Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Getting started

Prerequisites

Ask your TRE operator for a projected Client bootstrap and confirmation that your OIDC identity is admitted. The Client document contains Deployment identity, Trusted-runtime origin, and TLS trust, but no credentials.

Check the local installation

ahri-tre version
ahri-tre doctor --strict

Top-level version and doctor work without configuration, a daemon or login. doctor reports read-only local build and filesystem observations, their times and evidence limits. A successful local report does not establish remote readiness. Skipped checks suggest existing diagnostic commands for the next step; doctor does not run them. Neither command contacts the Trusted runtime.

doctor --format json includes the same findings and next steps as text. Any error exits 2; a required warning exits 1 under --strict; other reports exit 0.

Authenticate and start the Managed runtime

ahri-tre --config /etc/ahri-tre/client.toml auth login
ahri-tre --config /etc/ahri-tre/client.toml auth status

Open the authorization URL printed by auth login. The Trusted runtime owns the callback, validates the OIDC response, and retains the upstream OAuth artifacts. The Managed runtime receives only its short-lived opaque credential at the fixed ephemeral path.

ahri-tre --config /etc/ahri-tre/client.toml daemon start
ahri-tre daemon version
ahri-tre daemon doctor
ahri-tre daemon status

Explicit selection never falls back to a different document, local daemon endpoint, dotenv file, or process environment.

The daemon commands after start report the local Managed-runtime lifecycle, protocol compatibility, socket, state, and Session journals. A rendered or parseable Client bootstrap is not evidence that the client can reach the Trusted runtime. Local diagnostics deliberately do not claim client ready; that requires a successful authenticated remote protocol operation using the operator-admitted Runtime login.

Work in a configured profile

Select an execution profile through the authenticated Trusted-runtime protocol. The profile determines the allowed Datastore and workflow dependencies. Once a Session is authorized, ordinary domain, study, asset, dataset, transformation, and ingest commands use that Session capability.

Use ahri-tre --help and ahri-tre <command> --help for the installed command surface. Stop the managed daemon with ahri-tre daemon stop when finished. End the Runtime login with ahri-tre --config /etc/ahri-tre/client.toml auth logout.