STRAZAdocs

strazactl

Straza admin CLI

Synopsis

A command that talks to strazad goes to --server, else $STRAZA_SERVER, else the server of your strazactl login. It authenticates with that login, or with an admin API token when STRAZA_API_TOKEN holds one. With a token, every admin call sends it in place of the login, and one line on stderr says so. strazactl login, connect and disconnect act as a person and refuse to run while the token is set, and strazactl logout still ends the stored login.

Inside a coding agent, a command that changes Straza refuses to run on your login, because the agent would act as you. Reads and checks such as policy simulate still work. For automation, use an admin API token in STRAZA_API_TOKEN. An agent proposes config changes through the built-in straza MCP server’s drafting tools. strazactl knows it runs inside a coding agent from the environment variables that Claude Code, the Gemini CLI and the npm build of Codex set for the commands they run.

Every command exits 0 when it did its job and 1 when it did not. An unknown verb exits 1 too. strazactl drafts and strazactl policy diff name other exit codes in their help. A retired verb exits 2 and names what replaced it.

Options

      --server string   strazad base URL (overrides $STRAZA_SERVER and the server you logged into)

Commands

Search documentation

Search page titles, commands, and article text.

↑ ↓ Choose resultEnter OpenEsc Close