Getting started
Prerequisites
Ask your TRE operator for a projected Client bootstrap and confirmation that your OIDC identity is admitted. The Client document contains Deployment identity, Trusted-runtime origin, and TLS trust, but no credentials.
Check the local installation
ahri-tre version
ahri-tre doctor --strict
Top-level version and doctor work without configuration, a daemon or login.
doctor reports read-only local build and filesystem observations, their times
and evidence limits. A successful local report does not establish remote
readiness. Skipped checks suggest existing diagnostic commands for the next
step; doctor does not run them. Neither command contacts the Trusted runtime.
doctor --format json includes the same findings and next steps as text. Any
error exits 2; a required warning exits 1 under --strict; other reports exit 0.
Authenticate and start the Managed runtime
ahri-tre --config /etc/ahri-tre/client.toml auth login
ahri-tre --config /etc/ahri-tre/client.toml auth status
Open the authorization URL printed by auth login. The Trusted runtime owns
the callback, validates the OIDC response, and retains the upstream OAuth
artifacts. The Managed runtime receives only its short-lived opaque credential
at the fixed ephemeral path.
ahri-tre --config /etc/ahri-tre/client.toml daemon start
ahri-tre daemon version
ahri-tre daemon doctor
ahri-tre daemon status
Explicit selection never falls back to a different document, local daemon endpoint, dotenv file, or process environment.
The daemon commands after start report the local Managed-runtime lifecycle,
protocol compatibility, socket, state, and Session journals. A rendered or
parseable Client bootstrap is not evidence that the client can reach the
Trusted runtime. Local diagnostics deliberately do not claim client ready;
that requires a successful authenticated remote protocol operation using the
operator-admitted Runtime login.
Work in a configured profile
Select an execution profile through the authenticated Trusted-runtime protocol.
The profile determines the allowed Datastore and workflow dependencies. Once a
Session is authorized, ordinary domain, study, asset, dataset,
transformation, and ingest commands use that Session capability.
Use ahri-tre --help and ahri-tre <command> --help for the installed command
surface. Stop the managed daemon with ahri-tre daemon stop when finished.
End the Runtime login with ahri-tre --config /etc/ahri-tre/client.toml auth logout.