Skip to main content

ankra targets

Manage host deploy targets: machines outside Kubernetes that run the ankra-host-agent and receive releases from ‘kind: deploy’ pipeline stages. A host joins an environment with a single-use join token:
The agent only ever connects outbound over HTTPS; the host needs no inbound port.

ankra targets get

Show a host deploy target
Flags

ankra targets join-token

Mint join tokens that let a host register into an environment

ankra targets join-token create

Mint a single-use join token a host registers into the environment with. The environment is created when it does not exist yet. The token is shown exactly once: the platform keeps only its hash. Without -o it is the only thing written to stdout (the expiry and the next step go to stderr), so it can be piped straight into ‘ankra targets register --token-stdin’ on the host.
Examples
Flags

ankra targets list

List host deploy targets
Flags

ankra targets register

Register this machine as a host deploy target and start its agent. Run it as root on the host itself, with a join token from ‘ankra targets join-token create’ on stdin. The command:
  1. downloads ankra-host-agent for this machine’s OS and architecture and its systemd unit from the agent release, and refuses them unless their SHA-256 matches the release’s SHA256SUMS;
  2. installs the binary as /usr/local/bin/ankra-host-agent;
  3. runs ‘ankra-host-agent register’, passing the join token on stdin - the agent does the registration and stores its own identity token;
  4. installs and starts ankra-host-agent.service.
The CLI never sends the join token anywhere itself and needs no ‘ankra login’ on the host. --no-install prints these steps without doing any of them. The agent reaches the platform at --base-url (or the configured base URL), over outbound HTTPS only.
Examples
Flags

ankra targets revoke

Revoke a host deploy target. Its identity token and every session stop working at once and it receives no further deploy jobs; the releases already on the host keep running. A revoked host registers again only with a new join token.
Flags