MAQPNADocs

maqpna session exec

Run a command in a session's sandbox through the gateway (governed and audited)

Run agents-o json | yaml

Synopsis#

maqpna session exec S [-n NS] [--language sh] [--timeout 60s] [--workdir DIR] -- COMMAND...

Description#

From the help of maqpna session:

Sessions are AgentSession objects: start creates one, the operator provisions its sandbox and token. describe merges the object, its sandbox and pods with the gateway's view (cost, taint, pending approvals). exec, files and liveview go through the gateway session API and are governed and audited like any tool call (scope tools:maqpna-exec, admin role).

exec exits with the remote command's exit code. wait exits 1 on timeout or when the session fails.

Flags#

FlagTypeDescriptionDefault
--agentstringagent of the session (default: looked up from the AgentSession)none
--codestringcode to run (instead of COMMAND)none
--filestringread the code from FILE (- for stdin)none
--gatewaystringgateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway)none
--languagestringinterpreter: sh, bash, python, ... (default sh for COMMAND, python for --code/--file)none
-n, --namespacestringnamespacedefault
--oidc-token-filestringfile holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --tokennone
--timeoutdurationexecution timeout (whole seconds; the gateway caps it)1m0s
--tokenstringstatic admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass)none
--workdirstringrun COMMAND in this directory of the workspace (shell languages)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna session exec fix-test-7k2 -n team-a -- ls /workspace

What happens when you run it#

  • Talks to the gateway: --gateway, else MAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
  • Authenticates to the admin API with the token stored by maqpna login, --oidc-token-file, or a static --token (MAQPNA_ADMIN_TOKEN).
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna session exec --help.cast

This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.