About the Service Orchestration cMGD CLI
Routing Director provides the service orchestration Containerized Management Daemon (cMGD) CLI that allows root users to perform certain tasks for service provisioning. Before accessing the service orchestration cMGD CLI, you must deploy your cluster and install Routing Director on the cluster. After you log in to the Deployment Shell CLI as the root user, you must exit the Deployment Shell CLI and access the service orchestration cMGD CLI.
Only a root user can access the service orchestration cMGD CLI and execute commands for service provisioning tasks.
Access the Service Orchestration cMGD CLI
Directories in the Service Orchestration cMGD
The service orchestration cMGD has default directories that contain the service design YANG files, log files, and so on. Table 1 lists some of the important directories in the service orchestration cMGD.
|
Directory |
Description |
|---|---|
| /data-models/projects |
Projects contain one or more related service designs based on which service orchestration can provision a service. Routing Director provides the common.tgz, network-resource.tgz, onboard.tgz, L2VPN.tgz, and L3VPN.tgz projects and related YANG models. |
| /foghorn/network/projects |
Contains the projects that you upload to the service
orchestration cMGD environment by using the |
| /var/tmp/order_sync_conf.json |
Contains the configurations (in JSON format) that you synchronize
from the order manager to the service orchestration cMGD
environment by using the |
Service Order Candidates and Drafts
Routing Director tracks every service order in three places at once, and the service
orchestration cMGD CLI lets you see and control each of them. Understanding this
model explains why some commands come in pairs, and what the markers in the
show service order status output mean.
-
Committed base—The service instance as it currently exists in the order manager. This is the configuration that has been provisioned to the network.
-
Candidate—A proposed change to the service instance that has been staged in the order manager but not yet applied. A candidate is created from a draft. While a candidate is open you can review it, apply it, or drop it.
-
Draft—A local, uncommitted change made in the service orchestration cMGD configuration itself. You create a draft by editing the
foghorn:customershierarchy in configuration mode and committing it. A draft exists only in the cMGD; the order manager does not know about it until you stage it as a candidate.
The show service order status command marks these states with a
suffix on the service instance name. Table 2 lists the markers.
| Marker | Description |
|---|---|
| none | The service instance matches its committed base. There is no pending change. |
| * | A candidate is open in the order manager for this service instance. |
| + | A local, uncommitted draft exists in the service orchestration cMGD for this service instance. |
| *+ | Both a candidate and a local draft exist. |
The legend * candidate + draft is printed at the end of every show service
order status output.
There are two ways to apply a change to a service order. Use the express lane when
you are confident in the change. In the express lane, a single command stages the
candidate from the draft, commits it, and starts the workflow. The express lane
commands are request service order provision to create a service,
request service order modify to modify a service, and
request service order delete to delete a service.
Use the review lane when you want to inspect the change before it reaches the
network. Edit the service in configuration mode and commit, to create a draft.
Execute request service order load to stage the draft as a
candidate in the order manager. Review the staged change with the show |
compare command. Then execute request service order
submit to commit the candidate and start its workflow, or execute
request service order discard to drop the candidate and restore
the committed base.
Both lanes accept the dry-run option, which runs the workflow without applying any configuration to devices. Table 3 summarizes the effect of each command on the draft, the candidate and the workflow.
| Command | Effect |
|---|---|
| configure ... commit | Creates a draft. |
| request service order load | Consumes the draft and opens a candidate. The workflow is not started. |
| request service order submit | Commits the open candidate and starts its workflow. |
| request service order discard | Discards the open candidate and the local draft, restoring the committed base. |
| request service order provision | Consumes the draft, opens and commits a candidate, and starts the create workflow. |
| request service order modify | Consumes the draft, opens and commits a candidate, and starts the modify workflow. |
| request service order delete | Discards any open candidate, then opens and commits a delete candidate and starts the delete workflow. |
| request service order sync | Reloads the committed base from the order manager and overlays the open candidate as an uncommitted change for review with show | compare. Does not commit anything. |
| show service order status | Reports a draft with + and an open candidate with *. |
The following example shows the review lane end to end. A prefix is added to the internal_l3-addr service instance, staged, reviewed, and applied. First, edit the service and commit, which creates a draft:
root@cmgd-5bcb9568c6-hfkdj> configure
Entering configuration mode
[edit]
root@cmgd-5bcb9568c6-hfkdj# set foghorn:customers customer internal services
l3-addr l3-addr-0.2.17 l3-addr ipv4-prefixes link-32-32-0-0-16 prefix
32.32.0.0/16
[edit]
root@cmgd-5bcb9568c6-hfkdj# commit
commit complete
[edit]
root@cmgd-5bcb9568c6-hfkdj# run show service order status
ServiceInstance Type Timestamp Status
internal_l3-addr+ create 2026-08-24T09:38:55Z network resources
updated
* candidate + draft
The + marker shows that a local draft is waiting. Stage it as a candidate:
root@cmgd-5bcb9568c6-hfkdj> request service order load internal_l3-addr
Uploading service order for customer-id: 'internal' service-id: 'l3-addr'
Loading committed base configuration
Overlaying open candidate as an uncommitted change
Service order: internal_l3-addr
Committed base: design 'l3-addr' version '0.2.17'
Candidate: open (operation 'create')
Next: review with 'show | compare', apply with 'request service order
submit', or drop with 'request service order discard'
root@cmgd-5bcb9568c6-hfkdj> show service order status
ServiceInstance Type Timestamp Status
internal_l3-addr* create 2026-08-24T09:38:55Z network resources
updated
* candidate + draft
The draft has been consumed and a candidate is now open, shown by the * marker. Apply the candidate:
root@cmgd-5bcb9568c6-hfkdj> request service order submit internal_l3-addr
Submitting service order for customer-id: 'internal' service-id: 'l3-addr'
Service order: internal_l3-addr
Committed base: design 'l3-addr' version '0.2.17'
Candidate: none open
Next: 'request service order load' to stage a change
root@cmgd-5bcb9568c6-hfkdj> show service order status
ServiceInstance Type Timestamp Status
internal_l3-addr modify 2026-08-24T13:53:53Z network resources
updated
* candidate + draft
The marker has cleared and the operation type has become modify, and the modify
workflow has run. Use show service order workflows to see the
workflow run that was started, and show service order tasks to see
its tasks.
Service Orchestration cMGD CLI Commands
Root users can use the commands listed in Table 4 to execute service provisioning tasks in Routing Director:
|
Command |
Description |
|---|---|
| set org |
Set organization ID in service orchestration cMGD to set the context of all tasks that are executed, from operational mode. |
set foghorn:core org-id |
Set the organization ID in the service orchestration cMGD environment. |
set service design default version |
Set the default version for a service design. |
set dag state failed |
Set a workflow run to failed state. |
show service order network consumers |
Displays information about dependent service instances for a resource instance. |
show service order network resources |
Displays all network resources for the specified service instance. |
show service order status |
View the status of all service orders generated for an organization. |
show service order as-json |
View all or a specific service order in the JSON format. |
show service order as-yaml |
View all or a specific service order in the YAML format. |
show service designs |
View the service design catalog installed for an organization. |
show device dependent configuration |
View the device-centric configurations for provisioning services, in the XML format. |
show insights configuration |
View the configurations related to Paragon Insights for monitoring the services that Routing Director intends to provision on a device. |
show configuration foghorn:customers |
View configurations for all the services provisioned for a customer. |
show service instance lock status |
See the lock status of a service instance. A service instance is locked when the instance is being uploaded, modified, or if the network administrator has locked it. |
show service instance lock token |
See the lock token for a service instance. Note:
Only superusers must execute this command to acquire the secure lock token stored in the Routing Director database. |
show service catalog projects |
Displays the projects available in the service catalog for all organizations. |
show service projects |
Shows the projects that are added to the service orchestration cMGD. |
show service placement orphaned |
Show a list of all orphaned services in an organization and the network resources they hold. |
show service order history |
Shows the history of all service orders. |
show service order logs |
Displays the task logs of a service order's workflow run. |
show service order workflows |
Displays the workflow runs that have been started for a service order. |
show service order tasks |
Displays the tasks of a service order's workflow run. |
show airflow health |
Reports workflow import errors and failed workflow runs. |
show airflow dags |
View all workflows generated for an organization. |
show airflow dag-runs |
View the workflow runs generated for a workflow. |
show airflow dag-run |
Displays the task instances of a single workflow run. |
show routing-director orgs |
View all the organizations created in Juniper Routing Director. |
request service project add |
Add new service designs and the related YANG models to Routing Director. |
request service catalog project add |
Add new projects to the service catalog for all organizations. |
request service order sync |
Synchronize a service order from the order manager and store it in the service orchestration cMGD. |
request network resources load |
Add network resource pools to the Routing Director database. |
request service order load |
Upload a service order to the service orchestration cMGD environment. |
request service order place |
Select placement options and create placement configurations for a service. |
request service order modify |
Execute the modify workflow for a service. |
request service catalog project |
Download the projects available in the service catalog for all organizations. |
request service catalog design delete |
Delete an unused version of a service design from the service catalog. |
request service order delete |
Execute the delete workflow for a service. |
request service order submit |
Activate the provisioning workflow for a service order. |
request service order provision |
Create and execute the workflow for a service order. |
request service design uninstall |
Uninstall a service design version from the Routing Director database. |
request service design install |
Install a service design version to the database. |
request create graphdb |
Create a database for an organization in the service orchestration cMGD. |
request service order set |
Sets the delete operation for a service order in the service orchestration cMGD. This command does not execute the delete workflow for the order. |
request service instance modify design-version |
Modify the service design version of a service instance. |
request service instance lock |
Set a lock for a service instance. |
request service instance unlock |
Unlock a locked service instance. |
request service order discard |
Cancels the pending change for a service order, discarding its open candidate and local draft. |
request service models |
Retrieves the service models for the organization from the graph database. |
request service project design |
Launches the service design tool for an installed service project. |
request device inventory add |
Adds the configured device inventory to the service orchestration cMGD. |
request device schema add |
Adds the configured device schemas to the service orchestration cMGD. |
request service placement orphaned delete |
Deletes orphaned services from placement to release the network resources they hold. |