CLI Reference
The Vesta CLI is a Go binary built with Cobra. Install it and manage your entire platform from the terminal.
Installation
Install script (macOS & Linux)
curl -fsSL https://raw.githubusercontent.com/vesta-infra/vesta-kubernetes/develop/install.sh | sh
The script detects your OS and architecture, verifies the SHA-256 checksum of the
download, and installs vesta into /usr/local/bin. Both are overridable:
| Variable | Default | Description |
|---|---|---|
VESTA_VERSION | latest release | Version to install, e.g. 0.6.2 |
VESTA_INSTALL_DIR | /usr/local/bin | Where the binary is placed |
curl -fsSL https://raw.githubusercontent.com/vesta-infra/vesta-kubernetes/develop/install.sh \
| VESTA_VERSION=0.6.2 VESTA_INSTALL_DIR="$HOME/.local/bin" sh
Manual download
Every release ships archives on the
releases page:
vesta_<version>_<os>_<arch>.tar.gz for macOS and Linux (amd64 and arm64), and
vesta_<version>_windows_amd64.zip for Windows. Verify your download against
checksums.txt, extract it, and move vesta onto your PATH.
From source
make cli-install # /usr/local/bin/vesta
make cli-install CLI_INSTALL_DIR=~/.local/bin
Verify
vesta version
vesta 0.6.2
commit: 97ef728
built: 2026-08-20T13:35:13Z
go: go1.22 darwin/arm64
Global flags
Every command accepts these:
| Flag | Default | Description |
|---|---|---|
--api-url | http://localhost:8090 | Vesta API server URL |
--token | — | API token used as Authorization: Bearer <token> |
--help | — | Show help for any command |
Commands take an app ID — the name of the app as it exists in Vesta, not a display name.
Commands
Platform
Install, upgrade and inspect Vesta itself. These wrap Helm, so there is nothing here you could not do by hand — they remove the flags you would otherwise have to remember:
vesta install --postgres
vesta install --database-url "postgres://user:pass@db:5432/vesta?sslmode=disable"
vesta upgrade
vesta status
vesta upgrade takes no configuration flags. The installed values are carried forward,
and re-specifying them on upgrade is how a setting nobody meant to touch quietly changes.
Add --dry-run to either to print the Helm command instead of running it.
vesta status shows the running version of each component and whether a newer release
exists.
Updating the CLI
vesta self-update
vesta self-update --version 0.7.8
vesta self-update --dry-run
Downloads the release for your platform, verifies it against the release’s published
checksums.txt, and replaces the running binary. The replacement is a rename, so an
interrupted update leaves the working binary in place. It refuses to replace a development
build, or to go backwards, without --force.
Apps
vesta apps list
vesta apps get my-app
Deploy
Roll out a new image tag for an app. The repository and imagePullSecrets are already configured on the app, so only the tag changes:
vesta deploy my-app --tag v1.2.3 --environment production
vesta deploy my-app --tag v1.2.3 --environment production --reason "hotfix for #412" --commit 7f3c9a1
| Flag | Description |
|---|---|
--tag | Image tag to deploy (required) |
--reason | Free-text reason recorded on the deployment |
--commit | Git commit SHA to record against the deployment |
Builds
Build an image from the app’s git repository using its configured strategy
(dockerfile, nixpacks, or buildpacks):
vesta build my-app --environment production --branch main
vesta build my-app --environment staging --commit 7f3c9a1
| Flag | Description |
|---|---|
--environment | Target environment (required) |
--branch | Git branch to build |
--commit | Git commit SHA to build |
List build history and stream logs:
vesta builds my-app
vesta build-logs my-app 3f9c1a20-8d51-4c0e-9b77-2a1d5e6f0c13 --follow
Secrets
Secret values are write-only over the API — the CLI can list metadata and unbind shared secrets. Creating and revealing secrets is done in the web UI or via the API.
vesta secrets list
vesta secrets unbind stripe-keys --app my-app
vesta secrets unbind stripe-keys --app my-app --env staging
Omit --env to unbind the secret from every environment.
Add-ons
Managed datastores — PostgreSQL, MySQL, Redis and MongoDB — that run in your cluster.
vesta addons list --project my-project
vesta addons create --project my-project -f addon.yaml
vesta addons credentials cache --project my-project --env production
vesta addons delete cache --project my-project --force
addon.yaml describes one datastore:
name: cache
type: redis # postgres | mysql | redis | mongodb
version: "7" # optional; a sensible major is pinned by default
environment: production # optional; omit for one instance per environment
size: small # optional pod size preset
storage: 10Gi
deletionPolicy: Retain # Retain (default) keeps the volume when the add-on is deleted
Pass -f - to read from stdin.
Bind an add-on’s credentials into an app, so its connection string arrives as environment variables:
vesta addons bind cache --project my-project --app web
vesta addons bind cache --project my-project --app web --env staging,production
vesta addons unbind cache --project my-project --app web
Deleting an add-on requires --force, and retains its volume unless the add-on was created
with deletionPolicy: Delete. Losing a database to a mistyped command is not a recoverable
mistake.
Pipelines (deprecated)
vesta pipelines list
“Pipeline” was the earlier name for a project. The command is an alias for vesta project and
will be removed; use the project commands instead.