文档

shdctl command-line tool

Manage Self-Hosted Deployment releases on customer-operated Kubernetes clusters with the shdctl command-line tool
阅读时间2 分钟最后更新于 10 小时前

shdctl is the Unity command-line tool that manages Self-Hosted Deployment (SHD) releases on customer-operated Kubernetes clusters. It renders Helm chart values from a single
manifest.yaml
file. It can also pull release archives from the Unity registry, mirror images and ORAS artifacts to your registry, generate Kubernetes Secret manifests, and deploy to your cluster.
shdctl has one required operation and several optional ones. You decide how much of the deployment lifecycle shdctl runs and how much your CI handles.
Required: render Helm chart values from your
manifest.yaml
:
shdctl release generate
manifest.yaml
is the single declarative input that describes your whole deployment — registry, namespace, ingress, autoscaling, monitoring, infrastructure sizing, authentication. Customize it once for your cluster, commit it to version control, and
shdctl release generate
fans those settings out across every Helm chart in the release. The CUE-embedded schema catches misconfiguration before you deploy (for example, TLS enabled without a certificate,
maxReplicas < minReplicas
) — refer to the manifest reference.
Everything else is optional and can be replaced by your CI, GitOps controller, or operator workflow.

I want shdctl to...

Command

Render Helm charts from my manifest (required)
shdctl release generate
Check my cluster meets the prerequisites
shdctl cluster check
Pull the release archive from Unity's registry
shdctl release pull
Mirror images and ORAS artifacts to my registry
shdctl artifact sync ...
Check my registry holds what my manifest needs
shdctl artifact sync verify
Render Kubernetes Secret manifests
shdctl secret generate
Apply secrets to my cluster
shdctl secret deploy
Rebuild my secrets import file from a running cluster
shdctl secret export
Deploy charts (helm or argocd)
shdctl release deploy --format ...
The recommended path uses shdctl in CI to render charts and commits them to Git so ArgoCD deploys. Other ways to use shdctl covers the alternatives.
The three usage modes combine these operations differently for different security postures. Refer to Architecture and security for the complete trust boundary overview.