Skip to content

Commands

Run sslsync help to see these commands in your terminal.

Overview

Command Connects to Changes anything? What it does
sslsync init — creates .env, certs/, .gitignore here first-time setup; never overwrites
sslsync list — — how .env was read, plus warnings for typos
sslsync targets — — the target types and their settings
sslsync validate — — checks the certificate files (what is checked)
sslsync status ports (TLS only) — NEW / OLD for every VERIFY port; no SSH or passwords needed
sslsync plan — — exactly what deploy would run, per server
sslsync find USER@HOST [DOMAIN] one server (SSH) — finds certificate paths, TLS on every port, MinIO, Kubernetes
sslsync trust servers (SSH key scan) your ~/.ssh/known_hosts shows unknown host keys and saves the ones you confirm
sslsync check servers (SSH) — phases 1–6 of how it works; logged
sslsync deploy servers (SSH) yes phases 1–11; asks you to type yes; logged
sslsync version — — prints the version

Choosing servers

Every server command accepts:

Flag Example Meaning
--only --only web-prod,db-prod only these servers
--exclude --exclude db-prod all except these
--group --group staging servers whose <NAME>_GROUP is staging

Names can be written as in .env (WEB_PROD) or in lowercase with dashes (web-prod). An unknown name is an error, so a typo never silently selects zero servers.

sslsync check --group staging
sslsync deploy --only web-staging
sslsync deploy --group prod --exclude db-prod

Other flags

Flag Default Meaning
--env FILE .env settings file; repeat to combine several (later files win)
--parallel N 4 servers processed at the same time
--retries N 3 SSH connection attempts on network errors
--yes off deploy without the confirmation prompt (for scripts)
--log-dir DIR logs where run logs are written; empty = none

Exit codes

Code Meaning
0 every selected server succeeded (or, for status, every port is NEW)
1 at least one server failed, or the configuration or certificate is invalid
2 wrong command-line usage

Use them in scripts, for example sslsync status || notify "certificate not rolled out everywhere".

Makefile shortcuts (when working from a clone)

If you cloned the repository instead of installing the binary, make builds it and wraps the same commands. make with no arguments lists them all.

make same as
make setup build + sslsync init
make check ONLY=a,b GROUP=x EXCLUDE=y sslsync check --only a,b --group x --exclude y
make deploy YES=1 sslsync deploy --yes
make staging / make prod sslsync deploy --group staging / --group prod
make renew validate → check all → deploy staging → status → pause for confirmation → deploy prod → status
make find HOST=user@host DOMAIN=… sslsync find user@host …, also saved to reports/
make trust-hosts sslsync trust
make logs / make last-log list runs / show the newest log
make test / make lint / make docker development