MAQPNADocs

maqpna desk

Open the approvals inbox and dev window in your browser (what MAQPNA Desk shows)

Govern-o json | yaml

Synopsis#

maqpna desk [--gateway URL] [--token T | --oidc-token-file F] [--approver NAME] [--addr 127.0.0.1:0]
            [--json] [--no-open] [--no-port-forward] [--operator-namespace NS] [--service NAME] [--dev-dir DIR] [--no-dev]

Description#

Serves the approvals inbox and the dev window on 127.0.0.1 (a random port by default) and opens it in the browser. The URL carries a token generated for this launch; requests without it are refused. The MAQPNA desktop apps run "maqpna desk --json --exit-on-stdin-eof" and show the page in a native window.

The inbox lists pending approvals from the gateway (what the agent wants to call, the policy rule that asked for a human, the argument preview, a risk summary and any amount) and approves or denies them through the gateway's admin API. Votes use your own admin-API credential, as "maqpna approvals approve|deny" does: the OIDC token stored by "maqpna login" (the gateway takes your identity from it), an --oidc-token-file, or the static --token with --approver NAME (break-glass). Denying needs a reason. Nothing is ever approved without a click.

The gateway is --gateway, $MAQPNA_GATEWAY_URL or the context's gateway; else a kubectl port-forward to the gateway Service of the current kube context (as "maqpna console"); else the local gateway of "maqpna dev up" while it runs.

The dev window starts and stops "maqpna dev up" (state in --dev-dir) and shows the live timeline of the last "maqpna dev run" session, or any other session.

--json prints {"url","addr","token","version"} once and does not open a browser.

Flags#

FlagTypeDescriptionDefault
--addrstringlisten address (loopback only; port 0: a free port)127.0.0.1:0
--approverstringapprover name recorded with a static admin token (env MAQPNA_APPROVER; an OIDC token names you itself)$USER
--dev-dirstringstate directory of the dev window's maqpna dev up~/.config/maqpna/dev
--exit-on-stdin-eofswitchexit when stdin closes (the desktop apps hold it open)none
--gatewaystringgateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway)none
--jsonswitchprint the URL and token as JSON and do not open a browser (for the desktop apps)none
--no-devswitchhide the dev windownone
--no-openswitchprint the URL instead of opening a browsernone
--no-port-forwardswitchwithout a gateway URL, do not port-forward to the cluster's gateway Servicenone
--oidc-token-filestringfile holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --tokennone
--operator-namespacestringnamespace of the gateway Service (port-forward)maqpna-system
--servicestringgateway Service name (port-forward; default: found by label)none
--tokenstringstatic admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

# Approve or deny held tool calls from a local page
maqpna desk
maqpna desk --gateway https://gateway.example.eu --no-open
maqpna desk --no-dev --oidc-token-file token.txt

What happens when you run it#

  • Talks to the gateway: --gateway, else MAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
  • Authenticates to the admin API with the token stored by maqpna login, --oidc-token-file, or a static --token (MAQPNA_ADMIN_TOKEN).
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna desk.cast