# CLI Docs
[teleport](#teleport)
[tsh](#tsh)
[tctl](#tctl)
## teleport
The Teleport daemon is called `teleport` . It can be configured to run one or
more "roles" with the `--roles` flags. The arguments to `--roles` correspond to
the following services.
| Service | Role Name | Description
| ------- | --------- | ----------- |
| [Node](architecture/teleport_nodes.md) | `node` | Runs a daemon on a node which allows SSH connections from authenticated clients.
| [Auth](architecture/teleport_auth.md) | `auth` | Authenticates nodes and users who want access to Teleport Nodes or information about the cluster
| [Proxy](architecture/teleport_proxy.md) | `proxy` | The gateway that clients use to connect to the Auth or Node Services
## teleport start
### Flags
| Name | Default Value(s) | Allowed Value(s) | Description
|------|---------|----------------|----------------------------|
| `-d, --debug` | none | none | enable verbose logging to stderr
| `--insecure-no-tls` | `false` | `true` or `false` | Tells proxy to not generate default self-signed TLS certificates. This is useful when running Teleport on kubernetes (behind reverse proxy) or behind things like AWS ELBs, GCP LBs or Azure Load Balancers where SSL termination is provided externally.
| `-r, --roles` | `proxy,node,auth` | **string** comma-separated list of `proxy, node` or `auth` | start listed services/roles. These roles are explained in the [Teleport Architecture](architecture/teleport_architecture_overview.md) document.
| `--pid-file` | none | **string** filepath | create a PID file at the path
| `--advertise-ip` | none | **string** IP | advertise IP to clients, often used behind NAT
| `-l, --listen-ip` | `0.0.0.0` | [**net. IP**](https://golang.org/pkg/net/#IP) | binds services to IP
| `--auth-server` | none | **string** IP | proxy attempts to connect to a specified auth server instead of local auth, disables `--roles=auth` if set
| `--token` | none | **string** | set invitation token to register with an auth server on start, used once and ignored afterwards. Obtain it by running `tctl nodes add` on the auth server._We recommend to use tools like `pwgen` to generate sufficiently random tokens of 32+ byte length._
| `--ca-pin` | none | **string** `sha256:` | set CA pin to validate the Auth Server. Generated by `tctl status`
| `--nodename` | `hostname` command on the machine | **string** | assigns an alternative name for the node which can be used by clients to login. By default it's equal to the value returned by
| `-c, --config` | `/etc/teleport.yaml` | **string** `.yaml` filepath | starts services with config specified in the YAML file, overrides CLI flags if set
| `--bootstrap` | none | **string** `.yaml` filepath | bootstrap configured YAML resources
| `--labels` | none | **string** comma-separated list | assigns a set of labels to a node. See the explanation of labeling mechanism in the [Labeling Nodes](admin-guide.md#labeling-nodes) section.
| `--insecure` | none | none | disable certificate validation on Proxy Service, validation still occurs on Auth Service.
| `--fips` | none | none | start Teleport in FedRAMP/FIPS 140-2 mode.
| `--diag-addr` | none | none | Enable diagnostic endpoints
| `--permit-user-env` | none | none | flag reads in environment variables from `~/.tsh/environment` when creating a session.
!!! warning "Token Generation"
We recommend the use of tools like `pwgen` to generate sufficiently random tokens of 32+ byte length.
## teleport status
`teleport status` shows the status of a Teleport connection. This command is
only available from inside of a recorded SSH session.
## teleport configure
`teleport configure` dumps a **sample** configuration file in YAML format into
standard output.
**Caution**: This sample config is _not_ the default config and should be used
for reference only.
## teleport version
`teleport version` show the release version
## teleport help
`teleport help` shows help `teleport` and its subcommands like this `teleport
help `
# tsh
`tsh` is a CLI client used by Teleport Users. It allows users to interact with
current and past sessions on the cluster, copy files to and from nodes, and list
information about the cluster.
## tsh Global Flags
| Name | Default Value(s) | Allowed Value(s) | Description
|------|---------|----------------|----------------------------|
| `-l, --login` | none | an identity name | the login identity that the Teleport User should use
| `--proxy` | none | `host:https_port[,ssh_proxy_port]` | set SSH proxy address
| `--user` | `$USER` | none | the Teleport User name
| `--ttl` | none | relative duration like 5s, 2m, or 3h | set time to live for a SSH session, session ttl unrestricted if unset
| `-i, --identity` | none | **string** filepath | Identity file
| `--cert-format` | `file` | `file` or `openssh` | SSH certificate format
| `--insecure` | none | none | Do not verify server's certificate and host name. Use only in test environments
| `--auth` | `local` | any defined [authentication connector](admin-guide.md#authentication) | Specify the type of authentication connector to use.
| `--skip-version` | none | none | Skip version checking between server and client.
| `-d, --debug` | none | none | Verbose logging to stdout
| `-J, --jumphost` | none | A jump host | SSH jumphost
## tsh help
Prints help
**Usage** `tsh help`
## tsh version
Prints client version
**Usage** `tsh version`
## tsh ssh
Run shell or execute a command on a remote SSH node
**Usage**: `tsh ssh [] <[user@]host> [...]`
### Arguments
`<[user@]host> [...]`
* `user` The login identity to use on the remote host. If `[user]` is not specified
the user defaults to `$USER` or can be set with `--user` . If the flag `--user`
and positional argument `[user]` are specified the arg `[user]` takes precedence.
* `host` A `nodename` of a cluster node or a
* `command` The command to execute on a remote host.
### Flags
| Name | Default Value(s) | Allowed Value(s) | Description
|------|---------|----------------|----------------------------|
| `-p, --port` | none | port | SSH port on a remote host
| `-A, --forward-agent` | none | none | Forward agent to target node like `ssh -A`
| `-L, --forward` | none | none | Forward localhost connections to remote server
| `-D, --dynamic-forward ` | none | none | Forward localhost connections to remote server using SOCKS5
| `--local` | none | | Execute command on localhost after connecting to SSH node
| `-t, --tty` | `file` | | Allocate TTY
| `--cluster` | none | | Specify the cluster to connect
| `-o, --option` | `local` | | OpenSSH options in the format used in the configuration file
### [Global Flags](#tsh-global-flags)
These flags are available for all commands `--login, --proxy, --user, --ttl,
--identity, --cert-format, --insecure, --auth, --skip-version, --debug,
--jumphost `. Run ` tsh help ` or see the [Global Flags
Section](#tsh-global-flags)
### Examples
```
# Log in to node `grav-00` as OS User `root` with Teleport User `teleport`
$ tsh ssh --proxy proxy.example.com --user teleport -d root@grav-00
# `tsh ssh` takes the same arguments as OpenSSH client:
$ tsh ssh -o ForwardAgent=yes root@grav-00
$ tsh ssh -o AddKeysToAgent=yes root@grav-00
```
## tsh join
Joins an active session
**Usage**: `tsh join [] `
### Arguments
``
* `session-id` The UUID of the an active Teleport Session obtained by `teleport status` within
the session.
### Flags
| Name | Default Value(s) | Allowed Value(s) | Description
|------|---------|----------------|----------------------------|
| `--cluster` | none | a cluster_name | Specify the cluster to connect
### [Global Flags](#tsh-global-flags)
These flags are available for all commands `--login, --proxy, --user, --ttl,
--identity, --cert-format, --insecure, --auth, --skip-version, --debug,
--jumphost `. Run ` tsh help ` or see the [Global Flags
Section](#tsh-global-flags)
### Examples
```
tsh --proxy proxy.example.com join
```
## tsh play
Plays back a prior session
**Usage**: `tsh play [] `
### Arguments
``
* `session-id` The UUID of the a past Teleport Session obtained by `teleport status` within
the session or from the Web UI.
### Flags
| Name | Default Value(s) | Allowed Value(s) | Description
|------|---------|----------------|----------------------------|
| `--cluster` | none | a cluster_name | Specify the cluster to connect
### [Global Flags](#tsh-global-flags)
These flags are available for all commands `--login, --proxy, --user, --ttl,
--identity, --cert-format, --insecure, --auth, --skip-version, --debug,
--jumphost `. Run ` tsh help ` or see the [Global Flags
Section](#tsh-global-flags)
### Examples
```
tsh --proxy proxy.example.com play
```
## tsh scp
Copies files from source to dest
**Usage** `usage: tsh scp [] ... `
### Arguments
* `` - filepath to copy
* `` - target destination
### Flags
| Name | Default Value(s) | Allowed Value(s) | Description
|------|---------|----------------|----------------------------|
| `--cluster` | none | a cluster_name | Specify the cluster to connect
| `-r, --recursive` | none | none | Recursive copy of subdirectories
| `-P, --port` | none | port number | Port to connect to on the remote host
| `-q, --quiet` | none | none | Quiet mode
### [Global Flags](#tsh-global-flags)
These flags are available for all commands `--login, --proxy, --user, --ttl,
--identity, --cert-format, --insecure, --auth, --skip-version, --debug,
--jumphost `. Run ` tsh help ` or see the [Global Flags
Section](#tsh-global-flags)
### Examples
``` bsh
$ tsh --proxy=proxy.example.com scp -P example.txt user@host/destination/dir
```
## tsh ls
List cluster nodes
**Usage** `usage: tsh ls [] [