Enterprise Deployment
The Deploy section covers the server (Overview, Deployment Modes, Docker, Database, Secrets, Storage). This page is the CLI side of the same work.
Choose a mode at onboarding
vagaris onboard --bind lan
vagaris onboard --bind tailnet
--bind selects the reachability preset: loopback (trusted local, no login), lan (bind all interfaces, login required), tailnet (bind the Tailscale address, login required). Without --yes the wizard also asks for the database, LLM provider, logging, storage and secrets settings. With --yes --bind lan|tailnet the quickstart defaults are seeded from the environment — DATABASE_URL, VAGARIS_PUBLIC_URL, VAGARIS_DEPLOYMENT_MODE, VAGARIS_DEPLOYMENT_EXPOSURE, VAGARIS_STORAGE_*, VAGARIS_SECRETS_*, VAGARIS_DB_BACKUP_* and the rest listed on Environment Variables. If Tailscale is not detected during setup the config stays on loopback until VAGARIS_TAILNET_BIND_HOST is set.
Change a section later:
vagaris configure --section server
vagaris configure --section secrets
vagaris configure --section storage
Allow private hostnames
In authenticated private mode the server only answers for hostnames it knows:
vagaris allowed-hostname my-machine.tailnet.ts.net
Or set VAGARIS_ALLOWED_HOSTNAMES as a comma-separated list before onboarding. Login or redirect errors on a private hostname are the symptom of a missing entry.
Bootstrap the first administrator
vagaris auth bootstrap-ceo --expires-hours 24 --base-url https://vagaris.example.com
Creates a one-time invite for the first instance admin and prints its URL. The base URL comes from --base-url, then VAGARIS_PUBLIC_URL/VAGARIS_AUTH_PUBLIC_BASE_URL/BETTER_AUTH_URL, then the config's explicit public URL, then the bind host. --force issues a new invite even if an admin exists. vagaris run does this automatically on first start when the mode is authenticated and the database is the embedded one.
Render the deployment environment
vagaris env
Prints every deployment variable the current config implies, required ones first, each marked set, default or missing with its source. Use it to build the environment for a container or a systemd unit, and to spot a required value that is still missing before starting.
Secrets
vagaris secrets providers --company-id <company-id>
vagaris secrets create --company-id <company-id> --name anthropic-api-key --value-env ANTHROPIC_API_KEY
vagaris secrets link --company-id <company-id> --name prod-stripe-key --provider aws_secrets_manager --external-ref <provider-ref>
vagaris secrets declarations --company-id <company-id> --kind secret
vagaris secrets migrate-inline-env --company-id <company-id>
vagaris secrets migrate-inline-env --company-id <company-id> --apply
vagaris secrets doctor --company-id <company-id>
configure --section secrets sets the deployment-level provider used as the fallback; per-company provider vaults are managed in the UI. migrate-inline-env previews, and with --apply performs, the move of inline sensitive agent env values into secret references. Details on Secrets.
Backups
vagaris db:backup --dir /var/backups/vagaris --retention-days 30 --json
Scheduled backups are configured in database.backup (vagaris configure --section database). db:backup takes a one-off backup with the same pruning window.
Fleet machines as nodes
Enrol each machine that will host governed work with vagaris node enroll, verify with vagaris node doctor, and retire it with vagaris node revoke. Leases can then be bound to a specific machine. See Node Enrolment and Hybrid Execution.
Plugins
vagaris plugin list
vagaris plugin install @acme/plugin-linear@1.2
vagaris plugin inspect <plugin-key>
vagaris plugin disable <plugin-key>
vagaris plugin enable <plugin-key>
vagaris plugin uninstall <plugin-key> --force
vagaris plugin examples
vagaris plugin init @acme/plugin-hello --template default
plugin install accepts a local path or an npm package, optionally pinned; --local forces local-path semantics and --version pins. uninstall --force hard-purges the plugin's state and config. plugin init scaffolds a new plugin project (--output, --template, --category, --display-name, --description, --author, --sdk-path).
Operational pauses
vagaris routines disable-all --company-id <company-id>
Pauses every non-archived routine for a company in the local instance — before a migration, a restore, or an incident.
Telemetry and privacy
Set VAGARIS_TELEMETRY_DISABLED=1 in the deployment environment, or telemetry.enabled: false in the config. What telemetry collects and what it never collects is described in the repository README.
Support bundles
Before opening a support request from a production instance, run vagaris support-bundle --out bundle.json on the host. Every value is redacted and environment variables appear by name only. See Support.