init
./pikopod.yaml with mode 0600 and refuses to overwrite an existing one.
doctor
data_dir is writable, the salt is present or creatable, the agent port is free or already pikopod, and every upstream target answers a HEAD request.
✗ and the command exits 2. Running it creates data_dir and the salt if they do not exist.