Skip to content

CLI commands

Run ./bin/servestead --help or ./bin/servestead <command> --help for the complete flag list.

Terminal window
mkdir -p bin
go build -o ./bin/servestead ./backend
Terminal window
./bin/servestead setup

This is the primary interactive interface. It opens the profile picker, DigitalOcean provisioning, reviewed setup stages, stack management, and run history.

Terminal window
./bin/servestead doctor
Terminal window
./bin/servestead keygen
Terminal window
./bin/servestead setup --ip 203.0.113.10

This starts an interactive profile-aware run for the known server address. Use --fresh to create a separate local profile for an address that already has saved profiles.

For a fully supplied scripted run:

Terminal window
./bin/servestead setup \
--ip 203.0.113.10 \
--private-key "$HOME/.ssh/id_ed25519" \
--domain example.com \
--email admin@example.com \
--yes
Terminal window
./bin/servestead provision \
--provider digitalocean \
--name production-vps \
--ssh-key provider-key-id-or-fingerprint

Direct provisioning creates a billable Droplet and stops after reporting the public IPv4 address. It does not create a profile-aware setup plan.

Terminal window
./bin/servestead bootstrap \
--host 203.0.113.10 \
--admin-public-key "$HOME/.ssh/id_ed25519.pub" \
--private-key "$HOME/.ssh/id_ed25519"
Terminal window
./bin/servestead harden \
--host 203.0.113.10 \
--private-key "$HOME/.ssh/id_ed25519"
Terminal window
./bin/servestead network \
--host 203.0.113.10 \
--private-key "$HOME/.ssh/id_ed25519"
Terminal window
./bin/servestead proxy \
--host 203.0.113.10 \
--private-key "$HOME/.ssh/id_ed25519" \
--domain example.com \
--email admin@example.com \
--server-secret 'replace-with-a-long-random-secret'

Prefer the reviewed profile workflow unless a script intentionally manages each stage and secret.

Terminal window
./bin/servestead pangolin-credentials --profile <profile-id>
./bin/servestead pangolin-credentials --ip 203.0.113.10
Terminal window
./bin/servestead github-token set --profile <profile-id> --file /path/to/token.txt
./bin/servestead github-token set --profile <profile-id> --from-env
./bin/servestead github-token status --profile <profile-id>
./bin/servestead github-token remove --profile <profile-id>
Terminal window
./bin/servestead stack add \
--profile <profile-id> \
--compose /path/to/docker-compose.yml \
--publish web:3000:app
Terminal window
./bin/servestead stack env set --profile <profile-id> --stack <name> --file /path/to/.env
./bin/servestead stack env remove --profile <profile-id> --stack <name>
Terminal window
./bin/servestead secrets init --profile <profile-id>
./bin/servestead secrets status --profile <profile-id>
./bin/servestead secrets export-key --profile <profile-id>
./bin/servestead secrets import-key --profile <profile-id> --file /path/to/stack-secret-key.txt
Terminal window
SOPS_AGE_KEY_FILE=/path/to/stack-secret-key.txt \
sops -d stacks/<name>/servestead.secrets.yaml

Set SERVESTEAD_CONFIG_DIR to keep profiles and default configuration repositories below an explicit directory:

Terminal window
SERVESTEAD_CONFIG_DIR=/path/to/isolated-servestead ./bin/servestead setup

This is useful for disposable tests and separate operator environments. The directory becomes the Servestead root itself.