---
title: "Operating a Core"
url: "https://control.actana.ai/docs/core/operating"
description: "The machine verbs: status, logs, start/stop, update, rotate identity, uninstall — and their Docker equivalents."
updated: 2026-09-01T09:03:14+00:00
---

The **machine verbs** operate this machine's Core. They do not take `--core` — the Core they mean is the one on the box you are typing on. (Driving Cores near or far is the [client commands](/docs/cli/commands).)

## Install and activate

Installing is not activating.

| Verb | What it does |
| --- | --- |
| `actana install` | Fetch a release, verify the checksum, unpack, and start a Core. |
| `actana place` | Put an extracted bundle here and link the launcher, then stop. Nothing is started, no identity is minted. This is what `install.sh` runs. |
| `actana setup` | Activate from a placed bundle — or fetch one when there is none. Writes the auto-start unit, starts the daemon, registers this Core with this machine's `actana`. |

Details: [Install Core](/docs/install/install-core) and [Actana Setup](/docs/install/actana-setup).

## Day-to-day

```bash
actana status
actana logs -f
actana start
actana stop
actana restart
```

`status` prints the daemon's health, versions, endpoint, and Harness availability — and exits non-zero when the Core is not healthy, so it works as a health check in scripts. `logs` takes `-f` / `--follow` and `-n` / `--lines <n>`; on Linux it reads the journal, on macOS it tails `~/Library/Logs/Actana/core.log`. `start`, `stop` and `restart` drive systemd or launchctl for you.

Pairing lifecycle — mint, list, revoke — is on [Create a Pairing Code](/docs/pairing/create-a-pairing-code):

```bash
actana pair new
actana pair ls
actana pair revoke <target>
```

`actana pair` is the Core end; `actana core pair` is the client end.

## Update

```bash
actana update
```

`update` asks for the newest **release**, verifies the tarball against `SHA256SUMS`, installs it beside the running one, and repoints `current` before restarting. Pairing stays intact. Pin with `actana update --version x.y.z`. A beta machine is left alone by a bare `update` — see [Installing a Beta](/docs/install/installing-a-beta). Once a day `status` names a newer release if one exists; nothing downloads until you type `update`. `ACTANA_UPDATE_CHECK=0` turns the check off.

## Rotate identity

```bash
actana token regenerate
```

Mints a fresh CA, certificates and bearer secret, then restarts the daemon — **every paired client stops working** and must pair again. There is no `actana token` that reprints a credential. The full re-pairing choreography, including the Panel's remove-first step: [Rotate the CA](/docs/pairing/create-a-pairing-code#rotate-the-ca).

## Install a Harness later

```bash
actana harnesses install opencode
```

The id is the Harness name or its command (`claude-code` and `claude` both work). After an install the Core re-probes immediately, so a paired Panel sees the new Harness without a restart. See [Harnesses](/docs/core/harnesses).

## Uninstall

```bash
actana uninstall              # keep sessions and credentials
actana uninstall --purge-data # also delete those; cannot be undone
```

Without `--purge-data`, reinstalling picks up where you left off with the same Panel still paired. Both forms ask for confirmation; pass `--yes` in a script.

## Inside the Core image

The image is the install, so lifecycle verbs **refuse** and print the Docker command that does the same job:

| Verb | On the host |
| --- | --- |
| `setup` | set `ACTANA_PUBLIC_HOST`, then `docker compose up -d` |
| `start` / `stop` / `restart` | `docker compose up -d` / `stop` / `restart` |
| `update` | `docker compose pull && docker compose up -d` |
| `logs` | `docker compose logs -f core` |
| `uninstall` | `docker compose down` (`-v` also deletes sessions and pairing) |

These still work inside the container: `status`, `pair`, `token regenerate` (then `docker compose restart` so the daemon loads the new material), `harnesses`. The image reads `ACTANA_PUBLIC_HOST` (required, never guessed), `ACTANA_PORT`, and `ACTANA_LABEL`. Client commands are never refused in the image.

## See also

- [Actana Setup](/docs/install/actana-setup)
- [Create a Pairing Code](/docs/pairing/create-a-pairing-code)
- [Observability](/docs/reference/observability) — where logs land, lines worth grepping.
- [Environment Variables](/docs/reference/environment-variables)
