noset is the gate: one binary for the CLI and the daemon.
| Command |
What it does |
noset login [--server URL] [--ca-cert FILE] |
Connect this server to Noset. Without --server: Noset Cloud. |
noset login --token-file FILE |
Connect with an enrollment token, without a browser (- reads standard input). |
noset logout [--force] |
Disconnect this server. Its evidence stays. |
noset status |
The connection, the rules in force, running agents. |
noset run [flags] -- COMMAND |
Run a command, usually an agent, inside the sandbox. |
noset pending [--json] |
Requests waiting for approval. |
noset verify FILE |
Check an evidence file offline. |
noset daemon |
Keep the link to Noset while no agent runs (what noset.service runs). |
noset version |
The version and the commit it was built from. |
| Flag |
|
--credential NAME |
Give the agent a key through the gate: the key stays in the gate’s environment, the agent sees a placeholder. |
--workspace DIR |
The folder shared at /workspace (default: the current directory; never $HOME or /). |
--agent NAME |
The agent’s name in approvals and evidence (default: the command’s name). |
-e KEY=VALUE |
An environment variable for the agent. The host environment is never passed in. |
--cpus N, --memory MIB |
The sandbox’s size. |
| Path |
|
/usr/local/bin/noset |
the binary |
/var/lib/noset/gate |
the gate’s keys, login and evidence (only its user can read it) |
/var/lib/noset/images |
the sandbox’s kernel, root file system and tools disk |
/etc/systemd/system/noset.service |
the daemon |