diff --git a/content/en/docs/overview.md b/content/en/docs/overview.md index f263d57..aaae17f 100644 --- a/content/en/docs/overview.md +++ b/content/en/docs/overview.md @@ -79,7 +79,9 @@ Both are for administrators by default, so `sudo nspawn ...` works as it always did, and a desktop session (or a terminal where you started `pkttyagent`) is asked for a password instead. Root is never asked, which is also how the service keeps working where polkit is not installed: there, nobody but root can -call it. +call it. One interface asks nothing: `org.nspawn.Names` hands out the names of +machines, images, networks and volumes, and nothing else about them, to any +user. To drive nspawn without a password, an administrator hands an action to a group in a rule of their own. The packages ship one as an example in their diff --git a/content/en/docs/reference.md b/content/en/docs/reference.md index 99f8526..c4f5283 100644 --- a/content/en/docs/reference.md +++ b/content/en/docs/reference.md @@ -769,9 +769,24 @@ not a command to type; `--install` is. nspawn completions bash|elvish|fish|powershell|zsh ``` -Writes the completions for that shell on standard output; they come from the -same definition the command line itself is built from. The packages install -them, so this is for a binary you built yourself: +Writes the completions for that shell on standard output. Commands and flags +come from the same definition the command line itself is built from; besides +them, TAB completes names, asked from the service as it goes: + +| After | TAB offers | +| --- | --- | +| `stop`, `exec`, `kill`, `pause`, `unpause`, `top`, `shell`, `stats` | the running machines | +| `start` | the images that do not run | +| `rm`, `inspect`, `logs`, `restart`, `update`, `images rm` | every machine and image | +| `create`, `push` | the local images | +| `run` | the references of the local images | +| `--network` | the networks, and `host`, `none` and `veth` | +| `network rm`, `network inspect` | the networks | +| `volume rm` | the volumes | + +The service hands those names to any user without asking polkit, so this works +under `sudo` and without a password; secrets are not completed. The packages +install the completions, so this is for a binary you built yourself: ```shell nspawn completions bash > ~/.local/share/bash-completion/completions/nspawn diff --git a/hugo.yaml b/hugo.yaml index 1a9dc15..0d65832 100644 --- a/hugo.yaml +++ b/hugo.yaml @@ -53,7 +53,7 @@ params: privacy_policy: /about/#privacy # Version of nspawn the documentation describes. - version: 1.8.0 + version: 1.9.0 archived_version: false # In-page links to open issues and suggest changes.