A new printer is useless until CUPS has a queue for it, and lpadmin creates, configures and deletes that queue. You will finish with a queue that points at an IPP Everywhere printer, accepts jobs, and can be checked from the command line. The examples use lpadmin from Ubuntu's cups-client package, version 2.4.7-1.2ubuntu7.14 on this machine.
Allow about fifteen minutes. You need a running CUPS scheduler, the printer's IPP device URI, and an account allowed to administer CUPS. Administration commonly needs elevated privileges or an authentication prompt, depending on the server configuration. The commands that only inspect state do not need elevation.
Warning: this guide creates or changes a queue. Do not use the example name on a production host unless you have checked that it is unused.
Start with the installed command's help. This is read-only and confirms that the binary accepts the options used below:
$ command -v lpadmin
/usr/sbin/lpadmin
$ lpadmin --help
Usage: lpadmin [options] -d destination
lpadmin [options] -p destination
lpadmin [options] -x destination
The exact help text can vary slightly between CUPS builds. The important forms are -p to configure a queue, -d to select the server default, and -x to delete a queue.
Find the device URI with a read-only probe when the CUPS backends are available:
$ lpinfo -v
network ipp
network ipps
# Your output will contain the printer-specific URI, if it is discoverable.
Discovery is not guaranteed. If the printer is not listed, get its documented IPP URI from the printer or its administrator. A typical URI is ipp://printer.example.test/ipp/print. Treat a URI copied from an untrusted source as configuration data, not as a command.
Replace both placeholders, then run this as a CUPS administrator:
$ lpadmin -p OFFICE_PRINTER -E \
-v "ipp://PRINTER_HOST/ipp/print" \
-m everywhere
-p names the destination. -v supplies its device URI. The everywhere model asks the printer for its IPP capabilities and is the preferred route for modern IPP printers; older driver and PPD based models are deprecated in this CUPS interface.
Here's the trap: -E after -p enables the destination and accepts jobs, but the same flag placed before -p, -d, or -x means something completely different, it forces encryption for the connection to the CUPS scheduler. That historical double meaning is an easy copy-and-paste error.
There is normally no success message. Check the queue explicitly:
$ lpstat -p OFFICE_PRINTER -l
$ lpstat -d
system default destination: OFFICE_PRINTER
The first command should report the queue's state and configuration. The default command only shows the new queue after step 3. If lpadmin reports an authorisation or connection error, stop there and fix CUPS access rather than retrying with random options.
Setting a default is a separate, state-changing action. It affects later jobs submitted through lp or lpr when they do not name a destination:
$ lpadmin -d OFFICE_PRINTER
$ lpstat -d
system default destination: OFFICE_PRINTER
The default belongs to the CUPS server you contacted. If you administer a remote server, use -h server[:port] consistently when checking and changing it, or you may assume your local default changed when the command actually targeted another scheduler.
Use -D for a human-readable description and -L for the physical location. Quote values that contain spaces:
$ lpadmin -p OFFICE_PRINTER \
-D "Office colour printer" \
-L "First floor, east corridor"
$ lpstat -p OFFICE_PRINTER -l
For server-side print defaults, use the -o name-default=value form. For example, this sets the default number of pages placed on each output page:
$ lpadmin -p OFFICE_PRINTER -o number-up-default=2
$ lpoptions -p OFFICE_PRINTER -l
The option is only a default; a job can still request another value. The available PPD options, if this queue exposes them, are listed by lpoptions. Do not guess names or values from a different printer.
To remove a server-side default later, use -R with the complete option name:
$ lpadmin -p OFFICE_PRINTER -R number-up-default
$ lpstat -p OFFICE_PRINTER -l
New queues are shared by default according to the installed manpage. Sharing can publish a destination on the LAN, so make the boundary explicit on a machine that should not advertise this queue:
$ lpadmin -p OFFICE_PRINTER -o printer-is-shared=false
$ lpstat -p OFFICE_PRINTER -l
User access rules are also a security-sensitive change. For example, this permits two named users and one UNIX group:
$ lpadmin -p OFFICE_PRINTER -u allow:alice,bob,@printusers
Do not assume root bypasses this list: the CUPS manpage states that it does not. The special forms allow:all and deny:none turn user-level access control off entirely, so use them only when that is the intended policy.
CUPS stores queue data in implementation files such as printers.conf and classes.conf. Do not edit those files directly; use lpadmin so the scheduler applies the change consistently.
Warning: deleting a destination is destructive. It removes pending jobs and aborts a job currently printing:
$ lpadmin -x OFFICE_PRINTER
$ lpstat -p OFFICE_PRINTER
lpstat: Unknown destination "OFFICE_PRINTER".
Recovery: there is no undo for deleted jobs. To recover the queue itself, recreate it with the original device URI and -m everywhere, then restore any description, location, defaults, sharing and access rules. Record those values before deleting a queue.
If you only need to remove a default, use -R as shown above. Avoid -i and -P for new configurations: interface scripts are unsupported, and PPD files and printer drivers are deprecated in this CUPS command.
lpstat -p OFFICE_PRINTER -l and checked its state.lpstat -d shows the intended default, or you deliberately left it unchanged.-E enabled a queue or forced an encrypted scheduler connection.