CLI command reference
Find Openstead commands, context flags, secret input patterns, and automation exit codes.
Run openstead --help or openstead COMMAND --help for the exact options supported by your installed release.
Command groups
| Command | Purpose |
|---|---|
login, logout, whoami, workspaces, link | Credentials, workspace profiles, and local service context. |
catalog | Available plans, runtimes, and capabilities. |
services, projects, environments, groups | Resource configuration. |
deploy, deploys | Queue, inspect, wait, cancel, or roll back deployments. |
status, logs, metrics | Runtime state and diagnostic output. |
restart, suspend, resume, open | Operate a service or open its public URL. |
env, secret-files | Manage encrypted application secrets. |
shell, jobs | Interactive terminal and one-off commands. |
domains, disks, headers, redirects, schedules | Service resource settings. |
backups | Queue, list, download, delete, or restore database backups. |
github | Repository access, branches, and framework detection. |
blueprints | Saved YAML, validation, and project creation. |
integrations, registries, connections, routing, scaling | Integrations and runtime information. |
workspace, members, invitations, audit, notifications | Workspace administration and history. |
usage, billing | Consumption, invoices, and dashboard checkout. |
completion | Bash, zsh, fish, and PowerShell completions. |
All operations use the caller's permissions and service entitlements. Some non-core lists return only their latest records; GitHub listings support --page, with nextPage in JSON output.
Common context
| Flag | Environment variable | Purpose |
|---|---|---|
--workspace, -w | OPENSTEAD_WORKSPACE | Workspace UUID. |
--service, -s | OPENSTEAD_SERVICE | Service name or UUID for commands that accept it. |
--profile | OPENSTEAD_PROFILE | Saved authorization profile. |
--api-url | OPENSTEAD_API_URL | API origin. |
--token-file | OPENSTEAD_TOKEN_FILE | Private credential file. |
--json | — | Machine-readable output. |
--yes, -y | — | Approve the command's confirmation. |
OPENSTEAD_API_KEY supplies a key directly. A token file takes precedence over that environment key, which takes precedence over the keychain. For workspace/service context, explicit flags and environment values precede local openstead.toml, then the active profile. OPENSTEAD_CONFIG_DIR can select another CLI configuration directory. The corresponding RUNIVO_* environment names remain supported as fallbacks. Existing runivo.toml files are read when openstead.toml is absent.
The default API origin is https://openstead-dashboard.vercel.app; the CLI uses its API proxy. SDK base URLs include /api/v1, while this CLI option is an origin.
CLI profiles remain pinned to the origin where they were authorized. You can select another origin with --api-url, but saved credentials are never forwarded to a different origin automatically.
Create and update resources
openstead services create --file service.json
openstead services update example-api --file service-update.json
openstead projects create --name production
openstead domains create --service example-api --name app.example.com
openstead domains verify app.example.com --service example-api --yes--file accepts the operation's JSON request body; --file - reads stdin. Service creation saves configuration. Add --deploy to request an initial release, subject to payment, quota, and runtime requirements.
Supply secrets
Use a private file or stdin so values do not become command-line arguments:
openstead env set API_TOKEN --file ./api-token.txt --service example-api
openstead env import --file variables.json --service example-api --yes
openstead secret-files set credentials.json --file ./credentials.json --service example-apiThese file-based commands work across supported shells. You can also pipe the exact intended bytes to env set. Secret input preserves trailing newlines. Imports apply one key at a time and can partially succeed; inspect the command result before retrying.
To target environment-group secrets, use env --group NAME_OR_ID.
Observe and run commands
openstead logs --service example-api --follow
openstead shell --service example-api
openstead jobs run --service example-worker --command 'python manage.py check' --wait --yesShell access and jobs follow service entitlements. Disconnect an interactive shell with Ctrl+]. A one-off command runs inside your workload and can affect its data.
Output and exit codes
JSON goes to stdout; errors and progress go to stderr. Follow and watch commands emit newline-delimited JSON. The CLI does not automatically retry a mutation after an uncertain network result; inspect the target resource first.
| Exit | Meaning |
|---|---|
| 0 | Command succeeded; asynchronous work may still be queued unless observed with --wait. |
| 1 | Request, network, or other error. |
| 2 | Confirmation declined. |
| 3 | Authentication required or expired. |
| 4 | Permission or entitlement denied. |
| 5 | Resource not found. |
| 6 | Conflict. |
| 7 | Rate limited. |
| 8 | Deployment wait timed out. |
| 9 | Deployment or job failed, was cancelled, or was superseded. |
| 130 | Interrupted. |
Raw workspace API calls
openstead api PATH sends a request relative to the current authorized workspace. It does not bypass access checks. Use the published core reference for REST integrations that need the stable public contract; prefer dedicated CLI commands for other console workflows.