Skip to content

Running Orbit ​

Checking on it ​

sh
sudo orbit status                      # administrator, installation, operations, servers, agents, certificate validity
journalctl -u orbit -f                 # the control plane
journalctl -u orbit-agent -f           # the agent
journalctl -u k3s                      # Kubernetes
sudo k3s kubectl get pods -A           # what runs on the server

orbit status reads Orbit's database read-only and works while Orbit runs.

Metrics ​

Every 30 seconds Orbit samples each server and the workloads it runs, and keeps 8 days of samples:

  • Applications: CPU as a share of their limit, the memory of the busiest instance, network in and out, and restarts with their cause.
  • Databases: the same, plus the storage used on their volume and the connected clients.
  • Servers: CPU, memory and disk in use.

The pages show current usage and charts over 1 hour, 24 hours or 7 days. When Orbit could not sample (it was down, or Kubernetes did not answer), the charts show the gap instead of a line, and the timeline says for how long.

What the logs never hold ​

Every log line, operation log and failure detail goes through the same redaction: credentials in URLs, bearer tokens and known token prefixes, password=- and token=-style values, JSON secrets, private keys, Kubernetes and enrollment tokens.

Backing up Orbit ​

sh
sudo orbit backup --output /root/orbit-$(date +%F).tar.gz
  • The backup is consistent while Orbit runs.
  • It holds Orbit's database, the agents' certificate authority and the key that seals secrets. Copy it off the server and keep it as private as the server itself.
  • It does not include Kubernetes' state or your applications' data: database backups are separate.

To recover the control plane on the same machine:

sh
sudo systemctl stop orbit
sudo orbit restore --input /root/orbit-2026-10-09.tar.gz
sudo systemctl start orbit

Restore refuses while Orbit answers, refuses archives it did not write, and checks the database's integrity and that it is not newer than the binary. The files it replaces are kept in /var/lib/orbit/before-restore-<time>/.

Removing Orbit ​

sh
sudo systemctl disable --now orbit orbit-agent k3s orbit-firewall orbit-buildkit
sudo rm -rf /var/lib/orbit /var/lib/orbit-agent /etc/orbit-agent /var/lib/rancher /etc/rancher /usr/local/lib/orbit /var/lib/orbit-buildkit \
  /usr/local/bin/{orbit,orbit-agent,k3s,kubectl,crictl,ctr} /etc/systemd/system/{orbit,orbit-agent,k3s,orbit-firewall,orbit-buildkit}.service
sudo reboot   # clears the network interfaces and firewall rules K3s and Orbit created

This deletes every application and database on the server with their data. Backups in external storage stay where they are.

Orbit by Cortex Labs