Skip to content

Agent flags

The Agent is the shardkeep-agent binary in the agent image.

Flag Default Meaning
-controller The Controller’s session address, host:port, such as shardkeep.example.com:8443. Required
-enroll the -controller host on port 8444 The Controller’s enrollment address
-token $SHARDKEEP_ENROLL_TOKEN The one-time enrollment token, needed on the first start only
-enroll-token-file Read the token from this file, waiting until it appears (the Agent bundled with a Controller)
-state-dir /var/lib/shardkeep-agent The Agent’s identity (its key and certificate) and local state. Keep this volume
-backup-dir <state-dir>/backups Where backups to Node-directory destinations go. Mount a disk or an NFS export here
-docker-host $DOCKER_HOST, else unix:///var/run/docker.sock The Docker Engine to use
-proc-dir /host/proc The host’s /proc, for CPU and memory figures (falls back to /proc)
-disk-path / A path on the file system that holds Docker’s data, for disk figures
-self-container auto The Agent’s own container, joined to the servers’ network so the Agent can reach them. auto detects it; empty disables it
-ping-published-host Check servers on their published ports on this host instead of over the servers’ network, for engines the Agent cannot share a network with
-version Print the version and exit

The Agent container needs:

  • /var/run/docker.sock: the Docker Engine. This is root-equivalent access: run only the official, signed image.
  • A volume at /var/lib/shardkeep-agent: its identity and state.
  • /proc read-only at /host/proc: the host’s CPU and memory.