CLI Reference
Current release-facing deku command surface.
Core Commands
Section titled “Core Commands”deku setupdeku versiondeku restartdeku dashboarddeku uninstalldeku apps list|create|destroy|info|rename|clonedeku auth enable|forward|disable|statusdeku backup schedule|schedules|status|unscheduledeku build-host setup|info|check|init|unsetdeku checks run|routingdeku config list|set|unsetdeku deploy run|list|rollback|tokendeku doctordeku alerts [--all]deku env list|create|removedeku domains list|add|removedeku exec <app> <command>...deku letsencrypt enable|disable|status|configdeku logs [-n] [--follow] [--timeout]deku maintenance on|off|statusdeku ps list|scale|limitsdeku redirects list|add|removedeku registry setup|info|unsetdeku run <app> <command>...deku ssh add|list|removedeku plugins list|install|uninstalldeku objectstore setup|info|test|unset|status|link|unlinkdeku postgres create|destroy|link|unlink|list|info|connect|logs|backup|backups|restoredeku redis create|destroy|link|unlink|list|info|connect|logs|backup|backups|restoredeku mysql create|destroy|link|unlink|list|info|connect|logs|backup|backups|restoredeku mariadb create|destroy|link|unlink|list|info|connect|logs|backup|backups|restoredeku mongodb create|destroy|link|unlink|list|info|connect|logs|backup|backups|restoredeku network create|destroy|attach|detach|list|reportdeku storage ensure-directory|mount|unmount|listdeku cron list|add|removedeku git set|report|remote add|doctor
Command Groups
Section titled “Command Groups”deku setup
Section titled “deku setup”setup— interactive first-run configuration for the server
deku version
Section titled “deku version”version— print the current tagged Deku release version--version/-v— print the same version string
deku restart
Section titled “deku restart”restart— restart the localdekusystemd service on packaged Linux installs
deku dashboard
Section titled “deku dashboard”dashboard— print the server-reachable dashboard URL, local loopback URL, token status, SSH tunnel / firewall guidance, and reset guidancedashboard --json— print non-secret access metadata as JSONdashboard reset-token [--yes]— rotate the dashboard token and print the new value once
deku uninstall
Section titled “deku uninstall”uninstall— interactive packaged-install removal flowuninstall --keep-data— remove host install artifacts and keep local state and Docker volumesuninstall --full-remove— remove host install artifacts and Deku-owned persisted stateuninstall --yes— skip the destructive confirmation promptuninstall --dry-run— print the uninstall plan without making changes
deku apps
Section titled “deku apps”apps list— tabular output (name, status, created)apps create <name>— create app, print IDapps destroy <name> [--force]— confirmation prompt unless--forceapps info <name>— JSON pretty-printapps rename <name> <new-name>— rename an app; running containers keep servingapps clone <name> <new-name>— copy an app’s portable settings into a new app
apps rename rewrites the vhost and keeps the app running, but container names still reference the
old name until the next deploy, and any git remote that used the old name needs updating.
apps clone copies config vars, resource limits, redirects, and app auth. It deliberately does not
copy domains, port mappings, storage mounts, cron entries, service links, or deploy tokens, because
those would conflict with the source or duplicate work. The command prints both lists.
deku config
Section titled “deku config”config list <app> [--environment <slug>]— KEY=VALUE output, with(global)marking global vars and(override)marking a value that applies to one environmentconfig set <app> KEY=VAL [KEY=VAL ...] [--environment <slug>]— batch set via per-key API writes; with--environmentthe value overrides the app-wide one inside that environment onlyconfig unset <app> KEY [--environment <slug>]— without--environmentthe app-wide value is removed; with it, only that environment’s override isconfig import <app> --file .env [--overwrite]— import a.envfile, skipping vars that already exist unless--overwriteis passed
deku deploy token
Section titled “deku deploy token”deploy token create <app> [--name ci]— mint a token; printed oncedeploy token list <app>— id, name, creation time, last usedeploy token revoke <app> <id>
A deploy token can only trigger deploys for its own app. See Deploy tokens.
deku deploy
Section titled “deku deploy”deploy run <app> [--path .] [--image img] [--builder b] [--build-host local|name] [--environment <slug>]deploy token create|list|revoke— CI credentials scoped to one app- With
--image: POST to/api/apps/:name/deploy - Without: Tar.gz source directory, POST multipart to
/api/apps/:name/deploy/archive - Streams SSE deploy log to terminal
deploy list <app>— tabular deployment history, with the URL each deployment is currently reachable at (-once it is no longer retained, or when noglobal_domainis set)deploy rollback <app> [--to <id>]
deku domains
Section titled “deku domains”domains list <app>domains add <app> <domain>domains remove <app> <domain>
deku logs
Section titled “deku logs”logs <app> [-n 100]— stored lines, build and runtime, for every deploymentlogs <app> --follow [--timeout secs]— live log lines over SSE;--timeoutstops after idle secondslogs <app> --search <term>— case-insensitive full-text search over stored lineslogs <app> --source build|runtime,--stream stdout|stderr,--level ERROR— narrow by originlogs <app> --deployment <id>,--environment <slug>— narrow to one deployment or environment
Lines are stored, so a retired deployment’s logs remain readable. See Logs.
deku run
Section titled “deku run”run <app> <command>...— run a command in a fresh container from the app image, then remove it
deku exec
Section titled “deku exec”exec <app> <command>...— run a command inside the app’s running web container
See Runtime access for exit-code behavior and what the container can see.
deku maintenance
Section titled “deku maintenance”maintenance on <app> [--message text]— serve a 503 instead of proxyingmaintenance off <app>— resume servingmaintenance status <app>
deku redirects
Section titled “deku redirects”redirects list <app>redirects add <app> <source> <target> [--code 301|302|307|308]— one exact path per entryredirects remove <app> <id>
See Traffic control for how both reach the proxy.
deku auth
Section titled “deku auth”auth enable <app> --user user [--password pass]— HTTP basic auth, password prompted when omittedauth forward <app> --url https://auth.example/verify— delegate to a forward-auth endpointauth disable <app>auth status <app>
See App authentication.
deku ps
Section titled “deku ps”ps list <app>— running process/container viewps scale <app> PROC=N [PROC=N ...]ps limits <app> [--process type] [--cpu 0.5|500m] [--memory 512m|1g]— show or set limits
See Resource limits for accepted formats.
deku ssh
Section titled “deku ssh”ssh add <name> <key-or-path>— reads.pubfile if path givenssh list— name + fingerprint tablessh remove <name>
deku plugins
Section titled “deku plugins”plugins list— reports whether the running daemon includes the dynamic plugin runtimeplugins install <path-to-.so>— fails with an explanation on builds without the runtimeplugins uninstall <name>
The in-process runtime is compiled out by default. Rebuild with --features dynamic-plugins to
enable it, or use lifecycle hooks instead.
deku letsencrypt
Section titled “deku letsencrypt”letsencrypt enable <app>letsencrypt disable <app>letsencrypt status <app> [--json]— human-readable summary, including days until expiryletsencrypt config --email <address>— the ACME account contact, also used by automatic certificates
deku acme
Section titled “deku acme”Automatic certificates for generated hostnames. See Automatic certificates.
acme status— what was asked for, where the token comes from, and whether a certificate has been issued yet; exits non-zero when the certificate exists but cannot be used
deku objectstore
Section titled “deku objectstore”objectstore setupobjectstore infoobjectstore testobjectstore unsetobjectstore status <app>objectstore link <app> [--prefix path]objectstore unlink <app>
deku build-host
Section titled “deku build-host”build-host setup [--host ssh://user@host[:port]] [--name builder] [--identity-file path] [--buildkit-host endpoint]build-host info— configured host plus registry, password redactedbuild-host check— probes ssh, docker, railpack, BuildKit; exits1when a check failsbuild-host init— creates or starts the managed BuildKit container on the hostbuild-host unset
Builds run on the build host and reach the deploy host through the registry. See Build server.
deku registry
Section titled “deku registry”registry setup [--server ghcr.io/acme] [--username user] [--password secret] [--namespace deku]registry info— password redactedregistry unset
deku postgres
Section titled “deku postgres”- Create, destroy, link, unlink, list, info, connect, logs, backup, backups, restore
deku redis
Section titled “deku redis”- Create, destroy, link, unlink, list, info, connect, logs, backup, backups, restore
deku mysql
Section titled “deku mysql”- Create, destroy, link, unlink, list, info, connect, logs, backup, backups, restore
deku mariadb
Section titled “deku mariadb”- Create, destroy, link, unlink, list, info, connect, logs, backup, backups, restore
- Uses the same command shape as
mysql, withMARIADB_URLas the injected env key
deku mongodb
Section titled “deku mongodb”- Create, destroy, link, unlink, list, info, connect, logs, backup, backups, restore
- Injects
MONGODB_URLand authenticates against theadmindatabase
Generic service routes
Section titled “Generic service routes”Postgres, Redis, and MySQL have per-type routes (/api/postgres/services/...). MariaDB and MongoDB
use the generic family, and the per-type routes remain as aliases:
GET|POST /api/services/{type}GET|DELETE /api/services/{type}/{name}POST|DELETE /api/services/{type}/{name}/link/{app}GET /api/services/{type}/{name}/logsGET|POST /api/services/{type}/{name}/backupsPOST /api/services/{type}/{name}/restore/{backup_id}
{type} is one of postgres, redis, mysql, mariadb, or mongodb.
deku backup
Section titled “deku backup”backup schedule <service> [--interval-hours 24] [--keep 7]backup schedules— every schedule with last run status and next run timebackup status <service>backup unschedule <service>
See Backups.
deku network
Section titled “deku network”network create <name>network destroy <name>network attach <app> <network>network detach <app> <network>network listnetwork report <app>
deku storage
Section titled “deku storage”storage ensure-directory <app> <path>storage mount <app> <host-path> <container-path>storage unmount <app> <id>storage list <app>
deku cron
Section titled “deku cron”cron list <app>cron add <app> <schedule> <command>cron remove <app> <id>
deku checks
Section titled “deku checks”checks run <app> [--path /health] [--timeout 5]checks routing [app]
deku git
Section titled “deku git”git set <app> <key> <value>git report <app>git remote add <app>git doctor
deku env
Section titled “deku env”Every app has a production environment, which is what a plain deku deploy run <app> targets.
Additional environments are named deployment targets for the same app, served on derived
<app>-<slug>.<global_domain> hostnames over HTTP.
env list <app>— slug, display name, tracked branch, and whether it is productionenv create <app> <name> [--slug <slug>] [--branch <ref>]— create one; the slug is derived from the name unless given, and an explicit slug must be lowercase letters, digits, and-env remove <app> <slug>— remove one; production cannot be removed
Target one with deku deploy run <app> --environment <slug>, and set values that apply only there
with deku config set <app> KEY=VAL --environment <slug>. --branch records the git ref an
environment tracks; it is metadata today, and nothing auto-deploys on push. See
Environments.
deku alerts
Section titled “deku alerts”alerts— active alerts (severity, rule, subject, first seen, message)alerts --all— alert history, including resolved alerts
Deku does not renew or issue certificates; the alert watcher reports expiry so an operator or external automation can act.
deku doctor
Section titled “deku doctor”doctor— run host and daemon checks; exits1when any check has failed
See Diagnostics.