Install shdctl
Install the shdctl command-line tool, configure registry credentials, and review external CLI requirements
읽는 시간 5분최근 업데이트: 19시간 전
Unity provides as part of your Self-Hosted Deployment onboarding package, and every release from 2.0.0 on carries it under . To move a deployment of an earlier release from vpctl to shdctl, follow Install shdctl 1.0.0 before you pull instead. Once you have the script, run:
install-shdctl.shcommon/scripts/./install-shdctl.sh latest
The following sections explain the script's options, the external CLIs that shdctl uses for specific operations, and how to configure the registry credentials shdctl uses to pull releases.
Requirements
shdctl is a single Go binary; it has no runtime dependencies of its own. External CLIs are required only for operations that shell out to them:
You need... | Required for... |
|---|---|
| The install script ( |
| |
| |
| |
| |
| Only if you want to validate |
shdctl release pullshdctl release generateshdctl secret generateshdctl manifest init/validate/schemashdctl configureInstall the shdctl binary
The install script automatically detects your OS and architecture and downloads the correct binary from the Unity registry.
Prerequisites: You need registry credentials (username and password). Unity provides these credentials.
The script supports interactive mode for users and non-interactive mode for CI and automation.
Interactive mode
-
Run the script without setting credentials. It prompts you for your username and password:./install-shdctl.sh latestYou can also pin a specific version:./install-shdctl.sh 1.0.0
-
Enter your credentials at the prompt:[install-shdctl] Logging in to uccmpprivatecloud.azurecr.io (interactive)...[install-shdctl] Please enter your registry credentials:Username: <your-username>Password: <your-password>
Non-interactive mode for CI and automation
For automated environments, set both and environment variables:
ORAS_USERNAMEORAS_PASSWORDexport ORAS_USERNAME="<your-username>"export ORAS_PASSWORD="<your-password>"./install-shdctl.sh latest
You can also pin a specific version:
export ORAS_USERNAME="<your-username>"export ORAS_PASSWORD="<your-password>"./install-shdctl.sh 1.0.0
Custom installation directory
Specify a custom installation directory as the second argument:
./install-shdctl.sh latest /opt/bin
The script creates a missing directory, with when you cannot create it yourself — as a non-root user, for instance.
sudo/opt/binScript actions
The script performs the following actions:
- Auto-detects your platform (/
linux/darwin) and architecture (windows/amd64)arm64 - Checks whether the CLI is installed, and stops with a link to its installation instructions if it is not
oras - Authenticates to the registry by using interactive or non-interactive mode based on environment variables. The login stays in your Docker credential store afterwards; run if you don't want it kept
oras logout <registry> - Downloads and extracts the correct shdctl binary
- Installs it to or the directory you specify, using
/usr/local/binto create that directory or copy into it when you cannotsudo - Links the tool's previous name, , to it (except on Windows), so scripts that still call
vpctlkeep working until shdctl 2.0.0vpctl - Verifies the installation by running
shdctl version
Environment variables
Variable | Required | Default | Description |
|---|---|---|---|
| No* | - | Registry username (for non-interactive mode) |
| No* | - | Registry password (for non-interactive mode) |
| No | | Registry URL |
* Both and must be set together for non-interactive mode, or both unset for interactive mode.
ORAS_USERNAMEORAS_PASSWORDConfigure registry credentials
Before you can pull releases, configure your registry credentials.
-
Run the interactive configuration command:shdctl configureThe command prompts you for:
- Username
- Password (input is hidden)
The registry defaults to. To configure credentials for a different registry, pass it as a positional argument:uccmpprivatecloud.azurecr.io.shdctl configure set <registry-url> -
Alternatively, configure credentials non-interactively. The registry argument is positional and defaults to. You can provide the password by using one of the non-interactive methods in Security: providing registry credentials.
uccmpprivatecloud.azurecr.io
Credentials are stored in , readable only by your user (, in a directory) but not encrypted — protect it like any other credential file. Only reads it; uses your Docker credentials instead.
~/.shdctl/config.json06000700shdctl release pullartifact syncSecurity: providing registry credentials
shdctl configure set- — read the password from stdin. Best for CI/CD pipelines:
--password-stdinecho "$REGISTRY_PASSWORD" | shdctl configure set <registry-url> --username "$REGISTRY_USERNAME" --password-stdin - environment variable — non-interactive without piping. Pair with
SHDCTL_PASSWORD. The pre-renameSHDCTL_USERNAMEandVPCTL_USERNAMEare still read, with a deprecation notice, until shdctl 2.0.0:VPCTL_PASSWORDexport SHDCTL_USERNAME=<username>export SHDCTL_PASSWORD=<password>shdctl configure set <registry-url> - Interactive prompt — the default when you run without flags. Password input is hidden.
shdctl configure set <registry-url> - flag — discouraged. The password is exposed in your shell history and in the process list (
--password <value>). shdctl emits a warning to stderr:ps aux
Kept for backward compatibility; not recommended.WARNING: Using --password via the CLI is insecure (visible in shell history and the process list).Use --password-stdin, set SHDCTL_PASSWORD, or omit --password to be prompted interactively.
--password--password-stdinSHDCTL_PASSWORDshdctl configure setTo view or delete stored credentials, and for every subcommand, refer to Manage registry credentials.
configure