Openstead CLI
Deploy, inspect, and operate your applications from Windows, macOS, Linux, or CI.
The Openstead CLI uses your workspace's permissions and plan limits. It deploys connected repositories and configured container images; it does not upload a local source directory.
Install
Build the Openstead CLI from the source repository with Go 1.27 or newer:
git clone https://github.com/Layerrail/openstead-cli.git
cd openstead-cli
git checkout f79730ed7ca9f207145f2b1de80d49d529e211e3
go build -o openstead ./cmd/opensteadOn Windows, use go build -o openstead.exe ./cmd/openstead. Place the resulting executable on your PATH, then run openstead --version. Use a reviewed source commit for reproducible production and CI installations.
The examples below use the Openstead source version. Older release archives retain their original executable names. Existing runivo commands and configuration remain supported; new source builds also provide the openstead entry point.
Sign in
openstead login
openstead whoami
openstead services listLogin opens a browser approval page. Check its displayed code, choose a workspace, and approve access. The CLI stores the resulting key in your OS keychain. Login keys expire after 30 days.
Use openstead login --read-only for observation or --no-browser when signing in from a remote machine. Linux keychain storage requires Secret Service. On a headless machine, explicitly use a private token file:
openstead login --no-browser --token-file /private/path/openstead-token
openstead whoami --token-file /private/path/openstead-tokenKeep that file readable only by its owner. Use the same token-file option on later commands.
Link and deploy a service
openstead link example-api
openstead deploy --wait
openstead logs --followlink writes IDs to openstead.toml in the current directory. It does not change Git configuration or upload files. deploy builds the service's configured repository branch or image.
To target a service explicitly:
openstead deploy --service SERVICE_UUID --wait
openstead status --service SERVICE_UUID --watchA timeout stops the local wait. Resume observation with openstead deploys wait DEPLOYMENT_UUID; do not assume the deployment stopped.
Work with multiple workspaces
openstead login --profile production
openstead login --read-only --profile staging
openstead workspaces list
openstead workspaces use productionEach profile authorizes one workspace. workspaces list shows locally authorized profiles. Saved credentials are bound to their API origin and are not forwarded to a different origin.
Use in CI
Install a verified CLI release in the runner. Put OPENSTEAD_API_KEY in the CI system's masked secret store and set OPENSTEAD_WORKSPACE and OPENSTEAD_SERVICE to the intended UUIDs.
openstead deploy --wait --jsonThe CLI reads these environment values without browser login. Use --yes only where the pipeline intentionally approves a command that requires confirmation. Paid service terms must be purchased through the dashboard; openstead billing open opens that flow.
Sign out
openstead logout --yesYou can also revoke a credential in the dashboard's API Keys page. See the command reference for resource commands, exit codes, and context precedence.