docs: describe SSH that sets itself up and the CLI inside a workspace - #22
Merged
Merged
Conversation
…I and SSH setup The command pages now follow CLI revision 1880d04 (0.13.0-rc.4 plus the unreleased fixes): `ssh add --name` is optional and sets up `ssh <workspace>`, `rig api --body` takes inline JSON, `completions --no-rc` needs `--install`, `ai defaults` shows the defaults with no flags, `tools ls` shows status and URL, `init --name` is slugged, tool and template examples name real ids, and every `--app` accepts a subdomain. Workspace mode gains ai, api, config, completions, update, build and volume, `--query` and the saved output default, and a `--workspace` that defaults to the current workspace for metrics, ports, services, resize, reconcile and app expose-port. The export was reconstructed from that revision's `--help` output and root help snapshots rather than `export_docs`, with argument metadata carried over from the rc.2 export; it reproduced every unchanged command byte for byte first. scripts/generate-cli-reference.md records this so the next real export replaces it. Curated notes say where each command runs: laptop-only commands, the workspace lifecycle verbs, and setup-script/service-spec changes refuse inside a workspace; deploy, logs --follow, ssh-info, update, and recipe install describe their new behaviour.
rig login, rig ssh add and workspace spawn/start/restart/ssh-info now register the local key (creating one when there is none), keep a Host entry per workspace in ~/.config/rigbox/ssh_config included from ~/.ssh/config, and trust the gateway host keys in ~/.config/rigbox/known_hosts, so `ssh <workspace>` works from a terminal, an editor or the Claude desktop app. The SSH guide now leads with that setup and the alias, shows the managed entry and ssh-info output (alias, full command, spawn link hint), and covers `rig config set ssh-setup false`, the stopped-workspace message on stderr, `ssh -t` with a command, SFTP/scp/rsync by alias, and that port, agent and X11 forwarding are unavailable. The key, file transfer and troubleshooting pages, the install guide, quickstart, workspace guide, Spawn page and security boundaries follow suit. Legacy anchors are kept.
…kspaces too rig update now downloads this platform's build from the public release mirror, checks that it runs, and renames it over the binary that is running (or into RIG_INSTALL_DIR), which also works for /usr/local/bin inside a workspace. Document that, --version <tag>, the daily update notice and RIGBOX_NO_UPDATE_CHECK, and the workspace's own update timer, which also lifts a CLI below the supported minimum.
Inside a workspace the CLI now offers update, api, ai, config, completions, build and volume alongside the app, deploy and workspace commands, and answers the laptop-only commands (login, logout, api-key, ssh, ci, release, rollback, uninstall), the workspace lifecycle verbs, template deploy and setup-script/service-spec changes with one `unsupported` line saying where they work. The execution-modes page now lists both, with the refusal output, how --workspace defaults to the current workspace, how rig deploy deploys into the workspace it runs in and refuses clone, re-image and image deploys, --output/--query and logs --follow there, and what the bridge won't serve (account keys) or serves read-only (AI defaults, setup scripts, service specs). The using-CLI, deploy, configuration, setup script, service spec, app log and security pages point at it.
Anthropic clients (Claude Code, the Anthropic SDKs) add /v1/messages themselves, so their base URL is the proxy root; OpenAI-compatible clients take the /v1 base. Add a base-URL table, show the managed-mode hint that `rig workspace ai mode` now prints with both (without -w inside a workspace), and note that `rig ai defaults` with no flags shows the defaults and only reads them inside a workspace. `rig proxy on` exports RIGBOX_AI_PROXY_URL, OPENAI_BASE_URL and OPENAI_API_KEY rather than OpenRouter variables, and `rig proxy off` only unsets variables that still point at the proxy or hold its placeholder key, leaving a user's own keys and endpoints set.
…ogins `rig recipe app install --ref claude -w <ws>` adds a built-in coding agent to a workspace that already exists (a bare catalog id or @rigbox/<id>@Builtin, from the laptop or inside the workspace with its own name), while `workspace spawn --catalog` covers new workspaces. List all six built-in agents (claude, codex, opencode, kilocode, junie, pi) with their routing. The Claude Code item no longer overrides the user's own Claude setup: it only merges hasCompletedOnboarding into ~/.claude.json, leaves settings.json and permission prompts alone, and routes through the workspace (proxy root as ANTHROPIC_BASE_URL) only while there is no `claude` login, saved key, apiKeyHelper or Anthropic variable, with a ~/.config/rigbox/claude-own-auth opt-out. The catalog guide also stops claiming that recipe install blocks until the job completes or infers --workspace inside a VM, and its app start, stop and rm examples pass --app.
- rig api --body takes inline JSON (or a file, or - for stdin) and prints a failed response verbatim with its status; the authentication page says so and the rename/custom-domain examples use inline bodies. - Tool ids are architecture and virtual-browser; tools launch/install fail when the server did nothing, and tools ls shows STATUS and URL, which is where a launched tool's URL is read back. - app new defaults --workspace to the current workspace, or on a laptop to the one this directory's rig.yaml deploys to. The expose-port example no longer wraps without --name, and the page explains the prompt and its refusal without a terminal. - rig init --name is slugged into a name deploy accepts; ai defaults with no flags shows the defaults. - rig login without a terminal names RIG_API_KEY and --import-token, reports only a rejected key as invalid, and sets up SSH access.
…restarts A login that arrives while the platform restarts a service now waits up to about ten seconds for the workspace's keys instead of failing with Permission denied, so the troubleshooting pages point a persistent Permission denied at the key.
ssh-info no longer prints a line for another tool, so the sample output, the Spawn page, and the command reference stop describing one.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
These are the docs for the rig CLI gap-report fixes:
What changes
guides/ssh-access.mdx, rewritten):rig login,rig ssh addandworkspace spawn/start/restart/ssh-infoset up SSH themselves. They register the key, write aHostentry per workspace in~/.config/rigbox/ssh_config, and trust the gateway's host keys.ssh <workspace>then works from a terminal, an editor or the Claude desktop app.rig config set ssh-setup false, the stopped-workspace message on stderr,ssh -twith a command, and SFTP, scp and rsync by alias.cli-reference/execution-modes.mdx):--workspacedefaulting to the current workspace;rig deploydeploying into the workspace it runs in;rig update(guides/install-cli.mdx): it replaces the running binary from the public mirror, inside workspaces too. The page covers--version, the update notice,RIGBOX_NO_UPDATE_CHECKand the workspace's own update timer./v1;rig proxy offonly unsets variables that point at the proxy.rig recipe app install --ref claude -w <ws>adds an agent to an existing workspace;rig api --bodytakes inline JSON;tools lsshows status and URL;app newdefaults--workspaceto the current workspace, or to the onerig.yamldeploys to;init --nameis slugged;rig loginwithout a terminal points atRIG_API_KEYand--import-token.ssh-infono longer describes a line for another tool.Before merging
export_docs. It was rebuilt from the branch's--helpoutput, with argument metadata carried over from the rc.2 export. It reproduced every unchanged page byte for byte first.scripts/generate-cli-reference.mdrecords this.cli-reference/commands/ci/status.mdx, which still describes the oldrig ci status.generate-cli-reference.py --check,check-docs.pyandbuild-navigation.py --checkpass.🤖 Generated with Claude Code