# shdctl command reference

> Reference documentation for shdctl commands, flags, workflows, and deployment operations

Use this page to find command references for shdctl. To get started with shdctl and learn about recommended deployment workflows, refer to [shdctl](/self-hosted-deployment/shdctl.md) and [Architecture and security](/self-hosted-deployment/shdctl/architecture.md).

[Release](/self-hosted-deployment/shdctl/commands/release.md): pull, generate, deploy, uninstall.
[Artifact](/self-hosted-deployment/shdctl/commands/artifact.md): sync preflight, sync images, sync oras, sync verify.
[Secret](/self-hosted-deployment/shdctl/commands/secret.md): generate, deploy, export.
[Manifest](/self-hosted-deployment/shdctl/commands/manifest.md): init, validate, schema.
[Cluster](/self-hosted-deployment/shdctl/commands/cluster.md): check.
[Configure](/self-hosted-deployment/shdctl/commands/configure.md): set, get, delete.


## Global flags

You can use these flags with any command:

* `--manifest <path>`: Path to manifest.yaml file (default: auto-discover)
* `--log-level <level>`: Set logging level (`trace`, `debug`, `info`, `warn`, `error`, `fatal`, `panic`; default: `info`)
* `--json`: Output logs in JSON format

Logs go to stderr. A command's own output goes to stdout — a `--dry-run` command list, the `cluster check` results, a `verify` report, the commands a deploy runs — so a pipeline can capture one without the other.

Example:

```sh
shdctl release pull --version 2.0.0 --log-level debug
```

## Command summary

| Command                              | Description                                                                                                                                                                  |
| ------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `shdctl version`                     | Print the version number                                                                                                                                                     |
| `shdctl configure`                   | Set registry credentials (interactive)                                                                                                                                       |
| `shdctl configure get`               | View configuration                                                                                                                                                           |
| `shdctl configure set [registry]`    | Set registry credentials (prompts on a terminal; `--username` with `--password-stdin` or `SHDCTL_*` for CI)                                                                  |
| `shdctl configure delete [registry]` | Delete registry credentials                                                                                                                                                  |
| `shdctl manifest init`               | Initialize a new manifest file interactively                                                                                                                                 |
| `shdctl manifest validate`           | Validate a manifest file against the CUE schema                                                                                                                              |
| `shdctl manifest schema`             | Display the CUE schema (or export it for standalone validation)                                                                                                              |
| `shdctl cluster check`               | Validate that the cluster meets the deployment prerequisites (read-only; `--probe-storage` adds an opt-in volume probe, `--dry-run` prints the command plan)                 |
| `shdctl release pull`                | Pull a release from the registry                                                                                                                                             |
| `shdctl release generate`            | Generate release configuration (Helm/ArgoCD charts)                                                                                                                          |
| `shdctl release deploy`              | Deploy a release (Helm or ArgoCD)                                                                                                                                            |
| `shdctl release uninstall`           | Uninstall a release                                                                                                                                                          |
| `shdctl artifact sync preflight`     | Verify registry authentication by syncing one image and one ORAS artifact                                                                                                    |
| `shdctl artifact sync images`        | Sync Docker images from the source registry to the target registry — those the manifest's enabled features require, or all of them with `--all`                              |
| `shdctl artifact sync oras`          | Sync ORAS artifacts from the source registry to the target registry                                                                                                          |
| `shdctl artifact sync verify`        | Report which images the manifest requires are missing from the target registry, and which it holds that the manifest does not require (read-only; exits non-zero on missing) |
| `shdctl secret generate`             | Generate Kubernetes secret YAML from schema definitions                                                                                                                      |
| `shdctl secret deploy`               | Deploy secrets to your Kubernetes cluster                                                                                                                                    |
| `shdctl secret export`               | Reconstruct the secrets import file from the secrets already in a cluster                                                                                                    |
| `shdctl completion <shell>`          | Print a shell completion script (bash, zsh, fish, powershell)                                                                                                                |
