influxd-ctl CLI

The influxd-ctl CLI provides commands for managing your InfluxDB Enterprise cluster. The influxd-ctl utility is available on all InfluxDB Enterprise meta nodes.

Usage

influxd-ctl [global-flags] <command> [command-flags] [arguments]

Commands

CommandDescription
add-dataAdd a data node
add-metaAdd a meta node
backupBack up a cluster
copy-shardCopy a shard between data nodes
copy-shard-statusShow all active copy shard tasks
entropyManage entropy in a cluster
joinJoin a meta or data node
kill-copy-shardAbort an in-progress shard copy
ldapManage LDAP in a cluster
leaveRemove a meta or data node
remove-dataRemove a data node
remove-metaRemove a meta node
remove-shardRemove a shard from a data node
restoreRestore a backup of a cluster
showShow cluster members
show-shardsShows shards in a cluster
node-labelsManage node labels
tokenGenerates a signed JWT token
truncate-shardsTruncate current shards
update-dataUpdate a data node

Global flags

FlagDescription
-auth-typeAuthentication type to use (none default, basic, jwt)
-bindMeta node HTTP bind address (default is localhost:8091)
-bind-tlsUse TLS
-ca-certCA certificate used to verify the meta node’s server certificate (ignored without -bind-tls). v1.13.0+
-certClient certificate for mutual TLS (mTLS), used unless -client-cert is given (ignored without -bind-tls). v1.13.0+
-client-certClient certificate for mutual TLS (mTLS), overriding -cert (ignored without -bind-tls). v1.13.0+
-client-keyClient private key for -client-cert (ignored without -bind-tls). v1.13.0+
-configConfiguration file path
-ignore-cert-sanity-checksPresent the client certificate even if it fails the checks for whether a client can use it. v1.13.0+
-insecure-certificateSkip file-permission checks on the certificate and private key. v1.13.0+
-kSkip certificate verification (ignored without -bind-tls)
-keyClient private key for -cert (ignored without -bind-tls). v1.13.0+
-pwdPassword for basic authentication (ignored without -auth-type basic)
-secretJWT shared secret (ignored without -auth-type jwt)
-timeoutOverride the default timeout of 10s for operations (for example, 30s, 1m). v1.12.3+
-userUsername (ignored without -auth-type basic or jwt)

Examples

Bind to a remote meta node

influxd-ctl -bind meta-node-02:8091

Authenticate with JWT

influxd-ctl -auth-type jwt -secret oatclusters

Authenticate with basic authentication

influxd-ctl -auth-type basic -user admin -pwd passw0rd

Override the default timeout

influxd-ctl -timeout 30s show-shards

Connect with mutual TLS (mTLS)

When the cluster’s meta nodes require a client certificate (https-client-auth-type), use -cert and -key to present a client certificate and private key, and use -ca-cert to verify the meta node’s server certificate:

influxd-ctl -bind-tls \
  -cert /etc/ssl/influxd-ctl-client.crt \
  -key /etc/ssl/influxd-ctl-client.key \
  -ca-cert /etc/ssl/cluster-ca.crt \
  show

To present a dedicated client certificate that overrides -cert, use -client-cert and -client-key:

influxd-ctl -bind-tls \
  -client-cert /etc/ssl/influxd-ctl-client.crt \
  -client-key /etc/ssl/influxd-ctl-client.key \
  -ca-cert /etc/ssl/cluster-ca.crt \
  show

For more information about configuring mTLS in a cluster, see Enable mutual TLS (mTLS).

Troubleshoot influxd-ctl authentication


Was this page helpful?

Thank you for your feedback!