reindeerctl
reindeerctl is the command line client that talks to Reindeer as a machine identity over mutual TLS.
Environment
Section titled “Environment”| Variable | Flag | Meaning |
|---|---|---|
REINDEER_SERVER |
-server |
Server address (https only) |
REINDEER_CERT |
-cert |
Client certificate |
REINDEER_KEY |
-key |
Private key |
REINDEER_CA |
-ca |
The server’s CA certificate |
The bootstrap code is read from REINDEER_BOOTSTRAP_CODE or the first line of standard input, so it never appears in the process list.
Commands
Section titled “Commands”| Command | What it does |
|---|---|
keygen -key key.pem |
Creates an ECDSA P-256 key (file mode 0600, never overwrites). |
bootstrap -key key.pem -out cert.pem [-ca-out ca.pem] |
Swaps the one-time code and a CSR for the first certificate. |
renew -key key.pem -out cert.pem |
Renews the certificate over mutual TLS and replaces the file atomically. |
session open -partition P -mode initial|incremental |
Opens an ingest session (-id, -author, -ts, -ts-format; the defaults are the tweet format). |
session show|commit|abort SESSION |
Shows, commits or aborts a session. |
upload -session S -n N [-zstd] FILE |
Sends one batch with its digest. |
dry-run -session S FILE |
Validates the first 1,000 lines and stores nothing. |
changes [-cursor C] [-limit N] [-wait S] |
Reads the change feed. |
export create [-partition P]... [-from DAY -to DAY] |
Creates an export. |
export show EXPORT | part EXPORT N [-out FILE] |
Shows an export or downloads a part; the record count and SHA-256 are checked. |
get RECORD_ID -partition P -day YYYY-MM-DD |
Point read. |
delete -kind record|author|record_before|batch [-batch N] [FILE] |
Requests a deletion (one id per line). |
deletion show DELETION |
Shows the state of a deletion request. |
status, partitions, keys |
Server status, published partitions, epoch key states. |
audit keys | journal primary|dr [-pin KEY] | erasures [-pin KEY] |
Prints the public keys, verifies a journal chain and erasure certificates. |
Typical machine flow
Section titled “Typical machine flow”- An administrator requests the machine identity, a second person approves, the administrator issues the bootstrap code.
keygen, thenbootstrap.renewfrom a timer before the seven days run out.session open,upload,session commit.- Read, delete and audit commands.