Documentation

CLI Reference

The Vesta CLI is a Go binary built with Cobra. Install it and manage your entire platform from the terminal.

Installation

Install script (macOS & Linux)

curl -fsSL https://raw.githubusercontent.com/vesta-infra/vesta-kubernetes/develop/install.sh | sh

The script detects your OS and architecture, verifies the SHA-256 checksum of the download, and installs vesta into /usr/local/bin. Both are overridable:

VariableDefaultDescription
VESTA_VERSIONlatest releaseVersion to install, e.g. 0.6.2
VESTA_INSTALL_DIR/usr/local/binWhere the binary is placed
curl -fsSL https://raw.githubusercontent.com/vesta-infra/vesta-kubernetes/develop/install.sh \
  | VESTA_VERSION=0.6.2 VESTA_INSTALL_DIR="$HOME/.local/bin" sh

Manual download

Every release ships archives on the releases page: vesta_<version>_<os>_<arch>.tar.gz for macOS and Linux (amd64 and arm64), and vesta_<version>_windows_amd64.zip for Windows. Verify your download against checksums.txt, extract it, and move vesta onto your PATH.

From source

make cli-install                          # /usr/local/bin/vesta
make cli-install CLI_INSTALL_DIR=~/.local/bin

Verify

vesta version
vesta 0.6.2
  commit:  97ef728
  built:   2026-08-20T13:35:13Z
  go:      go1.22 darwin/arm64

Global flags

Every command accepts these:

FlagDefaultDescription
--api-urlhttp://localhost:8090Vesta API server URL
--token—API token used as Authorization: Bearer <token>
--help—Show help for any command

Commands take an app ID — the name of the app as it exists in Vesta, not a display name.

Commands

Platform

Install, upgrade and inspect Vesta itself. These wrap Helm, so there is nothing here you could not do by hand — they remove the flags you would otherwise have to remember:

vesta install --postgres
vesta install --database-url "postgres://user:pass@db:5432/vesta?sslmode=disable"
vesta upgrade
vesta status

vesta upgrade takes no configuration flags. The installed values are carried forward, and re-specifying them on upgrade is how a setting nobody meant to touch quietly changes. Add --dry-run to either to print the Helm command instead of running it.

vesta status shows the running version of each component and whether a newer release exists.

Updating the CLI

vesta self-update
vesta self-update --version 0.7.8
vesta self-update --dry-run

Downloads the release for your platform, verifies it against the release’s published checksums.txt, and replaces the running binary. The replacement is a rename, so an interrupted update leaves the working binary in place. It refuses to replace a development build, or to go backwards, without --force.

Apps

vesta apps list
vesta apps get my-app

Deploy

Roll out a new image tag for an app. The repository and imagePullSecrets are already configured on the app, so only the tag changes:

vesta deploy my-app --tag v1.2.3 --environment production
vesta deploy my-app --tag v1.2.3 --environment production --reason "hotfix for #412" --commit 7f3c9a1
FlagDescription
--tagImage tag to deploy (required)
--reasonFree-text reason recorded on the deployment
--commitGit commit SHA to record against the deployment

Builds

Build an image from the app’s git repository using its configured strategy (dockerfile, nixpacks, or buildpacks):

vesta build my-app --environment production --branch main
vesta build my-app --environment staging --commit 7f3c9a1
FlagDescription
--environmentTarget environment (required)
--branchGit branch to build
--commitGit commit SHA to build

List build history and stream logs:

vesta builds my-app
vesta build-logs my-app 3f9c1a20-8d51-4c0e-9b77-2a1d5e6f0c13 --follow

Secrets

Secret values are write-only over the API — the CLI can list metadata and unbind shared secrets. Creating and revealing secrets is done in the web UI or via the API.

vesta secrets list
vesta secrets unbind stripe-keys --app my-app
vesta secrets unbind stripe-keys --app my-app --env staging

Omit --env to unbind the secret from every environment.

Add-ons

Managed datastores — PostgreSQL, MySQL, Redis and MongoDB — that run in your cluster.

vesta addons list --project my-project
vesta addons create --project my-project -f addon.yaml
vesta addons credentials cache --project my-project --env production
vesta addons delete cache --project my-project --force

addon.yaml describes one datastore:

name: cache
type: redis               # postgres | mysql | redis | mongodb
version: "7"              # optional; a sensible major is pinned by default
environment: production   # optional; omit for one instance per environment
size: small               # optional pod size preset
storage: 10Gi
deletionPolicy: Retain    # Retain (default) keeps the volume when the add-on is deleted

Pass -f - to read from stdin.

Bind an add-on’s credentials into an app, so its connection string arrives as environment variables:

vesta addons bind cache --project my-project --app web
vesta addons bind cache --project my-project --app web --env staging,production
vesta addons unbind cache --project my-project --app web

Deleting an add-on requires --force, and retains its volume unless the add-on was created with deletionPolicy: Delete. Losing a database to a mistyped command is not a recoverable mistake.

Pipelines (deprecated)

vesta pipelines list

“Pipeline” was the earlier name for a project. The command is an alias for vesta project and will be removed; use the project commands instead.