Command-line interface for Argus — a test tracking system for automated pipelines. Use it to inspect test runs, fetch logs, stream activity, submit comments, and manage SSH tunnels into Argus clusters.
Download the latest release from the releases page and place the binary somewhere on your $PATH.
For a quick install example, see the root README.
Requires Go 1.25+.
git clone https://github.com/scylladb/argus
cd argus/cli
go build -o argus .Most users only need one of these:
Use this on a developer machine when connecting to argus.scylladb.com or another Argus instance protected by Cloudflare Access.
argus authUse environment variables instead of keychain-based auth:
export ARGUS_CF_ACCESS_CLIENT_ID=your-client-id
export ARGUS_CF_ACCESS_CLIENT_SECRET=your-client-secret
export ARGUS_AUTH_TOKEN=your-patUse a direct token against a local or internal deployment:
argus auth-token <your-token>Check the current CLI configuration:
argus config listThis is where most people get stuck. Read this section before running any command.
The CLI needs two things to talk to Argus:
- A Personal Access Token (PAT) — a long-lived token stored in your system keychain (macOS Keychain, Windows Credential Manager, Linux Secret Service /
pass). - A Cloudflare Access credential — required only when Argus is behind Cloudflare Access (the default for production at
argus.scylladb.com).
The first time you run argus auth, it fetches both automatically and stores them. Subsequent commands pull them from the keychain silently. If a credential expires, the CLI re-authenticates transparently and retries.
cloudflared is Cloudflare's tunnel client. The CLI uses it to obtain a short-lived JWT that proves to Cloudflare Access that you are allowed through the firewall before your request ever reaches Argus.
You need cloudflared when:
- Connecting to
argus.scylladb.comor any other Argus instance protected by Cloudflare Access. - Running
argus auth(browser-based login).
You do NOT need cloudflared when:
- Connecting to
localhostor any loopback address — the CLI detects this automatically and skips all Cloudflare logic. - Using a service-account (headless) setup with
CF-Access-Client-Id/CF-Access-Client-Secretcredentials. - Running in CI/CD where you set
ARGUS_AUTH_TOKENorARGUS_TOKENdirectly. - You explicitly disable it (see Bypassing Cloudflare below).
The CLI manages cloudflared for you. It checks $PATH, then its own cache at $XDG_CACHE_HOME/argus-cli/cloudflared, and downloads the latest release from GitHub if neither is found. You do not need to install it manually.
For humans authenticating against a production Argus behind Cloudflare Access.
argus auth
Flow:
- Checks keychain — exits early if credentials are still valid.
- Invokes
cloudflared access login— opens a browser window for Cloudflare Access SSO. - Asks Argus about the PAT already in the keychain, if any (
GET /api/v1/user/tokenauthenticated with that token). A token Argus accepts that has not expired is kept and the flow stops here. - Otherwise exchanges the resulting JWT for an Argus session.
- Converts the session into a PAT valid for 14 days and stores it in the keychain.
You only need to do this once. After that, every command works without re-authentication.
If you are running on a server or in CI, this is the only supported mode.
The keychain-based modes (browser login and argus auth-token) require a system keychain daemon — macOS Keychain, Windows Credential Manager, or Linux Secret Service / pass. Most servers and CI runners do not have one. Without it, any command that tries to read from the keychain fails silently and the CLI has no credentials to send.
The solution is to skip the keychain entirely and supply credentials through environment variables:
export ARGUS_CF_ACCESS_CLIENT_ID=your-client-id
export ARGUS_CF_ACCESS_CLIENT_SECRET=your-client-secret
export ARGUS_AUTH_TOKEN=your-patSet these in your CI secret store or server environment and every argus command will pick them up automatically — no argus auth step, no keychain, no browser.
To get a service-account client ID and secret, ask your Cloudflare Access administrator. To get an Argus PAT, run argus auth once on a developer machine and copy the token out of the keychain, or have an admin generate one via the Argus web UI.
On a machine that does have a keychain, argus auth headless stores all three interactively:
argus auth headless
Prompts (masked) for the CF Access Client ID, CF Access Client Secret, and Argus PAT, then writes them to the keychain and sets use_cloudflare: false in the config file. After that, the CLI sends the CF Access service-account headers on every request instead of invoking cloudflared.
For local Argus instances or any deployment without Cloudflare Access.
argus auth-token <your-token>
Stores the PAT directly. Cloudflare is never consulted. This is equivalent to setting ARGUS_AUTH_TOKEN but persists the token to the keychain.
Several mechanisms disable Cloudflare integration. Use whichever fits your workflow:
| Mechanism | Scope | When to use |
|---|---|---|
Loopback URL (localhost, 127.*, ::1) |
automatic | Local dev — no action needed |
ARGUS_DISABLE_CLOUDFLARE=true |
env var, process-wide | CI/CD, scripts, one-off commands (also settable via argus config set use_cloudflare false) |
--disable-cloudflare flag |
single command | Ad-hoc overrides |
argus config set use_cloudflare false |
config file, persistent | When you always connect without CF |
Credentials are layered — later sources override earlier ones, so environment variables always win over the keychain.
Cloudflared mode (default, use_cloudflare: true):
- PAT from keychain
- Session cookie from keychain — fallback when no PAT is stored
- CF Access JWT from
cloudflared— fetched alongside #1 or #2; required by the CF firewall ARGUS_AUTH_TOKENenv var — overrides keychain PAT / sessionARGUS_TOKENenv var — fallback ifARGUS_AUTH_TOKENis unsetARGUS_CF_ACCESS_CLIENT_ID+ARGUS_CF_ACCESS_CLIENT_SECRET— overrides the cloudflared JWT
Headless mode (use_cloudflare: false):
- PAT from keychain
- CF service-account bundle from keychain — fallback when no PAT is stored (holds both CF headers and an Argus PAT, stored by
argus auth headless) ARGUS_AUTH_TOKENenv var — overrides keychain PATARGUS_TOKENenv var — fallback ifARGUS_AUTH_TOKENis unsetARGUS_CF_ACCESS_CLIENT_ID+ARGUS_CF_ACCESS_CLIENT_SECRET— overrides CF headers from keychain
argus auth logout
Removes all stored credentials (PAT, session, CF service-account bundle) from the system keychain.
Config file lives at $XDG_CONFIG_HOME/argus-cli/config.yaml (on Linux: ~/.config/argus-cli/config.yaml). It is created with defaults on first run.
url: https://argus.scylladb.com
use_cloudflare: trueManage it with:
argus config list
argus config get url
argus config set url https://my-argus.internal
argus config set use_cloudflare false| Purpose | Path |
|---|---|
| Config file | $XDG_CONFIG_HOME/argus-cli/config.yaml |
| Cached responses | $XDG_CACHE_HOME/argus-cli/cache/ |
| Cloudflared binary | $XDG_CACHE_HOME/argus-cli/cloudflared |
| Logs | $XDG_CACHE_HOME/argus-cli/logs/ |
| Credentials | System keychain |
On Linux $XDG_CONFIG_HOME defaults to ~/.config and $XDG_CACHE_HOME to ~/.cache.