot be adjusted, it falls\nback to the unix socket with a systemd drop-in that grants the worker access.",[150,2075,2076],{},"The worker starts even when Caddy is unreachable (it logs a warning and serves\nmanagement, builds, and logs); deploys are refused with a clear message until\nCaddy answers again.",[1571,2078,2080],{"id":2079},"tool-status-and-service-lifecycle","Tool status and service lifecycle",[150,2082,2083,2084,2086,2087,2089],{},"Every tool ",[154,2085,1564],{}," knows exposes ",[154,2088,1929],{},":",[234,2091,2093],{"className":236,"code":2092,"language":238,"meta":239,"style":239},"ant nest tools nixpacks status  # installed, version, path, install hint\nant nest tools docker status    # also reports whether the daemon answers\n",[154,2094,2095,2100],{"__ignoreMap":239},[243,2096,2097],{"class":245,"line":246},[243,2098,2099],{},"ant nest tools nixpacks status  # installed, version, path, install hint\n",[243,2101,2102],{"class":245,"line":252},[243,2103,2104],{},"ant nest tools docker status    # also reports whether the daemon answers\n",[150,2106,2107,2109,2110,2113,2114,976,2117,2119,2120,2123,2124,2127,2128,2131],{},[154,2108,1929],{}," reports whether the binary is on ",[154,2111,2112],{},"PATH",", its version, path, and install\nhint. For Docker it also reports the ",[159,2115,2116],{},"daemon",[154,2118,1929],{}," is ",[154,2121,2122],{},"ok"," only when\n",[154,2125,2126],{},"docker info"," answers, so a stopped daemon shows as ",[154,2129,2130],{},"daemon unreachable",", not as\n\"not installed\".",[150,2133,2134,2135,887,2138,2089],{},"Only the one tool ant runs as a service (the local Caddy proxy) also exposes\n",[154,2136,2137],{},"restart",[154,2139,1454],{},[234,2141,2143],{"className":236,"code":2142,"language":238,"meta":239,"style":239},"ant nest tools caddy status     # listeners, routes, and a drift warning\nant nest tools caddy restart    # stop + start, applying a changed listen config\nant nest tools caddy stop       # stop it (domains go offline)\n",[154,2144,2145,2150,2155],{"__ignoreMap":239},[243,2146,2147],{"class":245,"line":246},[243,2148,2149],{},"ant nest tools caddy status     # listeners, routes, and a drift warning\n",[243,2151,2152],{"class":245,"line":252},[243,2153,2154],{},"ant nest tools caddy restart    # stop + start, applying a changed listen config\n",[243,2156,2157],{"class":245,"line":258},[243,2158,2159],{},"ant nest tools caddy stop       # stop it (domains go offline)\n",[150,2161,2162,2163,353,2166,2169,2170,2173,2174,2177,2178,2181,2182,2185],{},"The other tools have no lifecycle to manage, so the verbs are not offered:\n",[154,2164,2165],{},"nixpacks",[154,2167,2168],{},"pack",", and ",[154,2171,2172],{},"railpack"," are one-shot build CLIs (they run, produce an\nimage, and exit), and Docker's daemon is a ",[159,2175,2176],{},"host service ant does not own",":\nrestarting it stops every container and needs root, so ",[154,2179,2180],{},"ant nest tools install","\nonly prints the ",[154,2183,2184],{},"systemctl enable --now docker"," hint.",[150,2187,2188,2189,2192,2193,2195,2196,650,2199,2202,2203,2206,2207,2210,2211,2213,2214,2216],{},"The local managed Caddy (which serves ",[154,2190,2191],{},"*.localhost"," domains) is the one service\ntoday. Its ",[154,2194,1929],{}," reports the configured ",[154,2197,2198],{},"http_listen",[154,2200,2201],{},"https_listen",", the\nprogrammed routes, and warns when the running proxy listens on different\naddresses than ",[154,2204,2205],{},"~\u002F.ant\u002Fconfig.json"," now asks for. A listen change does not reach\na running proxy by itself: the next local deploy restarts it automatically, or\nrun ",[154,2208,2209],{},"ant nest tools caddy restart"," to apply it immediately. A restart clears the\nprogrammed routes until the next deploy re-applies them. Both ",[154,2212,2137],{}," and\n",[154,2215,1454],{}," work on the proxy whether or not ant still holds its PID file (they fall\nback to Caddy's admin API).",[150,2218,2219,2221,2222,2225,2226,2228,2229,2232,2233,2236],{},[154,2220,2172],{}," additionally needs a BuildKit daemon. Provisioning starts one\n(",[154,2223,2224],{},"docker run --name buildkit --privileged moby\u002Fbuildkit",") when ",[154,2227,2172],{}," is\nalready installed, and points the worker at it with\n",[154,2230,2231],{},"BUILDKIT_HOST=docker-container:\u002F\u002Fbuildkit","; install railpack first and re-run\n",[154,2234,2235],{},"ant nest bootstrap"," to enable it.",[1571,2238,985],{"id":985},[150,2240,2241,2244,2245,2247],{},[154,2242,2243],{},"ant nest edit"," changes this project's ",[154,2246,276],{}," in place, with comments\npreserved, the same edits the dashboard dialogs make.",[279,2249,2250,2258],{},[282,2251,2252],{},[285,2253,2254,2256],{},[288,2255,560],{},[288,2257,563],{},[295,2259,2260,2280,2350,2368,2385,2400,2415,2430,2442],{},[285,2261,2262,2267],{},[300,2263,2264],{},[154,2265,2266],{},"edit file",[300,2268,2269,2270,2272,2273,650,2276,2279],{},"- (opens ",[154,2271,276],{}," in ",[154,2274,2275],{},"$VISUAL",[154,2277,2278],{},"$EDITOR"," and re-validates it)",[285,2281,2282,2287],{},[300,2283,2284],{},[154,2285,2286],{},"edit deploy",[300,2288,2289,353,2291,353,2293,353,2296,353,2298,353,2301,353,2303,353,2306,353,2309,353,2312,353,2315,353,2318,353,2321,353,2324,353,2327,353,2330,353,2333,353,2335,615,2338,353,2341,353,2344,353,2347],{},[154,2290,1184],{},[154,2292,1187],{},[154,2294,2295],{},"--dockerfile",[154,2297,1190],{},[154,2299,2300],{},"--files",[154,2302,1193],{},[154,2304,2305],{},"--cpu",[154,2307,2308],{},"--memory",[154,2310,2311],{},"--health-path",[154,2313,2314],{},"--health-interval",[154,2316,2317],{},"--health-timeout",[154,2319,2320],{},"--health-retries",[154,2322,2323],{},"--zero-downtime",[154,2325,2326],{},"--replicas",[154,2328,2329],{},"--log-max-size",[154,2331,2332],{},"--log-max-files",[154,2334,695],{},[154,2336,2337],{},"--profile",[154,2339,2340],{},"--group-network",[154,2342,2343],{},"--machine-network",[154,2345,2346],{},"--build-services",[154,2348,2349],{},"--env",[285,2351,2352,2357],{},[300,2353,2354],{},[154,2355,2356],{},"edit env list\u002Fset\u002Funset",[300,2358,2359,2361,2362,205,2364,2367],{},[154,2360,2349],{}," (deployment; default ",[154,2363,310],{},[154,2365,2366],{},"list"," defaults to all)",[285,2369,2370,2375],{},[300,2371,2372],{},[154,2373,2374],{},"edit secret add\u002Flist\u002Fremove",[300,2376,2377,353,2380,205,2382],{},[154,2378,2379],{},"add --build-time",[154,2381,2349],{},[154,2383,2384],{},"remove --env",[285,2386,2387,2392],{},[300,2388,2389],{},[154,2390,2391],{},"edit domain add\u002Fremove\u002Flist",[300,2393,2394,205,2397],{},[154,2395,2396],{},"add --subdomain --domain --path --group-domain --service --port --scheme --strip-slash --env",[154,2398,2399],{},"remove DOMAIN --env",[285,2401,2402,2407],{},[300,2403,2404],{},[154,2405,2406],{},"edit deployment add\u002Flist\u002Fset\u002Fremove",[300,2408,2409,205,2412],{},[154,2410,2411],{},"add --compose-file --port-offset --auto-open",[154,2413,2414],{},"set --port-offset --auto-open",[285,2416,2417,2422],{},[300,2418,2419],{},[154,2420,2421],{},"edit volume add\u002Flist\u002Fremove",[300,2423,2424,205,2427],{},[154,2425,2426],{},"add SOURCE:TARGET[:ro] [--source --target --read-only --target-machine]",[154,2428,2429],{},"remove TARGET [--target-machine]",[285,2431,2432,2437],{},[300,2433,2434],{},[154,2435,2436],{},"edit network add\u002Flist\u002Fremove",[300,2438,2439],{},[154,2440,2441],{},"add NAME [--driver --subnet --external]",[285,2443,2444,2449],{},[300,2445,2446],{},[154,2447,2448],{},"edit group set\u002Funset",[300,2450,1280],{},[150,2452,2453],{},"Notable deploy-level flags:",[234,2455,2457],{"className":236,"code":2456,"language":238,"meta":239,"style":239},"ant nest edit file                              # open the whole ant.yaml\nant nest edit deploy --replicas 2 --cpu 0.5 --memory 512m\nant nest edit deploy --machine-network          # join the machine-wide network\nant nest edit deploy --machine-network=false     # opt out\nant nest edit deploy --group-network=false       # opt out of the group network\nant nest edit deploy --env dev --file docker-compose.dev.yml\nant nest edit deploy --profile worker            # activate a compose profile\n",[154,2458,2459,2464,2469,2474,2479,2484,2489],{"__ignoreMap":239},[243,2460,2461],{"class":245,"line":246},[243,2462,2463],{},"ant nest edit file                              # open the whole ant.yaml\n",[243,2465,2466],{"class":245,"line":252},[243,2467,2468],{},"ant nest edit deploy --replicas 2 --cpu 0.5 --memory 512m\n",[243,2470,2471],{"class":245,"line":258},[243,2472,2473],{},"ant nest edit deploy --machine-network          # join the machine-wide network\n",[243,2475,2476],{"class":245,"line":485},[243,2477,2478],{},"ant nest edit deploy --machine-network=false     # opt out\n",[243,2480,2481],{"class":245,"line":491},[243,2482,2483],{},"ant nest edit deploy --group-network=false       # opt out of the group network\n",[243,2485,2486],{"class":245,"line":497},[243,2487,2488],{},"ant nest edit deploy --env dev --file docker-compose.dev.yml\n",[243,2490,2491],{"class":245,"line":503},[243,2492,2493],{},"ant nest edit deploy --profile worker            # activate a compose profile\n",[150,2495,2496,2498,2499,2272,2501,650,2503,2505,2506,650,2509,650,2512,650,2515,2518],{},[154,2497,2266],{}," is the escape hatch for anything the structured subcommands do not\ncover: it opens ",[154,2500,276],{},[154,2502,2275],{},[154,2504,2278],{}," (falling back to\n",[154,2507,2508],{},"nvim",[154,2510,2511],{},"vim",[154,2513,2514],{},"vi",[154,2516,2517],{},"nano",") and re-reads it when the editor exits, so a syntax or\nconfig error is reported immediately. The edit is kept as written, so it can be\nfixed in place and the command re-run.",[1571,2520,2521],{"id":2521},"domain",[150,2523,2524,2527,2528,2530,2531,2533,2534],{},[154,2525,2526],{},"ant nest edit domain add|remove|list"," manages ONE deployment's routes\n(",[154,2529,2349],{},", default ",[154,2532,310],{},"). Each entry carries its routing target: ",[154,2535,2536],{},"--service",[968,2538,2539],{},[971,2540,2541,2543,2544,2546,2547,2550,2551,2554,2555,2558,2559,2562],{},[154,2542,1193],{}," for a compose service, or just ",[154,2545,1193],{}," (defaults to ",[154,2548,2549],{},"deploy.port","\nfor a single-container project). Domains are ",[159,2552,2553],{},"opt-in",": ant never adds one.\nOmit ",[154,2556,2557],{},"--domain"," to use the project's group base domains; add ",[154,2560,2561],{},"--group-domain","\nto pin one of them.",[234,2564,2566],{"className":236,"code":2565,"language":238,"meta":239,"style":239},"ant nest edit domain add --subdomain api --service web --port 3000\nant nest edit domain add --subdomain eu --group-domain example.org --service api --port 8080\nant nest edit domain add --path \u002Finternal\nant nest edit domain add api.other.org --service api --port 8080\nant nest edit domain list\nant nest edit domain remove api.localhost\n",[154,2567,2568,2573,2578,2583,2588,2593],{"__ignoreMap":239},[243,2569,2570],{"class":245,"line":246},[243,2571,2572],{},"ant nest edit domain add --subdomain api --service web --port 3000\n",[243,2574,2575],{"class":245,"line":252},[243,2576,2577],{},"ant nest edit domain add --subdomain eu --group-domain example.org --service api --port 8080\n",[243,2579,2580],{"class":245,"line":258},[243,2581,2582],{},"ant nest edit domain add --path \u002Finternal\n",[243,2584,2585],{"class":245,"line":485},[243,2586,2587],{},"ant nest edit domain add api.other.org --service api --port 8080\n",[243,2589,2590],{"class":245,"line":491},[243,2591,2592],{},"ant nest edit domain list\n",[243,2594,2595],{"class":245,"line":497},[243,2596,2597],{},"ant nest edit domain remove api.localhost\n",[1571,2599,2600],{"id":2600},"deployment",[150,2602,2603,2606,2607,353,2609,2612,2613,2616,2617,2620,2621,2624],{},[154,2604,2605],{},"ant nest edit deployment add|set|remove|list"," manages the per-environment\noverlays (",[154,2608,310],{},[154,2610,2611],{},"dev",", …). ",[154,2614,2615],{},"--compose-file"," sets that environment's compose\nfile; ",[154,2618,2619],{},"--port-offset"," shifts its host port so two local deployments do not\ncollide; ",[154,2622,2623],{},"--auto-open"," opens the browser after a local deploy.",[1571,2626,1040],{"id":1040},[234,2628,2630],{"className":236,"code":2629,"language":238,"meta":239,"style":239},"ant nest volume list               # name, driver, owner project, in-use\nant nest volume list --json\nant nest volume list --all         # include volumes no ant container uses\nant nest volume rm NAME --yes\nant nest volume rm NAME --yes --force\nant nest volume rm other-data --yes --all\nant nest volume list --machine prod\n",[154,2631,2632,2637,2642,2647,2652,2657,2662],{"__ignoreMap":239},[243,2633,2634],{"class":245,"line":246},[243,2635,2636],{},"ant nest volume list               # name, driver, owner project, in-use\n",[243,2638,2639],{"class":245,"line":252},[243,2640,2641],{},"ant nest volume list --json\n",[243,2643,2644],{"class":245,"line":258},[243,2645,2646],{},"ant nest volume list --all         # include volumes no ant container uses\n",[243,2648,2649],{"class":245,"line":485},[243,2650,2651],{},"ant nest volume rm NAME --yes\n",[243,2653,2654],{"class":245,"line":491},[243,2655,2656],{},"ant nest volume rm NAME --yes --force\n",[243,2658,2659],{"class":245,"line":497},[243,2660,2661],{},"ant nest volume rm other-data --yes --all\n",[243,2663,2664],{"class":245,"line":503},[243,2665,2666],{},"ant nest volume list --machine prod\n",[150,2668,2669,2671,2672,2675,2676,2679,2680,2683],{},[154,2670,1205],{}," overrides a ",[159,2673,2674],{},"stopped"," container's reference; a ",[159,2677,2678],{},"running"," container\nstill blocks removal. Pass ",[154,2681,2682],{},"--machine M"," to operate on a remote nest's volumes\n(the same list the dashboard shows on a machine's page).",[150,2685,2686,2687,2690,2691,2021,2694,650,2697,2700,2701,205,2704,2706],{},"To edit the project's own container mounts, use ",[154,2688,2689],{},"ant nest edit volume add|remove|list"," (short syntax ",[154,2692,2693],{},"SOURCE:TARGET[:ro]",[154,2695,2696],{},"--source",[154,2698,2699],{},"--target","\u002F\n",[154,2702,2703],{},"--read-only",[154,2705,1199],{}," scopes a mount to one nest).",[1571,2708,1037],{"id":1037},[234,2710,2712],{"className":236,"code":2711,"language":238,"meta":239,"style":239},"ant nest containers list                     # name, status, image, CPU, memory\nant nest containers list --json\nant nest containers restart NAME\nant nest containers rm NAME --yes\nant nest containers list --machine prod\n",[154,2713,2714,2719,2724,2729,2734],{"__ignoreMap":239},[243,2715,2716],{"class":245,"line":246},[243,2717,2718],{},"ant nest containers list                     # name, status, image, CPU, memory\n",[243,2720,2721],{"class":245,"line":252},[243,2722,2723],{},"ant nest containers list --json\n",[243,2725,2726],{"class":245,"line":258},[243,2727,2728],{},"ant nest containers restart NAME\n",[243,2730,2731],{"class":245,"line":485},[243,2732,2733],{},"ant nest containers rm NAME --yes\n",[243,2735,2736],{"class":245,"line":491},[243,2737,2738],{},"ant nest containers list --machine prod\n",[150,2740,2741,2742,2744,2745,2748],{},"Lists and controls the ant-managed containers on the active machine; ",[154,2743,769],{},"\ntargets a remote nest's worker. This is also the container list for the local\nmachine, which ",[154,2746,2747],{},"ant trail ps"," used to provide.",[1571,2750,2752],{"id":2751},"machines-network","machines network",[234,2754,2756],{"className":236,"code":2755,"language":238,"meta":239,"style":239},"ant nest machines network local                              # show the effective network\nant nest machines network local --name ant-local --driver bridge\nant nest machines network local --subnet 172.30.0.0\u002F16 --external\nant nest machines network local --clear                      # back to the default\n",[154,2757,2758,2763,2768,2773],{"__ignoreMap":239},[243,2759,2760],{"class":245,"line":246},[243,2761,2762],{},"ant nest machines network local                              # show the effective network\n",[243,2764,2765],{"class":245,"line":252},[243,2766,2767],{},"ant nest machines network local --name ant-local --driver bridge\n",[243,2769,2770],{"class":245,"line":258},[243,2771,2772],{},"ant nest machines network local --subnet 172.30.0.0\u002F16 --external\n",[243,2774,2775],{"class":245,"line":485},[243,2776,2777],{},"ant nest machines network local --clear                      # back to the default\n",[150,2779,2780,2781,2784,2785,2788,2789,353,2791,353,2793,353,2795,1016,2797,353,2800,194],{},"Shows or sets the machine-wide network projects opt into with\n",[154,2782,2783],{},"deploy.use_machine_network",". ",[154,2786,2787],{},"ant nest groups network \u003Cgroup>"," does the same for\na group's shared network (",[154,2790,602],{},[154,2792,1390],{},[154,2794,1393],{},[154,2796,1396],{},[154,2798,2799],{},"--no-attach",[154,2801,778],{},[1571,2803,995],{"id":995},[150,2805,2806,2807,2810,2811,229],{},"A group's ",[159,2808,2809],{},"base domains"," are what member deployments route under; a deployment\nadds a subdomain, a path, or uses one as-is. Add several bases with repeated\n",[154,2812,2557],{},[234,2814,2816],{"className":236,"code":2815,"language":238,"meta":239,"style":239},"ant nest groups list\nant nest groups create backend --domain example.com --domain example.org\nant nest groups domains backend example.com example.org\nant nest groups add backend api worker\nant nest groups remove worker\nant nest groups rename backend services\nant nest groups delete backend --yes\n",[154,2817,2818,2823,2828,2833,2838,2843,2848],{"__ignoreMap":239},[243,2819,2820],{"class":245,"line":246},[243,2821,2822],{},"ant nest groups list\n",[243,2824,2825],{"class":245,"line":252},[243,2826,2827],{},"ant nest groups create backend --domain example.com --domain example.org\n",[243,2829,2830],{"class":245,"line":258},[243,2831,2832],{},"ant nest groups domains backend example.com example.org\n",[243,2834,2835],{"class":245,"line":485},[243,2836,2837],{},"ant nest groups add backend api worker\n",[243,2839,2840],{"class":245,"line":491},[243,2841,2842],{},"ant nest groups remove worker\n",[243,2844,2845],{"class":245,"line":497},[243,2846,2847],{},"ant nest groups rename backend services\n",[243,2849,2850],{"class":245,"line":503},[243,2851,2852],{},"ant nest groups delete backend --yes\n",[150,2854,2855,2858,2859,353,2862,353,2865,891,2868,2870,2871,2874,2875,2877],{},[154,2856,2857],{},"create"," also takes ",[154,2860,2861],{},"--display-name",[154,2863,2864],{},"--color",[154,2866,2867],{},"--description",[154,2869,1199],{}," (the nest the group belongs to). ",[154,2872,2873],{},"domains \u003Cgroup> [domain...]","\nreplaces the base domains; add ",[154,2876,778],{}," to remove them.",[263,2879,2881,2883],{"id":2880},"ant-colony-account-and-users",[154,2882,186],{},", account and users",[234,2885,2887],{"className":236,"code":2886,"language":238,"meta":239,"style":239},"ant colony signup | login | logout | whoami\nant colony profile --name \"Ada\" --email ada@example.com\nant colony export --out ant-account.json [--passphrase P | --no-passphrase]\nant colony import ant-account.json [--passphrase P]\nant colony users                  list | add | update | remove | system-user\nant colony invite                 --role deployer --machine prod\nant colony join                   --token ant_inv_… [--alias NAME]\nant colony invites                [--revoke NONCE]\nant colony election-status\nant colony elect-owner \u003Cnodeid>\nant colony recover                --add-owner \u003Cnodeid>\n",[154,2888,2889,2894,2899,2904,2909,2914,2919,2924,2929,2934,2939],{"__ignoreMap":239},[243,2890,2891],{"class":245,"line":246},[243,2892,2893],{},"ant colony signup | login | logout | whoami\n",[243,2895,2896],{"class":245,"line":252},[243,2897,2898],{},"ant colony profile --name \"Ada\" --email ada@example.com\n",[243,2900,2901],{"class":245,"line":258},[243,2902,2903],{},"ant colony export --out ant-account.json [--passphrase P | --no-passphrase]\n",[243,2905,2906],{"class":245,"line":485},[243,2907,2908],{},"ant colony import ant-account.json [--passphrase P]\n",[243,2910,2911],{"class":245,"line":491},[243,2912,2913],{},"ant colony users                  list | add | update | remove | system-user\n",[243,2915,2916],{"class":245,"line":497},[243,2917,2918],{},"ant colony invite                 --role deployer --machine prod\n",[243,2920,2921],{"class":245,"line":503},[243,2922,2923],{},"ant colony join                   --token ant_inv_… [--alias NAME]\n",[243,2925,2926],{"class":245,"line":509},[243,2927,2928],{},"ant colony invites                [--revoke NONCE]\n",[243,2930,2931],{"class":245,"line":515},[243,2932,2933],{},"ant colony election-status\n",[243,2935,2936],{"class":245,"line":521},[243,2937,2938],{},"ant colony elect-owner \u003Cnodeid>\n",[243,2940,2941],{"class":245,"line":527},[243,2942,2943],{},"ant colony recover                --add-owner \u003Cnodeid>\n",[150,2945,432,2946,205,2949,2952,2953,205,2956,205,2959,205,2962,328,2965,2968,2969,205,2972,205,2975,205,2978,2952,2981,205,2984,2952,2987,205,2990,2993,2994,2997,2998,3001],{},[154,2947,2948],{},"signup --name --email",[154,2950,2951],{},"login --bundle --identity --passphrase",";\n",[154,2954,2955],{},"whoami --json",[154,2957,2958],{},"export --out --passphrase --no-passphrase",[154,2960,2961],{},"import --passphrase",[154,2963,2964],{},"invite --role --email --ttl",[154,2966,2967],{},"72h","); ",[154,2970,2971],{},"join --token --alias",[154,2973,2974],{},"invites --revoke",[154,2976,2977],{},"recover --add-owner",[154,2979,2980],{},"users list --json",[154,2982,2983],{},"users add \u003Cnodeid> --role --name --email",[154,2985,2986],{},"users update \u003Cnodeid> --role --name --email --system-user --no-system-user",[154,2988,2989],{},"users remove \u003Cnodeid> --purge",[154,2991,2992],{},"users system-user \u003Cnodeid> --op create|lock|unlock|delete",". The ",[154,2995,2996],{},"users"," subcommands also take ",[154,2999,3000],{},"--mirror"," (read\nand write the local roster mirror without contacting the machine daemon).",[150,3003,3004,650,3007,3010,3011,2119,3013,1603,3016,3019,3020,3023,3024,3027,3028,3031,3032,3035,3036,3039,3040,3043],{},[154,3005,3006],{},"ant colony export",[154,3008,3009],{},"import"," move your account as a passphrase-encrypted bundle\n(",[154,3012,3009],{},[154,3014,3015],{},"login --bundle",[154,3017,3018],{},"ant colony users update"," changes a member's\nrole (",[154,3021,3022],{},"--role","), name, email, or linked unix account (",[154,3025,3026],{},"--system-user NAME","\nlinks, including an existing account; ",[154,3029,3030],{},"--no-system-user"," detaches). ",[154,3033,3034],{},"ant colony users system-user --op create|lock|unlock|delete"," prints the matching root-run command. ",[154,3037,3038],{},"ant colony profile"," edits your own account. ",[154,3041,3042],{},"ant colony recover --add-owner"," is the\nbreak-glass path back onto a machine you are locked out of.",[150,3045,3046,3047,3050,3051,3053],{},"A user reference (",[154,3048,3049],{},"\u003Cnodeid>"," above) may be a full NodeID, an unambiguous prefix\nof one, or an unambiguous name\u002Femail. With no ",[154,3052,769],{},", the local machine's\nsingle user (your account) is targeted, so its linked system account can be\nset there too.",[263,3055,3057,3060],{"id":3056},"ant-nest-groups-project-groups",[154,3058,3059],{},"ant nest groups",", project groups",[150,3062,3063,3064,3067,3068,3070,3071,805,3074,229],{},"See ",[906,3065,995],{"href":3066},"#groups"," above; groups live in the client config\n(",[154,3069,2205],{},") and are referenced by the ",[154,3072,3073],{},"group:",[154,3075,276],{},[263,3077,3079],{"id":3078},"project-secrets-and-env","Project secrets and env",[150,3081,3082,3083,3085,3086,3088,3089,2089],{},"Secrets are referenced by name in ",[154,3084,276],{}," and resolved from the environment\nat deploy time; env vars are per-deployment. Both are edited through\n",[154,3087,2243],{}," and printed by ",[154,3090,172],{},[234,3092,3094],{"className":236,"code":3093,"language":238,"meta":239,"style":239},"ant nest edit secret add API_TOKEN\nant nest edit secret add NPM_TOKEN --build-time\nant nest edit env set LOG_LEVEL=debug --env staging\nant trail env                     [deployment]\n",[154,3095,3096,3101,3106,3111],{"__ignoreMap":239},[243,3097,3098],{"class":245,"line":246},[243,3099,3100],{},"ant nest edit secret add API_TOKEN\n",[243,3102,3103],{"class":245,"line":252},[243,3104,3105],{},"ant nest edit secret add NPM_TOKEN --build-time\n",[243,3107,3108],{"class":245,"line":258},[243,3109,3110],{},"ant nest edit env set LOG_LEVEL=debug --env staging\n",[243,3112,3113],{"class":245,"line":485},[243,3114,518],{},[263,3116,3118],{"id":3117},"ant-ui",[154,3119,193],{},[234,3121,3123],{"className":236,"code":3122,"language":238,"meta":239,"style":239},"ant ui                            [--host 127.0.0.1] [--port 4000]      # serve the dashboard\nant ui run                        [--host H] [--port P]                # same, explicit form\nant ui passwd                     [--clear | --password-stdin]         # set the dashboard password\nant ui install                    [--host H] [--port P] [--force]\nant ui status                     [--json]\nant ui start | stop | restart | recreate\nant ui logs                       [-f] [--lines N]\nant ui uninstall\n",[154,3124,3125,3130,3135,3140,3145,3150,3155,3160],{"__ignoreMap":239},[243,3126,3127],{"class":245,"line":246},[243,3128,3129],{},"ant ui                            [--host 127.0.0.1] [--port 4000]      # serve the dashboard\n",[243,3131,3132],{"class":245,"line":252},[243,3133,3134],{},"ant ui run                        [--host H] [--port P]                # same, explicit form\n",[243,3136,3137],{"class":245,"line":258},[243,3138,3139],{},"ant ui passwd                     [--clear | --password-stdin]         # set the dashboard password\n",[243,3141,3142],{"class":245,"line":485},[243,3143,3144],{},"ant ui install                    [--host H] [--port P] [--force]\n",[243,3146,3147],{"class":245,"line":491},[243,3148,3149],{},"ant ui status                     [--json]\n",[243,3151,3152],{"class":245,"line":497},[243,3153,3154],{},"ant ui start | stop | restart | recreate\n",[243,3156,3157],{"class":245,"line":503},[243,3158,3159],{},"ant ui logs                       [-f] [--lines N]\n",[243,3161,3162],{"class":245,"line":509},[243,3163,3164],{},"ant ui uninstall\n",[150,3166,3167,3170,3171,3174,3175,3178,3179,3181,3182,3184],{},[154,3168,3169],{},"ant ui install"," sets up a background service (a systemd user unit on Linux, a\nlaunchd agent on macOS) that keeps the dashboard running; ",[154,3172,3173],{},"ant ui recreate","\nreinstalls it after a host\u002Fport change. The dashboard is local-only by design;\n",[154,3176,3177],{},"ant ui passwd"," sets the password required to bind it to a non-loopback address\nfor your own access (and ",[154,3180,778],{}," removes it). See the\n",[906,3183,30],{"href":31}," page.",[263,3186,3188],{"id":3187},"surface-parity","Surface parity",[150,3190,3191],{},"Everyday machine operations are on both surfaces. A few are deliberately\nCLI-only or dashboard-only:",[968,3193,3194,3253],{},[971,3195,3196,3199,3200,3203,3204,887,3207,205,3210,205,3213,2952,3216,3219,3220,3222,3223,650,3225,3227,3228,2968,3231,205,3234,2213,3237,3240,3241,3244,3245,3248,3249,3252],{},[159,3197,3198],{},"CLI-only:"," account ",[154,3201,3202],{},"export"," (signup\u002Flogin\u002Flogout\u002Fprofile are on both);\n",[154,3205,3206],{},"colony join",[154,3208,3209],{},"colony recover",[154,3211,3212],{},"nest identity generate",[154,3214,3215],{},"nest ping",[154,3217,3218],{},"nest machines decommission","; the root-run ",[154,3221,1015],{}," printing and\n",[154,3224,1019],{},[154,3226,1022],{}," (the dashboard shows the plans and can provision over\nSSH); swarm management (",[154,3229,3230],{},"nest swarm …",[154,3232,3233],{},"nest tunnel",[154,3235,3236],{},"trail env",[154,3238,3239],{},"trail doctor","; tool ",[154,3242,3243],{},"install --dry-run"," and the generic\n",[154,3246,3247],{},"nest tools allow-ports"," (the dashboard installs tools and offers Caddy's\nport grant); and ",[154,3250,3251],{},"ant ui …",", which manages the dashboard's own service.",[971,3254,3255,3258,3259,3262],{},[159,3256,3257],{},"Dashboard-only:"," live Caddy route state and Caddy lifecycle;\n",[154,3260,3261],{},"project_dirs"," and the raw config\u002Ffile editors; theme, refresh, and\nnotification settings; the filesystem picker and global search; async job\nhistory\u002Fstreams; deploy-event detail; and reassigning a project's machine\nafter init.",[263,3264,3266],{"id":3265},"exit-codes","Exit codes",[150,3268,3269],{},"Ant exits non-zero when Docker is missing or its daemon is unreachable. Caddy\nand the optional builders are warnings only.",[3271,3272,3273],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":239,"searchDepth":252,"depth":252,"links":3275},[3276,3277,3279,3281,3297,3299,3301,3302,3303,3304],{"id":265,"depth":252,"text":266},{"id":406,"depth":252,"text":3278},"ant haul, build",{"id":459,"depth":252,"text":3280},"ant trail, deploy and manage",{"id":954,"depth":252,"text":3282,"children":3283},"ant nest, machines, tools, scaffolding",[3284,3285,3286,3287,3288,3289,3290,3291,3292,3293,3294,3295,3296],{"id":1573,"depth":258,"text":1574},{"id":1003,"depth":258,"text":1003},{"id":1012,"depth":258,"text":1012},{"id":1015,"depth":258,"text":1015},{"id":2050,"depth":258,"text":2051},{"id":2079,"depth":258,"text":2080},{"id":985,"depth":258,"text":985},{"id":2521,"depth":258,"text":2521},{"id":2600,"depth":258,"text":2600},{"id":1040,"depth":258,"text":1040},{"id":1037,"depth":258,"text":1037},{"id":2751,"depth":258,"text":2752},{"id":995,"depth":258,"text":995},{"id":2880,"depth":252,"text":3298},"ant colony, account and users",{"id":3056,"depth":252,"text":3300},"ant nest groups, project groups",{"id":3078,"depth":252,"text":3079},{"id":3117,"depth":252,"text":193},{"id":3187,"depth":252,"text":3188},{"id":3265,"depth":252,"text":3266},"Every command group, global flag, and the common flows.","md",null,{},{"icon":133},{"title":130,"description":3311},"The ant command surface (haul, trail, nest, colony, ui) plus global flags.","fZhXAO698-lBhEIvgZxpAbBBsU9FdB_ZeT4I_WvFbpY",[3314,3316],{"title":120,"path":121,"stem":122,"description":3315,"icon":123,"children":-1},"Deferred work, with why and the path forward.",{"title":135,"path":136,"stem":137,"description":3317,"icon":138,"children":-1},"Notable changes to Ant.",1791494554236]