Run on the server host (systemd + root).
| Command | Description |
|---|---|
seikan-server run [flags] |
Run the server process in the foreground. This is what systemd's ExecStart=seikan-server run invokes; use it directly for non-systemd setups (e.g. containers). The bare seikan-server just prints help. |
seikan-server install [--admin-host H …] |
Set up the hardened systemd service (creates the user, state dir, env file, unit, setcap, enables it) but leaves it stopped. Non-interactive — this is what the install.sh bootstrap invokes (alias exec-install; accepts --bin <dir>). The admin host is optional here: pass --admin-host / SEIKAN_ADMIN_HOST, or set it later with configure. Re-running upgrades the binary in place (restarting only if it was running). Accepts the SEIKAN_* env vars as flags; --no-service/--bin/--unit-dir for non-standard targets. |
seikan-server configure [--set K=V …] [--no-restart] |
Set env values. --set SEIKAN_ADMIN_HOST=… --set SEIKAN_ACME_EMAIL=… (repeatable) edits the env file non-interactively — no editor — for scripted installs; with no --set it opens $EDITOR. On save it applies the change live if the service is running; a stopped (freshly-installed) service is left stopped — start it next. |
seikan-server update [--check] [--no-restart] |
Check SEIKAN_SITE (set at install time, in the env file) for a newer release; if one exists, download + SHA-256-verify it, replace the running binary in place, and restart the service if it was running. --check reports the available version without installing it. |
seikan-server start | stop | restart | status |
Manage the installed systemd service — thin systemctl <action> seikan-server wrappers. start/restart refuse to run until SEIKAN_ADMIN_HOST is configured. If setup isn't finished, start and restart print the setup key and the /_admin URL right in your terminal rather than leaving them in the journal. |
seikan-server setup-key |
Print the setup key that authorizes creating the first administrator. Safe to run while the server is up — it reads the state directory, not the database. Says so plainly once setup is complete. |
seikan-server user add|list|passwd|rm <username> |
Manage administrator accounts directly against the state DB — the password-recovery path, and how to add administrators until the UI manages them. --password for scripts, otherwise prompted without echo. Stop the service first: bbolt locks the database exclusively. |
seikan-server uninstall [--purge] |
Stop + remove the service, unit and env file (alias exec-uninstall); --purge also removes the state dir, system user and binary. |
seikan-server logs [-f] [-n 100] |
Stream the service journal (journalctl -u seikan-server); -f follows, -n sets line count. |
seikan-server verbose on|off|status |
Toggle per-request access logging on the running process — live, no restart. |
seikan-server version | help |
Print version / show help. |
The first-time flow is install → configure → start:
curl -fsSL https://seikan.okonomi.cloud/server/install.sh | sudo bash # install (service stopped)
sudo seikan-server configure --set SEIKAN_ADMIN_HOST=admin.example.com # or run with no --set to open $EDITOR
sudo seikan-server start # start; prints the setup key
start waits for the server to report its state and then prints the setup key and the URL to finish at. Open https://<admin-host>/_admin, paste the key, and create the first administrator (username + password). If you'd rather supply the setup key than have one generated, set SEIKAN_SETUP_KEY before the first start.
That account is what lets clients in. Each one runs seikan init --server <admin-host>, which shows a confirmation code and waits for you to approve it under Requests in the admin UI — or you issue a client key on the Client keys page and hand it over yourself.
To update, run sudo seikan-server update — it checks the configured site for a newer release and, if found, downloads, verifies, and swaps the binary in place, then restarts the service only if it was running. Re-running the installer (or sudo seikan-server install with a newer binary in hand) also still works and additionally backfills the env file with any new settings — your config is preserved either way.