influxd-ctl CLI
The influxd-ctl CLI provides commands for managing your InfluxDB Enterprise cluster.
The influxd-ctl utility is available on all InfluxDB Enterprise
meta nodes.
Usage
influxd-ctl [global-flags] <command> [command-flags] [arguments]Commands
| Command | Description |
|---|---|
| add-data | Add a data node |
| add-meta | Add a meta node |
| backup | Back up a cluster |
| copy-shard | Copy a shard between data nodes |
| copy-shard-status | Show all active copy shard tasks |
| entropy | Manage entropy in a cluster |
| join | Join a meta or data node |
| kill-copy-shard | Abort an in-progress shard copy |
| ldap | Manage LDAP in a cluster |
| leave | Remove a meta or data node |
| remove-data | Remove a data node |
| remove-meta | Remove a meta node |
| remove-shard | Remove a shard from a data node |
| restore | Restore a backup of a cluster |
| show | Show cluster members |
| show-shards | Shows shards in a cluster |
| node-labels | Manage node labels |
| token | Generates a signed JWT token |
| truncate-shards | Truncate current shards |
| update-data | Update a data node |
Global flags
| Flag | Description |
|---|---|
-auth-type |
Authentication type to use (none default, basic, jwt) |
-bind |
Meta node HTTP bind address (default is localhost:8091) |
-bind-tls |
Use TLS |
-ca-cert |
CA certificate used to verify the meta node’s server certificate (ignored without -bind-tls). v1.13.0+ |
-cert |
Client certificate for mutual TLS (mTLS), used unless -client-cert is given (ignored without -bind-tls). v1.13.0+ |
-client-cert |
Client certificate for mutual TLS (mTLS), overriding -cert (ignored without -bind-tls). v1.13.0+ |
-client-key |
Client private key for -client-cert (ignored without -bind-tls). v1.13.0+ |
-config |
Configuration file path |
-ignore-cert-sanity-checks |
Present the client certificate even if it fails the checks for whether a client can use it. v1.13.0+ |
-insecure-certificate |
Skip file-permission checks on the certificate and private key. v1.13.0+ |
-k |
Skip certificate verification (ignored without -bind-tls) |
-key |
Client private key for -cert (ignored without -bind-tls). v1.13.0+ |
-pwd |
Password for basic authentication (ignored without -auth-type basic) |
-secret |
JWT shared secret (ignored without -auth-type jwt) |
-timeout |
Override the default timeout of 10s for operations (for example, 30s, 1m). v1.12.3+ |
-user |
Username (ignored without -auth-type basic or jwt) |
Examples
- Bind to a remote meta node
- Authenticate with JWT
- Authenticate with basic authentication
- Override the default timeout
- Connect with mutual TLS (mTLS)
Bind to a remote meta node
influxd-ctl -bind meta-node-02:8091Authenticate with JWT
influxd-ctl -auth-type jwt -secret oatclustersAuthenticate with basic authentication
influxd-ctl -auth-type basic -user admin -pwd passw0rdOverride the default timeout
influxd-ctl -timeout 30s show-shardsConnect with mutual TLS (mTLS)
When the cluster’s meta nodes require a client certificate
(https-client-auth-type),
use -cert and -key to present a client certificate and private key, and use
-ca-cert to verify the meta node’s server certificate:
influxd-ctl -bind-tls \
-cert /etc/ssl/influxd-ctl-client.crt \
-key /etc/ssl/influxd-ctl-client.key \
-ca-cert /etc/ssl/cluster-ca.crt \
showTo present a dedicated client certificate that overrides -cert, use
-client-cert and -client-key:
influxd-ctl -bind-tls \
-client-cert /etc/ssl/influxd-ctl-client.crt \
-client-key /etc/ssl/influxd-ctl-client.key \
-ca-cert /etc/ssl/cluster-ca.crt \
showFor more information about configuring mTLS in a cluster, see Enable mutual TLS (mTLS).
Was this page helpful?
Thank you for your feedback!
Support and feedback
Thank you for being part of our community! We welcome and encourage your feedback and bug reports for InfluxDB Enterprise v1 and this documentation. To find support, use the following resources:
Customers with an annual or support contract can contact InfluxData Support.