maqpna desk
Open the approvals inbox and dev window in your browser (what MAQPNA Desk shows)
Synopsis#
maqpna desk [--gateway URL] [--token T | --oidc-token-file F] [--approver NAME] [--addr 127.0.0.1:0]
[--json] [--no-open] [--no-port-forward] [--operator-namespace NS] [--service NAME] [--dev-dir DIR] [--no-dev]Description#
Serves the approvals inbox and the dev window on 127.0.0.1 (a random port by default) and opens it in the browser. The URL carries a token generated for this launch; requests without it are refused. The MAQPNA desktop apps run "maqpna desk --json --exit-on-stdin-eof" and show the page in a native window.
The inbox lists pending approvals from the gateway (what the agent wants to call, the policy rule that asked for a human, the argument preview, a risk summary and any amount) and approves or denies them through the gateway's admin API. Votes use your own admin-API credential, as "maqpna approvals approve|deny" does: the OIDC token stored by "maqpna login" (the gateway takes your identity from it), an --oidc-token-file, or the static --token with --approver NAME (break-glass). Denying needs a reason. Nothing is ever approved without a click.
The gateway is --gateway, $MAQPNA_GATEWAY_URL or the context's gateway; else a kubectl port-forward to the gateway Service of the current kube context (as "maqpna console"); else the local gateway of "maqpna dev up" while it runs.
The dev window starts and stops "maqpna dev up" (state in --dev-dir) and shows the live timeline of the last "maqpna dev run" session, or any other session.
--json prints {"url","addr","token","version"} once and does not open a browser.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--addr | string | listen address (loopback only; port 0: a free port) | 127.0.0.1:0 |
--approver | string | approver name recorded with a static admin token (env MAQPNA_APPROVER; an OIDC token names you itself) | $USER |
--dev-dir | string | state directory of the dev window's maqpna dev up | ~/.config/maqpna/dev |
--exit-on-stdin-eof | switch | exit when stdin closes (the desktop apps hold it open) | none |
--gateway | string | gateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway) | none |
--json | switch | print the URL and token as JSON and do not open a browser (for the desktop apps) | none |
--no-dev | switch | hide the dev window | none |
--no-open | switch | print the URL instead of opening a browser | none |
--no-port-forward | switch | without a gateway URL, do not port-forward to the cluster's gateway Service | none |
--oidc-token-file | string | file holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --token | none |
--operator-namespace | string | namespace of the gateway Service (port-forward) | maqpna-system |
--service | string | gateway Service name (port-forward; default: found by label) | none |
--token | string | static admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
# Approve or deny held tool calls from a local page
maqpna desk
maqpna desk --gateway https://gateway.example.eu --no-open
maqpna desk --no-dev --oidc-token-file token.txtWhat happens when you run it#
- Talks to the gateway:
--gateway, elseMAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context). - Authenticates to the admin API with the token stored by
maqpna login,--oidc-token-file, or a static--token(MAQPNA_ADMIN_TOKEN). - Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |