CLI Commands
Practical arcane-cli invocations for everyday tasks.
The arcane-cli commands you’ll use most often, grouped by task. For the full flag list run arcane-cli <command> --help, and for the complete command tree run arcane-cli --help.
Set your server URL and sign in first. See CLI Configuration.
Sign in
Log in interactively with the device-code flow:
Check who you’re signed in as, or sign out:
For CI, use an API key or a federated credential instead of an interactive login — see Federated Credentials.
Choose an environment
Most resource commands act on your default environment. Set it once:
Or override it for a single command with --env:
List environments and check one is reachable:
Containers
Show which containers have a newer image available:
Pull the newer image and recreate the container:
Projects
Bring a project up, or take it down:
Pull the latest images and restart:
projects up, projects redeploy, and projects pull print the raw Docker output line by line as the operation runs, so you see the same thing you would from docker compose directly. These commands allow up to 30 minutes for large pulls and builds.
Remove a project and its resources:
destroy removes the project’s files from disk by default. Pass --remove-files=false to keep them. Volumes are kept unless you add --remove-volumes.
Images and volumes
Reclaim space:
Find out what’s using a volume before you remove it:
GitOps
Check a sync’s state, then run it now:
System
Free up space across the environment:
Check whether an Arcane upgrade is available, and apply it:
Turn a docker run command into Compose:
Vulnerabilities
Get an overview of scan results, or the full findings list:
Scan an image now, or show one image’s findings:
Silence a CVE you’ve reviewed (and list or undo ignores with ignored / unignore):
System backups
Manage Arcane system backups from the terminal:
There are also subcommands for retention policies (policies), the recovery key (recovery), uploading a local backup to S3 (upload), and finding S3 restore points not in the database (discover).
Activities and webhooks
Follow what the server is doing:
Manage webhooks, or fire one by its token:
Updater
Inspect the automatic updater and trigger a run:
History shows one row per resource — resource, type, status, whether the update was applied, and when it started. Use --limit (-n) to change how many entries you get back; the default is 50.
Update the CLI
Switch between the stable and next release channels:
Diagnose problems and set up your shell
Diagnose connectivity and configuration problems:
Install shell completion:
Generate secrets and certificates for a new install:
Scripting
Every command accepts --output json (or the shorthand --json), which makes the CLI easy to pair with jq:
Add --yes to skip confirmation prompts in unattended scripts.
List commands are paginated. --all (-a) returns every item, ignoring pagination — it cannot be combined with --limit or --start:
--all means “ignore pagination”, not “include stopped containers”. containers list already returns containers in every state.