Skip to content

The noset command

noset is the gate: one binary for the CLI and the daemon.

Command What it does
noset login [--server URL] [--ca-cert FILE] Connect this server to Noset. Without --server: Noset Cloud.
noset login --token-file FILE Connect with an enrollment token, without a browser (- reads standard input).
noset logout [--force] Disconnect this server. Its evidence stays.
noset status The connection, the rules in force, running agents.
noset run [flags] -- COMMAND Run a command, usually an agent, inside the sandbox.
noset pending [--json] Requests waiting for approval.
noset verify FILE Check an evidence file offline.
noset daemon Keep the link to Noset while no agent runs (what noset.service runs).
noset version The version and the commit it was built from.
Flag
--credential NAME Give the agent a key through the gate: the key stays in the gate’s environment, the agent sees a placeholder.
--workspace DIR The folder shared at /workspace (default: the current directory; never $HOME or /).
--agent NAME The agent’s name in approvals and evidence (default: the command’s name).
-e KEY=VALUE An environment variable for the agent. The host environment is never passed in.
--cpus N, --memory MIB The sandbox’s size.
Path
/usr/local/bin/noset the binary
/var/lib/noset/gate the gate’s keys, login and evidence (only its user can read it)
/var/lib/noset/images the sandbox’s kernel, root file system and tools disk
/etc/systemd/system/noset.service the daemon