# Agent-registry.json is suddently empty

**URL:** https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841
**Category:** zrok
**Created:** [July 3, 2025, 10:12am UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841 "2025-07-03T10:12:12Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)
#### Post date: [July 3, 2025, 10:12am UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/1 "2025-07-03T10:12:12Z")

</div>

Could you please help with agent-registry.json file. Suddenly this file has lost his entries.  
The only remaining entry is an unused entry. We have created this entry for testing and have forgotten to remove it. But all useful entries are disappeared. Hopefully we have found a backup and restored this file.

What is possible reason for a such strange behavior? It is possible that for a while zrok(v1.0.4) was unable to connect to zrok-controlle/ziti-controller. It is possible also that the user has transferred .zrok directory to a different pc and had two identical environment running. It is difficult to know what has happened.

How to avoid this happens again. Could we remove write permissions allowing only read access?

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [July 3, 2025, 12:55pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/2 "2025-07-03T12:55:40Z")

</div>

We'd need actual details to help with this in any meaningful way.

The agent registry is just a convenience to re-start existing reserved shares and private access instances. Both of those things can easily be re-started manually if something happens to the agent registry. Manually re-starting them in the agent will just recreate the agent registry entries.

---

<div class="post-metadata">

### Author: ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)
#### Post date: [July 3, 2025, 1:09pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/3 "2025-07-03T13:09:21Z")

</div>

Unfortunately the user (76) is unfamiliar with zrok.  
The main concern is the fact that the entries have been disappeared.  
Can we set read only permission on this file? This way he can simply restart his pc to get everything work again.

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [July 3, 2025, 1:14pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/4 "2025-07-03T13:14:30Z")

</div>

You can try it... but that's not how it's designed to work.

This is the first time anyone has reported an issue with the agent registry. It's a very simple facility... it's already designed to restart reserved shares and private accesses when the agent is restarted.

If an entry is lost for some reason, simply just `zrok share reserved` or `zrok access private` again, and it will resume restarting those things for you automatically.

---

<div class="post-metadata">

### Author: ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)
#### Post date: [July 3, 2025, 1:18pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/5 "2025-07-03T13:18:26Z")

</div>

I understand. It's unrealistic for some of us who is above 76.  
So someone has to drive 300miles to simply restore the file.

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [July 3, 2025, 1:20pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/6 "2025-07-03T13:20:26Z")

</div>

You have your own instance, yes? Turn on agent remoting and remotely control his agent.

---

<div class="post-metadata">

### Author: ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)
#### Post date: [July 3, 2025, 1:24pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/7 "2025-07-03T13:24:12Z")

</div>

Yes. I will do this. Thank you.

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [July 3, 2025, 1:26pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/8 "2025-07-03T13:26:09Z")

</div>

Let us know if you run into anything setting it up. The docs on that are here:

> **[Agent Remoting | zrok](https://docs.zrok.io/docs/guides/agent/remoting/)**
>
> As of v1.0.5 the zrok Agent and controller support secure, opt-in remote control for creating shares and accesses through the central zrok API.

It's being used successfully in a couple of private zrok environments.

---

<div class="post-metadata">

### Author: ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)
#### Post date: [July 13, 2025, 11:10am UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/9 "2025-07-13T11:10:40Z")

</div>

On the share side we have found the following error:

```auto
zrok[1987]: {"file":"/__w/zrok/zrok/agent/agent.go:132","func":"github.com/openziti/zrok/agent.(*Agent).ReloadRegistry","level":"error","msg":"error restarting private access '\u0026{share_name localhost:port false 0 0 []}': unable to start access: Post "https://zrok.controller.domain.name:port/api/v1/access": context deadline exceeded","time":"2025-07-12T22:48:52.981Z"}

```

It is possible that ISP is too slow. Some requests take up to 5-8 secs. Majority is about 1 sec or under.

What is allowed timeout for the requests?

---

<div class="post-metadata">

### Author: ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)
#### Post date: [July 14, 2025, 12:55pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/10 "2025-07-14T12:55:44Z")

</div>

Agent Remoting works like a charm. Thank you. 😀

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [July 14, 2025, 1:57pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/11 "2025-07-14T13:57:11Z")

</div>

> [@Rantanplan](#):
>
> What is allowed timeout for the requests?

The timeout for most requests is currently 30 seconds.

There is an issue open to figure out some solution to keep the registry intact in the face of errors. Will be getting to it in a week or two.

---

<div class="post-metadata">

### Author: ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)
#### Post date: [July 19, 2025, 7:48am UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/12 "2025-07-19T07:48:10Z")

</div>

I have noticed a curious thing: after sending kill to _zrok access_ the corresponding binding has been removed from agent-registry.json

For some reasons linux may want to send kill to a process. In a such situation the corresponding frontend token will be removed.

---

<div class="post-metadata">

### Author: ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)
#### Post date: [August 5, 2025, 7:50pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/13 "2025-08-05T19:50:41Z")

</div>

The tokens are still disappearing in zrok 1.0.8

```auto
curl -s -H "X-TOKEN: secret" -XPOST -H "Content-Type: application/zrok.v1+json" -d '{"envZId": "envId"}' https://${ZROK_CTRL}/api/v1/agent/status

{"accesses":null,"shares":null}

```

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [August 5, 2025, 7:55pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/14 "2025-08-05T19:55:36Z")

</div>

Yes. Nothing has been changed yet with regard to this issue. When your shares or accesses encounter errors, they will end up being removed. There is an open issue for it that will get worked on as soon as we can get to it. When it’s fixed there will be an entry in the `CHANGELOG.md` about it.

> <https://github.com/openziti/zrok/issues/1000>
>
> Provide an option to persist agent registry entries even when connectivity error…s, etc. occur.

It ends up not being a simple change. Requires the agent being able to manage processes in errored states.

---

<div class="post-metadata">

### Author: ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)
#### Post date: [August 5, 2025, 8:21pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/15 "2025-08-05T20:21:35Z")

</div>

Usually I restart my shares with a script, it stops all shares and starts them.

You mean the tokens will be lost at this point.

Thus after restarting the shares I need to check all connected devices.

Unfortunately after a check I need to restart zrok controller to kill _agent remoting_ api-sessions. Otherwise the ziti controller will die.

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [August 5, 2025, 8:59pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/16 "2025-08-05T20:59:34Z")

</div>

The zrok agent only stores _reserved_ shares (or private accesses) in the agent registry (in order to restart them). In neither case is a “token lost”. A reserved share still exists. And a private access is always ephemeral and it’s existence has nothing to do with the lifecycle of the share it’s attached to.

Not sure what you’re doing, but the issue I’m talking about is only relevant in the case where you’re starting an agent, it has shares or accesses listed in its agent registry, and when it goes to start those back up, they error out. In that case, they will be removed from the registry.

If you’re describing something else, I’m not sure I understand.

---

<div class="post-metadata">

### Author: ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)
#### Post date: [August 6, 2025, 9:59am UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/17 "2025-08-06T09:59:00Z")

</div>

I am talking about _reserved shares._

You say that the life cycles of an access and a share are different. So there is no any relation.

It is possible that at the time user has started its pc there was no internet yet. The network cable was unplugged. They do it. They do not care about the order: unplug the cable , then switch off pc/ turn on pc then connect the cable. Any order is possible.

Another user never turns off its pc. But he can have network connectivity issues.

I am talking about disappearing _frontend tokens_ not the _reserved_ ones.

I remember that I restarted the zrok-controller and after that I have checked the agent status. The output was empty = there are no frontend tokens.

```auto
{"accesses":null,"shares":null}

```

In the current situation I do not know what is the cause of this behavior. The _frontend_ tokens continue to disappear.

To check that everything works as it should I have written a small script. But zrok-controller does not close _agent-remoting_ api-sessions. Thus the number of api-sessions is always increasing because of my regular monitoring of the agent status on all pc. Sadly a large number of _agent-remoting_ api-sessions just kill the ziti-controller.

Instead of regularly querying the agent status via api/v1/agent/status It might be possible to look at the _identityId_ and _service.name_ using ziti edge list sessions. There is might be a relation between zrok’s _frontend_ token and ziti session?

The idea is to detect somehow that a _frontent_ token has been lost and to recreate the missing binding via agent-remoting, api/v1/agent/access.

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [August 6, 2025, 4:10pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/18 "2025-08-06T16:10:43Z")

</div>

The persistence of frontends and reserved shares works exactly the same in the zrok agent. If the zrok access fails to start when the agent starts, it will be removed from the agent registry. It’s the same issue I described with reserved shares.

There is a change coming to agent remoting that should improve the api session behavior. It will be released in `v1.1`.

---

<div class="post-metadata">

### Author: ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)
#### Post date: [August 6, 2025, 4:44pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/19 "2025-08-06T16:44:03Z")

</div>

This is a scary mystery. I was always able to recreate the frontend tokens using agent-remoting/curl.

Thank you for this advice.

So far user’s agent is always available - agent is able to create a Bind.

However other frontend tokens (Dial) can disappear.

---

<div class="post-metadata">

### Author: ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)
#### Post date: [August 6, 2025, 5:12pm UTC](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841/20 "2025-08-06T17:12:31Z")

</div>

I don’t think this is scary nor is it much of a mystery.

Yes, you can re-create the frontends. Private frontends will end up with a new `frontendToken` each time.

[Next page](https://openziti.discourse.group/t/agent-registry-json-is-suddently-empty/4841.md?page=2)
