Skip to content

CLI reference

ernolf edited this page Sep 24, 2026 · 1 revision

CLI reference

dcm-cli is the only privileged part of dcm. It lives at /usr/local/sbin/dcm-cli, is identical on every node — the sync pushes the binary itself — and it is the single entry point the web frontend has into anything that needs root:

www-data ALL=(root) NOPASSWD: /usr/local/sbin/dcm-cli *

Nothing about a dnsmasq release or a node IP is hardcoded in it: the paths come from /etc/default/dnsmasq and the merged drop-ins, the node list from /etc/dcm/nodes, and the listen addresses from hosts/local.

Commands

dcm-cli sync                           sync config + binary to all other nodes
dcm-cli restart local|remote|all       systemctl restart dnsmasq
dcm-cli status  local|remote           systemctl status dnsmasq
dcm-cli logs    [N]                    last N log lines (default 200)
dcm-cli tail-f  local|remote           stream the log (used by the live view)
dcm-cli stats   local|remote [period]  log analytics (all|today|1h|24h|7d)
dcm-cli health                         live sync/restart/build state as key=value (used by the UI bell)
dcm-cli diff                           list what a sync would change on each remote node
dcm-cli node-report                    this node's restart state and dnsmasq build (used by health)

What each one does

sync writes the local listen.conf, then rsyncs /etc/default/dnsmasq, /etc/dnsmasq.d/ (excluding listen.conf), /etc/dcm/nodes and /usr/local/sbin/dcm-cli to every other node and regenerates their listen.conf from hosts/local. It never restarts dnsmasq.

restart / status are systemctl on dnsmasq — locally, on the remote nodes, or on all of them. A config change only takes effect after a restart, which is what the bell's restart pending state is about.

logs / tail-f read log-facility. tail-f is what the Live Log page streams through its SSE endpoint, one stream per node.

stats filters the log for the requested period and reduces it in a single awk pass to key=value scalars and TSV arrays — query types, cache hits, per-hour counts, top upstreams, domains and clients. This is the Analytics page.

health is what the bell polls. It dry-runs rsync --checksum for drift (content, not timestamps), asks every node's node-report for its restart state and its dnsmasq build, and reports sync pending, restart pending, version mismatch, feature mismatch and unknown directives as key=value. It also refreshes the build cache in /var/lib/dcm/cluster-build.

diff lists the exact paths a sync would change on each remote node — the Dashboard's What differs? button.

node-report is the per-node half of health: this node's restart state and its dnsmasq build. It is what health calls over SSH, not a command you normally run yourself.

See also

  • Architecture — the sync flow and the cluster build detection in detail
  • Installation — the sudoers drop-in and the root SSH the sync needs

dcm

Getting started

Managing the cluster

Under the hood

What comes next

Clone this wiki locally