Documentation
¶
Overview ¶
Command agentd runs the security agent daemon, which holds a private key in memory and makes it available to other processes.
Loads the credentials from the specified directory into memory. Then optionally starts a command with access to these credentials via agent protocol.
Other processes can access the agent credentials when V23_AGENT_PATH is set to <credential dir>/agent.sock.
Example:
$ agentd --v23.credentials=$HOME/.credentials $ V23_AGENT_PATH=$HOME/.credentials/agent.sock principal dump
Usage:
agentd [flags] command [command_args...]
The command is started as a subprocess with the given [command_args...].
The agentd flags are:
-additional-principals= If non-empty, allow for the creation of new principals and save them in this directory. -new-principal-blessing-name= If creating a new principal (--v23.credentials does not exist), then have it blessed with this name. -restart-exit-code= If non-empty, will restart the command when it exits, provided that the command's exit code matches the value of this flag. The value must be an integer, or an integer preceded by '!' (in which case all exit codes except the flag will trigger a restart). -v23.credentials= The directory containing the (possibly encrypted) credentials to serve. Must be specified. -with-passphrase=true If true, user will be prompted for principal encryption passphrase.
The global flags are:
-alsologtostderr=true log to standard error as well as files -log_backtrace_at=:0 when logging hits line file:N, emit a stack trace -log_dir= if non-empty, write log files to this directory -logtostderr=false log to standard error instead of files -max_stack_buf_size=4292608 max size in bytes of the buffer to use for logging stack traces -metadata=<just specify -metadata to activate> Displays metadata for the program and exits. -stderrthreshold=2 logs at or above this threshold go to stderr -time=false Dump timing information to stderr before exiting the program. -v=0 log level for V logs -vmodule= comma-separated list of globpattern=N settings for filename-filtered logging (without the .go suffix). E.g. foo/bar/baz.go is matched by patterns baz or *az or b* but not by bar/baz or baz.go or az or b.* -vpath= comma-separated list of regexppattern=N settings for file pathname-filtered logging (without the .go suffix). E.g. foo/bar/baz.go is matched by patterns foo/bar/baz or fo.*az or oo/ba or b.z but not by foo/bar/baz.go or fo*az
Click to show internal directories.
Click to hide internal directories.