targets.json
The file your targets are kept in: where it lives, what each field means, and how to edit it safely.
On this page
Your targets are kept in one file:
~/.ysra/targets.json
It lives only on your computer. It's readable and writable by you alone
(mode 0600, inside ~/.ysra, which is 0700). It's never uploaded. Ysra's
servers learn each target's name, kind, via, cli, mode and
production, so I know what I can ask for. They never learn ssh_alias, a
host name, an address, a user or a port.
Tip
Prefer the commands (ysra target …) or Settings → Targets. They check
what you enter and pin the host key. Edit the file by hand only for the cases
listed under Editing it safely.
Example#
[
{
"name": "edge-01",
"kind": "linux",
"via": "ssh",
"ssh_alias": "edge-01",
"mode": "observe",
"production": false,
"host_key_fingerprint": "SHA256:pV3n0cT7q…k9Q"
},
{
"name": "lab-vcenter",
"kind": "esxi",
"via": "cli",
"cli": "govc",
"mode": "change",
"production": true
}
]
The file is a list. Each entry is one target.
Fields#
| Field | Required | Values | Meaning |
|---|---|---|---|
name |
Yes | Lowercase letters, digits, ., _, -. Starts with a letter or digit. Up to 63 characters |
What you and I call the target. Also the name you type to confirm a destructive step on production |
kind |
Yes | linux, esxi, network, oss, other |
What sort of machine it is |
via |
Yes | ssh or cli |
How I reach it |
ssh_alias |
When via is ssh |
A Host from your ~/.ssh/config |
The host, user, port and key all come from your SSH config. None of that is copied here |
cli |
When via is cli |
One tool name, for example govc, kubectl |
The command-line tool I run on your computer with your sign-in. Not a shell, sudo, ssh or a scripting language |
mode |
Yes | observe or change |
observe: I only read. change: I may run changes, each after your OK |
production |
Yes | true or false |
true: destructive commands need the target's name typed |
host_key_fingerprint |
SSH targets | SHA256:… |
The fingerprint you confirmed when adding the target. Shown in lists so you can recognise it. For display |
Editing it safely#
| Change | By hand? | Better |
|---|---|---|
mode |
Fine | ysra target mode <name> observe\|change |
production |
Fine | ysra target production <name> on\|off |
kind |
Fine | — |
| Add an SSH target | No | ysra target add. Only adding it properly fetches the host key, shows you the fingerprint and pins it. An SSH target without a pinned key is refused |
Change ssh_alias |
No | Remove the target and add it again, so the new host's key is checked |
| Rename a target | No | Remove and add again. The pinned key and the log are kept under the name |
host_key_fingerprint |
No | Changing the text doesn't change which key is pinned |
If you do edit by hand:
- Close Ysra first, so it doesn't write over your edit.
- Keep it valid JSON. If the file can't be read, I treat it as having no targets and say so. Nothing is deleted.
- Keep it private:
chmod 600 ~/.ysra/targets.json. - Run
ysra target listto confirm it reads the way you meant.
Don't put passwords, keys or tokens in this file. There's no field for them, and I never use one.
Related files#
| Path | What |
|---|---|
~/.ysra/targets/known_hosts |
The pinned host keys. Managed for you; don't edit |
~/.ysra/targets/<name>/log.jsonl |
What ran on that target and who approved it. Kept when the target is removed |
Moving to another computer#
Targets don't sync, by design. On the new computer, add each one again with
ysra target add and confirm its host key there.