Documentation

influxd-ctl CLI

The influxd-ctl CLI provides commands for managing your InfluxDB Enterprise cluster. The influxd-ctl utility is available on all InfluxDB Enterprise meta nodes.

Usage

influxd-ctl [global-flags] <command> [command-flags] [arguments]

Commands

Command Description
add-data Add a data node
add-meta Add a meta node
backup Back up a cluster
copy-shard Copy a shard between data nodes
copy-shard-status Show all active copy shard tasks
entropy Manage entropy in a cluster
join Join a meta or data node
kill-copy-shard Abort an in-progress shard copy
ldap Manage LDAP in a cluster
leave Remove a meta or data node
remove-data Remove a data node
remove-meta Remove a meta node
remove-shard Remove a shard from a data node
restore Restore a backup of a cluster
show Show cluster members
show-shards Shows shards in a cluster
node-labels Manage node labels
token Generates a signed JWT token
truncate-shards Truncate current shards
update-data Update a data node

Global flags

Flag Description
-auth-type Authentication type to use (none default, basic, jwt)
-bind Meta node HTTP bind address (default is localhost:8091)
-bind-tls Use TLS
-ca-cert CA certificate used to verify the meta node’s server certificate (ignored without -bind-tls). v1.13.0+
-cert Client certificate for mutual TLS (mTLS), used unless -client-cert is given (ignored without -bind-tls). v1.13.0+
-client-cert Client certificate for mutual TLS (mTLS), overriding -cert (ignored without -bind-tls). v1.13.0+
-client-key Client private key for -client-cert (ignored without -bind-tls). v1.13.0+
-config Configuration file path
-ignore-cert-sanity-checks Present the client certificate even if it fails the checks for whether a client can use it. v1.13.0+
-insecure-certificate Skip file-permission checks on the certificate and private key. v1.13.0+
-k Skip certificate verification (ignored without -bind-tls)
-key Client private key for -cert (ignored without -bind-tls). v1.13.0+
-pwd Password for basic authentication (ignored without -auth-type basic)
-secret JWT shared secret (ignored without -auth-type jwt)
-timeout Override the default timeout of 10s for operations (for example, 30s, 1m). v1.12.3+
-user Username (ignored without -auth-type basic or jwt)

Examples

Bind to a remote meta node

influxd-ctl -bind meta-node-02:8091

Authenticate with JWT

influxd-ctl -auth-type jwt -secret oatclusters

Authenticate with basic authentication

influxd-ctl -auth-type basic -user admin -pwd passw0rd

Override the default timeout

influxd-ctl -timeout 30s show-shards

Connect with mutual TLS (mTLS)

When the cluster’s meta nodes require a client certificate (https-client-auth-type), use -cert and -key to present a client certificate and private key, and use -ca-cert to verify the meta node’s server certificate:

influxd-ctl -bind-tls \
  -cert /etc/ssl/influxd-ctl-client.crt \
  -key /etc/ssl/influxd-ctl-client.key \
  -ca-cert /etc/ssl/cluster-ca.crt \
  show

To present a dedicated client certificate that overrides -cert, use -client-cert and -client-key:

influxd-ctl -bind-tls \
  -client-cert /etc/ssl/influxd-ctl-client.crt \
  -client-key /etc/ssl/influxd-ctl-client.key \
  -ca-cert /etc/ssl/cluster-ca.crt \
  show

For more information about configuring mTLS in a cluster, see Enable mutual TLS (mTLS).

Troubleshoot influxd-ctl authentication


Was this page helpful?

Thank you for your feedback!


InfluxDB OSS 2.9.0: API tokens are hashed by default

Stronger token security in InfluxDB OSS 2.9.0 — tokens are hashed on disk by default. Existing tokens are hashed on first startup and can’t be recovered afterward. Capture any plaintext tokens you still need before you upgrade.

View InfluxDB OSS 2.9.0 release notes

Hashed tokens authenticate exactly like unhashed tokens — clients and integrations keep working.

Also new in 2.9.0:

  • Configurable backup compression
  • Restore support for backups containing hashed tokens
  • Tighter Edge Data Replication queue validation
  • Flux upgrade
  • Compaction reliability improvements

Key enhancements in Explorer 1.9

Explorer 1.9 is now available with InfluxQL support, an AI-assisted Flux to SQL converter (beta), and new live sample data simulators.

View Explorer 1.9 release notes

Explorer 1.9 includes new features and improvements that make it easier to query, visualize, and manage data.

Highlights:

  • Flux to SQL converter (beta): Convert Flux queries to SQL with an AI-assisted converter.
  • InfluxQL support: Query data with InfluxQL in the Data Explorer and dashboards, and save and load InfluxQL queries.
  • InfluxQL visualizations: Render line and bar charts from InfluxQL results with per-tag series grouping.
  • Query error history: Review a history of query errors in the query tool.
  • Live sample data simulators: Generate continuous live sample data with new bird data and signal generator simulators.

For more details, see Explorer 1.9 release notes

InfluxDB 3.10 is now available

InfluxDB 3 Core 3.10 adds an automatic catalog format upgrade, a configurable query-concurrency limit, and processing engine improvements.

Key updates in InfluxDB 3 Core 3.10:

  • Catalog format upgrade: the on-disk catalog automatically upgrades from format v2 to v3 on first 3.10 startup. Migration is one-way—back up your catalog before upgrading.
  • --max-concurrent-queries: limit concurrent queries (adjustable at runtime).
  • GET /ready endpoint for readiness probes.
  • Processing engine: cross-database queries and trigger lockdown flags.

For more information, see the InfluxDB 3 Core release notes.

InfluxDB 3.10 is now available

InfluxDB 3 Enterprise 3.10 adds automated backup and restore, row-level deletions, and user management, with an automatic catalog format upgrade and performance preview improvements.

Key updates in InfluxDB 3 Enterprise 3.10:

  • Catalog format upgrade: the on-disk catalog automatically upgrades from format v2 to v3 on first 3.10 startup. Migration is one-way—back up your catalog before upgrading.
  • Automated backup and restore (beta)
  • Row-level deletions
  • User management (authentication and RBAC) — preview
  • Performance preview improvements

Backup and restore, row-level deletions, and the performance preview require the Enterprise storage engine upgrade (opt-in beta). Beta and preview features are subject to breaking changes and aren’t recommended for production use.

For more information, see the InfluxDB 3 Enterprise release notes

Telegraf Enterprise is now generally available

Telegraf Enterprise is now generally available, along with Telegraf Controller v1.0.

Telegraf Enterprise combines Telegraf Controller, a centralized management console for Telegraf, with official support from InfluxData. Manage configurations, monitor fleet health, and operate tens of thousands of Telegraf agents from a single system.

InfluxDB Docker latest tag changing to InfluxDB 3 Core

On September 15, 2026, the latest tag for InfluxDB Docker images will point to InfluxDB 3 Core. To avoid unexpected upgrades, use specific version tags in your Docker deployments.

If using Docker to install and run InfluxDB, the latest tag will point to InfluxDB 3 Core. To avoid unexpected upgrades, use specific version tags in your Docker deployments. For example, if using Docker to run InfluxDB v2, replace the latest version tag with a specific version tag in your Docker pull command–for example:

docker pull influxdb:2