Reference
CLI reference.
Thirteen subcommands make up the renest command-line tool — pack, restore, start, doctor, verify, watch, lint, serve, presign, update-rules, list, export and support — and --json makes their output machine-readable. This page lists what each does and the flags that matter.
Run renest --help on your own install for the authoritative list — this page
follows it, but your version is the one that's true.
pack — seal the setup that worked
$ renest pack --dir ./run --workflow workflow-api.json --out ./nests
--dir— the environment root (the folder holdingComfyUI/). Required.--out— where to write the nest. Required for a real pack; only--dry-runcan skip it. It is laid out like the drive: the manifest goes to<out>/nests/<nest-id>/manifest.json, the files under<out>/blobs/.--workflow— for image runs, the workflow exported in API format (ComfyUI: Export (API)). The ordinary saved workflow is refused.--auto— pack the ComfyUI folder as it stands, with no workflow named.--framework kohya|llamafactory— for fine-tuning runs instead of a workflow. Needs--run-record, the JSON record of the run that worked.--dry-run— print the plan, write nothing.--offline— pack with no network at all. The nest is still a faithful record of this machine, but packages pinned to a vendor-only version (liketorch==…+cu124) keep no download address, so it is marked as not rebuildable on another machine. (Pinning those packages to direct wheel links is on by default;--pin-wheelsonly matters to switch it back on together with--offline.)--dest hosted— also upload it to your Renest drive (needs an access token, see Signing in).--dest s3uploads to a bucket of your own instead.--mine PATH— declare a file as your own work (a LoRA you trained), so it travels on a hand-off. Files you did not make are treated as restricted by default. Repeatable.--nest-name— a human name for it.
Exactly one of --workflow, --auto, --spec or
--framework tells pack what to capture.
Details and what it deliberately skips: Capture a run.
restore — bring a nest back on this machine
$ renest restore --manifest ./nests/nests/<nest-id>/manifest.json --dir ./run
--manifestor--grant— a manifest (file or URL), or a restore code. One of the two.--dir— where to rebuild. Required.--plan— check this machine, then list what the rebuild would do (downloads, dependency resolution, and every setup command it would run, in full) and stop before fetching anything. If the machine fails the check, you get the check's verdict and no plan.--check-only— check whether everything this nest does not carry can still be fetched on this machine, then stop. Needs no GPU, so you can run it on a laptop before renting anything.--force— proceed despite a blocking pre-flight result.--no-resume— start clean instead of continuing an interrupted pull.--reverify— check everything against its fingerprint again, including what an earlier run already confirmed.--skip-launch— restore files and dependencies without starting the app or running the packed workflow.--package-source ADDRESS— install dependencies from a closer package index; every package is still checked against the nest.--no-setup— don't run the setup commands the nest brought with it.--no-report— don't send progress back to your drive when restoring from a drive-issued code.--trust-sender/--trust-host— for nests from other people, and for internal mirrors.
Details: Restore anywhere.
start — run the app the restore brought back
$ renest start --dir ./run --listen 0.0.0.0
A successful restore ends by naming the command that starts the app. start
runs that same command for you: same program from the nest's own environment, same working
folder, same environment variables. Its exit code is the app's. If the app listens on a
port, it says which one — on a rented machine you still have to expose that port in your
provider's panel to reach it from your browser.
--dir— the folder you restored into. Defaults to the current folder.--listen ADDRESS— listen on this address instead of the one recorded. Use0.0.0.0to reach the app from your own browser on a rented box.--dry-run— print the command it would run, then stop.
It only runs what a successful restore recorded. If there is nothing recorded in that
folder — no restore yet, or a nest in an older format — it stops and tells you to run
renest restore instead of guessing a command. If renest --help on
your install doesn't list start, your copy predates it: use the command the
restore's closing lines print.
Signing in to your drive
list, export and pack --dest hosted talk to your
Renest drive, so they need an access token. Generate one in the web console, then give it to
the tool in one of two ways:
- Environment variable —
export RENEST_TOKEN=…for the current shell. If it is set, it wins. - Config file — put it in your user config file, under
[auth]:The file is[auth] token = "rnt_…"
~/.config/renest/config.tomlon Linux and~/Library/Application Support/renest/config.tomlon macOS;--config PATHpoints the tool at a different file. It is a plain-text secret, so make it readable only by you (chmod 600on the file) and keep it out of any folder you commit or sync.
There is deliberately no command-line flag for the token: anything typed as an argument lands in your shell history and is visible to other processes on the machine. Without a token these commands stop before sending anything, with exit code 3.
doctor — can this machine do it?
$ renest doctor # just this machine $ renest doctor ./manifest.json # this machine, against that nest $ renest doctor --storage # check the bucket settings too
verify — prove what came back
$ renest verify ./manifest.json --dir ./run
--check bytes (the default) checks every file against its recorded fingerprint
and costs nothing. A failure names how many files are missing or wrong; --json
or --report lists which ones. --check image compares a picture rendered after rebuilding
against the one from packing time — pass it with --rendered, or add
--render to let Renest start the rebuilt app and render it for you (it asks
first: that uses this machine's GPU). --check both does both, and needs one of
those two flags for the same reason. --report writes the outcome to a file.
The other eight
- watch — run your training command through it, and the nest
records which machine libraries the run really loaded:
renest watch -- accelerate launch train.py. A trainer exits when it is done, so by packing time there is nothing left to ask; this records it while the run is happening. It changes nothing about the run — same arguments, same output, same exit code. - lint — check a nest file for problems before you rely on it.
- serve — run the local engine ComfyUI talks to (that's how the
panel's "Nest this run" button reaches the tool). It listens on this machine only, on port
7799 unless you pass
--port;--token-filesays where its token is kept. - presign — for nests in a bucket of your own: sign a restore code of
time-limited links on the computer that holds the bucket key, so a rented machine never
sees it. It needs that key configured (
renest doctor --storageprints the steps) and stops without one. Codes for nests on your Renest drive come from the web console instead.Shell$ renest presign --manifest ./nests/nests/<nest-id>/manifest.json --out code.json
--manifestis the usual way in;--nest IDsigns for a nest already in your bucket.--expires-in SECONDSsets how long the links last: 6 hours by default, 24 hours at most. - update-rules — refresh the checks and compatibility data the tool uses.
- list — list the nests on your Renest drive; add an id to see its versions.
- export — take a complete copy of a nest off your drive, to this machine or on into your own bucket.
- Both list and export talk to your drive, so they need an access token — see Signing in to your drive.
- support — turn a failed run into something you can read, then paste into a ticket. It never goes online and never uploads.
More flags, by command
The flags above are the ones most people need. These are the next most useful; renest
<command> --help lists every one.
| Command | Flag | What it does |
|---|---|---|
| pack | --comfyui-dir | The ComfyUI folder, when it isn't found under --dir. |
| pack | --program-dir | Where ComfyUI's own program files are, when they are kept apart from your nodes and models (the ComfyUI desktop app does this). |
| pack | --nest-id / --new-nest | Add this pack as a new version of the nest you name, or start a separate nest. By default a repeat pack of the same folder becomes a new version of the same nest. |
| pack | --i-know | Pack even though something in your code folder looks like a credential. Handing the nest off still asks again. |
| pack | --full-rehash | Read every file again, instead of only the ones whose size, time or place on disk moved since the last pack of this folder. |
| pack | --no-licence-lookup | Don't look up licences; every licence stays marked as your own claim, unchecked. |
| pack | --no-report | Don't report pack progress to your drive. |
| restore | --blob-base URL | Where to download files from, when the nest lists no sources and you have no restore code. |
| restore | --trust-unsafe-urls | Allow every unrecognised dependency source at once. For automation over your own nests; as a person, use --trust-host. |
| doctor | --storage | Check your own bucket end to end, including where its key is kept. |
| doctor | --lock FILE | Check that a lockfile's NVIDIA packages come from one CUDA release and that this driver is new enough for them. |
| doctor | --no-skip-net | Also run the download speed test, which is skipped by default. |
| verify | --yes | Answer yes to the rendering question up front, for unattended scripts. |
| watch | --env-root | The folder that will be packed; the record is written inside it. Defaults to the current folder. |
| lint | --blobs / --strict | Also check a local folder of stored files; treat warnings as failures. |
| support | --dir / --run | The folder you were restoring into (required), and which run's records to read (default: the newest). |
| list | NEST_ID | Show that nest's versions instead of all nests. |
| export | --nest / --version / --out | Which nest and version to export (default: the latest fully checked one), and the local folder to write it to. |
| export | --dest s3 | Also push the exported copy into a bucket of your own. |
Machine-readable output
--json works before or after the subcommand, and comes in two shapes:
- doctor · lint · verify · presign · update-rules print one JSON document.
- pack · restore print a stream of events, one JSON object per line, and the last line is always the final report — so a script can tail the progress and still get a single authoritative answer at the end.
One exception today: restore prints its final report as a JSON document
on standard output even without --json (the progress narration you see
in a terminal goes to standard error). If you capture a restore's standard output, expect JSON either way.
The closing lines of a successful restore (Done, then What's next) go to standard
error after that report, so they are the last thing on your screen; standard output stays
pure JSON.
--verbose sends debug logs to standard error, leaving standard output clean
for the JSON.
These docs describe renest 0.1.15, the latest release.