Airlock provides a unified airlock command with subcommands.
Export or import Airlock configurations (config.yaml, .env, logs/airlock-knobs.json) as a .zip archive.
airlock config export # creates a zip archive in the current directory
airlock config export --dir ~ # creates a zip archive in the home directory
airlock config import backup.zip # extracts into current directory
airlock config import backup.zip --dir ~ # extracts into home directoryExisting files will be safely backed up before being overwritten during an import.
Mint scoped administrative/capability tokens and perform the local FathomDB per-client erasure operation:
airlock admin mint-token --sub ops --scope admin:read --ttl 15m
airlock admin erase-client key:90abcdef --confirm key:90abcdeferase-client calls the running proxy's loopback admin API; it never opens the
database file from the CLI process. It is irreversible for the FathomDB store,
idempotent to retry after an incomplete result, and does not erase JSONL logs.
See Admin API → Erase one client's FathomDB records.
Generate config.yaml, .env, and logs/ in the current directory.
airlock init # generate in current directory
airlock init --dir /opt # generate in specified directory
airlock init --force # overwrite existing filesLaunch the proxy (headless, no TUI).
airlock start
airlock start --host 0.0.0.0 --port 8080
airlock start --config /etc/airlock/config.yamlCheck if the proxy is running.
airlock status # probe localhost:4000
airlock status --host myproxy --port 8080Exit code 0 if healthy, 1 if unreachable.
Launch the terminal dashboard.
airlock tui --start # start proxy + dashboard
airlock tui # dashboard only (connect to running proxy)
airlock tui --start --daemon # start proxy and leave it running after the TUI exits
airlock tui --host H --port P # monitor a proxy on a specific host/port
airlock tui --fleet-inventory /secure/fleet.yaml # manual read-only same-host fleet viewSee TUI Dashboard for screen details.
--fleet-inventory is isolated from the ordinary dashboard and remote Admin
mode: it cannot start or own a proxy and requires explicit target selection for
each refresh. See Admin API for the
owner-only inventory, TLS, and loopback-only deployment contract.
Run offline log analysis.
airlock analyze # last 7 days, text output
airlock analyze --days 30 # last 30 days
airlock analyze --json # machine-readable JSON
airlock analyze -o report.txt # write to fileSummarize semantic prompt-injection classifier verdicts from the request logs. See Prompt-Injection Detection for how to read the output.
airlock semantic-report # last 7 days, formatted
airlock semantic-report --days 30 # longer window
airlock semantic-report --json # machine-readable JSON
airlock semantic-report --samples 50 # more detection samples
airlock semantic-report -o report.txt # write to fileReports detections, clean, and unavailable counts per classifier, plus the
unavailable_reason breakdown — unavailability fails open, so a provider outage
otherwise looks like quiet traffic. Detection samples list request IDs and never
prompt text.
Ask the LLM-powered advisor about operational data.
airlock advise "why is model X failing?"
airlock advise --interactive
airlock advise --local-only "what should I tune?"
airlock advise --model local-llama "check health"
airlock advise --host myproxy --port 8080 "summarize errors"See Advisor for details.
Run Power-On Self-Test to validate configuration.
airlock post # full check
airlock post --skip-llm # skip provider connectivity
airlock post --skip-llm --skip-mcp # config + guardrails only
airlock post --json # machine-readable output
airlock post -v # verbose per-check details
airlock post --timeout 10 # per-check timeout (seconds; default 30)Skip flags: --skip-llm (provider connectivity), --skip-storage (log dir / S3 /
SQL), --skip-guardrails (guardrail dependencies), --skip-mcp (MCP server health).
--no-color disables ANSI output.
Manage Claude Code client-side hooks.
airlock hooks install # install pre-submit and session hooks
airlock hooks status # check hook installation statePrint shell commands to configure Claude Code to route through Airlock.
eval $(airlock dogfood) # bash/zsh (default)
airlock dogfood --shell fish | source # fish syntax
airlock dogfood --master-key "$KEY" # override the master key in the exports--shell accepts bash, zsh, or fish (default bash); --host/--port target
a specific proxy.
Install Airlock as a systemd user service so the proxy starts
automatically and is managed by systemctl --user. Copies
deploy/airlock.service to ~/.config/systemd/user/, then reloads,
enables, and starts the unit. Requires systemctl, and a .env file in
the project root (run airlock init first) for API keys.
airlock install-service # install, enable, and start
airlock install-service --dry-run # print the commands without executingManage the running service with:
systemctl --user status airlock
systemctl --user restart airlock
journalctl --user -u airlock -fIf systemd "linger" is disabled the service only runs while you are
logged in. To start it at boot: loginctl enable-linger $USER.