Machines read secrets with their own keys, as described in CLI. To manage a Burrow from the terminal, sign in as yourself and open a session. You can do what your role on the Burrow allows, the same as in the browser.
Sign in#
ratel login https://burrow.example.comYour browser opens on RatelKey's sign-in. Approve there and the terminal is signed in. The sign-in appears on the Burrow's Sessions page as the CLI, with this machine's name.
When the Burrow uses its own certificate, ratel login shows its key fingerprint to check against Settings, Network. --fingerprint <fingerprint> passes it without asking. If your browser is on another device, approve there and paste the address it ends up on into the terminal; --no-browser skips opening one on this machine.
Open a session#
ratel interactiveThis signs you in first if you need to, then opens a prompt on the Burrow. Type a command and press Enter. Tab completes commands, projects, environments and secret names, and the up arrow brings back earlier commands. help lists every command, and help secret shows everything one of them does. A plural works too: secrets is secret.
Move into a project or environment with use, and commands act there until you move again. use .. goes up a level, use / to the top, and use - back to where you were. Any command that acts on an environment also takes --env <project/env> to act somewhere else once.
use myapp/prod
secrets
secret show DATABASE_URL
secret set API_KEY --env myapp/stagingDeleting asks you to confirm first. A change that needs you to confirm it's you opens your browser to do that, then carries on.
Command | What it does |
|---|---|
| Move into a project or environment. Alone, says where you are. |
| Who you're signed in as, and your role. |
| List the commands, or everything one command does. |
| Clear the screen. |
| Sign out of the Burrow and leave. |
| Leave and stay signed in. Ctrl+D does the same. |
Projects and environments#
Command | What it does |
|---|---|
| List the projects. |
| Create a project with dev, staging and prod environments. |
| Rename a project. |
| Delete a project and everything in it. |
| List a project's environments. |
| Create an environment in the current project, at that stage. Give project/name to create it elsewhere. |
| Rename an environment. |
| Delete an environment and every value in it. |
Secrets#
Secrets are named within the environment you're in. A structured secret's field is NAME.field, for example DATABASE.host.
Command | What it does |
|---|---|
| List the secrets in an environment, names only. |
| Show a value. The read is recorded in the audit log. |
| Copy a value to the clipboard without showing it. The clipboard is cleared after 30 seconds. |
| A secret's type, fields, version and history, without its value. |
| Set a value, creating the secret if it's new. You type the value at a hidden prompt. |
| Create a secret, refused if the name is already taken in the project. |
| List a secret's versions. |
| Make an earlier version current again, as a new version. |
| Rename a secret in every environment of its project. |
| Delete a secret from this environment. |
| Arm a canary. |
| Disarm a canary. |
--version <N> shows or copies an earlier version. --file <path> takes the value from a file, for certificates and keys, and --type <type> sets a new secret's type. secret create --structured makes a secret with named fields and asks you for each one. secret create --canary makes a canary: a machine that reads it while it's armed is disabled.
secret create DATABASE --structured
secret show DATABASE.host
secret set TLS_CERT --file ./cert.pem
secret revert API_KEY v3Share links#
Command | What it does |
|---|---|
| List a secret's live share links. |
| Make a share link to a secret. The link is shown once. |
| Revoke a share link. |
A link opens once and lives 24 hours unless you say otherwise: --views <N> and --expires <30m|12h|7d>. --passphrase also requires a passphrase, which you send separately, and --members-only opens it only for this Burrow's members.
share create API_KEY --views 2 --expires 1hMachine access#
Command | What it does |
|---|---|
| The machines that can read a project, and which stages. |
| Let a machine read these stages of a project, in addition to what it has. |
| Take a machine's access to a project away, or only some stages. |
access grant web-01 myapp:prod,staging
access revoke web-01 myapp:devMachines#
Command | What it does |
|---|---|
| List the live machines. |
| Make a one-time code that enrolls a machine. |
| Add a machine that signs in with GitHub Actions OIDC. You're asked for its details. |
| Approve a machine waiting for approval. |
| Stop a machine's access. It keeps its identity and grants. |
| Restore a disabled machine's access. |
| Rename a machine. |
| Remove a machine for good. |
| List unused one-time codes. |
| Show a code again. |
| Cancel a code. |
--connection <encrypted|pinned|system> on machine add, invite show and token create chooses how the machine checks the Burrow's connection, as described in CLI. The default is encrypted.
Machine tokens#
Command | What it does |
|---|---|
| List reusable machine tokens. |
| Create a token that enrolls many machines. |
| Show a token's enrollment code again. |
| Stop a token enrolling machines. |
--grant <project>:<stage,…> sets what its machines may read; repeat it for more projects. A token enrolls machines for 7 days (--expires) and each machine lives 1 hour (--machine-lifetime). --source <cidr>, --hostname <regex> and --name-pattern <regex> limit which machines can enroll, and --description notes what uses it.
token create ci --grant myapp:dev,staging --machine-lifetime 2hIP allowlist#
Command | What it does |
|---|---|
| The addresses machines may connect from, and whether that's enforced. |
| Allow an address or range. |
| Remove one. |
| Enforce the allowlist. |
| Stop enforcing it. |
Members and roles#
Command | What it does |
|---|---|
| List the members and invitations. |
| Invite someone by email. |
| Change a member's role. |
| Cut a member's access. They keep their role. |
| Restore a member's access. |
| Remove a member, or withdraw an invitation. |
| List the roles. |
| What a role can do. |
| Create a role with these capabilities. |
| Add capabilities to a role. |
| Take capabilities away from a role. |
| Rename a role. |
| Delete a role. |
| The devices signed in to the Burrow, numbered. |
| Sign a device out. To sign this one out, use |
A capability is an area and what may be done there: <area>.read, <area>.write, <area>.delete, or <area>.* for all three. The areas are secret, machine, token, audit, webhook, note, share, member, session, console, burrow_config, display, remote_access, network, security, backup and encryption.
member invite [email protected] --role Developer
role create Deployer secret.read machine.*
role grant Deployer audit.readAudit log#
Command | What it does |
|---|---|
| The latest events, newest first. |
| The event codes recorded, and how often. |
| Everyone and everything that has done something. |
| Save the matching events to a file only you can read. |
audit and audit export take the same filters: --search <text>, --actor <name> (repeat for several), --type <type>, --severity <level>, --event <code>, --ip <address>, --since <24h|7d>, and --from / --to <YYYY-MM-DD>. audit shows 20 events a page; --limit shows up to 100 and --page goes back further.
audit --severity critical --since 24h
audit --event secret.read --actor web-01
audit export --since 30d --format jsonWebhooks#
Command | What it does |
|---|---|
| List the webhooks. |
| Every event a webhook can send. |
| Create a webhook. Its signing secret is shown once. |
| Change where it sends ( |
| Start sending. |
| Stop sending. |
| Send a test event. |
| Show its signing secret. |
| Delete a webhook. |
--event takes a code (secret.read), a prefix (machine.*) or *, and can be repeated. --provider chooses how the message is formatted and signed; the default is generic.
webhook create alerts https://hooks.example.com/x --event 'secret.canary.*'Notes#
Command | What it does |
|---|---|
| Show the Burrow's note. 1 is the newest; older ones by number. |
| Post a new note. Type |
| Edit a note. |
| Delete a note. |
Run commands from a script#
ratel -p runs one of the commands above as you and exits:
ratel -p "secrets myapp/prod"
echo -n "$NEW_KEY" | ratel -p "secret set myapp/prod/API_KEY"
ratel -p "project delete old-app" --yes
ratel -p "audit --severity critical --since 24h" --jsonA value is read from standard input, --yes answers a confirmation, and --json prints what the Burrow answered. ratel -p help lists the commands. It exits with status 0 when done, 1 when refused or failed, 2 when used wrongly or a confirmation was needed, and 3 when you aren't signed in.
Several Burrows#
You can be signed in to several Burrows at once. ratel login list shows each one and whether its sign-in is still active (--json for scripts). ratel interactive asks which one to open, and --burrow <name> picks one directly:
ratel interactive --burrow my-burrow
ratel -p "secrets myapp/prod" --burrow my-burrowSign out#
ratel logoutThis ends the sign-in on the Burrow and removes it from this machine; logout inside a session does the same. Add --burrow to pick which one. Ending the CLI's session on the Burrow's Sessions page signs it out too.
Sign-in commands#
Command | What it does |
|---|---|
| Sign in to a Burrow as yourself, through your browser. |
| List the Burrows you're signed in to, each checked just now. |
| Open a session on a Burrow, signing in first if you need to. |
| Run one session command from a script. |
| List the Burrow's members and invitations. |
| Show the machine identity and who you're signed in as. |
| Sign out of a Burrow. |