# shdctl command-line tool

> Manage Self-Hosted Deployment releases on customer-operated Kubernetes clusters with the shdctl command-line tool

shdctl is the Unity command-line tool that manages Self-Hosted Deployment (SHD) releases on customer-operated Kubernetes clusters. It renders Helm chart values from a single `manifest.yaml` file. It can also pull release archives from the Unity registry, mirror images and ORAS artifacts to your registry, generate Kubernetes Secret manifests, and deploy to your cluster.

shdctl has **one required operation** and several optional ones. You decide how much of the deployment lifecycle shdctl runs and how much your CI handles.

**Required:** render Helm chart values from your `manifest.yaml`:

```sh
shdctl release generate
```

`manifest.yaml` is the single declarative input that describes your whole deployment — registry, namespace, ingress, autoscaling, monitoring, infrastructure sizing, authentication. Customize it once for your cluster, commit it to version control, and `shdctl release generate` fans those settings out across every Helm chart in the release. The CUE-embedded schema catches misconfiguration before you deploy (for example, TLS enabled without a certificate, `maxReplicas < minReplicas`) — refer to the [manifest reference](/self-hosted-deployment/shdctl/manifest.md).

Everything else is optional and can be replaced by your CI, GitOps controller, or operator workflow.

| I want shdctl to...                                   | Command                              |
| ----------------------------------------------------- | ------------------------------------ |
| Render Helm charts from my manifest (required)        | `shdctl release generate`            |
| Check my cluster meets the prerequisites              | `shdctl cluster check`               |
| Pull the release archive from Unity's registry        | `shdctl release pull`                |
| Mirror images and ORAS artifacts to my registry       | `shdctl artifact sync ...`           |
| Check my registry holds what my manifest needs        | `shdctl artifact sync verify`        |
| Render Kubernetes Secret manifests                    | `shdctl secret generate`             |
| Apply secrets to my cluster                           | `shdctl secret deploy`               |
| Rebuild my secrets import file from a running cluster | `shdctl secret export`               |
| Deploy charts (helm or argocd)                        | `shdctl release deploy --format ...` |

The [recommended path](/self-hosted-deployment/shdctl/workflows.md#recommended-workflow:-ci-+-argocd) uses shdctl in CI to render charts and commits them to Git so ArgoCD deploys. [Other ways to use shdctl](/self-hosted-deployment/shdctl/workflows.md#other-ways-to-use-shdctl) covers the alternatives.

The three usage modes combine these operations differently for different security postures. Refer to [Architecture and security](/self-hosted-deployment/shdctl/architecture.md) for the complete trust boundary overview.

[Install shdctl](/self-hosted-deployment/shdctl/install.md): Install the shdctl binary, configure registry credentials, and review external CLI requirements.
[Architecture and security](/self-hosted-deployment/shdctl/architecture.md): Three usage modes and what shdctl accesses on the network and in your cluster.
[Workflows](/self-hosted-deployment/shdctl/workflows.md): The recommended CI and ArgoCD pipeline, and the other ways to run shdctl.
[Manifest reference](/self-hosted-deployment/shdctl/manifest.md): The declarative input file that drives every shdctl operation.
[Command reference](/self-hosted-deployment/shdctl/commands.md): Per-command walkthroughs with flags, examples, and dry-run instructions.
[Troubleshooting](/self-hosted-deployment/shdctl/troubleshooting.md): Common shdctl errors and resolutions.
[Changelog](/self-hosted-deployment/shdctl/changelog.md): Release history: new commands and flags, behavior changes, and breaking changes.
