# Happy Paths — CLI

Five paths covering the CLI surface end-to-end: the auth wire, command
execution, provider invocation, storage round-trip, and the token
lifecycle.

Walk top-down. The CLI is the user-facing entry point for almost every
Lakeshore action — these paths are the ones that fail loudest when
something breaks.

## The list

| # | Path | Verifies |
| - | ---- | -------- |
| 02 | [Hello, hosted CP](/cli/happy-paths/02-hello-hosted-cp.md) | `auth login` + `auth status` against a real control plane |
| 04 | [Smoke-exec cascade](/cli/happy-paths/04-smoke-exec-cascade.md) | The whole `daemon exec` surface — stdout, stderr, exit codes, env, stdin, timeout, long-poll |
| 07 | [SSH provider smoke](/cli/happy-paths/07-ssh-provider-smoke.md) | `ssh upload` / `providers add` + `providers test` against a real host |
| 09 | [Storage round-trip](/cli/happy-paths/09-storage-round-trip.md) | `storage add` + `presign` + `credentials` against a real bucket |
| 15 | [Token lifecycle](/cli/happy-paths/15-token-lifecycle.md) | `admin tokens create` + `auth login` against a token-enforced control plane |

## Cross-surface prereqs

| For path | You also need green |
| -------- | ------------------- |
| 04 | [03 · Hello, local stack](/admin/happy-paths/03-hello-local-stack.md) (Operator) |
| 07 | An SSH-reachable host |
| 09 | S3/R2 credentials registered as a Lakeshore secret |
| 15 | A control plane with `LAKESHORE_ADMIN_TOKEN` set (not open mode) |

## The cascade

`02` is the wire test against the hosted control plane — it proves auth
works. `04` exercises the entire `daemon exec` contract in one shell
script and bails on the first failure, which makes it cheap and
comprehensive. `07` validates the provider abstraction without
involving a daemon. `09` covers the storage record plus the presign and
STS credential paths. `15` is the auth-mode story: admin token → client
token → SDK.

→ Switch surface: [Python SDK](/python-sdk/happy-paths.md) · [Operator](/admin/happy-paths.md)
