strazactl drafts
Check, store, review and publish drafts of changes to MCP servers, roles, access rows and policy sets
On this page
Synopsis
A draft holds App, Role, PolicySet and Removal documents that publish together or not at all. Straza checks every draft against live state, and nothing in a draft changes live state until a person publishes it with strazactl drafts publish.
Exit status: 0 when the command did its job and, for check, create, update, revert, rebase and publish, the documents can be published as they stand. 1 when the server looked and said no: the verdict refuses, the server refused an update, a revert, a rebase, a contact or a publish, or a contacted server did not answer. 2 when the command could not do its job, for usage, a file, the credential, a refusal of the caller, the network or the server. list, show and discard never exit 1.
Inside a coding agent on your strazactl login, check, list and show run, and the verbs that change a draft refuse to run. With STRAZA_API_TOKEN set they run as that token, and publish then meets the server’s refusal, because only a person publishes.
strazactl drafts [flags]
Options inherited from parent commands
--server string strazad base URL (overrides $STRAZA_SERVER and the server you logged into)
See also
- strazactl: Straza admin CLI
- strazactl drafts check: Check documents against live state and print the verdict, storing nothing
- strazactl drafts contact: Contact a remote server a draft proposes, once and with no credential, and list its tools
- strazactl drafts create: Store the documents as a new draft and print its verdict
- strazactl drafts discard: Discard an open draft, which changes nothing live
- strazactl drafts list: List drafts, newest first, the open ones unless --state names others
- strazactl drafts publish: Publish a draft whole, after acknowledging every line that widens access
- strazactl drafts rebase: Check a draft again on live state, keeping the fields it changes and taking every other field from live
- strazactl drafts revert: Make a new draft that undoes a published one, checked like any other
- strazactl drafts show: Show a draft: who proposed it, each object against live state, its verdict and who gains what
- strazactl drafts update: Replace an open draft’s documents with a new revision and print its verdict