Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion docs/docs/sidebar/architecture/architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -155,7 +155,7 @@ configure them — see the Features section:
- [File Management](../features/file-management.md) — upload, deploy, templates
- [Container Management](../features/container-management.md) — Docker
lifecycle, exec, pull
- [Cron Management](../features/cron-management.md) — cron drop-in file
- [Schedule Management](../features/schedule-management.md) — cron drop-in file
management
- [Sysctl Management](../features/sysctl-management.md) — kernel parameter
management
Expand Down
2 changes: 1 addition & 1 deletion docs/docs/sidebar/architecture/system-architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -93,7 +93,7 @@ role-based expansion.
### Authorization

Access control uses fine-grained `resource:verb` permissions. Each API endpoint
declares a required permission (e.g., `node:read`, `cron:write`,
declares a required permission (e.g., `node:read`, `schedule:write`,
`command:execute`). Built-in roles (`admin`, `write`, `read`) expand to default
permission sets, and custom roles can be defined in config. See
[Authentication & RBAC](../features/authentication.md) for the full permission
Expand Down
2 changes: 1 addition & 1 deletion docs/docs/sidebar/architecture/ui.md
Original file line number Diff line number Diff line change
Expand Up @@ -60,7 +60,7 @@ labels, and drain/undrain actions.

### Configure (`/configure`)

Block-based operations builder: sidebar with block categories (Cron, File,
Block-based operations builder: sidebar with block categories (Schedule, File,
Docker, Command, DNS, Network), blocks gated by RBAC permissions, per-block
target picker (`_all`, `_any`, hostname, labels), sequential apply with
per-block spinners, and result rendering.
Expand Down
10 changes: 5 additions & 5 deletions docs/docs/sidebar/features/authentication.md
Original file line number Diff line number Diff line change
Expand Up @@ -63,11 +63,11 @@ flowchart TD

Built-in roles expand to these default permissions:

| Role | Permissions |
| ------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `admin` | `agent:read`, `agent:write`, `node:read`, `node:write`, `network:read`, `network:write`, `job:read`, `job:write`, `health:read`, `audit:read`, `command:execute`, `command:shell`, `file:read`, `file:write`, `docker:read`, `docker:write`, `docker:execute`, `cron:read`, `cron:write`, `sysctl:read`, `sysctl:write`, `ntp:read`, `ntp:write`, `timezone:read`, `timezone:write`, `power:execute`, `process:read`, `process:execute`, `user:read`, `user:write`, `package:read`, `package:write`, `log:read`, `certificate:read`, `certificate:write`, `service:read`, `service:write` |
| `write` | `agent:read`, `node:read`, `node:write`, `network:read`, `network:write`, `job:read`, `job:write`, `health:read`, `file:read`, `file:write`, `docker:read`, `docker:write`, `cron:read`, `cron:write`, `sysctl:read`, `sysctl:write`, `ntp:read`, `ntp:write`, `timezone:read`, `timezone:write`, `process:read`, `user:read`, `user:write`, `package:read`, `package:write`, `log:read`, `certificate:read`, `certificate:write`, `service:read`, `service:write` |
| `read` | `agent:read`, `node:read`, `network:read`, `job:read`, `health:read`, `file:read`, `docker:read`, `cron:read`, `sysctl:read`, `ntp:read`, `timezone:read`, `process:read`, `user:read`, `package:read`, `log:read`, `certificate:read`, `service:read` |
| Role | Permissions |
| ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `admin` | `agent:read`, `agent:write`, `node:read`, `node:write`, `network:read`, `network:write`, `job:read`, `job:write`, `health:read`, `audit:read`, `command:execute`, `command:shell`, `file:read`, `file:write`, `docker:read`, `docker:write`, `docker:execute`, `schedule:read`, `schedule:write`, `sysctl:read`, `sysctl:write`, `ntp:read`, `ntp:write`, `timezone:read`, `timezone:write`, `power:execute`, `process:read`, `process:execute`, `user:read`, `user:write`, `package:read`, `package:write`, `log:read`, `certificate:read`, `certificate:write`, `service:read`, `service:write` |
| `write` | `agent:read`, `node:read`, `node:write`, `network:read`, `network:write`, `job:read`, `job:write`, `health:read`, `file:read`, `file:write`, `docker:read`, `docker:write`, `schedule:read`, `schedule:write`, `sysctl:read`, `sysctl:write`, `ntp:read`, `ntp:write`, `timezone:read`, `timezone:write`, `process:read`, `user:read`, `user:write`, `package:read`, `package:write`, `log:read`, `certificate:read`, `certificate:write`, `service:read`, `service:write` |
| `read` | `agent:read`, `node:read`, `network:read`, `job:read`, `health:read`, `file:read`, `docker:read`, `schedule:read`, `sysctl:read`, `ntp:read`, `timezone:read`, `process:read`, `user:read`, `package:read`, `log:read`, `certificate:read`, `service:read` |

`command:execute` and `command:shell` are two distinct permissions: the former
guards the argv-only `exec` endpoint, the latter guards the `/bin/sh -c` based
Expand Down
2 changes: 1 addition & 1 deletion docs/docs/sidebar/features/features.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ OSAPI provides a comprehensive set of features for managing Linux systems.
| 📋 | [Audit Logging](audit-logging.md) | Structured API audit trail with 30-day retention |
| 🔐 | [Authentication & RBAC](authentication.md) | JWT with fine-grained `resource:verb` permissions |
| 📦 | [Container Management](container-management.md) | Docker lifecycle, exec, and pull through pluggable runtime drivers |
| ⏰ | [Cron Management](cron-management.md) | Cron drop-in file and periodic script management |
| ⏰ | [Schedule Management](schedule-management.md) | Scheduled task and periodic script management |
| 🔧 | [Sysctl Management](sysctl-management.md) | Kernel parameter management via `/etc/sysctl.d/` |
| 🕐 | [NTP Management](ntp-management.md) | Chrony NTP server configuration and sync status |
| 🌍 | [Timezone Management](timezone-management.md) | System timezone get and set via timedatectl |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
sidebar_position: 9
---

# Cron Management
# Schedule Management

OSAPI manages cron entries on target hosts. It supports two placement modes:

Expand All @@ -11,10 +11,10 @@ OSAPI manages cron entries on target hosts. It supports two placement modes:
- **Periodic interval** — writes to `/etc/cron.{hourly,daily,weekly,monthly}/`
as executable scripts

Cron entries reference scripts stored in the NATS Object Store by name. Upload a
script first with the file management commands, then create a cron entry
pointing at it. This separates script content from scheduling configuration and
enables versioned updates.
Scheduled entries reference scripts stored in the NATS Object Store by name.
Upload a script first with the file management commands, then create a cron
entry pointing at it. This separates script content from scheduling
configuration and enables versioned updates.

## How It Works

Expand Down Expand Up @@ -88,8 +88,8 @@ deploy time with `--vars`:
osapi client node file upload --name backup-script.tmpl \
--content-type template --file ./backup.sh.tmpl

# Create a cron entry that renders the template on deploy
osapi client node schedule cron create --target web-01 \
# Create a scheduled entry that renders the template on deploy
osapi client node schedule create --target web-01 \
--name backup --schedule "0 2 * * *" \
--object backup-script.tmpl \
--vars "retention_days=30,s3_bucket=my-bucket"
Expand All @@ -116,30 +116,30 @@ osapi client node file upload --name backup-script \
--file ./backup.sh

# Create with a custom schedule (/etc/cron.d/)
osapi client node schedule cron create --target web-01 \
osapi client node schedule create --target web-01 \
--name backup --schedule "0 2 * * *" \
--object backup-script --user root

# Create with an interval (/etc/cron.daily/)
osapi client node schedule cron create --target web-01 \
osapi client node schedule create --target web-01 \
--name logrotate --interval daily \
--object logrotate-script

# List all managed cron entries
osapi client node schedule cron list --target web-01
osapi client node schedule list --target web-01

# Get a specific entry
osapi client node schedule cron get --target web-01 --name backup
osapi client node schedule get --target web-01 --name backup

# Update: upload a new script version and redeploy
osapi client node file upload --name backup-script \
--file ./backup-v2.sh --force
osapi client node schedule cron update --target web-01 \
osapi client node schedule update --target web-01 \
--name backup --schedule "0 3 * * *" \
--object backup-script

# Delete an entry (undeploys file from disk; state preserved in KV)
osapi client node schedule cron delete --target web-01 --name backup
osapi client node schedule delete --target web-01 --name backup
```

All commands support `--json` for raw JSON output.
Expand Down Expand Up @@ -181,13 +181,13 @@ OS family detection.

## Permissions

| Operation | Permission |
| ---------------------- | ------------ |
| List, Get | `cron:read` |
| Create, Update, Delete | `cron:write` |
| Operation | Permission |
| ---------------------- | ---------------- |
| List, Get | `schedule:read` |
| Create, Update, Delete | `schedule:write` |

All built-in roles (`admin`, `write`, `read`) include `cron:read`. The `admin`
and `write` roles also include `cron:write`.
All built-in roles (`admin`, `write`, `read`) include `schedule:read`. The
`admin` and `write` roles also include `schedule:write`.

## Naming Rules

Expand Down Expand Up @@ -217,6 +217,7 @@ and `/node/{hostname}/schedule/timer`.

- [File Management](file-management.md) — uploading scripts and template
rendering
- [CLI Reference](../usage/cli/client/node/schedule/cron.md) — cron commands
- [CLI Reference](../usage/cli/client/node/schedule/schedule.md) — schedule
commands
- [Platform Detection](../sdk/platform/detection.md) — OS family detection
- [Configuration](../usage/configuration.md) — full configuration reference
2 changes: 1 addition & 1 deletion docs/docs/sidebar/sdk/client/client.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ resp, err := client.Hostname.Get(ctx, "_any")
| Service | Description |
| ------------------------------ | ---------------------------- |
| [Service](services/service.md) | Service management (systemd) |
| [Cron](services/cron.md) | Cron schedule management |
| [Cron](services/schedule.md) | Cron schedule management |

### Software

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -85,10 +85,10 @@ resp, err := c.Cron.Delete(ctx, "web-01", "backup-daily")

## Permissions

| Operation | Permission |
| ---------------------- | ------------ |
| List, Get | `cron:read` |
| Create, Update, Delete | `cron:write` |
| Operation | Permission |
| ---------------------- | ---------------- |
| List, Get | `schedule:read` |
| Create, Update, Delete | `schedule:write` |

Cron management is supported on the Debian OS family (Ubuntu, Debian, Raspbian).
On unsupported platforms (Darwin, generic Linux), operations return
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,16 +2,17 @@
sidebar_position: 1
---

# Cron
# Schedule

Manage cron drop-in files in `/etc/cron.d/` on target hosts.
Manage scheduled entries on target hosts. On Debian family hosts these are cron
drop-in files in `/etc/cron.d/`.

## List

List all osapi-managed cron entries:
List all osapi-managed scheduled entries:

```bash
$ osapi client node schedule cron list --target web-01
$ osapi client node schedule list --target web-01

HOSTNAME STATUS NAME SCHEDULE OBJECT USER
web-01 ok backup-daily 0 2 * * * backup-script root
Expand All @@ -25,7 +26,7 @@ $ osapi client node schedule cron list --target web-01
Get a specific cron entry by name:

```bash
$ osapi client node schedule cron get --target web-01 --name backup-daily
$ osapi client node schedule get --target web-01 --name backup-daily

HOSTNAME STATUS NAME SCHEDULE OBJECT USER
web-01 ok backup-daily 0 2 * * * backup-script root
Expand All @@ -46,7 +47,7 @@ $ osapi client file upload --name backup-script \
Then create the cron entry using `--object` to reference the uploaded file:

```bash
$ osapi client node schedule cron create --target web-01 \
$ osapi client node schedule create --target web-01 \
--name backup-daily \
--schedule "0 2 * * *" \
--object backup-script \
Expand All @@ -68,7 +69,7 @@ should be rendered with agent facts before being written to disk.
Update an existing cron entry:

```bash
$ osapi client node schedule cron update --target web-01 \
$ osapi client node schedule update --target web-01 \
--name backup-daily \
--schedule "0 3 * * *"

Expand All @@ -85,7 +86,7 @@ Only the fields you specify are updated. If nothing changed, `Changed: false`.
Delete a cron entry:

```bash
$ osapi client node schedule cron delete --target web-01 --name backup-daily
$ osapi client node schedule delete --target web-01 --name backup-daily

HOSTNAME STATUS NAME CHANGED
web-01 changed backup-daily true
Expand All @@ -98,6 +99,6 @@ $ osapi client node schedule cron delete --target web-01 --name backup-daily
All commands support `--json` for raw JSON output:

```bash
$ osapi client node schedule cron list --target web-01 --json
$ osapi client node schedule list --target web-01 --json
{"results":[{"name":"backup-daily","schedule":"0 2 * * *","user":"root","object":"backup-script"}],"job_id":"..."}
```
Loading
Loading