Doctor
vagaris doctor
vagaris doctor --repair
vagaris doctor --repair --yes
vagaris doctor --json
doctor reads the instance config and runs its checks in a fixed order. vagaris run runs the same checks (with repair and --yes enabled) and refuses to start the server if any fails.
Checks
| # | Check | What passes |
|---|---|---|
| 1 | Config file | The config exists and parses. Fails first and stops the rest if not — run vagaris onboard. |
| 2 | Deployment/auth mode | The server.deploymentMode, exposure, bind and auth settings are consistent |
| 3 | Agent JWT secret | VAGARIS_AGENT_JWT_SECRET is present in the environment or the instance .env (repairable: generates it). An install that only carries the legacy PAPERCLIP_AGENT_JWT_SECRET passes with a warning, and --repair adds the canonical key with the same value |
| 4 | Secrets adapter | The configured secrets provider is usable, including its key file or AWS settings (repairable) |
| 5 | Storage | The storage provider's directory or bucket settings are valid (repairable where local) |
| 6 | Database | The embedded or external database can be reached (repairable where local) |
| 7 | LLM provider | Reports the instance llm setting |
| 8 | Log directory | The log directory exists and is writable (repairable) |
| 9 | Server port | The configured port is free or held by this instance |
Each result is pass, warn or fail with a message; failing or warning checks print a repair hint naming the command to run (for example vagaris configure --section database).
Repair
With --repair, a check that can repair itself asks Repair "<name>"? after failing; --yes answers yes to all. After a repair the instance .env is reloaded and the check runs again, so the printed result is the post-repair state. Repairs never run in --json mode.
JSON output
{
"passed": 8,
"warned": 1,
"failed": 0,
"checks": [
{ "name": "Config file", "status": "pass", "message": "..." },
{ "name": "LLM provider", "status": "warn", "message": "...", "repairHint": "..." }
]
}
Nothing else is written to stdout in JSON mode, so the output can be parsed directly. doctor itself does not set a non-zero exit code on failed checks; check failed in the JSON. vagaris run exits 1 when failed > 0.
Other doctors
| Command | Scope |
|---|---|
vagaris node doctor | This machine's enrolment, attestation, health, heartbeat recency and platform (Node Enrolment) |
vagaris secrets doctor --company-id <id> | Secret provider health through the API |
vagaris env-lab doctor | Prerequisites for the SSH environment fixture |
vagaris support-bundle runs a wider set of checks than doctor — it adds server reachability, protocol version, node identity and lease state — and includes their results in the bundle. See Support.