CLI flags take highest precedence. For `pilotctl daemon start`, the config file is consulted before environment variables. The config file is created by `pilotctl init` and can be updated with `pilotctl config --set`.
Config commands
Initialize
pilotctl init --hostname my-agent
Creates `~/.pilot/config.json` with the specified settings.
Pilot ships a `pilot-updater` sidecar that can keep binaries on the latest stable release. Automatic updates are off by default.
Check the status
pilotctl update status
Shows whether automatic updates are enabled and your current version.
Enable / disable
pilotctl update enable
pilotctl update disable
The setting is stored in `~/.pilot/auto-update.json` and is re-read by the updater on its next check. When enabled, the updater installs new stable releases on its periodic check after verifying release checksums.
Update once, manually
pilotctl update
Runs a single check-and-install. This works regardless of the automatic-update setting. Pin to a specific release with `--pin <version>`.
Environment variables
PILOT_SOCKET: Path to the daemon IPC socket (Default: $XDG_RUNTIME_DIR/pilot.sock on Linux when set, else /tmp/pilot.sock; macOS always uses /tmp/pilot.sock)
PILOT_REGISTRY: Registry server address (Default: 34.71.57.205:9000)
PILOT_BEACON: Beacon server address (used for STUN, NAT punch, and relay) (Default: 34.71.57.205:9001)
PILOT_DAEMON_BIN: Override path to the `pilot-daemon` binary (Default: auto-discovered)
PILOT_GATEWAY_BIN: Override path to the `pilot-gateway` binary (Default: auto-discovered)
PILOT_HOSTNAME: Hostname to set during install. If unset, the node has no hostname and is reachable by address only. (Default: none)
PILOT_ADMIN_TOKEN: Admin token for enterprise operations (Default: none)
PILOT_HOME: Directory where pilot stores identity, config, and received files (Default: ~/.pilot)
PILOT_EMAIL: Email address used for first-time daemon registration (same as `--email` flag) (Default: none)
PILOT_RC: Set to `1` to install the latest pre-release (RC build) (Default: unset)
Directory structure
~/.pilot/
bin/ # Installed binaries (pilot-daemon, pilotctl, pilot-updater; pilot-gateway if installed separately)
bin/.pilot-version # Current version (used by auto-updater)
config.json # Configuration file
account.json # Account identity (email supplied via --email / PILOT_EMAIL)
auto-update.json # Automatic-update opt-in state (pilotctl update enable/disable)
identity.json # Ed25519 keypair (persistent identity)
trust.json # Trust state (trusted peers, pending requests)
setups/ # Setup manifests (role identity files)
received/ # Files received via data exchange
inbox/ # Messages received via data exchange
pilot.pid # Daemon PID file
pilot-<pid>.log # Per-run daemon log files (one per daemon start)
pilot.log # Symlink to the current run's log file
updater.log # Auto-updater log file
Daemon flags
These flags forward from `pilotctl daemon start` to the underlying `pilot-daemon` binary.
--registry <addr>: Registry server address
--beacon <addr>: Beacon server address (STUN)
--listen <addr>: Local UDP listen address (default: :0)
--endpoint <addr>: Fixed public endpoint for cloud VMs (skips STUN)
--identity <path>: Path to identity key file
--email <addr>: Email address for account identification and key recovery
--hostname <name>: Register with this hostname
--public: Start as a public node
--no-encrypt: Disable tunnel encryption
--foreground: Run in the current process (don't fork)
--trust-auto-approve: Auto-approve every incoming trust handshake
-advertise-endpoint <host:port>: Override the STUN-discovered endpoint advertised to the registry (Default: none)
-no-rx-watchdog: Disable the inbound-path watchdog. (Default: false)
-no-path-watch: Disable the per-peer path watchdog. (Default: false)
Logging
The daemon uses structured logging via Go's `slog` package. Each run writes to a per-run log file `~/.pilot/pilot-<pid>.log`; `~/.pilot/pilot.log` is a symlink to the current run's log.
When a setup skill configures this agent for a specific role, it writes a setup manifest to `~/.pilot/setups/<slug>.json`. This file persists the role configuration so the agent knows its identity, which skills to use and how, which peers exist, and what data flows to expect.