nasiko CLI, a Nasiko cluster to connect it to, and an account on that cluster. Coding-agent discovery (nasiko agents discover) works with just the CLI.
Nasiko ships two command-line tools, both standalone Rust binaries:
Install the CLI
~/.cargo/bin. Reinstall with --force to update. Every build reports version 0.1.0, so nasiko --version can’t tell you whether a newer command is present.
Get a cluster
- Your organization's cluster
- Docker Compose (recommended locally)
- nasiko up
Get the URL and an account from your administrator. An administrator creates your account and gives you either a username and password, or an access key and secret. The secret is shown once, so save it.
Connect and sign in
1
Register the cluster
nasiko up does this step for you.2
Pick the active cluster
3
Sign in
~/.nasiko/config.json. Check it with nasiko auth status. Sign out with nasiko auth logout.Signing in (and connect or use while signed in) also installs session reporting for any detected coding agent that doesn’t have it yet. See Discover and register.Troubleshooting nasiko up
missing required env var: ADMIN_PASSWORD, or JWT_SECRET must be set
missing required env var: ADMIN_PASSWORD, or JWT_SECRET must be set
The server needs Then sign in as
ADMIN_PASSWORD and JWT_SECRET at startup, and nasiko up doesn’t set them. Export them in the shell you run it from:admin with the password you chose.Routing a coding agent fails with an authentication error
Routing a coding agent fails with an authentication error
Model routing needs
AGENT_JWT_SECRET on the server, and nasiko up doesn’t set it. Without it, the server refuses to issue routing credentials. Deployed agents also need LLM_GATEWAY_BASE_URL to be routed through Nasiko. Export both before starting:Sessions show up, but traces, tokens and cost stay empty
Sessions show up, but traces, tokens and cost stay empty
nasiko up doesn’t set TEMPO_URL, LOKI_URL or CODING_AGENT_OTLP_ENDPOINT, so the server starts with observability off even though Tempo and Loki are running. Export them before starting:Pulling the server image fails
Pulling the server image fails
nasiko up pulls nasiko/cp:latest from Docker Hub (or <DOCKERHUB_USER>/cp:latest if you set DOCKERHUB_USER) and extracts the server binary to ~/.nasiko/bin/nasiko-cp. It only pulls when that file doesn’t exist. If the pull fails, build the server from source and put it there:The server stops when you close the terminal
The server stops when you close the terminal
The infrastructure containers run detached, but the server is a child process of the shell you ran
nasiko up in. Closing that terminal stops it. Keep the terminal open, or use Docker Compose, which runs the server as a container.Admin CLI (nasiko-ee)
Enterprise. Everything in this section applies to the Enterprise edition only.
- Install script
- Build from source
~/.local/bin, never uses sudo, and never edits your shell rc files — it prints the PATH line to add.If piping
curl into bash is disallowed at your organization, download and review the script first.nasiko-ee --version.
Provision a cluster
~/.nasiko/.ee.env with a template for cloud credentials (AWS, DigitalOcean, Azure or GCP), your Docker Hub org, and optional keys such as OPENAI_API_KEY. Fill it in, then:
Registry access
The Enterprise server image comes from a private registry. Save the read-only pull token Nasiko provides:~/.nasiko/registry-values.json, which the cluster install commands use to authenticate pulls.
All nasiko-ee commands: Enterprise CLI reference.