Post by @andyc

#LittleFedi includes a powerful CLI that allows administrators to perform any operation available in the GUI. Useful for management and scripting.

$ littlefedi --config littlefedi.toml admin
Usage: littlefedi admin <command> [options]

Admin commands:
  self-destruct          Confirm decommissioning, or show delivery status when enabled.
  create-user --username <name> [--password <pw>] [--admin] [--email <addr>]
    Create a new local user. If --password is omitted, you will be prompted. If --admin is set, the user is 
    created as an administrator. Use --email to set the user's email address.
  set-admin --username <name>
   Toggle admin status for a user.
  list-users              List all local users.
  email-verification-report
    List existing users that require_email would lock out.
  show-user --username <name>
    Show detailed information about a local user.
  reset-password --username <name> [--password <pw>]
     Reset a user's password. Prompts if --password omitted.
  set-email --username <name> --email <addr>
     Set or change the email address of a local user.
  mfa-disable --username <name>
     Disable MFA for recovery; requires local CLI access.
  keys <status|encrypt|decrypt>
     Seal the ActivityPub private keys of local accounts at rest, or return them to plaintext.
     Needs LITTLEFEDI_FEDERATION_KEY_ENCRYPTION_KEY.
  delete-user --username <name> [--confirm]
      Delete a local user. Tombstones, federates Delete(Person), and removes all data. Requires --confirm.
  approve --username <name>
      Approve a pending registration.
  reject --username <name>
      Reject a pending registration (deletes the account).
  suspend --username <name>
      Suspend a user (tombstone + federate Delete(Person)).
  unsuspend --username <name>
     Clear suspension and reinstate a user.
  silence --username <name>
     Silence a user (hide from public timelines).
  unsilence --username <name>
     Remove silence from a user.
  disable --username <name>
     Disable a local user's login without removing content.
  enable --username <name>
     Re-enable a disabled local user.
  invite generate [--code <code>] [--uses <n>] [--expires <date>]
     Generate an invite code. Uses: max number of uses (0 = unlimited).
     Expires: YYYY-MM-DD.
  invite list             List all invite codes.
  invite revoke --code <code>
      Revoke an invite code.
  domain-block create --domain <domain> [--severity silence|suspend|noop]
                          [--comment <text>] [--public] [--reject-media]
                          [--reject-reports] [--obfuscate]
      Add an instance-wide domain block.
  domain-block list       List all domain blocks.
  domain-block delete --domain <domain>
      Remove an instance-wide domain block.
  domain-block import --file <path>
      Import text, generic CSV, or Mastodon CSV blocks.
  domain-allow create|list|delete|import
      Manage limited-federation domain allows.
  federation mode open|allowlist
      Change federation mode without restarting.
  commercial-bigtech enable|disable|refresh|status
     Manage the official commercial Big Tech list.
  media prune             Remove orphaned media (DB records with no status) and unreferenced 
                                   media files (disk files with no DB record).
  media prune-orphans     Remove only orphaned media DB records.
  media prune-files       Remove only unreferenced media files from disk.
  media storage-migrate DESTINATION_CONFIG
      Start a native, resumable owned-media migration.
  media storage-status    Show the active migration.
  media storage-cancel ID Request cancellation.
  media storage-resume ID Resume or retry a migration.
  media storage-manifest  Emit owned-media JSONL for rclone verification.
  relay add --actor <https-url>
      Save and enable a LitePub relay actor.
  relay list             List relays and handshake states.
  relay status --actor <https-url>
  relay enable --actor <https-url>
  relay disable --actor <https-url>
  relay remove --actor <https-url>
  blog rebuild [--username <name>]
      Regenerate a local account's static blog site now (blog build only; requires [blog] enabled = true).
  blog rebuild-all       Regenerate every allowed-to-blog local account's static site now (blog build only).
  refresh-actors          Queue a forced refresh of every known remote actor, even if not yet due. 
                                  Fetches run in the normal background queue workers, not immediately.