Skip to main content

CLI overview

@dash-ota/cli builds, signs and publishes releases, and manages them once they're out. It holds your Ed25519 private key, so run it on your machine or in CI. The backend never sees the private key, which is why a breached backend can't forge an update.

Install​

Add it to your app as a dev dependency and run it from the app root:

npm i -D @dash-ota/cli
npx dash-ota <command> [flags]

npx dash-ota runs the copy in your project's node_modules, at the version your lockfile pins. In a folder without the CLI installed, npx dash-ota downloads the dash-ota package, a small wrapper that runs the latest @dash-ota/cli. Install the CLI itself in projects: installing both packages directly gives two packages with the same dash-ota command. The CLI needs Node 20.19 or later. It includes a native zstd module (@mongodb-js/zstd); if your npm version asks you to approve install scripts, run npm install-scripts approve @mongodb-js/zstd.

Server and auth flags​

Commands that talk to the backend accept:

FlagEnvDefaultMeaning
--serverOTA_SERVERhttp://localhost:4455backend base URL
--admin-tokenOTA_ADMIN_TOKENnoneadmin credential for /admin/*
--allow-insecure—offallow plain http:// to a host other than localhost

There is no default admin token. A command that needs one fails with:

✗ admin token required: pass --admin-token or set OTA_ADMIN_TOKEN (no default — the CLI is the trust root).

Plain http:// to anything other than localhost is refused unless you pass --allow-insecure. Prefer the environment variables to the flags in shared shells and CI logs: a flag's value shows up in process listings and shell history.

The release lifecycle​

Commands​

keygen · register-key · fingerprint · bundle · publish · list · rollout · pause · rollback · native-policy · dashboard

npx dash-ota --help lists them, and npx dash-ota <command> --help prints one command's flags, which are required, and their defaults. The full reference is Commands.

Prefer a web page?​

dash-ota dashboard serves a local page for the same operations: a release table, rollout controls and a live publish log. It listens on 127.0.0.1 only and reads its environments from a config file you keep next to your app.

→ Release workflow · Environments