2014-02-07 16:41:03 -08:00
---
layout: "docs"
page_title: "Commands"
sidebar_current: "docs-commands"
2014-10-19 19:40:10 -04:00
description: |-
Consul is controlled via a very easy to use command-line interface (CLI). Consul is only a single command-line application: `consul` . This application then takes a subcommand such as agent or members. The complete list of subcommands is in the navigation to the left.
2014-02-07 16:41:03 -08:00
---
2014-02-18 17:32:13 -08:00
# Consul Commands (CLI)
2014-02-07 16:41:03 -08:00
2014-02-18 17:32:13 -08:00
Consul is controlled via a very easy to use command-line interface (CLI).
Consul is only a single command-line application: `consul` . This application
2014-02-07 16:41:03 -08:00
then takes a subcommand such as "agent" or "members". The complete list of
subcommands is in the navigation to the left.
2014-02-18 17:32:13 -08:00
The `Consul` CLI is a well-behaved command line application. In erroneous
2014-02-07 16:41:03 -08:00
cases, a non-zero exit status will be returned. It also responds to `-h` and `--help`
as you'd most likely expect. And some commands that expect input accept
2014-02-18 17:32:13 -08:00
"-" as a parameter to tell Consul to read the input from stdin.
2014-02-07 16:41:03 -08:00
2014-02-18 17:32:13 -08:00
To view a list of the available commands at any time, just run `consul` with
2014-02-07 16:41:03 -08:00
no arguments:
2014-10-19 19:40:10 -04:00
```text
2014-02-18 17:32:13 -08:00
$ consul
usage: consul [--version] [--help] < command > [< args > ]
2014-02-07 16:41:03 -08:00
Available commands are:
2014-02-18 17:32:13 -08:00
agent Runs a Consul agent
2016-09-26 10:12:14 -05:00
configtest Validate config file
2014-09-01 15:03:37 -07:00
event Fire a new event
exec Executes a command on Consul nodes
2014-02-07 16:41:03 -08:00
force-leave Forces a member of the cluster to enter the "left" state
2014-02-23 17:09:59 -08:00
info Provides debugging information for operators
2014-02-18 17:32:13 -08:00
join Tell Consul agent to join cluster
2014-02-07 16:41:03 -08:00
keygen Generates a new encryption key
2015-01-19 16:43:38 -10:00
keyring Manages gossip layer encryption keys
2017-04-04 12:33:22 -04:00
kv Interact with the KV store
2014-02-18 17:32:13 -08:00
leave Gracefully leaves the Consul cluster and shuts down
2015-01-19 16:43:38 -10:00
lock Execute a command holding a lock
2016-09-26 10:12:14 -05:00
maint Controls node or service maintenance mode
2014-02-18 17:32:13 -08:00
members Lists the members of a Consul cluster
monitor Stream logs from a Consul agent
2016-08-29 19:09:57 -07:00
operator Provides cluster-level tools for Consul operators
2014-06-11 11:03:59 -07:00
reload Triggers the agent to reload configuration files
2015-10-16 00:56:15 -07:00
rtt Estimates network round trip time between nodes
2014-02-18 17:32:13 -08:00
version Prints the Consul version
2014-08-21 17:25:42 -07:00
watch Watch for changes in Consul
2014-02-07 16:41:03 -08:00
```
To get help for any specific command, pass the `-h` flag to the relevant
2014-06-11 11:08:19 -07:00
subcommand. For example, to see help about the `join` subcommand:
2014-02-07 16:41:03 -08:00
2014-10-19 19:40:10 -04:00
```text
2014-06-11 11:08:19 -07:00
$ consul join -h
Usage: consul join [options] address ...
2014-02-07 16:41:03 -08:00
2014-06-11 11:08:19 -07:00
Tells a running Consul agent (with "consul agent") to join the cluster
by specifying at least one existing member.
2014-02-07 16:41:03 -08:00
2017-02-28 13:41:09 -08:00
HTTP API Options
2014-02-07 16:41:03 -08:00
2017-02-28 13:41:09 -08:00
-http-addr=< address >
The `address` and port of the Consul HTTP agent. The value can be
an IP address or DNS address, but it must also include the port.
This can also be specified via the CONSUL_HTTP_ADDR environment
variable. The default value is http://127.0.0.1:8500. The scheme
can also be set to HTTPS by setting the environment variable
CONSUL_HTTP_SSL=true.
-token=< value >
ACL token to use in the request. This can also be specified via the
CONSUL_HTTP_TOKEN environment variable. If unspecified, the query
will default to the token of the Consul agent at the HTTP address.
Command Options
-wan
Joins a server to another server in the WAN pool.
2014-02-07 16:41:03 -08:00
```
2017-01-09 12:02:06 -05:00
## Environment Variables
In addition to CLI flags, Consul reads environment variables for behavior
defaults. CLI flags always take precedence over environment variables, but it
is often helpful to use environment variables to configure the Consul agent,
particularly with configuration management and init systems.
These environment variables and their purpose are described below:
## `CONSUL_HTTP_ADDR`
This is the HTTP API address to the *local* Consul agent
(not the remote server) specified as a URI:
```
CONSUL_HTTP_ADDR=127.0.0.1:8500
```
or as a Unix socket path:
```
CONSUL_HTTP_ADDR=unix://var/run/consul_http.sock
```
### `CONSUL_HTTP_TOKEN`
This is the API access token required when access control lists (ACLs)
are enabled, for example:
```
CONSUL_HTTP_TOKEN=aba7cbe5-879b-999a-07cc-2efd9ac0ffe
```
### `CONSUL_HTTP_AUTH`
This specifies HTTP Basic access credentials as a username:password pair:
```
CONSUL_HTTP_AUTH=operations:JPIMCmhDHzTukgO6
```
### `CONSUL_HTTP_SSL`
This is a boolean value (default is false) that enables the HTTPS URI
scheme and SSL connections to the HTTP API:
```
CONSUL_HTTP_SSL=true
```
### `CONSUL_HTTP_SSL_VERIFY`
This is a boolean value (default true) to specify SSL certificate verification; setting this value to `false` is not recommended for production use. Example
for development purposes:
```
CONSUL_HTTP_SSL_VERIFY=false
```
2017-04-14 13:37:29 -07:00
### `CONSUL_CACERT`
Path to a CA file to use for TLS when communicating with Consul.
```
CONSUL_CACERT=ca.crt
```
### `CONSUL_CAPATH`
Path to a directory of CA certificates to use for TLS when communicating with Consul.
```
CONSUL_CAPATH=ca_certs/
```
### `CONSUL_CLIENT_CERT`
Path to a client cert file to use for TLS when `verify_incoming` is enabled.
```
CONSUL_CLIENT_CERT=client.crt
```
### `CONSUL_CLIENT_KEY`
Path to a client key file to use for TLS when `verify_incoming` is enabled.
```
CONSUL_CLIENT_KEY=client.key
```
### `CONSUL_TLS_SERVER_NAME`
The server name to use as the SNI host when connecting via TLS.
```
CONSUL_TLS_SERVER_NAME=consulserver.domain
```