kuiper Docs

Reference

CLI reference

Every kuiper command and subcommand with what it does and the flags it takes.

On this page

Conventions#

Every command prints a table or a short message. Add --json to get the raw JSON response instead.

kuiper units --json

Run kuiper --help, or kuiper <command> --help, for the exact flags of your version.

Global options#

OptionWhat it does
--jsonPrint raw JSON responses.
-p, --project SLUGThe project to act on. Defaults to the project set with kuiper use, or KUIPER_PROJECT.
-u, --unit SLUGThe unit to act on. Defaults to web.
-V, --versionPrint the CLI's version.
-h, --helpPrint help.

-p and -u work before or after a nested subcommand, so kuiper env set -u agent NAME=value and kuiper env -u agent set NAME=value are the same. Commands that act on a whole project take -p only. Commands that act on one unit take -p and -u.

Environment#

VariableWhat it does
KUIPER_API_URLThe instance to talk to. Overrides the config file.
KUIPER_TOKENThe API token. Overrides the config file.
KUIPER_PROJECTThe default project, the same as -p.
XDG_CONFIG_HOMEWhere the config file lives. The default is ~/.config.

The config file is kuiper/config.json in that directory. It holds the API URL, the token and the default project, and is readable only by you.

Sign in and projects#

CommandWhat it does
kuiper loginSign in and store the API URL and token. Opens the dashboard in your browser to approve a short code.
kuiper login --no-browserPrint the link to approve instead of opening a browser.
kuiper login --token kpr_…Sign in with an API token. Without --token the token is read from standard input.
kuiper login --api-url URLSign in to a specific instance, such as a self-hosted one. The default is the saved instance, else https://app.kuiper.sh.
kuiper login --browserUse the browser flow even when standard input is not a terminal.
kuiper config showShow the saved settings. The token is never printed.
kuiper config set api-url URLPoint the CLI at another instance. A saved token for a different instance is dropped; one for the same instance is kept. The install script runs this for you.
kuiper whoamiShow the organisation the CLI is signed in to.
kuiper use SLUGSet the default project.
kuiper projectsList projects. The same as kuiper projects list.
kuiper projects create NAMECreate a project. --name DISPLAY sets a display name when the first argument should stay the slug.
kuiper projects delete SLUGDelete a project.

Units#

CommandWhat it does
kuiper unitsList units. The same as kuiper units list.
kuiper units create SLUGCreate a unit. --kind agent|station|service, --placement, --class.
kuiper units delete SLUGDelete a unit.
kuiper statusShow a unit's state, address, live deployment and placements.
kuiper outputsList the outputs a unit exports, such as INTERNAL_URL, and the reference for each.
kuiper settingsShow or change a unit's build and run settings. They apply from the next build.
kuiper dashboardShow a Station or Foundry unit's web dashboard, turn it on or off, or change its login.

kuiper settings takes --root-dir, --install-command, --build-command, --start-command, --port (0 clears it) and --dashboard-url. An empty value clears a setting.

kuiper dashboard takes --enable, --disable, --username NAME and --password -|generate|VALUE.

Deploy and build#

CommandWhat it does
kuiper deploy --source DIRBuild and deploy a directory, with no repository.
kuiper deploy --image IMAGEDeploy an existing image with its kuiper.json.
kuiper linkLink a Git repository to a unit, so a push builds and deploys.
kuiper buildQueue a build of the linked repository.
kuiper buildsList a unit's builds.
kuiper manifest validate [PATH]Check a kuiper.json. Offline.
kuiper manifest schemaPrint the JSON Schema for kuiper.json. Offline.
kuiper manifest init [DIR]Write the kuiper.json the builder would infer for a Foundry or Station app. Offline.

kuiper deploy takes --source DIR or --image IMAGE, one of them, plus --manifest PATH (default kuiper.json) and --wait, which waits until the deployment is live or fails.

kuiper link takes --repo URL, --branch (default main), --root-dir (default .), --build-env NAME=VALUE (repeat it), and --credential NAME.

kuiper build takes --ref REF and --no-deploy.

kuiper manifest init takes --station or --foundry, --out PATH (default kuiper.json) and --force.

Deployments and operations#

CommandWhat it does
kuiper deploymentsList a unit's deployments.
kuiper deployment IDShow one deployment, including its resolved environment with secrets masked.
kuiper rollback DEPLOYMENTRedeploy a previous deployment's image and manifest.
kuiper restartApply pending variable and secret changes. Restarts at a turn boundary.
kuiper logsPrint a unit's logs. --tail N (default 200), -f to follow, --deployment ID for an earlier deployment.
kuiper eventsPrint the project's activity feed.
kuiper usageShow reserved and used resources for the last 30 days.
kuiper volumesList the project's persistent volumes.
kuiper regionsList the fleet's regions and their capacity.
kuiper moveMove a unit to another region or node. --region, --node, --force.
kuiper migrationsList the moves of a unit that carried its volumes, newest first.

--force on kuiper move moves a unit that has a volume without copying the data first.

Variables and secrets#

CommandWhat it does
kuiper env listList a unit's variables with their templates.
kuiper env set NAME=TEMPLATE…Set variables. Run kuiper restart to apply them.
kuiper env unset NAME…Remove variables.
kuiper secrets listList the project's secrets. Values are never shown.
kuiper secrets set NAME=VALUE…Set secrets. NAME=- reads the value from standard input.
kuiper secrets rm NAME…Remove secrets.
kuiper shared listList the project's shared variables.
kuiper shared set NAME=VALUE…Set shared variables. NAME=- reads the value from standard input.
kuiper shared rm NAME…Remove shared variables.
kuiper resources listList external resources and their outputs.
kuiper resources add SLUG OUTPUT=VALUE…Add an external resource. --secret OUTPUT marks an output as secret.
kuiper resources rename SLUG NEW_SLUGRename an external resource. Templates are rewritten.
kuiper resources rm SLUGRemove an external resource.

Databases and buckets#

CommandWhat it does
kuiper db listList the project's managed databases.
kuiper db create ENGINE SLUGCreate a database. ENGINE is postgres or redis. --size small|medium|large, --version.
kuiper db show SLUGShow one database.
kuiper db credentials SLUGPrint the database's connection values, masked. --reveal shows them.
kuiper db restart SLUGRestart a database with its pinned image and existing data.
kuiper db delete SLUG --confirm SLUGPermanently delete a database and its volume.
kuiper buckets listList buckets.
kuiper buckets create SLUGCreate a bucket.
kuiper buckets show SLUGShow one bucket.
kuiper buckets credentials SLUGPrint the bucket's access values, masked. --reveal shows them.
kuiper buckets delete SLUG --confirm SLUGDelete an empty bucket that no variable references.

Domains#

CommandWhat it does
kuiper domains listList every hostname of the project with its status and certificate. The alias is ls.
kuiper domains add HOSTNAMEAdd a domain and print the DNS records to create. -u UNIT, --redirect-to HOST, --www.
kuiper domains inspect HOSTNAMEShow a domain's status, what DNS says and the records to create.
kuiper domains verify HOSTNAMECheck DNS now. --wait keeps checking, and --timeout SECONDS (default 600) gives up.
kuiper domains claim HOSTNAMEMove a domain from another project into this one. Needs its TXT record. -u UNIT, --redirect-to HOST.
kuiper domains set HOSTNAMEServe a different unit with -u, or redirect with --redirect-to HOST. --redirect-to none serves the unit again.
kuiper domains rm HOSTNAMERemove a domain. The alias is remove.

Station#

CommandWhat it does
kuiper station keysList a Station unit's API keys and the project secret each one is kept in.
kuiper station create-key NAMECreate a key for another service. It is printed once. --scope read,trigger,cancel,admin,execution,registry (comma-separated or repeated), --no-secret.
kuiper station revoke-key IDRevoke a key. Its secret is removed too, unless a variable still references it.

Registries, Git and tokens#

CommandWhat it does
kuiper registry listList the project's registry credentials.
kuiper registry add REGISTRYAdd or replace credentials for a registry host. --username is required. The password is read from standard input unless you pass --password.
kuiper registry rm REGISTRYRemove credentials for a registry.
kuiper git listList the credentials your organisation can build with.
kuiper git add-token NAMEAdd a personal access token. --token, --host (default github.com), --username. The token is read from standard input unless you pass --token.
kuiper git rm NAMERemove a credential.
kuiper git githubSay whether the GitHub App is available. Connect it from the dashboard.
kuiper tokens listList the organisation's API tokens, revoked ones included. * marks the one in use.
kuiper tokens create NAMECreate an API token. It is printed once.
kuiper tokens revoke IDRevoke a token. The organisation's last active token cannot be revoked.

Operators#

kuiper admin is for the people who run a Kuiper installation. It talks to the admin API, which is reachable only over the operator's private network. It takes --admin-url (or KUIPER_ADMIN_URL, default http://127.0.0.1:8081) and --admin-token (or KUIPER_ADMIN_TOKEN).

CommandWhat it does
kuiper admin nodesList nodes with their state, region and capacity.
kuiper admin register-node NAMERegister a node and print its ID and token. --region, --label KEY=VALUE.
kuiper admin set-node NODESet a node's region and labels.
kuiper admin drain NODEMove every placement off a node.
kuiper admin cordon NODEKeep new placements off a node.
kuiper admin uncordon NODEAllow placements on a node again.
kuiper admin reset-node-key NODEForget a node's pinned mesh key so a reinstalled kuiperd can register a new one.
kuiper admin mesh-probe SOURCE TARGETSend a few megabytes between two nodes and report whether both ends agree. --no-wait.
kuiper admin transfersList node-to-node transfers. --state open|all|done|failed.
kuiper admin edgesList the edges the control plane pushes routes to.
kuiper admin add-edge NAMERegister an edge. --caddy-admin-url URL is required. --region, --serves-api.
kuiper admin remove-edge EDGERemove an edge.
kuiper admin routesShow the current routes.
kuiper admin headroomShow capacity and whether to add a node.
kuiper admin allowlist [CAPABILITY IMAGE…]Show the images each capability may run, or set them.
kuiper admin usageShow fleet usage.
kuiper admin create-org NAMECreate an organisation and print its first token.
kuiper admin tokens --org ORGList an organisation's API tokens.
kuiper admin create-token --org ORGCreate another token for an organisation. --name.
kuiper admin revoke-token --org ORG TOKEN_IDRevoke an organisation's token, even its last one.
kuiper admin domainsList every domain on this Kuiper. The same as kuiper admin domains list.
kuiper admin domains add HOSTNAMEAdd a platform domain. --org, --project, --unit, --redirect-to.
kuiper admin domains rm HOSTNAMERemove a domain. The alias is remove.
kuiper admin domains rehome --from DOMAINMove every app under an old apps domain to the current one. The old names keep working as redirects.
kuiper admin githubShow the GitHub App's status and its linked installations.
kuiper admin github-link --org ORG --installation IDLink a GitHub App installation to an organisation by hand.