Secrets, modes, tunnels, config, nymph
Part of the CLI examples cookbook. Auth setup lives on Auth + setup.
Secrets
Server-stored credentials referenced by providers, mounts, storage
entries, and tunnels. Plaintext only flows on the way in — list
and show return metadata.
--kind is required and must be one of ssh_key, aws_keypair,
gcp_sa_json, or opaque.
secrets add — from a file
secrets add — from stdin
When --from-file is absent the CLI reads piped stdin, which keeps the
plaintext off disk.
secrets list / show — metadata only
secrets rotate — replace the plaintext
Same input rules as add: --from-file, or piped stdin.
secrets remove
Secrets are referenced elsewhere by the $secret marker — e.g.
--kwarg 'creds.$secret=aws-prod-keys' on storage add and
mounts add, or --creds aws-prod-keys as shorthand on storage add.
Modes
A mode is a server-stored RunConfig: a named compute target (provider, resources, tags). The Python API dispatches against modes; the CLI manages their definitions.
Every other group's inline override flag is --kwarg. modes add and
modes update use --field. (The generated shell completion still
advertises --kwarg here — that table is stale.)
modes add — from a file
modes add — inline field overrides
Dotted keys nest.
modes list / show / update / remove
update merges; =null drops a key.
Tunnels
WireGuard configs the control plane uses to reach providers behind a
VPN. --kind defaults to wireguard, and wireguard is the only
supported value.
tunnels add — from a config file
--config-file accepts .conf (wg-quick INI), .yaml, or .json.
tunnels add --conf — inline INI
tunnels list / show / remove
remove refuses while any provider still references the tunnel.
Attach a tunnel to a provider with providers update <name> --tunnel <tunnel> — see
Providers and discover.
Nymph binaries
For rolling debug builds at a fleet without cutting an R2 release.
Pair with daemon update --url. Both subcommands need an admin token —
--admin-token, defaulting to $LAKESHORE_ADMIN_TOKEN.
nymph push — upload a binary
--target <triple> defaults to a value inferred from the ELF header's
e_machine; --name <label> labels the upload.
The url field in the --json envelope is a path, not an absolute
URL. Daemons OTA from the fully-qualified address — the full: line in
the human output. Prefix the server origin yourself when scripting.
nymph list — what's stored
Push and roll the fleet
nymph push deliberately has no --update <daemon...> flag. Chain it
to daemon update --url as above.
Config
Diagnostics for the resolved .dreamrc. None of the three subcommands
take flags.
config source prints one of env, workspace, home, server,
cache, or none, matching the resolution order (first hit wins):
--dreamrc <path>— the CLI's one global option (reported asexplicit).DREAMRCenv var →env../.dreamrc, walking up from cwd →workspace.$HOME/.dreamrc→home.- A server pull (needs auth or
LAKESHORE_URL) →server. - The on-disk cache from a previous pull →
cache. - Nothing — an empty DreamRc →
none.
The server pull composes a DreamRc from the namespace's providers and
modes, and caches it at
$XDG_CACHE_HOME/lakeshore/<server-host>/<namespace>/dreamrc.yml
(dir 0700, file 0600). If the pull fails, the CLI falls back to that
cache and prints ⚠ server unreachable, using cached config from <ts>.
.dreamrc (providers + modes, YAML with !providers.<Kind> tags) is
not the same as .lakeshore / .lakeshore.local (project defaults
for daemon launch, a top-level daemon: block, walked up from cwd
and stopped at the git root), and neither is lakeshore.yaml (the
compose file for up / down / ps / status / logs, read from
cwd only). See Configuration.
Completion
Full details — the static tree, the dynamic __suggest callback, and
the 30-second cache — at /cli/completion.
Read next
- Auth and secrets — the server-side model.
- Tunnels · Configuration
- Daemons + exec/run — where
daemon update --urllands.