Skip to content

Latest commit

 

History

History
190 lines (136 loc) · 6.04 KB

File metadata and controls

190 lines (136 loc) · 6.04 KB

CLI Reference

Airlock provides a unified airlock command with subcommands.

Commands

airlock config

Export or import Airlock configurations (config.yaml, .env, logs/airlock-knobs.json) as a .zip archive.

airlock config export          # creates a zip archive in the current directory
airlock config export --dir ~  # creates a zip archive in the home directory

airlock config import backup.zip          # extracts into current directory
airlock config import backup.zip --dir ~  # extracts into home directory

Existing files will be safely backed up before being overwritten during an import.

airlock admin

Mint scoped administrative/capability tokens and perform the local FathomDB per-client erasure operation:

airlock admin mint-token --sub ops --scope admin:read --ttl 15m
airlock admin erase-client key:90abcdef --confirm key:90abcdef

erase-client calls the running proxy's loopback admin API; it never opens the database file from the CLI process. It is irreversible for the FathomDB store, idempotent to retry after an incomplete result, and does not erase JSONL logs. See Admin API → Erase one client's FathomDB records.

airlock init

Generate config.yaml, .env, and logs/ in the current directory.

airlock init              # generate in current directory
airlock init --dir /opt   # generate in specified directory
airlock init --force      # overwrite existing files

airlock start

Launch the proxy (headless, no TUI).

airlock start
airlock start --host 0.0.0.0 --port 8080
airlock start --config /etc/airlock/config.yaml

airlock status

Check if the proxy is running.

airlock status                         # probe localhost:4000
airlock status --host myproxy --port 8080

Exit code 0 if healthy, 1 if unreachable.

airlock tui

Launch the terminal dashboard.

airlock tui --start            # start proxy + dashboard
airlock tui                    # dashboard only (connect to running proxy)
airlock tui --start --daemon   # start proxy and leave it running after the TUI exits
airlock tui --host H --port P  # monitor a proxy on a specific host/port
airlock tui --fleet-inventory /secure/fleet.yaml  # manual read-only same-host fleet view

See TUI Dashboard for screen details.

--fleet-inventory is isolated from the ordinary dashboard and remote Admin mode: it cannot start or own a proxy and requires explicit target selection for each refresh. See Admin API for the owner-only inventory, TLS, and loopback-only deployment contract.

airlock analyze

Run offline log analysis.

airlock analyze                  # last 7 days, text output
airlock analyze --days 30        # last 30 days
airlock analyze --json           # machine-readable JSON
airlock analyze -o report.txt    # write to file

airlock semantic-report

Summarize semantic prompt-injection classifier verdicts from the request logs. See Prompt-Injection Detection for how to read the output.

airlock semantic-report                  # last 7 days, formatted
airlock semantic-report --days 30        # longer window
airlock semantic-report --json           # machine-readable JSON
airlock semantic-report --samples 50     # more detection samples
airlock semantic-report -o report.txt    # write to file

Reports detections, clean, and unavailable counts per classifier, plus the unavailable_reason breakdown — unavailability fails open, so a provider outage otherwise looks like quiet traffic. Detection samples list request IDs and never prompt text.

airlock advise

Ask the LLM-powered advisor about operational data.

airlock advise "why is model X failing?"
airlock advise --interactive
airlock advise --local-only "what should I tune?"
airlock advise --model local-llama "check health"
airlock advise --host myproxy --port 8080 "summarize errors"

See Advisor for details.

airlock post

Run Power-On Self-Test to validate configuration.

airlock post                          # full check
airlock post --skip-llm               # skip provider connectivity
airlock post --skip-llm --skip-mcp    # config + guardrails only
airlock post --json                   # machine-readable output
airlock post -v                       # verbose per-check details
airlock post --timeout 10             # per-check timeout (seconds; default 30)

Skip flags: --skip-llm (provider connectivity), --skip-storage (log dir / S3 / SQL), --skip-guardrails (guardrail dependencies), --skip-mcp (MCP server health). --no-color disables ANSI output.

airlock hooks

Manage Claude Code client-side hooks.

airlock hooks install    # install pre-submit and session hooks
airlock hooks status     # check hook installation state

airlock dogfood

Print shell commands to configure Claude Code to route through Airlock.

eval $(airlock dogfood)                  # bash/zsh (default)
airlock dogfood --shell fish | source    # fish syntax
airlock dogfood --master-key "$KEY"      # override the master key in the exports

--shell accepts bash, zsh, or fish (default bash); --host/--port target a specific proxy.

airlock install-service

Install Airlock as a systemd user service so the proxy starts automatically and is managed by systemctl --user. Copies deploy/airlock.service to ~/.config/systemd/user/, then reloads, enables, and starts the unit. Requires systemctl, and a .env file in the project root (run airlock init first) for API keys.

airlock install-service            # install, enable, and start
airlock install-service --dry-run  # print the commands without executing

Manage the running service with:

systemctl --user status airlock
systemctl --user restart airlock
journalctl --user -u airlock -f

If systemd "linger" is disabled the service only runs while you are logged in. To start it at boot: loginctl enable-linger $USER.