-
-
Notifications
You must be signed in to change notification settings - Fork 0
CLI Reference
flareover <phase> [args]
flareover version
All credentials are read from environment variables, never passed on the command line. See Security for the full list.
List every zone the token can see (an account-scoped read-only token can migrate any or all of them). Needs CLOUDFLARE_API_TOKEN.
Read a live zone (read-only API) into a snapshot JSON on stdout. Needs CLOUDFLARE_API_TOKEN.
flareover extract example.com > zone.snapshot.jsonClassify a snapshot into an honest AUTO/ASK/MANUAL coverage report.
| Flag | Effect |
|---|---|
--md |
Emit the report as Markdown (a migration-report fragment) |
--json |
Emit the raw findings as JSON |
--html |
Emit a self-contained, shareable HTML report |
Exit codes: 0 = all AUTO · 11 = has ASK items · 10 = has MANUAL items. (Useful as a CI gate.)
Walk the ASK questions into a decisions.lock. Interactive on a TTY.
| Flag | Effect |
|---|---|
--defaults |
Accept the safe default for every ASK |
--merge <file> |
Layer answers onto an existing lock |
Estimate managed-edge tier/add-on cost vs a flat EU sovereign stack.
| Flag | Effect |
|---|---|
--vps <eur/mo> |
Override the assumed EU VPS monthly price |
Generate the target-stack artifacts (Caddyfile, caddy-waf rules, PowerDNS zone, …) for the AUTO + answered-ASK surface, plus a MIGRATION.md report.
| Flag | Effect |
|---|---|
--decisions <file> |
JSON map of ASK question id → answer (decisions.lock) |
--edge-ip <ip> |
Public IP of the new Caddy edge (proxied records repoint here) |
--ca <name> |
Default cert CA: letsencrypt (default) | actalis (EU CA) |
--stack <id> |
Target stack profile (default: caddy) |
--dns <id> |
Authoritative DNS target — see DNS Targets |
--out <dir> |
Write artifacts under <dir> (default: stdout preview) |
--validate |
Prove the generated Caddyfile + zone parse (caddy validate) |
--mesh-edge [name=]<host:port> |
WireGuard tunnel to keep an existing origin unchanged; repeat for an HA edge front |
--edge-provider <key> |
Emit a cloud-init to boot each edge on that provider (requires --mesh-edge) |
Stand the target up via APIs (DNS zone + DNSSEC, CertMate DNS-01 certs).
| Flag | Effect |
|---|---|
--snapshot <file> / --decisions <file>
|
Inputs |
--edge-ip <ip> |
The edge IP proxied records point at |
--pdns-url <url> |
Self-hosted PowerDNS API (auth: PDNS_API_KEY env) |
--dns <id> |
Managed DNS target instead of PowerDNS — see DNS Targets |
--nameservers a,b |
Delegation NS to record for the registrar step |
--certmate-url <url> |
CertMate API (auth: CERTMATE_TOKEN env) |
--certmate-dns <provider> |
DNS provider CertMate solves DNS-01 against (pre-cutover, use the source) |
--ca <name> |
letsencrypt | actalis
|
Parity gate: probe the live edge vs the staged edge (--after-addr <host:port>) and diff status / redirects / headers / body. Exit 12 on a HARD divergence.
Orchestrate the phases live up to the gated cutover. The DNS flip stays your explicit step. Exit 12 if the cutover is blocked.
Migrate object storage (R2/S3) → self-hosted MinIO (default) or managed EU S3. See Object Storage.
| Flag | Effect |
|---|---|
--dest <id> |
minio (default) | scaleway | ovh | contabo | aruba
|
--region <r> |
Provider region (EU-scoped) |
--minio-endpoint <url> |
S3 endpoint (required for --dest aruba; also the self-host MinIO endpoint) |
--extract-r2 / --extract-s3
|
Extract buckets from R2 / S3 first |
Read-only pre-flight — is every target reachable, authorized, and configured? GO/NO-GO before you provision (exit 0 only when ready).
| Flag | Effect |
|---|---|
--pdns-url <url> |
Probe the PowerDNS API + auth (PDNS_API_KEY env) |
--certmate-url <url> |
Probe CertMate health + DNS-provider config (CERTMATE_TOKEN env) |
--minio-endpoint <url> |
Probe MinIO/S3 reachability |
--spm-url <url> |
Probe secure-proxy-manager readiness |
--check-caddy |
Check the local Caddy build (caddy-waf + souin present) |
Failguards watchdog: health-watch + rollback/failover trigger.
| Flag | Effect |
|---|---|
--on-unhealthy "<cmd>" |
Command to run on an unhealthy result |
--interval <dur> |
Poll interval (e.g. 30s) |
--once |
Run a single check and exit |
List EU edge providers with their honest sovereignty tier (EU-owned vs US-operator/EU-region). Use a key with prepare --edge-provider <key>. See Sovereignty Tiers.
Print the build version.
| Code | Where | Meaning |
|---|---|---|
0 |
all | Success / clean |
1 |
all | Runtime error |
2 |
all | Usage / bad arguments |
10 |
assess, storage
|
MANUAL items present |
11 |
assess, storage
|
ASK items present (no MANUAL) |
12 |
present, execute
|
Parity divergence / cutover blocked |
flareover — deterministic migration off the orange cloud to EU-sovereign, self-hosted infrastructure · 📖 Docs · Repository · Releases · AGPL-3.0-only · © Fabrizio Salmi
Start here
Concepts
Reference
Help