Repository navigation
Commands
github-actions[bot] edited this page Sep 22, 2026
·
5 revisions
conductor run [--config PATH] start the daemon
conductor run <name> [--input k=v ...] [--json '{…}'] fire a manual trigger via the running daemon
conductor once <trigger> [--event PATH] [--event-name NAME] [--fail-on LIST] [--require-match]
run ONE event through ONE trigger, for real, no daemon; exit = outcome
conductor validate [--config PATH] load & validate config (both schemas), then exit
conductor replay <event.json> run a saved webhook through the pipeline, verbs stubbed
conductor sweep [--now] one catch-up sweep (dry-run print / signal the daemon)
conductor force <kind> <owner/repo>#<n> force an action for a target now (via the daemon)
conductor status live agents, in-flight workflows, stuck/attention
conductor report [--days N] dispatches by kind/outcome + attention counts + spend
conductor runs [--limit N] recorded executions, newest first (id, status, cost)
conductor runs <id> one run's step-by-step detail (also: conductor run <id>)
conductor runs retry <id> [--from <step>] [--force-replay] re-run a recorded execution (recorded inputs pinned; succeeded steps need --force-replay)
conductor watch [<run-id>] [--json] tail the live run event stream (steps, gates, outcomes)
conductor pause | resume stop / resume dispatch at runtime (no restart; also verbs: conductor.pause/resume)
conductor reload tell the running daemon to re-read its config (SIGHUP → re-exec; also verb: conductor.reload)
conductor update [--force] [--tag vX] self-update to the latest release
conductor service install|sync|uninstall manage the background service unit
conductor connectors ls each connector: resolved use:/origin, state, events, verbs, triggers
conductor schema <connector> full event/filter/context/verb/option/output schemas
conductor plugin list [--caps] every connector + runtime, with ORIGIN and kind (--caps: permissions)
conductor plugin show <name> one implementation's surface (Decl + permission manifest + disclosure)
conductor plugin add <ref> [--runtime] install it, show the permissions it declares, print the config stub
conductor plugin update [name] bump everything unpinned, or just one
conductor plugin remove <name> drop it from local install state and delete its binary
conductor connector auth ls each oauth2 connector's login state + token expiry
conductor connector auth <name> [--revoke] one-time OAuth2 login (or clear stored tokens)
conductor secrets check unlock every vault, resolve every reference, report (no values)
conductor vault <name> init|add|get|ls|rm manage a named vaults: entry
conductor unlock seed the default vault key for non-interactive restarts
conductor config migrate [--dry-run] transform a legacy config to the connectors schema
conductor mcp memory --socket <path> stdio MCP server for the live agent tools (memory + run_step; launched by runtimes, not by hand)
conductor workflows [ls] config + saved (agent-promoted) workflows with review state and health
conductor workflows review <name> print the workflow's provenance + FULL steps, then clear it for reuse (dry-run it first; runs stay policy-guarded)
conductor workflows rm <name> remove a saved workflow
conductor version
- validate — runs each connector/integration's own checks, the cross-config agent-profile checks, and the connectors-model semantic pass (position-scoped references, verb options, workflow inputs/outputs, cycles). Service start gates on it.
-
run
<name>— fires theon: manualtrigger with that name through the running daemon's control socket: same validation, policy, quiet-hours, and audit as any firing.--input k=v(repeatable, string values) and--json(one structured object;--inputoverlays it) land in the trigger context as{{.inputs.*}}. The connectors-model successor toforce. Errors clearly when the daemon is down or the name is unknown. -
once
<trigger>— the no-daemon entry point (One-Shot): takes ONE event (--event, default$GITHUB_EVENT_PATH), matches it to the named trigger, and runs that trigger's steps for real in this process, to completion — with none of the daemon's background loops. Exit0on success or a non-match,3on a--fail-onoutcome,1when it could not run. Built for GitHub Actions;--fixturetakes areplayfixture for local testing. paseo and interactive hand-offs are refused up front. -
replay — reads a
{"event": …, "body": {…}}fixture (seetestdata/), translates it, and prints what would dispatch; connectors-model triggers run with every outbound verb stubbed and agents mocked, so a workflow can be authored without side effects. -
runs / watch — the run-inspection pair (Runs):
runsreads the history directory straight off disk (works with the daemon down);watchandruns retrygo through the running daemon's control socket.run <id>shows the same detail when the argument names a recorded run rather than a manual trigger (a configured trigger name always wins). - report — three sections over the audit window: dispatches by kind/outcome + attention counts, spend (Cost-Accounting), and agent quality (Outcomes).
-
connectors ls / schema — the introspection pair: what is configured and
what each type accepts.
schemaalso takes a bare type name. -
mcp memory — the stdio MCP server behind the live agent memory tool
(Memory). The daemon launches it into agent sessions on runtimes that
support live tools (ACP
mcpServers), with the socket path and the dispatch's provenance baked into the flags — there is no reason to run it by hand. -
connector auth — the only interactive auth step.
auth <name>runs the grant's flow (authorization_code: consent URL + localhost redirect capture;device: prints a user code and polls) and stores the access + refresh tokens in the connector'stoken_vault; restarts never prompt.auth lsshows each oauth2 connector's grant, token_vault, login state, and access-token expiry;--revokeclears the stored tokens. See Configuration. - secrets check — unlocks every vault and resolves each connector's credentials; failures name the vault/reference, values are never printed. A vault that won't unlock is reported and disables its dependents — the daemon still boots.
-
vault / unlock —
vault <name> …targets avaults:entry (write ops only on writable backends); see Secrets for the unlock chain and why it is non-interactive in steady state. -
config migrate — the manual face of the automatic on-boot migration;
--dry-runprints the transformed YAML plus a mapping summary. See Migration. -
pause / resume — the runtime kill switch (a control file, no restart);
in config, disable one connector or trigger in place with its own
enabled: false(there is no policy-level kill switch — see Policy). -
reload — re-read the config without a manual restart. Sends
SIGHUPto the running daemon (pid from the pidfile), which re-execs itself in place so the new config loads at boot; in-flight runs checkpoint and resume on the new process. The same restart theconductor.reloadverb triggers.
Related: Configuration · Secrets · Migration
Setup
The model
- Connectors
- Workflows
- Reuse
- Settings-and-Templating
- Packs
- Verbs
- Code-Steps
- Stores
- Runtimes
- Model-Selection
- Model-Discovery
- Steps
- Decide-Steps
- Grouping
- Memory
- Binary-Data
- Agent-Skill
- Policy
- Gates
- Teams
- Outcomes
- Cost-Accounting
- Secrets
- Hosts
- Isolation
- Trust-and-Isolation
Connectors
Operations
- One-Shot
- Callable-Service
- Runs
- Hand-offs
- Notifications
- Migration
- Controllers (legacy name → Runtimes)