chatcli connect runs your local ChatCLI against a remote ChatCLI server: the model calls go to the server, which holds the provider keys. Everything else (the REPL, /agent and /coder loops, @ tools, contexts, memory) runs on your machine, so tools read and change your files.
Connect
Flags
Client-side environment only (no flags):
There is no
--server flag and no TLS server-name override: the name you dial must be in the server certificate.
TLS and mTLS
kubectl port-forward you dial localhost, so the server certificate needs localhost (and 127.0.0.1) in its SANs.
LLM credential modes
- Server credentials
- Your API key
- Local OAuth
- StackSpot
- Ollama
No credential flags: the server uses its own provider and keys.Requests that name no provider or model go through the server’s fallback chain when it has one.
One-shot mode
-p sends one SendPrompt and exits with a non-zero status on error. Each run opens a new connection and authenticates again; that is fine for a tight loop, because the server’s failed-authentication limiter only counts authentications that fail.
Interactive mode
Without-p you get the full REPL with the remote model:
/agent,/coder,@file,@git,@commandand the other tools run locally; only the model calls go to the server./switchchanges provider or model;/costprices the real token usage the server reports for each reply.- Replies stream as the provider produces them (
StreamPrompt); the final message carries the usage, stop reason, and the provider and model that answered.
Remote plugins, sessions and watcher status
chatcli connect binds the session to the server exactly like the in-REPL /connect command, which switches an already running local session:
The server lists and executes plugins for
user and admin callers only: a readonly credential sees no remote plugins and cannot download one (PermissionDenied).
/connect accepts --token, --tls, --ca-cert (which implies --tls here too), --provider, --model, --llm-key, --use-local-auth and the StackSpot/Ollama flags. It does not read CHATCLI_REMOTE_TOKEN; pass --token. CHATCLI_ALLOW_INSECURE and the mTLS variables apply as for chatcli connect.
/watch status on a remote server prints:
Environment defaults
Multiple replicas
The client resolves the address withdns:/// and balances round-robin across every address, pinging each connection every 30 seconds (5 seconds timeout) to drop dead pods. Against a Kubernetes server with more than one replica, point it at a headless Service (service.headless: true in the chart; automatic in the operator when spec.replicas > 1).
Troubleshooting
Next steps
Server Mode
Configure and operate the server
Docker & Kubernetes
Deploy it
K8s Watcher
Kubernetes context in every prompt