openstead
Developer tools & integrations

CLI command reference

Find Openstead commands, context flags, secret input patterns, and automation exit codes.

Suggest a change

Run openstead --help or openstead COMMAND --help for the exact options supported by your installed release.

Command groups

CommandPurpose
login, logout, whoami, workspaces, linkCredentials, workspace profiles, and local service context.
catalogAvailable plans, runtimes, and capabilities.
services, projects, environments, groupsResource configuration.
deploy, deploysQueue, inspect, wait, cancel, or roll back deployments.
status, logs, metricsRuntime state and diagnostic output.
restart, suspend, resume, openOperate a service or open its public URL.
env, secret-filesManage encrypted application secrets.
shell, jobsInteractive terminal and one-off commands.
domains, disks, headers, redirects, schedulesService resource settings.
backupsQueue, list, download, delete, or restore database backups.
githubRepository access, branches, and framework detection.
blueprintsSaved YAML, validation, and project creation.
integrations, registries, connections, routing, scalingIntegrations and runtime information.
workspace, members, invitations, audit, notificationsWorkspace administration and history.
usage, billingConsumption, invoices, and dashboard checkout.
completionBash, zsh, fish, and PowerShell completions.

All operations use the caller's permissions and service entitlements. Some non-core lists return only their latest records; GitHub listings support --page, with nextPage in JSON output.

Common context

FlagEnvironment variablePurpose
--workspace, -wOPENSTEAD_WORKSPACEWorkspace UUID.
--service, -sOPENSTEAD_SERVICEService name or UUID for commands that accept it.
--profileOPENSTEAD_PROFILESaved authorization profile.
--api-urlOPENSTEAD_API_URLAPI origin.
--token-fileOPENSTEAD_TOKEN_FILEPrivate credential file.
--json—Machine-readable output.
--yes, -y—Approve the command's confirmation.

OPENSTEAD_API_KEY supplies a key directly. A token file takes precedence over that environment key, which takes precedence over the keychain. For workspace/service context, explicit flags and environment values precede local openstead.toml, then the active profile. OPENSTEAD_CONFIG_DIR can select another CLI configuration directory. The corresponding RUNIVO_* environment names remain supported as fallbacks. Existing runivo.toml files are read when openstead.toml is absent.

The default API origin is https://openstead-dashboard.vercel.app; the CLI uses its API proxy. SDK base URLs include /api/v1, while this CLI option is an origin.

CLI profiles remain pinned to the origin where they were authorized. You can select another origin with --api-url, but saved credentials are never forwarded to a different origin automatically.

Create and update resources

openstead services create --file service.json
openstead services update example-api --file service-update.json
openstead projects create --name production
openstead domains create --service example-api --name app.example.com
openstead domains verify app.example.com --service example-api --yes

--file accepts the operation's JSON request body; --file - reads stdin. Service creation saves configuration. Add --deploy to request an initial release, subject to payment, quota, and runtime requirements.

Supply secrets

Use a private file or stdin so values do not become command-line arguments:

openstead env set API_TOKEN --file ./api-token.txt --service example-api
openstead env import --file variables.json --service example-api --yes
openstead secret-files set credentials.json --file ./credentials.json --service example-api

These file-based commands work across supported shells. You can also pipe the exact intended bytes to env set. Secret input preserves trailing newlines. Imports apply one key at a time and can partially succeed; inspect the command result before retrying.

To target environment-group secrets, use env --group NAME_OR_ID.

Observe and run commands

openstead logs --service example-api --follow
openstead shell --service example-api
openstead jobs run --service example-worker --command 'python manage.py check' --wait --yes

Shell access and jobs follow service entitlements. Disconnect an interactive shell with Ctrl+]. A one-off command runs inside your workload and can affect its data.

Output and exit codes

JSON goes to stdout; errors and progress go to stderr. Follow and watch commands emit newline-delimited JSON. The CLI does not automatically retry a mutation after an uncertain network result; inspect the target resource first.

ExitMeaning
0Command succeeded; asynchronous work may still be queued unless observed with --wait.
1Request, network, or other error.
2Confirmation declined.
3Authentication required or expired.
4Permission or entitlement denied.
5Resource not found.
6Conflict.
7Rate limited.
8Deployment wait timed out.
9Deployment or job failed, was cancelled, or was superseded.
130Interrupted.

Raw workspace API calls

openstead api PATH sends a request relative to the current authorized workspace. It does not bypass access checks. Use the published core reference for REST integrations that need the stable public contract; prefer dedicated CLI commands for other console workflows.

Need a hand? Contact Openstead support.

On this page