MAQPNADocs

maqpna kill

Kill switch: revoke sessions, agents, users or tokens at the gateway (break-glass)

Govern-o json | yaml

Synopsis#

maqpna kill --gateway URL [-n NS] [--agent A]... [--session S]... [--user U]... [--jti J]... [--all] --reason TEXT [--suspend|--terminate] [--ttl 1h] [--emit-yaml] [--yes]

Flags#

FlagTypeDescriptionDefault
--agentstringagent name or glob (repeatable)none
--allswitchevery session in scope (with -n: the namespace; without: the whole cluster)none
--emit-yamlswitchonly print the AgentRevocation manifest (pipe to kubectl apply -f -); nothing is sent to the gatewaynone
--gatewaystringgateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway)none
--gateway-namespacestringgateway namespace (cluster-wide revocations live there)maqpna-system
--jsonswitchprint the gateway response as JSONnone
--jtistringtoken ID (repeatable)none
-n, --namespacestringnamespace (default: every namespace)none
--namestringAgentRevocation name for --emit-yaml (default kill-<timestamp>)none
--oidc-token-filestringfile holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --tokennone
--reasonstringreason (recorded in the audit ledger and session events)none
--sessionstringsession name or glob (repeatable)none
--suspendswitchalso suspend matching sessionsnone
--terminateswitchalso terminate matching sessions (sandbox and token deleted)none
--tokenstringstatic admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass)none
--ttldurationrevocation lifetime (0 = until removed)none
--userstringon-behalf-of user or glob (repeatable)none
-y, --yesswitchdo not ask for confirmation (required when stdin is not a terminal)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

# Revoke one agent in a namespace and terminate its sessions
maqpna kill --gateway "$GW" -n team-a --agent coder --reason "INC-123" --terminate
# The same as a manifest, for GitOps or when the gateway is unreachable
maqpna kill -n team-a --agent coder --reason "INC-123" --terminate --emit-yaml | kubectl apply -f -

What happens when you run it#

  • Talks to the gateway: --gateway, else MAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
  • Authenticates to the admin API with the token stored by maqpna login, --oidc-token-file, or a static --token (MAQPNA_ADMIN_TOKEN).
  • --yes: do not ask for confirmation (required when stdin is not a terminal).
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna kill.cast