stado host
Invocation
stado host <COMMAND>Purpose
Manage operating-system resources on registry hosts
Required inputs and options
This command has no command-specific inputs or options.
Output and state effect
This command group selects one of the subcommands listed below; use its exact child invocation to perform an operation.
Refusals
- Before dispatch, Stado refuses a missing required token shown in the invocation, an unknown option, or a value outside a listed value set; argument-usage failures exit with code 2.
Subcommands
health— Show the latest Stado health beacon and log tail for TARGETpublish-beacon— Publish one locally collected beacon through the scoped Stado health APIbeacon-units— The unit ids the registry declares for THIS host, one per linecollect-beacon— Collect THIS host's health beacon from the registry's declarations and the init system's own answersreboot— Request a graceful reboot of TARGET through its approved channeluser— Manage local macOS and Linux user accountsgpu-power-limit— Persist and immediately reconcile TARGET's NVIDIA board power capuptime— Report TARGET's uptime, load averages and logged-in usersping— Check TARGET's ssh reachability AND health-beacon age as one verdictgates— Report HOST's measured disk space, its published memory refusal and the watermarks behind it, the published admission decision and the source, duration and error of every diagnostic readlink— Why TARGET went quiet: beacon age, the path and endpoint it published, its last sleep and wake, its interface changes, the silences recorded against it, and what readers refused because of themunit-log— The tail of one managed unit's own log on TARGETexec— Run one approved command on TARGET (allowlist, not a shell). Every entry is read-only except the declared provider sign-in repairsdeliver— Deliver one local file or directory into a canonical run directory on TARGETbuild— Build one declared Cargo binary inside a delivered managed run treerun-attached— Run one executable from a managed run tree with this process's standard input, output, and error attachedremove-run-directory— Recursively remove one complete managed run directorycron— Read TARGET's crontab, and optionally prune one entry from itrender-spis-admission-trust— Deliver the checked-in Weles receipt-trust renderer to TARGET and print the public five-field Spis receipt-trust document it builds from TARGET's own live Skarbiec. The admission authority's private half never leaves the hostinventory— Report TARGET's stado-managed binaries, fixed Cargo-home metadata and bin membership, forward markers and loopback listeners, and whether each marker still matches a live listenerconfig-show— Read TARGET's effective Stado configuration through its fleet channelconfig-set— Persist one dotted Stado configuration value on TARGETconfig-unset— Remove one dotted Stado configuration key from TARGET