hyperhive/docs/tools/swarmctl-cli.md
iris f22791b7a4 docs: clear the remaining error-level vale lints
Per #4128 (mara: allow-everywhere false positives go in a central
list, otherwise fix in source). Testing surfaced better fixes than
the plan posted on the issue:

- 5x Microsoft.Contractions 'that is' idiom false positives: adding
  the missing comma ("that is, ...") both reads better and satisfies
  the rule's own negative-lookahead, so no suppression is needed at
  all. Fixed in docs/integrations/forge.md, docs/tools/forge.md,
  docs/tools/hivectl.md, docs/web-ui/dashboard.md, and
  swarmctl-cli.md's generated source (swarmctl/src/main.rs, doc
  comment regenerated via markdown-docs).
- persistence.md's 'is not' matching inside 'is nothing': reworded to
  'there'\''s nothing' rather than add any exception -- dodges the trap
  and is a genuine contraction besides.
- ca.md's 'it is' matching inside the already-correct 'it isn'\''t':
  tried a central .vale.ini TokenIgnores entry first per the
  allow-everywhere framing, but testing against the real file (not
  just a synthetic snippet) found it silently fails to suppress
  whenever markdown emphasis syntax appears earlier in the same
  file -- an offset-drift bug in how Vale applies TokenIgnores, not
  a config mistake. Reworded to "it'\''s not" instead, same fix
  shape as persistence.md.
- config.md's 3 genuine Microsoft.Avoid 'backend' exceptions (already
  flagged and accepted on #4139 -- an actually-pluggable LLM API
  provider, matching the nix option's own name, not one internal
  system to name): scoped inline vale suppression around just that
  section, since this one really is context-specific rather than a
  rule bug.

Verified: fresh 'vale docs/ --minAlertLevel=error' is 0 errors AND
0 warnings (was 10 errors). nix fmt 0 changed beyond the edits
themselves. pre-push lints (tracker-tag/comment-block/doc-pointer)
clean. cargo clippy -p swarmctl -- -D warnings clean. Diffed the
regenerated swarmctl-cli.md against the old copy to confirm only
the intended line moved.
2026-09-09 22:55:28 +02:00

3.8 KiB

Command-Line Help for swarmctl

This document contains the help content for the swarmctl command-line program.

Command Overview:

swarmctl

swarm-level operator CLI

Usage: swarmctl [OPTIONS] <COMMAND>

Subcommands:
  • user — Manage subjects in the swarm's SSO provider
  • completions — Generate a shell completion script for swarmctl and print it to stdout
Options:
  • --authelia-bin <PATH> — authelia binary used to hash passwords. The argon2 parameters must match the verifier's, so this has to be the configured package rather than whatever is on PATH

  • --users-file <PATH> — Host-side path of authelia's users database — that is, the path inside the container, prefixed with the container's root.

    This is the only user store: it's read before every change and written in place, and swarm-authelia-bridge writes the same file.

swarmctl user

Manage subjects in the swarm's SSO provider

Usage: swarmctl user <COMMAND>

Subcommands:
  • add — Add a user, generating a password for them
  • update — Change an existing user's attributes
  • list — List every user in authelia's users database

swarmctl user add

Add a user, generating a password for them

Usage: swarmctl user add [OPTIONS] <USERNAME>

Arguments:
  • <USERNAME> — Login name. Conservative ASCII only — it's a YAML map key and reaches access-control rules and logs
Options:
  • --display-name <TEXT> — Name shown in the SSO UI. Defaults to the username
  • --email <ADDRESS>
  • --group <GROUP> — Repeatable

swarmctl user update

Change an existing user's attributes.

Every flag is optional and they compose, so one call can set multiple things at once. Deliberately doesn't touch the password: regenerating a credential is a different intent from editing an attribute, and folded together an attribute edit can invalidate a login by accident.

Usage: swarmctl user update [OPTIONS] <USERNAME>

Arguments:
  • <USERNAME> — Login name of an existing user
Options:
  • --display-name <TEXT> — Name shown in the SSO UI
  • --email <ADDRESS>
  • --add-group <GROUP> — Repeatable. Adding a group the user is already in isn't an error
  • --remove-group <GROUP> — Repeatable. Fails if the user isn't in the group — a revocation that reports success without revoking is the failure nobody re-checks

swarmctl user list

List every user in authelia's users database.

Read-only: it never writes the file. Shows every subject in it, including agent identities swarm-authelia-bridge created — one line per user: username, display name, email (if set), groups (if any).

Usage: swarmctl user list

swarmctl completions

Generate a shell completion script for swarmctl and print it to stdout.

Supports bash, zsh, fish, elvish and powershell. The nix package already installs bash/zsh/fish system-wide; this is for ad-hoc or other-shell use.

Dispatched before PathArgs::resolve() for the same reason as markdown-docs: emitting a completion script needs none of the SWARMCTL_AUTHELIA_* deployment env vars, and requiring them would make the package's own build-time invocation fail.

Usage: swarmctl completions <SHELL>

Arguments:
  • <SHELL> — Shell to emit completions for

    Possible values: bash, elvish, fish, powershell, zsh


This document was generated automatically by clap-markdown.