Command reference
Every command group, what it does, and where each one is explained in full.
Every command accepts --help. This page is the index; the pages it links to
have the detail, and the terminal is always current.
To install the CLI, see Installing the CLI.
Global flags
These go before the command name:
isogrid --api https://api.isogrid.skyvault.pro apps list
| Flag | |
|---|---|
--api URL |
The endpoint to use, instead of the one you last signed in to. |
--organization SLUG |
Act in this organization. It must be the one the credential is pinned to. |
And the environment, for scripts and pipelines:
| Variable | |
|---|---|
ISOGRID_API_URL |
Endpoint to use. |
ISOGRID_TOKEN |
Credential to use, instead of the stored one. Never written to disk. |
ISOGRID_ORGANIZATION |
Organization to act in. |
ISOGRID_CONFIG_HOME |
Where to keep config.json. Default ~/.isogrid. |
ISOGRID_INSTALL_DIR |
Where the installers put the binary. |
NO_COLOR |
Disable colour. It is also off whenever output is not a terminal. |
Things are named by slug, name or id, and flags may come before or after the
names: isogrid apps deploy shop --wait and isogrid apps deploy --wait shop
are the same command.
Signing in
isogrid login # opens a browser, approves this machine
isogrid logout [--revoke] # forgets the credential here; --revoke withdraws it on the server too
isogrid whoami # who you are, where, and what this credential may do
isogrid orgs list # the organizations you belong to, and which one is pinned
isogrid auth credentials # every credential issued for your account
isogrid auth revoke <id> # revoke one (from a browser session only)
login takes --scope a,b to ask for only some permissions, --name to label
the credential, --no-browser to print the address instead of opening it, and
--force to replace a credential you already have.
A credential is pinned to one organization: the one you were looking at in
the browser when you approved it. There is deliberately no orgs use: a
command that appeared to switch and then acted somewhere else would be worse
than no command at all. To work elsewhere, switch organizations in the web
console and run isogrid login --force.
A credential never holds more than you do. What you approve is a ceiling, checked against your role every time. Some things it can never do: billing, appointing administrators, and minting or revoking credentials. See Roles, permission groups and access.
Revoke anything you do not recognise, and the credential on any machine you no longer control. Revocation takes effect at once.
Applications: isogrid apps
isogrid apps list
isogrid apps get <app> [--exact]
isogrid apps create --name NAME --url REPO_URL|IMAGE_REF [flags]
isogrid apps update <app> [flags] [--deploy [--ref REF]]
isogrid apps build <app> [--ref REF]
isogrid apps deploy <app>
isogrid apps stop <app> | start <app>
isogrid apps status <app>
isogrid apps scale <app> [--replicas N] [--tier SIZE]
isogrid apps tiers <app>
isogrid apps logs <app> [--follow]
isogrid apps env <app>
isogrid apps secrets <app>
isogrid apps delete <app> [--yes]
Creating from GitHub, GitLab or an image, environment and secrets, merging
versus replacing, and what --wait counts as a failure:
Automating applications.
Deploying from CI/CD: isogrid ci
isogrid ci init github|gitlab [--app NAME] [--cluster REGION] [--output PATH]
Writes a ready-to-commit pipeline that deploys on every push. Minting a credential for it, the full templates, and what to do when a job fails: Deploying from CI/CD.
Repositories: isogrid repos
isogrid repos list
isogrid repos access <repo> --visibility private|administrators|organization|inherit
isogrid repos grant <repo> (--member EMAIL | --group SLUG) --preset NAME
isogrid repos grants <repo>
isogrid repos revoke <repo> <grant>
Members and groups: isogrid iam
isogrid iam members
isogrid iam groups list | get | create | update | delete
isogrid iam groups add-member <group> <email>
isogrid iam groups remove-member <group> <email>
isogrid iam permissions
Both are explained with examples in Repositories, groups and access.
Databases: isogrid database
isogrid database list
isogrid database instances
isogrid database create <name> [--instance ID]
database also answers to db.
Credentials are printed once, when the database is created, and cannot be retrieved afterwards. If you are scripting this, capture the output; if you lose them, create new ones. See Databases.
Regions: isogrid regions
isogrid regions list [--all]
Only regions accepting work are listed by default. A draining region still
serves what is already on it but takes nothing new. --all shows everything you
have access to.
Documentation: isogrid docs
isogrid docs search <term> [--language en|fr|ar]
isogrid docs show <section>/<slug> [--language en|fr|ar]
isogrid docs list [--section guide]
These work without signing in. docs show prints Markdown as written, so a
command copied out of a page is the command. Notices go to standard error, so
isogrid docs show guide/databases > databases.md produces a clean file.
The CLI itself
isogrid update [--check] # replace this executable with the platform's current build
isogrid version
See Installing the CLI.
Output for scripts
Most commands take --json and print the API's response unchanged. Anything a
person reads and a script does not — progress, prompts, hints — goes to standard
error, so isogrid apps list --json | jq works without filtering noise.
Exit codes: 0 success, 1 failure (including a failed or rolled-back
deployment under --wait), 2 a usage error, or a destructive command without
--yes and without a terminal to confirm on.
Edge cases worth knowing before you meet them
"not signed in" on a machine you signed in on. Credentials are per endpoint.
If you passed --api once, you signed in to that endpoint and the default one
is still anonymous.
A permission error the web console does not give you. A CLI credential can
be approved with a narrower scope than your account has. isogrid whoami shows
what this one carries; isogrid login --force authorises a wider one.
Your credential expired. Sign in again; nothing else is affected.
A command hangs. --follow is meant to stay attached, and --wait waits up
to --timeout. Interrupting cancels the request in flight rather than killing
the process mid-write, so Ctrl-C is safe.
A script works interactively and fails in CI. Almost always the credential:
ISOGRID_TOKEN is not set, or it is pinned to a different organization. Make
isogrid whoami the first step of the pipeline. See
Deploying from CI/CD.