ados plugin subcommand tree is the operator and developer interface
to the agent’s plugin host: install, enable, inspect, sign, and lint
plugins. This page documents all 16 subcommands, their flags, and the
exit codes every command shares.
Run ados plugin --help on the agent for the same list, or
ados plugin <command> --help for a single command.
The --json flag
Every subcommand accepts --json. With it, the command prints a single
machine envelope to stdout instead of human-readable text:
code is the process exit code (see Exit codes), kind
is the stable string form of that code, data is the per-command
payload, and hint (when present) is a suggested next step. Use the
JSON form in scripts and CI; parse .ok and .code rather than the
human text, which is not stable.
Exit codes
Everyados plugin subcommand returns one of these codes. The JSON
envelope’s kind field carries the same meaning as a string.
Lifecycle commands
list
List installed plugins.
The human table prints
ID, VERSION, STATUS, and SIGNER. Built-in
plugins (with --all) show status builtin and signer altnautica.
install
Install a .adosplug archive from a local path.
Install verifies the signature (unless
--allow-unsigned), validates the
manifest, and checks compatibility. It then prints the plugin id, its
risk level, and the permissions requested, and prompts for approval. If
you decline, the plugin is uninstalled and the command exits 0.
--yes approves the listed permissions without a prompt, but it refuses
any plugin whose risk is high or critical (exit 4); re-run those
interactively. A signature failure exits 3, a bad manifest exits 2, a
compatibility mismatch exits 8.
After a successful install the plugin is installed but not yet running.
Enable it next:
enable
Enable an installed plugin so the host starts it.
Exits 5 if no plugin with that id is installed.
disable
Disable a plugin. It stays installed, with its grants intact, but the
host stops running it.
remove
Stop, uninstall, and forget a plugin.
Inspection commands
info
Print a manifest summary and runtime state for one plugin.
The human output lists the version, status, signer, install source, and
each permission with its grant state. Exits 5 if the id is neither
installed nor a built-in.
perms
Show or revoke permissions on an installed plugin.
With no
--revoke, the command lists each recorded permission as
GRANTED or DENIED. With --revoke, it confirms intent (unless -y
or --json), then revokes the grant. The plugin loses access to the
protected resource on the next token rotation, which can interrupt a
running workload. Exits 5 if the plugin is not installed.
logs
Tail a plugin’s stdout and stderr log file.
The log file lives in the plugin log directory, named after the plugin
id with dots replaced by dashes. Exits 5 if no log file exists (the
plugin may never have started, or its log rotated out).
Update commands
pin
Pin a plugin to a version so auto-update skips it.
unpin
Clear the pinned version so auto-update can run again.
auto-update
Toggle auto-update on or off for one plugin.
check-updates
Run the auto-update poll once and print the outcome per plugin, instead
of waiting for the daily cadence.
It honours each plugin’s pin and auto-update flags. The agent must be
paired to the cloud relay (the registry credentials live in the pairing
state); if it is not paired, the command exits 1 and the hint suggests
running
ados pair first. Only enabled and running plugins are checked.
The hosted plugin registry is planned, not live.
check-updates and the
auto-update flags are wired against it for when it ships. See
Distribution: registry.Developer commands
These commands run on a developer workstation against a plugin directory or a packed archive, not against installed plugins.lint
Run static analysis on a packed .adosplug archive before submission.
Exits 0 when the report passes, 1 when it carries a finding at severity
error or critical, 2 when the manifest is invalid. The full rule set
is documented under Linting.
test
Run a plugin’s pytest suite under the SDK test harness.
The command validates the manifest, sets
ADOS_PLUGIN_ID,
ADOS_PLUGIN_VERSION, ADOS_PLUGIN_ROOT, and (when declared)
ADOS_PLUGIN_TEST_FIXTURES in the environment, then shells out to
pytest so your tests run against the canonical runner. Exits 0 when
pytest passes, 1 when it fails, 2 on a bad manifest, 5 when the tests
directory is missing.
sign
Pack a plugin directory into a signed .adosplug archive.
The command packs the directory, computes the canonical payload hash
(SHA-256 over the sorted entry hashes), signs that digest with the
Ed25519 key, and writes a
SIGNATURE entry into the archive plus a
.sha256 checksum file next to it. The signing details and the
monorepo-CI alternative (pack.sh and sign.sh) are covered under
Signing keys.
keygen
Generate a fresh Ed25519 keypair for plugin signing.
Writes
<signer-id>.pem (the public key, mode 0644) and
<signer-id>.priv.pem (the private key, mode 0600) under the output
directory, and prints a SHA-256 fingerprint of the public key for
cross-checking. Install the public PEM on each agent at
/etc/ados/plugin-keys/<signer-id>.pem and keep the private half
offline.