Skip to main content
chatcli connect runs your local ChatCLI against a remote ChatCLI server: the model calls go to the server, which holds the provider keys. Everything else (the REPL, /agent and /coder loops, @ tools, contexts, memory) runs on your machine, so tools read and change your files.

Connect

On success:
When the server runs a K8s watcher, a second line says so and its context is added to every prompt on the server side.
The connection is TLS by default, with or without --tls: a server with a publicly trusted certificate needs no flag, and one signed by a private CA needs --ca-cert ca.crt (a CA file implies --tls, so the CA is used even when --tls is omitted). Plaintext needs an explicit opt-out, CHATCLI_ALLOW_INSECURE=true. Against a plaintext server (a local chatcli server, a chart with tls.enabled=false behind kubectl port-forward) you need:
Without it the connection fails with tls: first record does not look like a TLS handshake.

Flags

Client-side environment only (no flags): There is no --server flag and no TLS server-name override: the name you dial must be in the server certificate.

TLS and mTLS

Through kubectl port-forward you dial localhost, so the server certificate needs localhost (and 127.0.0.1) in its SANs.

LLM credential modes

No credential flags: the server uses its own provider and keys.
Requests that name no provider or model go through the server’s fallback chain when it has one.

One-shot mode

-p sends one SendPrompt and exits with a non-zero status on error. Each run opens a new connection and authenticates again; that is fine for a tight loop, because the server’s failed-authentication limiter only counts authentications that fail.

Interactive mode

Without -p you get the full REPL with the remote model:
  • /agent, /coder, @file, @git, @command and the other tools run locally; only the model calls go to the server.
  • /switch changes provider or model; /cost prices the real token usage the server reports for each reply.
  • Replies stream as the provider produces them (StreamPrompt); the final message carries the usage, stop reason, and the provider and model that answered.

Remote plugins, sessions and watcher status

chatcli connect binds the session to the server exactly like the in-REPL /connect command, which switches an already running local session:
The server lists and executes plugins for user and admin callers only: a readonly credential sees no remote plugins and cannot download one (PermissionDenied). /connect accepts --token, --tls, --ca-cert (which implies --tls here too), --provider, --model, --llm-key, --use-local-auth and the StackSpot/Ollama flags. It does not read CHATCLI_REMOTE_TOKEN; pass --token. CHATCLI_ALLOW_INSECURE and the mTLS variables apply as for chatcli connect. /watch status on a remote server prints:

Environment defaults

Multiple replicas

The client resolves the address with dns:/// and balances round-robin across every address, pinging each connection every 30 seconds (5 seconds timeout) to drop dead pods. Against a Kubernetes server with more than one replica, point it at a headless Service (service.headless: true in the chart; automatic in the operator when spec.replicas > 1).

Troubleshooting

Next steps

Server Mode

Configure and operate the server

Docker & Kubernetes

Deploy it

K8s Watcher

Kubernetes context in every prompt