# urnet-tools (Go) β€” Provider-Aware Fleet Ops > Applies to v3.23.0-fix.27.0+ (updated through v3.23.0-fix.30.9). The legacy shell tool (POSIX `Provider_Install_Linux.sh` + Windows `urnet-tools.ps1`) is replaced by a single provider-aware Go binary. Subcommand names and usage are preserved and expanded; what changed is **how the tool decides which provider it operates on**. ## Why this exists The legacy `urnet-tools` resolved its target from a hardcoded path (`$HOME/.local/share/urnetwork-provider`) with zero awareness that other providers exist on the box. On a multi-provider machine it could act on the **wrong provider entirely** β€” and did (08-08 pool-wipe, 08-09 half-update). The Go rewrite makes the tool's single most important guarantee structural: **it never guesses which provider you mean.** ## The two binaries | Binary | What it manages | |---|---| | `urnet-tools` | Process/systemd providers (`--proxy_file`, internal config, systemd units) | | `urnet-docker` | Docker-deployed providers (discovers containers, delegates via `docker exec`) | Both are cross-compiled from one Go source β€” the shell↔PowerShell drift is gone. --- ## πŸ“‹ Complete Command Reference ### Core & Lifecycle Commands | Command | What it does | |---|---| | `providers` (`list`, `ps`) | List providers: your own OS user's by default, or all providers on the box with `--all` (JWT identities, systemd units, state dirs). | | `status [target]` | Show detailed status. On Linux, displays live `systemctl status` view; on Windows/macOS, renders styled panel. | | `start [target]` | Start provider service/process. | | `stop [target]` | Stop provider service/process. | | `restart [target]` | Restart provider service/process. | | `hot-restart [target]` | Restart provider unit behind confirm gate (`-f` skips prompt). | | `reinstall [target]` | Cleanly reinstall provider binary (delegates to latest updater). | | `uninstall [target]` | Uninstall provider, unit files, and optional state. Confirm-gated. | | `update [target]` | Update provider to the latest release (or `--tag `). Digest-verified. | | `hotswap` (`hot-swap`) | Zero-downtime in-process binary reload: hands live service to a verified candidate with no restart. Requires a `Type=notify` unit; see the deep-dive below. | | `self-update` (`selfupdate`) | Update the tool binary itself without touching running providers. | | `logs [target] [N]` | Stream provider logs (N lines, default 250). RAMLOGS-aware. | | `version` (`--version`, `-v`) | Print stamped binary version and build metadata. | ### Restored Provider & Session Commands (v3.23.0-fix.30.4+) | Command | What it does | |---|---| | `auth [target] [-f]` | Authenticate provider with an auth code. `-f` forces overwrite of existing JWT. Drops privileges to run as target user when called by root. | | `direct [on\|off\|status] [target]` | Toggle or report direct/local IP providing state. Taking effect immediately via reload. Available across `provider`, `urnet-tools`, and `urnet-docker`. | | `show-ip [on\|off\|status] [target]` | Control whether the provider appends its public IP to the dashboard label set by `rename`. Renamed from `ip-detect` in v3.23.0-fix.31.0, which is kept as an alias. This is about what the dashboard shows, not which address the provider serves on; for that see `direct`. | | `sn-status [--json] [target]` | Query and display Subnet 25 mining & node telemetry (v3.23.0-fix.30.9+): global rank, top-200 tier eligibility, net bandwidth provided, registered coldkey (SS58/Hex), current subnet epoch blocks, and finalized epoch pool payout share. Available across `urnet-tools`, `urnet-docker`, and `provider`. | | `usage [graphs\|graph ] [target]` | Display traffic & billing accounting: billable relay bytes vs control-plane protocol overhead, with rolling time-series summaries. Available across `urnet-tools` and `urnet-docker`. | | `choose-network [target]` | Point provider to custom API and WebSocket signaling endpoints. Use `--reset` to restore default bringyour endpoints. | | `fast-auth [on\|off\|status] [target]` | Toggle or check `~/.urnetwork/fast_auth` marker to bypass auth rate limiter. Confirm-gated. | | `set [help \| \| off \| ] [target]` | Get, set, or clear runtime provider state overrides (`node-name`, `report-interval`, `proxy-url-max`, `proxy-url-refresh`, `cleanup-scope`, `cleanup-interval`, `fast-auth`). Sent live over the provider control socket, or queued to `pending_overrides.json` if the provider is stopped. Confirm-gated. | | `rename [target]` | Set the dashboard identity label on the backend. Alias for `set node-name `. Writes `~/.urnetwork/node_name`, re-read on next tick β€” no restart. Use `off` to clear. Available across `urnet-tools` and `urnet-docker`. | | `session save [target]` | Export encrypted AES-256-CBC bundle of provider JWT identity and state. Prompts for passphrase. | | `session load [target] [--allow-different-account]` | Decrypt and load identity bundle into provider. Automatically backs up current state first. Verifies account identity unless bypassed. | | `self-heal [on\|off\|status] [target]` | Toggle or query resource-pressure self-healing monitor (`~/.urnetwork/proxy_self_heal`). | | `default [set \| show \| clear]` | Persist, inspect, or clear default provider target for current user in `os.UserConfigDir()/urnet-tools/default`. | ### Proxy Management Commands | Command | What it does | |---|---| | `proxy add [target]` | Merge proxies from text file (`host:port[:user:pass]`) or live URL. Supports straight paths with `~`, URLs (auto-routed to `add-source`), and flags (`--file=`, `--proxy_file=`, `--url=`). | | `proxy paste [target]` | Stream raw proxies from stdin or pipe without creating host files. Auto-detects formats and URLs. | | `proxy clear [target]` | Remove all proxies and URL sources. Confirm-gated (`-f` bypasses prompt). | | `proxy remove [addresses...] [target]` | Remove specific proxies or patterns. Use `--match=` for host substring matches, or `--all` for complete wipe. | | `proxy trim [target] [--preview]` | **(New in 30.4)** Set persistent hard cap of `` running proxies. Sheds worst A-F reachability graded proxies first. `proxy trim off` clears the cap. | | `proxy refresh [target] [--force]` | Reload proxy list into running provider without restarting. `--force` bypasses warmup lockout. | | `proxy add-source [target]` | Add live URL proxy source. Fetched and probed immediately. | | `proxy remove-source [target]` | Remove URL proxy source. | | `proxy ids [target]` | **(New in 31.0)** Show the `client_id` the platform assigned to each proxy, including the `direct` transport. Read from the provider's local client-JWT store; the bearer tokens themselves are never printed. | | Exclusion via `proxy remove --match=` | See `proxy remove` above. `--match=` removes matching proxies and persists the pattern so future URL refreshes skip them. There is no `proxy exclude` subcommand. | | `proxy health [target]` | Display live health state (Up, Down, Dead, Degraded). | | `proxy traffic [target]` | Display bandwidth, billable traffic, and active NAT sessions per proxy. | | `proxy remove-dead [target]` | Interactively prune dead and degraded proxies. Honors `--dry-run`. | | `summary [target]` | Fleet-style summary of proxy counts by source (url, file, internal). Top-level command, not a `proxy` subcommand. | ### Hub Command Family (v3.23.0-fix.30.4+) > [!WARNING] > **Deprecated (v31.3+):** The hub commands have been removed from `urnet-tools`. This section is retained for historical reference only. | Command | What it does | |---|---| | `hub init` | Initialize and configure the bandwidth hub service on this machine. Prompts for password (min 8 chars) or reads from stdin. | | `hub link ` | Pair provider with a remote bandwidth hub. Verifies TLS CA or SHA-256 certificate fingerprint (TOFU security). Confirm-gated on identity change. | | `hub unlink` | Unlink provider from bandwidth hub. | | `hub test` | Test reachability and TLS certificate chain validation to the configured hub. | | `hub onboard-cmd` | Generate one-line onboarding command with URL-escaped tokens for remote providers. | | `hub show-password` | Display current hub admin access password. | | `hub open-port` | Configure firewall rules (ufw/iptables/firewalld) to open hub listener port. Confirm-gated. | | `hub update` | Update bandwidth hub binary to latest release. | | `hub set ` | Set raw reporting endpoint URL in `~/.urnetwork/report_url`. | | `hub off` | Disable hub reporting by clearing `report_url`. | | `hub install` | Install bandwidth hub binary and systemd service. | ### System & Performance Tuning | Command | What it does | |---|---| | `auto [on\|off]` | Enable or disable Smart Auto hardware profile. | | `optimize [-f]` | Tune kernel parameters (conntrack, socket buffers, port ranges, BBR). Platform-aware. Self-elevates to root when needed (apply live + persist atomically, or roll back). | | `eco [on\|off]` | Enable or disable Eco profile (RAM-constrained hosts). | | `turbo [v4\|v8\|off]` | Enable Turbo V4 or Turbo V8 high-throughput modes. | | `ramlogs [on\|off]` | Enable or disable RAM-disk logging (`/dev/shm`). | | `report ` | Set live bandwidth reporting URL (`report off` disables). Writes an override file the provider's bandwidth reporter re-reads on its next tick, so no restart is needed. | | `profile [name]` | **(New in 31.0)** Show or set the memory and GC tuning profile (`auto`, `turbo-v4`, `turbo-v8`, `eco`, `lowmem`; `v4` and `v8` are accepted aliases). With no argument, prints the current profile and what each one is for. | | `metrics [status\|on\|off\|listen ]` | Show where the Prometheus `/metrics` endpoint listens and the address to scrape, turn it on or off, or choose its listen address. Live, no restart, and persisted. See [Monitoring](Monitoring.md). | --- ### Configuration & Introspection (v3.23.0-fix.31.0+) | Command | What it does | |---|---| | `config [--json]` | Show every provider setting with the source it came from (`socket`, `env`, `pending`, `legacy`, `default`). The provider is the single source of truth; this is what it actually believes. | | `set ` | Set a runtime setting over the control socket. Prints `⚠ requires a restart to take effect` when the provider reports the key has no live effect. Queued to `pending_overrides.json` when the provider is down. | | `set ` | Show one setting's current value. Reads are not logged at the provider, because `status` polls them on every invocation. | | `set off` | Clear a runtime setting and restore its default. Same queueing behavior. | | `history [limit]` | Show the provider's command audit trail from its 1000-entry circular ring. Defaults to the last 50, maximum 100. | | `dashboard` | Rich terminal status panel: state indicators, active settings, proxy sources, and restart warnings. Aliases `dash`, `panel`. | | `baseline show [-n N] [--json]` | Show the newest rows of this box's own behaviour record: UTC time, kind, version, proxies up against desired, RSS, host memory available, swap, and the file's first and last timestamps and size. Default 20 rows, at most 200. Reads `~/.urnetwork/baseline.jsonl` directly, so it works on a box whose provider is stopped. | | `baseline mark