mirror of
https://github.com/openclaw/openclaw.git
synced 2026-09-28 14:12:28 +08:00
* fix(gateway): support pinned daemon runtime paths * fix(node): preserve pinned runtime on reinstall * test(cli): update daemon coverage runtime mock * refactor(daemon): keep runtime pin value type private Remove the unused export; the type remains owned by pin state. * refactor(daemon): isolate runtime pin type contracts Break the service contract cycle with a dependency-free type leaf. Preserve runtime behavior and all original contributor ancestry. * fix(daemon): preserve runtime pin intent across setup callers Carry inspected pin revisions through configure, onboarding and Doctor installs. Keep automatic runtime choices unpinned and explicit runtime resets intentional. * perf(ui): keep attachment caching out of startup vendor code Let the lazy text-attachment consumer own the Lit cache directive chunk. Preserve existing compression and startup budgets. * fix(ci): restore native fixture qualification * test: adopt canonical fixture repairs * fix(ci): align Slack contracts and cold fixture inputs Adopt the published Slack lifecycle type and approval receiver repair. Include the tracked plugin-source helper in cold preparation fixtures. Co-authored-by: Peter Steinberger <steipete@gmail.com> * refactor(slack): adopt canonical ingress lifecycle type * test(qwen): control elapsed time in request fixture * test(ui): keep archive failure roster reads unavailable --------- Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com> Co-authored-by: Tuyen <6668014+darkamenosa@users.noreply.github.com> Co-authored-by: Peter Steinberger <steipete@gmail.com>
4.8 KiB
4.8 KiB
summary, read_when, title
| summary | read_when | title | ||
|---|---|---|---|---|
| CLI reference for `openclaw daemon` (legacy alias for gateway service management) |
|
Daemon |
openclaw daemon
Legacy alias for Gateway service management. openclaw daemon ... maps to the same service-control commands as openclaw gateway .... Prefer openclaw gateway for current docs and examples.
Usage
openclaw daemon status
openclaw daemon install
openclaw daemon start
openclaw daemon stop
openclaw daemon restart
openclaw daemon uninstall
Subcommands and options
| Subcommand | Options |
|---|---|
status |
--url, --port, --token, --password, --timeout, --no-probe, --require-rpc, --deep, --json |
install |
--port, --runtime <node|bun>, --runtime-path <path>, --token, --wrapper <path>, --force, --json |
uninstall |
--json |
start |
--json |
stop |
--force, --json, --disable (launchd only: suppress KeepAlive/RunAtLoad until next start) |
restart |
--force, --safe, --skip-deferral, --wait <duration>, --json |
--json is accepted before or after every subcommand (for example, daemon --json status and daemon status --json).
status: shows service install state (launchd/systemd/schtasks) and probes Gateway health.status --port <port>: selects a local Gateway using the invoking CLI config for auth and TLS. Cannot combine with--url. Native service details remain diagnostic-only.install: installs and starts the service.--forcereinstalls an existing install and may restart a running Gateway. Finish offline configuration and runtime repairs before installation.- Node is the primary, default, and recommended service runtime. Bun 1.4+ with WAL-reset-safe
node:sqliteis available as an explicit opt-in withinstall --runtime bun. restart --safe: asks the running Gateway to preflight active work and schedule one coalesced restart after work drains, bounded to 5 minutes. When that budget expires, the restart is forced anyway. Plainrestartnormally uses the service manager directly. On Windows, commands launched from a Gateway service automatically use the safe restart path. Explicit lifecycle controls retain their behavior.--forceis the immediate override.restart --safe --skip-deferral: bypasses only the active-work deferral gate. Shutdown may still wait for pending replies to drain before the Gateway process exits. Requires--safe.
Notes
statusresolves configured auth SecretRefs for probe auth when possible. If a required SecretRef is unresolved,status --jsonreportsrpc.authWarning. Pass--token/--passwordexplicitly, or resolve the secret source first. Unresolved-auth warnings are suppressed once the probe otherwise succeeds.status --deepadds a best-effort system-level scan for other gateway-like services. The scan prints cleanup hints. One Gateway per machine is still the recommendation.status --deepalso runs config validation in plugin-aware mode. That mode surfaces plugin manifest warnings that the fast default path skips.- On Linux systemd installs, token-drift checks inspect both
Environment=andEnvironmentFile=unit sources. - Token-drift checks resolve
gateway.auth.tokenSecretRefs using merged runtime env (service command env first, then process env). If token auth is not effectively active (gateway.auth.modeofpassword/none/trusted-proxy, or unset with password able to win), config token resolution is skipped. installvalidates that a SecretRef-managedgateway.auth.tokenis resolvable. It never persists the resolved value into service environment metadata. If it cannot resolve the token,installfails closed.- If both
gateway.auth.tokenandgateway.auth.passwordare configured andgateway.auth.modeis unset,installblocks until you set the mode explicitly. - On macOS,
installwrites LaunchAgent plists with mode0644. Secrets stay in the generated owner-only environment file (0600), loaded through an owner-only wrapper (0700). - Running multiple Gateways on one host: isolate ports, config/state, and workspaces. See Multiple gateways.