Skip to content

Levelrail CLI Reference ​

Exhaustive reference of all Levelrail CLI commands, organized by command group and extracted directly from the source code.

See also ​

Scripting: --json and exit codes ​

Every command that returns data or a result supports --json (shorthand for --output json), and --query takes a JMESPath expression. With --json, stdout carries only the JSON result. The exceptions are completion bash|zsh|fish (a shell script) and control-plane-backups help-dr (a static runbook). A test walks the command tree and fails when a new command has no --json and is not on that exempt list.

On failure, --json also prints an error object to stdout (the message still goes to stderr):

json
{"error": "server returned 404: app not found", "code": "not_found", "exit_code": 4, "http_status": 404, "hint": "check the resource name with the matching list command"}

error is the original field. code is one of validation, network, unauthorized, forbidden, not_found, conflict, rate_limited, invalid_request, server_error, api_error. http_status, retry_after (rate limits) and hint appear when they apply.

Exit codes are stable and shared by every command:

CodeMeaning
0Success
1Usage error (unknown command, missing argument, bad flag); also a failed check for control-plane-backups verify and a critical item for attention
2Validation error: well-formed flags, but the request they describe is invalid
3Network error: the control plane could not be reached
4API error: the control plane replied with a non-2xx status (use code and http_status in the JSON error to tell auth, not found and conflict apart)
5Deploy failed: apps wait reached a failed deploy
6Deploy timeout: apps wait gave up before the deploy converged

Codes 3 and 4 are broad on purpose so existing scripts keep working; the JSON error object carries the finer distinction.

Top-level convenience aliases ​

levelrail deploy <name> --image IMAGE [flags]

Alias for apps deploy; deploy an image to an existing app.

levelrail rollback <name> --image IMAGE [flags]

Alias for apps rollback; redeploy an older image.

Apps ​

levelrail apps alerts create <app> --name NAME --kind threshold --metric METRIC --comparator OP --threshold N [flags]
levelrail apps alerts delete <app> <id> [flags]
levelrail apps alerts list <app> [flags]
levelrail apps alerts update <app> <id> --name NAME --kind threshold --metric METRIC --comparator OP --threshold N [flags]
levelrail apps auto-rollback enable <app-name> [flags]
levelrail apps auto-rollback disable <app-name> [flags]
levelrail apps auto-rollback status <app-name> [flags]
levelrail apps auto-rollback-slo-burn set <app-name> off|auto|dry_run|pause_for_human [flags]
levelrail apps auto-rollback-slo-burn status <app-name> [flags]
levelrail apps health get <name> [flags]
levelrail apps health set <name> --probe readiness|liveness (--path PATH | --exec CMD) [--scheme https] [--host HOST] [--tls-skip-verify] [--follow-redirects true|false] [--expected-status 200-399] [--interval 5s] [--timeout 2s] [--failures 3] [--ready-timeout 90s] [flags]
levelrail apps health clear <name> [--probe readiness|liveness] [flags]
levelrail apps builds trigger <name> --repo URL --ref REF [flags]

build an image from a git source and deploy it to an existing app

levelrail apps clear-environment <name> [flags]
levelrail apps clear-project <name> [flags]
levelrail apps clone <name> <new-name> [flags]
levelrail apps connect <app> <database> [--field FIELD] [--env-var NAME] [flags]

connect <app> to a managed database, injecting its resolved connection value as an env var; unlike apps database, an app can have any number of these

levelrail apps connections list <app> [flags]

list <app>'s current database connections, including whether each resolves to a mesh DNS name (cross-node-capable) or a container name

levelrail apps connections suggest <app> [flags]

list managed databases <app> could connect to, marking which are already connected

levelrail apps create --name NAME --image IMAGE --port PORT [flags]
levelrail apps create [flags]

create an app (existing image, git build, --file, or --interactive)

levelrail apps database set <name> --database-name NAME [flags]

attach an already-created managed database to <name> as its connection-env-var source

levelrail apps database clear <name> [flags]

detach the database <name> currently resolves its connection env var from

levelrail apps delete <name> [flags]
levelrail apps disconnect <app> <env-var> [flags]

remove one database connection from <app> by its env var name

levelrail apps deploy <name> --image IMAGE [flags]
levelrail apps wait <name> [flags]

poll until a deploy attempt actually converges, exit accordingly (a CI gate for "apps deploy"). On success it says what happened: rolled out, already up to date (the deploy changed nothing) or restarted; --json carries the same as outcome

levelrail apps timeline <name> [--limit N] [flags]

what happened to an app, newest first: deploys, rollbacks, restarts, env, secret and config changes (key names only, never values), scaling, stop and start

levelrail apps apply <name> [flags]

restart an app so saved env, secret and config changes reach the running container; does nothing when nothing is pending

levelrail apps domains list <name> [flags]
levelrail apps domains add <name> <domain>... [flags]
levelrail apps domains remove <name> <domain>... [flags]

show or change an app's domains; a domain already used by another app is refused and nothing is changed

levelrail apps deploy-compose <name> --file compose.yaml [flags]
levelrail apps validate --file <app.yaml|compose.yaml> [flags]

parse and validate an app.yaml or a Docker Compose file locally, no API call and no deploy; prints the detected format, service count, and every non-blocking notices entry a real deploy would also surface

levelrail apps deploy-notify-targets create <app> --channel-id ID [flags]
levelrail apps deploy-notify-targets delete <app> <id> [flags]
levelrail apps deploy-notify-targets list <app> [flags]
levelrail apps deploy-spec <name> --file app.yaml --repo-url <url> --ref <ref> [flags]
levelrail apps deploys list <name> [flags]

real, row-per-attempt deploy history, newest first

levelrail apps deploys compare <name> --from ID [--to ID] [flags]

diff two deploy attempts, or one against the current live state

levelrail apps deploys logs <name> <deploy-id> [flags]

one deploy attempt's full build/log output, printed to stdout (redirect to a file to save it)

levelrail apps deploys wait <name> [deploy-id] [--timeout 10m] [--poll-interval 2s] [flags]

blocks until one deploy is healthy, failed, canceled, superseded or blocked and prints the result with its failure; exits 0 healthy, 7 not healthy, 6 timeout

levelrail apps deploys show <name> [deploy-id] [flags]

one deploy attempt (the newest by default) with its structured failure: code, cause, failing step, redacted log excerpt, suggested fix, docs link and retryable, see Deploy failures

levelrail apps deploys failed [--since 24h] [flags]

every app's latest failed deploy in the window (default set by the server), with the image of its newest good deploy as a rollback target

levelrail deployments list [--status a,b] [--app NAME] [--branch B] [--trigger T] [--environment E] [--since 24h] [--until T] [--q TEXT] [--live] [--pr N] [--limit N] [--cursor C] [flags]
levelrail deployments summary [--window 24h] [flags]
levelrail deployments watch [flags]

deploys across every app you can read: a filterable newest-first list (with --cursor paging), a status and duration summary, and a live event stream (--json prints one object per event)

levelrail apps deploys steps <name> <deploy-id> [flags]

stream one deploy attempt's pipeline steps (detecting, building, pushing, deploying) until it ends; exits non-zero if a step failed. An already-finished attempt replays only a short two-point summary

levelrail deploy-approvals list [--status pending|all|approved|rejected|expired] [--service NAME] [flags]

list deploy approvals (status defaults to pending)

levelrail deploy-approvals get <id> [flags]
levelrail deploy-approvals approve <id> [flags]

approve a pending deploy; the gated deploy/promote runs now

levelrail deploy-approvals reject <id> [--reason TEXT] [flags]

reject a pending deploy; the app's desired state is left untouched

levelrail apps environments clone <id> --new-name NAME [--app-rename SOURCE=NEWNAME ...] [--domain SOURCE=D1,D2 ...] [--copy-secret-values] [flags]

clone a whole environment's app set plus config into a new environment

levelrail apps environments clone-preview <id> --new-name NAME [flags]

preview what cloning an environment would create, without applying it

levelrail apps environments create <project-id> --name NAME [--protected] [flags]

create an environment under a project

levelrail apps environments delete <id> [flags]
levelrail apps environments env-get <id> [flags]
levelrail apps environments env-set <id> --var KEY=VALUE [--var KEY=VALUE ...] [flags]
levelrail apps environments list <project-id> [flags]
levelrail apps environments update <id> --protected=true|false [flags]
levelrail apps exec <name> -- <command> [args...] [flags]
levelrail apps git-source get <name> [flags]

show an app's connected repo

levelrail apps images <name> [flags]
levelrail apps log-drain get <name> [flags]

show an app's configured log drain

levelrail apps logs <name> [flags]
levelrail apps metrics <name> --metric NAME [flags]
levelrail apps overview [name ...] [flags]
levelrail upgrade [--no-backup] [flags]

upgrade runs the preflight checks, takes a control plane backup and prints the upgrade command. It never upgrades by itself. See Installing.

levelrail apps moves list <name> [flags]

list every node-to-node move attempt for <name>, newest first

levelrail apps moves get <name> <id> [flags]

show one move attempt's step-by-step progress

levelrail apps organizations clear-project <project-id> [flags]
levelrail apps organizations create --name NAME [flags]

create an organization

levelrail apps organizations delete <id> [flags]
levelrail apps organizations env-get <id> [flags]
levelrail apps organizations env-set <id> --var KEY=VALUE [--var KEY=VALUE ...] [flags]
levelrail apps organizations get <id> [flags]
levelrail apps organizations list [flags]
levelrail apps organizations set-project <project-id> <org-id> [flags]
levelrail apps preview-env set <name> <key> --value VALUE [flags]

declare (or replace) a preview-specific env var override

levelrail apps preview-env clear <name> <key> [flags]

remove a preview-specific env var override

levelrail apps branch-env list <name> [flags]

list an app's branch-scoped env var overrides

levelrail apps branch-env set <name> <key> --branch PATTERN --value VALUE [--secret] [flags]

declare (or replace) a branch-scoped env var override, applied only when a preview's own branch matches PATTERN

levelrail apps branch-env clear <name> <id> [flags]

remove one branch-scoped override by its id (from list or set)

levelrail apps previews list <app-name> [flags]

list active previews for an app

levelrail apps previews pr-status enable <app-name> [flags]
levelrail apps previews sweep [flags]
levelrail apps previews teardown <app-name> <pr-number> [flags]
levelrail apps projects create --name NAME [flags]

create a project

levelrail apps projects delete <id> [flags]
levelrail apps projects env-get <id> [flags]
levelrail apps projects env-set <id> --var KEY=VALUE [--var KEY=VALUE ...] [flags]
levelrail apps projects get <id> [flags]
levelrail apps projects list [flags]
levelrail apps projects restart <id> [flags]
levelrail apps projects start <id> [flags]
levelrail apps projects stop <id> [flags]
levelrail apps promote <name> --to ENVIRONMENT_ID [--target NAME] [--preview] [flags]
levelrail apps restart <name> [flags]
levelrail apps rollback <name> --image IMAGE [flags]
levelrail apps scheduled-tasks create <app> --schedule CRON [--disabled] -- <command> [args...]
levelrail apps scheduled-tasks delete <app> <id> [flags]
levelrail apps scheduled-tasks get <app> <id> [flags]
levelrail apps scheduled-tasks list <app> [flags]
levelrail apps scheduled-tasks run <app> <id> [flags]
levelrail apps scheduled-tasks update <app> <id> --schedule CRON [--disabled] -- <command> [args...]
levelrail apps env import <name> --file .env [--dry-run] [--keep-existing] [--apply] [flags]

merge a .env file into an app's plain env vars, printing which keys are new, changed or unchanged (keys that are secrets are skipped); prints how many changes are pending, or restarts the app right away with --apply

levelrail apps env export <name> [--out FILE] [flags]

write an app's env vars as .env text; secret keys are written empty with a comment, never with a value

levelrail apps secrets list <name> [flags]

list an app's secret keys and their locked state

levelrail apps secrets set <name> <key> <value> [--apply] [flags]

set or rotate one secret's encrypted value and declare the key as secret-backed so it is injected; --apply restarts the app now

levelrail apps secrets delete <name> <key> [--force] [--apply] [flags]

delete a secret's value and stop declaring the key

levelrail apps secrets set <name> --env-file <path> [flags]

bulk-import every key in a .env-format file as its own secret

levelrail apps secrets lock <name> <key> --locked=true|false [flags]

toggle a secret's overwrite guard

levelrail apps set-environment <name> <environment-id> [flags]
levelrail apps set-project <name> <project-id> [flags]
levelrail apps start <name> [flags]
levelrail apps stop <name> [flags]
levelrail apps storage set <name> --storage-target-id ID [flags]

attach a connected bucket as object storage

levelrail apps vault-env set <name> <key> --path PATH --key FIELD [flags]

declare (or replace) a Vault-sourced env var

levelrail apps vault-env clear <name> <key> [flags]

remove a Vault-sourced env var declaration

levelrail apps webhook-deliveries list <app-name> [flags]

list recent inbound webhook requests

levelrail apps webhook-deliveries replay <app-name> <delivery-id> [flags]
levelrail apps tag <name> <tag> [flags]

attach a tag (by name) to an app, creating the tag if it doesn't exist

levelrail apps untag <name> <tag> [flags]

detach a tag (by name) from an app

Tags ​

levelrail tags list [flags]
levelrail tags create --name NAME [flags]
levelrail tags delete <name> [flags]

delete a tag, identified by name (detaches from all apps)

levelrail tags apps <name> [flags]

list every app attached to a tag, identified by name

Pipelines ​

levelrail pipelines list <app> [flags]
levelrail pipelines validate <file> [--json]

validate a pipeline file locally, no API call, exit status 2 when it has problems

levelrail pipelines save <app> <file-or-repo-dir> [--name N] [flags]

create or update pipelines from one file, or from every file in a repository's pipeline directory

levelrail pipelines delete <app> <name> [flags]
levelrail pipelines run <app> <name> [--ref R] [--sha S] [--input k=v]... [--follow] [flags]
levelrail pipelines runs <app> [<run-id>] [--pipeline N] [--limit N] [flags]

list runs, or show one run's jobs, steps, and approval gates

levelrail pipelines logs <app> <run-id> [--job KEY] [--follow] [flags]
levelrail pipelines cancel <app> <run-id> [flags]
levelrail pipelines approve <app> <run-id> [--reject] [--comment TEXT] [--approval ID] [flags]

decide approval gates, or release a run held for approval

levelrail pipelines sync <app> [--repo-truth=true|false] [flags]

sync pipeline files from the repository now, or set repository as source of truth

levelrail pipelines triggers <app> [flags]

why recent git events did or did not start runs

Lb ​

levelrail lb list [--state balancing|degraded|none] [--search Q] [flags]

every load balancer across apps with state and healthy upstream counts

levelrail lb show <app> [flags]

show an app's load balancer config

levelrail lb set <app> [--algorithm ...] [flags]

create or change the load balancer, only the flags you pass change

levelrail lb clear <app> [flags]

remove the load balancer, back to a single upstream

levelrail lb status <app> [flags]

live upstream table: state, weight, active requests, failures

levelrail lb export <app> --format terraform|cdk|cloudformation|caddy|caddy-json [--out FILE]

generate an infrastructure-as-code definition, no cloud API calls

levelrail lb import <app> --file app.yaml [--service S] [flags]

load the loadbalancer: block of an app.yaml

Preview ​

levelrail preview status <app> [flags]

show the app's deploy preview settings, storage used and latest result

levelrail preview enable <app> [--mode metadata|screenshot] [--path /] [--wait-ms N] [flags]

turn deploy previews on for the app: metadata reads the page title and social image (no browser), screenshot (the default here) runs a browser container per deploy

levelrail preview disable <app> [flags]

turn deploy previews off for the app

levelrail preview capture <app> [flags]

recapture the current release now

levelrail preview prune <app> [--all] [flags]

delete old previews now, or every preview of the app with --all

Supply chain ​

levelrail apps sbom <app> [deploy-id] [--download] [--file PATH] [flags]

show a deploy's software bill of materials (newest deploy with one by default), or print or save the raw SPDX or CycloneDX document

levelrail apps scan enable <app> [flags]

turn vulnerability scanning on for the app; the first scan pulls the scanner image

levelrail apps scan disable <app> [flags]

turn scanning off and reset the gate

levelrail apps scan status <app> [deploy-id] [flags]

show the scan settings and the latest scan result

levelrail apps scan run <app> [deploy-id] [flags]

scan a deploy's SBOM now

levelrail apps scan gate <app> off|warn|block_on_critical [flags]

choose what a scan may do to a release; block_on_critical keeps the previous release serving

levelrail apps scan override <app> --reason TEXT [flags]

let the next blocked release through once, with a recorded reason

Databases ​

levelrail databases clear-project <name> [flags]
levelrail databases create --name NAME --engine ENGINE --version VERSION [flags]
levelrail databases create [flags]

create a managed database

levelrail databases status <name> [flags]

show a database's current reconcile conditions (useful when it exists but is not running yet)

levelrail databases delete <name> [flags]
levelrail databases metrics <name> --metric NAME [flags]
levelrail databases public-access set <name> [--port N] [--bind-address ADDR] [flags]

expose a database on a host port; --bind-address is "private" (default), "public", or a literal IP

levelrail databases public-access clear <name> [flags]
levelrail databases set-resources <name> [--memory 512Mi] [--cpu 0.5] [flags]

applies memory/CPU limits to an already-created database, replacing whatever was set before (full replace, not a patch)

levelrail databases set-project <name> <project-id> [flags]
levelrail databases start <name> [flags]
levelrail databases stop <name> [flags]

Models ​

levelrail models list [flags]

list AI models with their status

levelrail models get <name> [flags]

show one model, its status and OpenAI-compatible base URL

levelrail models deploy --name NAME --engine ENGINE --model MODEL [flags]

deploy a model on a GPU node; prints the API key once. Flags: --node, --gpus, --gpu-devices, --context, --quantization, --domain, --hf-token-from-env

levelrail models logs <name> [flags]

search stored engine logs, or --follow to stream download and load progress live

levelrail models delete <name> [flags]

remove a model; the downloaded weights volume is kept

levelrail models restart <name> [flags]

recreate the engine container

levelrail models rotate-key <name> [flags]

issue a new API key, printed once

levelrail models gpus [flags]

list GPU nodes with driver, VRAM, usage and nvidia runtime status

levelrail models preflight <repo> [flags]

check a Hugging Face repo before deploying: access, size, quantizations with a fit estimate, free disk

levelrail models cache list|prune [flags]

list cached model weights per node, or prune unused ones (--dry-run first)

See AI models.

Auth ​

levelrail auth 2fa disable --code CODE|--recovery-code CODE [flags]
levelrail auth 2fa enable --code CODE [flags]
levelrail auth 2fa recovery-codes --code CODE [flags]
levelrail auth 2fa setup [flags]
levelrail auth 2fa status [flags]

show whether two-factor auth is enabled

levelrail auth login [flags]

authenticate and persist a new API token

levelrail auth whoami [flags]

Profile ​

levelrail profile list [flags]

list configured credentials profiles

Tokens ​

levelrail tokens create --name NAME --abilities LIST [--agent NAME] [--agent-description TEXT] [flags]

mint a new API token; --agent labels it as issued to an AI agent so audit entries record the agent name

levelrail tokens list [flags]
levelrail tokens revoke <id> [flags]

Domains ​

levelrail domains basic-auth get <app> <domain> [flags]

show a domain's basic auth state

levelrail domains check <app> <domain> [flags]
levelrail domains cloudflare-dns get [flags]

show the current settings

levelrail domains route53-dns get [flags]

show the current settings

levelrail domains list [flags]

list every app's domains in one call

levelrail domains maintenance get <app> <domain> [flags]

show a domain's maintenance state

levelrail domains redirect get <app> <domain> [flags]

show a domain's redirect state

levelrail domains tls-cert get <app> <domain> [flags]

show a domain's BYO certificate state

levelrail domains waf get <app> <domain> [flags]

show a domain's WAF and rate-limit state

levelrail domains error-pages get <app> <domain> [--code N] [flags]

show a domain's custom error pages

Backups ​

levelrail backups list <database> [flags]

list backup history for a database

levelrail backups list-all [flags]

list backup history across every database and app volume instance-wide

levelrail backups restore <database> --backup ID [--confirm NAME] [flags]
levelrail backups restore-as-new <database> --backup ID --new-name NAME [flags]
levelrail backups restores <database> [flags]

list restore attempt history for a database

levelrail backups clone-restores <database> [flags]

list restore-as-new attempt history for a database

levelrail backups schedule set <database> --target ID --cron EXPR [flags]

configure a recurring backup

levelrail backups trigger <database> --target ID [flags]
levelrail backups verifications <database> --backup ID [flags]
levelrail backups verify <database> --backup ID [flags]

App Volume Backups ​

levelrail app-volume-backups list <app> <volume> [flags]

list backup history for an app's named volume

levelrail app-volume-backups restore <app> <volume> --backup ID [--confirm APP/VOLUME] [flags]
levelrail app-volume-backups restore-as-new <app> <volume> --backup ID [--new-volume-name NAME] [flags]
levelrail app-volume-backups restores <app> <volume> [flags]

list restore attempt history for an app's named volume

levelrail app-volume-backups clone-restores <app> <volume> [flags]

list restore-as-new attempt history for an app's named volume

levelrail app-volume-backups schedule set <app> <volume> --target ID --cron EXPR [flags]

configure a recurring backup

levelrail app-volume-backups trigger <app> <volume> --target ID [flags]
levelrail app-volume-backups verifications <app> <volume> --backup ID [flags]
levelrail app-volume-backups verify <app> <volume> --backup ID [flags]

PITR Restores ​

levelrail pitr restores <database> [flags]

list point-in-time restore attempts for a database (base backup, target time, status, error)

Build ​

levelrail build detect --repo-url URL [--ref REF] [flags]

show which framework the builder detects for a public repo, without running a build. Prints no framework detected (exit 0) when nothing matches.

levelrail build branches --repo-url URL [flags]

list the branches a public repo advertises. Private or unreachable repos fail with an API error.

Cloudflare Tunnel ​

levelrail cloudflare-tunnel get [flags]

show the current settings and connection status

Vault ​

levelrail vault get [flags]

show the current external Vault integration settings

levelrail vault set --address URL --auth-method token|approle [flags]

configure and enable resolving app secrets from an external HashiCorp Vault instance

levelrail vault disconnect [flags]

disable and forget the stored credential

Channels ​

levelrail channels create --name NAME --kind KIND --notify-url URL [flags]
levelrail channels delete <id> [flags]
levelrail channels deliveries <id> [flags]
levelrail channels list [flags]

list connected notification channels

levelrail channels test <id> [flags]
levelrail channels update <id> --name NAME --kind KIND --notify-url URL [flags]

Backup Targets ​

levelrail backup-targets create --name NAME --provider PROVIDER --bucket BUCKET --access-key-id ID --secret-access-key KEY [flags]
levelrail backup-targets delete <id> [flags]
levelrail backup-targets get <id> [flags]
levelrail backup-targets list [flags]

list connected backup targets

levelrail backup-targets test <id> [flags]
levelrail backup-targets update <id> --name NAME --provider PROVIDER --bucket BUCKET [flags]

Storage ​

levelrail storage providers

list provider presets (aws, r2, b2, minio, wasabi, custom)

levelrail storage list
levelrail storage add --name N --provider P --bucket B --access-key-id ID --secret-access-key KEY [flags]
levelrail storage test <id>

write, read back and delete a probe object

levelrail storage delete <id>

Logs ​

levelrail logs archive set --target ID [--app NAME] [--interval 1h] [--retention-days N] [--disable]
levelrail logs archive status
levelrail logs archive remove [--app NAME]
levelrail logs dump --target ID --from TIME [--to TIME] [--app NAME] [--wait]
levelrail logs ls --target ID [--app NAME]
levelrail logs fetch --target ID --key KEY [--out FILE]
levelrail logs query <app> [--level LEVEL] [--since 30m] [--until T] [--deploy ID] [--text PHRASE] [--max-lines N] [--max-bytes N] [flags]

capped excerpt of an app's newest matching log lines with match counts and a truncation notice; the byte cap defaults to 8 KB or APP_MCP_LOG_MAX_BYTES

Registry Credentials ​

levelrail registry-credentials create --name NAME --registry-host HOST --username USER --password PASS [flags]
levelrail registry-credentials delete <id> [flags]
levelrail registry-credentials get <id> [flags]
levelrail registry-credentials list [flags]

list connected registry credentials

levelrail registry-credentials repositories <id> [flags]
levelrail registry-credentials tags <id> <repository> [flags]
levelrail registry-credentials test <id> [flags]
levelrail registry-credentials update <id> --name NAME --registry-host HOST --username USER [flags]

Registry ​

levelrail registry status [flags]

show the current settings and container status

Flags ​

levelrail flags create <app> --key KEY --name NAME [--description DESC] [--disabled] [--rollout PERCENT] [flags]
levelrail flags delete <app> <id> [flags]
levelrail flags get <app> <id> [flags]
levelrail flags list <app> [flags]
levelrail flags set <app> <id> --name NAME [--description DESC] [--disabled] [--rollout PERCENT] [flags]

Apply, Diff and Export ​

See Platform as code for the document format, secrets handling, prune rules and CI use.

levelrail apply -f file|dir|- [--dry-run] [--exit-code] [--prune --source NAME] [--project P] [--yes] [--secret K=env:VAR] [--var NAME=VALUE] [--var-file PATH] [--allow-env NAME[,NAME...]] [--no-deploy] [--continue-on-error] [flags]

validate resource files, print the plan, and apply it through the API with your own permissions. Exit 0 no changes or applied, 1 error, 2 changes pending (with --dry-run --exit-code). ${{ env.NAME }} placeholders are filled only from --var, --var-file or the names listed with --allow-env (a trailing * allows a prefix, but never covers credential looking names such as AWS_*, GITHUB_TOKEN or anything containing TOKEN, SECRET, PASSW or _KEY, which must be named exactly); an unresolved placeholder fails before anything is sent

levelrail diff -f dir [flags]

drift between the files and live state, exits 2 when they differ

levelrail export [--project P] [--app A] [-o dir|-] [--include-env-values=false] [flags]

write live state as stable resource files, never containing secret values. Secret looking values become ${{ env.NAME }} placeholders; supply them at apply time with --var, --var-file or --allow-env

Nodes ​

levelrail nodes delete <id> [flags]
levelrail nodes drain <id> [--target NODE-ID] [flags]
levelrail nodes get <id> [flags]
levelrail nodes health <id> [flags]
levelrail nodes join-token [flags]
levelrail nodes list [flags]
levelrail nodes list [flags]

list every node

levelrail nodes metrics <id> --metric NAME [flags]
levelrail nodes patch-status <id> [flags]
levelrail nodes events <id> [--limit N] [flags]
levelrail nodes workloads <id> --accepts-app=BOOL --accepts-build=BOOL [flags]
levelrail nodes reenroll-token <id> [flags]

mint a one-time token that re-issues a node's agent certificate, keeping its identity; prints the command to run on the node

levelrail nodes revoke-cert <id> [flags]

revoke a node's agent certificate and close its session; only a re-enroll token brings it back

nodes list shows each node's certificate state and days left (CERT) and agent version (AGENT); nodes get adds expiry, last renewal, key origin, platform and commit.

Status ​

levelrail status [flags]

Version ​

levelrail version [flags]
Audit Log and Audit Purge (administrative)

Audit Log ​

levelrail audit-log [flags]

Filter with --agent <name> (entries made with a token labeled with that agent name), --search <text> (case-insensitive substring across actor, ability, method, path and remote address) and --failed (status 400 or higher). Both are applied server side and carry into --format csv exports.

Audit Purge ​

levelrail audit-purge [flags]
Attention (troubleshooting)

Attention ​

levelrail attention [flags]

Lists everything that needs attention right now: failing apps, offline nodes, expired or expiring certificates, and doctor warnings or failures, critical first. It is the CLI side of the dashboard's Status page (/status). Exit code is 1 if any item is critical, 0 otherwise, so it works as a script gate. Supports --json, --output json|table|text, and --query.

Doctor (troubleshooting)

Doctor ​

levelrail doctor [flags]
Containers (low-level)

Containers ​

levelrail containers [flags]
System Maintenance (fleet-wide cleanup, requires an admin/root-scoped token)

System Prune ​

levelrail system-prune [flags]

Removes every stopped container, dangling image, and unused anonymous volume or build cache not part of the reconciler's current desired state, fleet-wide. Never touches a named volume (an app's storage attachment, a database's data volume), even one that's actually orphaned: see Orphaned Volumes below for those.

Control Plane Backups ​

levelrail control-plane-backups list [flags]
levelrail control-plane-backups create [flags]
levelrail control-plane-backups download <name> [--out FILE] [flags]
levelrail control-plane-backups verify <name> [flags]
levelrail control-plane-backups delete <name> [flags]
levelrail control-plane-backups list --offbox [flags]
levelrail control-plane-backups schedule show|set [flags]
levelrail control-plane-backups run-now [--no-wait] [flags]
levelrail control-plane-backups drill run|status [flags]
levelrail control-plane-backups escrow [--out FILE] [--recipient KEY] [--upload] [--ack] [flags]
levelrail control-plane-backups escrow ack [flags]
levelrail control-plane-backups escrow open <file> --identity FILE [--extract DIR]
levelrail control-plane-backups keys generate [--out FILE] [--hybrid]

Snapshots of the control plane's own database, stored under <data dir>/control-plane-backups/. create takes one now (manual snapshots are never auto-deleted), download saves one to --out FILE (or raw bytes to stdout), verify re-checks the checksum, SQLite integrity and schema version without restoring (exit 1 if any check fails), delete removes one. Snapshots never contain the master key. Restore is an offline server command, levelrail restore-db <file>; see Control plane backup and restore.

The --offbox, schedule, run-now, drill, escrow and keys subcommands drive encrypted off-box backups: keys generate makes an age key pair on your machine (private key to a 0600 file, public key to stdout), schedule set changes only the flags you pass, run-now and drill run wait for the run and exit 1 if it failed, drill status exits 1 when the last drill failed or none has run, and escrow writes the master key and agent CA key encrypted to your recipients (never uploaded unless --upload, and never to the backup bucket). Restore an off-box backup on the server with levelrail restore --from <s3://... | file> --identity FILE [--dry-run]. See Disaster recovery.

Orphaned Volumes ​

levelrail volumes-orphaned [flags]
levelrail volumes-orphaned-cleanup --names name1,name2 [flags]

Named Docker volumes (an app's storage attachment, a database's data volume) survive system-prune even after the app or database that created them is deleted, since Docker never removes a named volume on its own. volumes-orphaned lists every one this instance created that no current app, database, or storage attachment references any more. volumes-orphaned-cleanup removes exactly the volumes named with --names (comma-separated), after the control plane re-confirms each one is still genuinely orphaned; there is no flag that deletes every currently orphaned volume sight unseen, review the list first.

Users ​

levelrail invites create --email EMAIL --role ROLE [flags]

invite a new teammate

levelrail users create --email EMAIL --password PASSWORD --role ROLE [flags]
levelrail users delete <id> [flags]
levelrail users list [flags]

list every user

levelrail users roles [flags]
levelrail users set-abilities <id> --role ROLE [flags]

Iam ​

levelrail iam policies <verb> [flags]
levelrail iam policies attach <id> --principal-type TYPE --principal-id ID [flags]
levelrail iam policies attachments <id> [flags]
levelrail iam policies create --name NAME --document DOC [flags]

create a policy

levelrail iam policies delete <id> [flags]
levelrail iam policies detach <id> --principal-type TYPE --principal-id ID [flags]
levelrail iam policies get <id> [flags]
levelrail iam policies list [flags]
levelrail iam policies update <id> --name NAME --document DOC [flags]

Secrets ​

levelrail secrets rotate-master-key --new-key-file PATH [flags]
levelrail secrets binding-status [flags]

count stored secret values not yet bound to their slot

levelrail secrets rebind [flags]

bind every legacy secret value to its slot, safe to rerun

Migrate (one-time platform migration)

Migrate ​

levelrail migrate caprover --url URL --token TOKEN [flags]
levelrail migrate coolify --url URL --token TOKEN [flags]

migrate apps from a Coolify instance

levelrail migrate dokploy --url URL --token TOKEN [flags]
Import (from another platform)

Import platform ​

levelrail import platform coolify|dokploy|caprover --url URL [flags]

read apps and databases from another platform and create them here; use --dry-run first, see migrating from Coolify, Dokploy or CapRover

Completion (shell setup)
levelrail completion bash

print a bash completion script

Settings (system configuration)

Settings ​

levelrail settings email get [flags]
levelrail settings ingress get [flags]
levelrail settings dashboard-url get [flags]

shows the public dashboard URL

levelrail settings dashboard-url set --url URL [flags]

sets it; once it is https://, sign-in over plain HTTP is refused (--url "" clears it)

levelrail settings oauth list [flags]

show every OAuth sign-in provider's current settings

levelrail settings ai-assistant get [flags]

shows the current AI assistant settings (the key itself is never returned, only whether one is stored)

levelrail settings ai-assistant set --model NAME --api-key KEY [flags]

configures the AI assistant

levelrail settings ai-assistant clear [flags]

clears the stored key and resets provider/model

Git Integrations (Github, Gitlab, Bitbucket, Gitea setup)
levelrail git-providers [flags]

connection status and capabilities (list branches, register a webhook, authenticated clone) for github, gitlab, bitbucket, and gitea in one call

Github App ​

levelrail github-app status [flags]
levelrail github-app disconnect [flags]

forgets the stored connection locally; does not uninstall or delete the App on GitHub's own side

levelrail github-app repos [flags]

list repos the connected installation can access

Gitlab App ​

levelrail gitlab-app status [flags]
levelrail gitlab-app disconnect [flags]

forgets the stored connection locally; does not revoke the token or delete the Application on GitLab's own side

levelrail gitlab-app projects [flags]

list projects the connected account can access

Bitbucket App ​

levelrail bitbucket-app status [flags]
levelrail bitbucket-app disconnect [flags]

forgets the stored connection locally; does not revoke the token or delete the consumer on Bitbucket's own side

levelrail bitbucket-app repos [flags]

list repos the connected account can access

Gitea App ​

levelrail gitea-app status [flags]
levelrail gitea-app disconnect [flags]

forgets the stored connection locally; does not revoke the token or delete the application on Gitea's own side

levelrail gitea-app repos [flags]

list repos the connected account can access

Templates ​

levelrail templates list [flags]

browse the curated service catalog

Static Sites ​

levelrail static-sites list [flags]

Released under the Apache 2.0 License.