Storage, code, and mounts
Part of the CLI examples cookbook. Auth setup lives on Auth + setup.
Storage
lakeshore storage registers S3-compatible object stores. Note the
verb is singular — storage, not storages — even though every
sibling group is plural.
Two kinds:
| Kind | Meaning | Required config |
|---|---|---|
s3 | A full bucket | bucket |
s3-prefix | A scoped directory source | bucket, prefix |
Both also accept region, endpoint (for MinIO / R2 / Ceph /
Backblaze), and creds.$secret pointing at a registered
aws_keypair secret.
storage add — register a backend
The common fields have direct flags. --creds <secret> is shorthand
for --kwarg creds.$secret=<name>.
Non-AWS S3 needs --endpoint:
Longer configs can come from a file, and --kwarg sets arbitrary
config fields with dotted keys nesting:
storage add calls Commander's allowUnknownOption(). Any other
--<key> <value> pair you pass is folded into the config object as
key=value. That means a typo'd flag silently becomes a config field
instead of erroring — check storage show after adding.
storage add --provision — create the bucket too
Requires creds to resolve to an aws_keypair secret. The
controlplane calls CreateBucket on your behalf; it's idempotent if
the bucket already exists under the same account. --s3-option is
repeatable and is forwarded verbatim as a CreateBucket parameter.
storage list / show
storage update — patch the config
--kwarg deep-merges (pass null to drop a key); --config-file
replaces the config wholesale. --description updates the description.
storage remove — delete the entry
Deletes the record only. --purge also deletes the S3 bucket, which
needs credentials in the config.
storage presign — a presigned URL
Two positionals: the storage name and the object key (relative to the
storage prefix). Defaults to a GET; --put presigns an upload.
--expires-in defaults to 3600 seconds and is capped at 86400.
Because the result is a plain URL, curl is the object-verb surface:
storage credentials — temporary STS credentials
Short-lived credentials a local script or SDK can use against the
bucket directly. --duration defaults to 3600 seconds and accepts
900–129600.
Code
lakeshore code archives the current git tree and uploads it to a
storage entry, so a remote daemon can pull the exact snapshot.
code push — upload a snapshot
Deduped by (git remote, commit) — re-running on the same clean commit
is a no-op that reports already archived. The default storage entry
name is the literal code-staging.
An uncommitted working tree is refused (exit 2) unless you pass
--dirty, which stashes, archives, and pops.
If the storage entry doesn't exist yet, the failure message tells you how to create it:
code list — show pushed snapshots
Mounts
A mount is a declaration the runner attaches into the job workdir. The CLI writes metadata; the daemon does the actual mounting.
--kind is required and must be one of:
The mounts add --kind validator in CLI v0.2.0 accepts exactly the ten
kinds above. If you see a git kind documented elsewhere, it is ahead
of the shipped CLI.
Each kind has its own required config fields, validated server-side:
| Kind | Required | Also accepted |
|---|---|---|
nfs | server, path | — |
samba | server, share | path within the share, credentials |
ftp / sftp | server | path, credentials |
s3 | bucket | endpoint, region, prefix, creds |
s3fs | bucket | endpoint, region, prefix, creds, options |
google_drive | folderId | creds |
dropbox | path | creds |
bind | hostPath | readOnly |
configmap | kubeNamespace, name | items |
s3 is the userspace-client form (copy on read); s3fs is the
FUSE driver that gives job code a real filesystem path.
mounts add
--config-file supplies the same fields from YAML or JSON. --kind
stays on the command line either way:
Any $secret marker inside the config must name a secret that exists
in the same namespace, or the write is rejected with a 422.
mounts list / show / update / remove
Read next
- Storages · Mounts
- Payloads — how job inputs and outputs move.
- Secrets, modes, tunnels — registering the credentials these reference.