maqpna kill
Kill switch: revoke sessions, agents, users or tokens at the gateway (break-glass)
Synopsis#
maqpna kill --gateway URL [-n NS] [--agent A]... [--session S]... [--user U]... [--jti J]... [--all] --reason TEXT [--suspend|--terminate] [--ttl 1h] [--emit-yaml] [--yes]Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--agent | string | agent name or glob (repeatable) | none |
--all | switch | every session in scope (with -n: the namespace; without: the whole cluster) | none |
--emit-yaml | switch | only print the AgentRevocation manifest (pipe to kubectl apply -f -); nothing is sent to the gateway | none |
--gateway | string | gateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway) | none |
--gateway-namespace | string | gateway namespace (cluster-wide revocations live there) | maqpna-system |
--json | switch | print the gateway response as JSON | none |
--jti | string | token ID (repeatable) | none |
-n, --namespace | string | namespace (default: every namespace) | none |
--name | string | AgentRevocation name for --emit-yaml (default kill-<timestamp>) | none |
--oidc-token-file | string | file holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --token | none |
--reason | string | reason (recorded in the audit ledger and session events) | none |
--session | string | session name or glob (repeatable) | none |
--suspend | switch | also suspend matching sessions | none |
--terminate | switch | also terminate matching sessions (sandbox and token deleted) | none |
--token | string | static admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass) | none |
--ttl | duration | revocation lifetime (0 = until removed) | none |
--user | string | on-behalf-of user or glob (repeatable) | none |
-y, --yes | switch | do not ask for confirmation (required when stdin is not a terminal) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
# Revoke one agent in a namespace and terminate its sessions
maqpna kill --gateway "$GW" -n team-a --agent coder --reason "INC-123" --terminate
# The same as a manifest, for GitOps or when the gateway is unreachable
maqpna kill -n team-a --agent coder --reason "INC-123" --terminate --emit-yaml | kubectl apply -f -What happens when you run it#
- Talks to the gateway:
--gateway, elseMAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context). - Authenticates to the admin API with the token stored by
maqpna login,--oidc-token-file, or a static--token(MAQPNA_ADMIN_TOKEN). --yes: do not ask for confirmation (required when stdin is not a terminal).- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |