16 of the 23 error-level hits from a full-repo vale run were real: 'is/are/does/do NOT' and bold 'not' expanded per Microsoft.Contractions, one hyphen-as-negative-number fixed to an en dash per Microsoft.Negative (docs/web-ui/dashboard.md's -45 deg column-header tilt). Where the caps/bold was there for emphasis (contrasting X does this, Y does not), kept the emphasis by bolding the contraction rather than dropping it silently -- 'is not' -> 'isn't', 'does NOT' -> '**doesn't**', etc. docs/tools/swarmctl-cli.md's one genuine hit is generated -- fixed the source doc comment in swarmctl/src/main.rs and regenerated via 'cargo run --bin swarmctl -- markdown-docs', diffed against the old copy first to confirm only the intended line changed. Left 7 hits unfixed, false positives from the rule matching a substring rather than the actual pattern it names: - 4x 'that's instead of that is': every one is the explanatory 'that is' idiom (~= i.e.), not a contractible subject+verb -- 'that's' would misparse as a demonstrative-pronoun contraction and change the sentence's meaning. docs/integrations/forge.md:282, docs/tools/forge.md:260, docs/tools/hivectl.md:243, docs/web-ui/dashboard.md:457 (and the swarmctl-cli.md generated twin of the same category, source left alone for the same reason). - docs/agent-lifecycle/persistence.md:482 -- 'is not' matched inside 'is nothing' (the same has-not/has-nothing substring trap noted before in this doc's own git history). - docs/swarm/ca.md:182 -- 'it is' matched inside the already-correct 'it isn't'. Per #4128. Remaining errors on main after this: Microsoft.Avoid's 26 hits, already tracked + awaiting a house-style ruling on #4041.
3.8 KiB
Command-Line Help for swarmctl
This document contains the help content for the swarmctl command-line program.
Command Overview:
swarmctl↴swarmctl user↴swarmctl user add↴swarmctl user update↴swarmctl user list↴swarmctl completions↴
swarmctl
swarm-level operator CLI
Usage: swarmctl [OPTIONS] <COMMAND>
Subcommands:
user— Manage subjects in the swarm's SSO providercompletions— Generate a shell completion script forswarmctland print it to stdout
Options:
-
--authelia-bin <PATH>— authelia binary used to hash passwords. The argon2 parameters must match the verifier's, so this has to be the configured package rather than whatever is onPATH -
--users-file <PATH>— Host-side path of authelia's users database — that is the path inside the container, prefixed with the container's root.This is the only user store: it's read before every change and written in place, and
swarm-authelia-bridgewrites the same file.
swarmctl user
Manage subjects in the swarm's SSO provider
Usage: swarmctl user <COMMAND>
Subcommands:
add— Add a user, generating a password for themupdate— Change an existing user's attributeslist— List every user in authelia's users database
swarmctl user add
Add a user, generating a password for them
Usage: swarmctl user add [OPTIONS] <USERNAME>
Arguments:
<USERNAME>— Login name. Conservative ASCII only — it's a YAML map key and reaches access-control rules and logs
Options:
--display-name <TEXT>— Name shown in the SSO UI. Defaults to the username--email <ADDRESS>--group <GROUP>— Repeatable
swarmctl user update
Change an existing user's attributes.
Every flag is optional and they compose, so one call can set multiple things at once. Deliberately doesn't touch the password: regenerating a credential is a different intent from editing an attribute, and folded together an attribute edit can invalidate a login by accident.
Usage: swarmctl user update [OPTIONS] <USERNAME>
Arguments:
<USERNAME>— Login name of an existing user
Options:
--display-name <TEXT>— Name shown in the SSO UI--email <ADDRESS>--add-group <GROUP>— Repeatable. Adding a group the user is already in isn't an error--remove-group <GROUP>— Repeatable. Fails if the user isn't in the group — a revocation that reports success without revoking is the failure nobody re-checks
swarmctl user list
List every user in authelia's users database.
Read-only: it never writes the file. Shows every subject in it, including agent identities swarm-authelia-bridge created — one line per user: username, display name, email (if set), groups (if any).
Usage: swarmctl user list
swarmctl completions
Generate a shell completion script for swarmctl and print it to stdout.
Supports bash, zsh, fish, elvish and powershell. The nix package already installs bash/zsh/fish system-wide; this is for ad-hoc or other-shell use.
Dispatched before PathArgs::resolve() for the same reason as markdown-docs: emitting a completion script needs none of the SWARMCTL_AUTHELIA_* deployment env vars, and requiring them would make the package's own build-time invocation fail.
Usage: swarmctl completions <SHELL>
Arguments:
-
<SHELL>— Shell to emit completions forPossible values:
bash,elvish,fish,powershell,zsh
This document was generated automatically by
clap-markdown.