Cheatsheet
Todos os grupos de comandos e subcomandos, num só sítio. Gerado do --help real do binário.
All command groups and subcommands, in one place. Generated from the real --help of the binary.
Tarefas comunsCommon tasks
delonix container run -d --name web -p 8080:80 nginxdelonix container run --rm -it alpine shdelonix network create backend
delonix container run -d --net backend -p 8443:443 caddydelonix container update web --publish-add 9090:80delonix net ingress allow db tcp/5432 --from 10.219.0.0/16
delonix net ingress policy db denydelonix net egress net backend allowlist --to 10.0.0.0/8sudo delonix net flow --watchdelonix volume create media --driver nfs --opt server=10.0.0.5 --opt share=/mnt/pool/mediaprintf 'password=s3nha' | delonix secret create db-pass --from-env-file -delonix container run -d --name web --expose 80 nginx
delonix net tunnel expose 8080tunnel/tunnel-8080: running — https://oxipg-197-148-40-67.free.pinggy.netdelonix volume create nas --driver nfs --opt server=10.0.0.5 --opt share=/pool/data
delonix volume create tenant-a --parent nas --quota 5Gdelonix vm create node1 --disk base.qcow2 --ssh-key @~/.ssh/id_ed25519.pubdelonix cluster kubeadm --name lab --control-plane 1 --workers 2delonix stack apply -f delonix-manifest.yamldelonix system boot enabledelonix system pruneTodos os gruposAll groups
Cargas de trabalhoWorkloads
delonix container
| ComandoCommand | O que fazWhat it does |
|---|---|
container kill | Send a signal to one or more containers (default SIGKILL) |
container pause | Suspend a container's processes (cgroup v2 freezer) |
container restart | Stop then start one or more containers |
container rm | Remove one or more containers |
container run | Run a container from an image (pulls it if missing) |
container start | (Re)start stopped/crashed containers. Always detached |
container stop | Stop one or more containers (SIGTERM, then SIGKILL) |
container unpause | Resume a container suspended with `pause` |
container wait | Block until one or more containers exit, then print their exit code (one per line, in the order given) |
container describe | Human-readable detail of one or more containers, `kubectl describe`-style |
container diff | Files changed relative to the image: `A` = created/changed, `D` = deleted |
container healthcheck | Run the image's `HEALTHCHECK` inside the container. Exits with 1 if `unhealthy` — usable in a script/CI |
container inspect | Show the full spec of one or more containers (Store JSON) |
container logs | Show the logs (detached containers) |
container port | Published ports of a container (`hostPort/proto -> containerPort`) |
container ps | List containers [alias: ls] |
container stats | Resource usage (CPU/memory/PIDs) of the running containers |
container top | Processes running inside a container (read from `cgroup.procs`) |
container attach | Re-attach to a running container's output stream (output only) |
container commit | Create an image from a container's CURRENT rootfs state (whatever was written inside becomes a new layer) |
container cp | Copy files between the host and a container |
container exec | Execute a command inside a running container |
container rename | Give a container a new name |
container update | **Reconfigure a RUNNING container without stopping it** — ports, volumes, and bandwidth cap |
container apply | Apply the `kind: Container` documents of a manifest (idempotent by name) |
container init | Initialize a project with a Delonixfile + manifest |
container prune | Remove every stopped container and the rootfs debris they left behind |
delonix pod
| ComandoCommand | O que fazWhat it does |
|---|---|
pod create | Create a pod (N containers sharing a netns) from a manifest (`kind: Pod`) |
pod logs | Logs of a pod's container (defaults to the first member) |
pod attach | Re-attach to a pod member's output stream (output only) |
pod cp | Copy files between the host and one member of a pod |
pod exec | Execute a command inside one member of a pod (defaults to the first) |
pod port-forward | Forward one or more host ports to ports inside the pod's netns |
delonix vm
| ComandoCommand | O que fazWhat it does |
|---|---|
vm cloud-init | Change a STOPPED VM's cloud-init — hostname, user, SSH keys — for its next boot |
vm create | Create (or auto-recover) a VM |
vm destroy | Destroy VMs and everything they own — provider-side VM, disks, snapshots |
vm migrate | Move a VM to another `delonix` host — real downtime, no shared storage |
vm move | Move a VM to another node of its cluster — same VM, same record |
vm pause | Suspend a running VM's vCPUs — guest memory stays intact, unlike `stop` |
vm resize | Change a STOPPED VM's vCPUs and/or memory for its next boot |
vm restart | Stop (if running) then start — always a real reboot, unlike `start`. Same recovered-fields limits as `start` |
vm start | Start an existing, stopped VM — idempotent (already running = no-op) |
vm stop | Stop the VM (preserves disk, record and snapshots) |
vm unpause | Resume a VM suspended with `pause`. Refuses a VM that is not paused |
vm ls | List the VMs |
vm console | Attach to the VM's serial console (interactive terminal) |
vm ssh | SSH into a VM by NAME, or straight to an address |
vm vnc | Print the VNC address of a graphical VM (created with `--vnc`, libvirt) |
vm default-backend | Get or set the default VM backend |
vm bridge | EXPERIMENTAL (root): give a libvirt VM DIRECT IP reachability to a container SDN network |
vm reach | Which published ports a VM can actually reach, and how to fix the rest |
vm unbridge | Tear down a `vm bridge` (dry-run without `--apply`) |
vm build | Build a VM image (qcow2) from a `vm.yaml`, a `VMfile`, or the golden recipe |
vm convert | Convert a VM disk to the format another ecosystem imports |
vm ls-remote | List the tags available in a remote OCI repository |
vm pull | Pull a golden VM image from an OCI registry |
vm push | Push a local golden VM image to an OCI registry (`vm push <name> <target>`) |
vm apply | Apply the `kind: VirtualMachine` documents of a manifest |
vm init | Bootstrap a project with a VM manifest |
vm prune | Reclaim the VM state directory: everything in it no VM record accounts for |
vm snapshot | Point-in-time snapshots of a VM (checkpoints in the VM's own disk) |
delonix systemcontainer
| ComandoCommand | O que fazWhat it does |
|---|---|
systemcontainer clone | A full copy of a system container under a new name, registered here |
systemcontainer move | Move a system container to another node of its provider's cluster |
systemcontainer snapshot | Snapshots of a system container's root volume |
delonix workload
| ComandoCommand | O que fazWhat it does |
|---|---|
workload rm | Remove a workload by name |
workload stop | Stop a workload by name (routed to the owning backend) |
workload describe | Describe a workload by name (routed to the owning backend, kubectl-style) |
workload ls | List all workloads — containers AND VMs — in one table (or `-o json`) |
ArtefactosArtifacts
delonix image
| ComandoCommand | O que fazWhat it does |
|---|---|
image pull | Pull an image from a registry |
image push | Publish a local image to an OCI registry |
image remove | Remove a local image |
image describe | Human-readable detail of one or more images, `kubectl describe`-style |
image history | Layers of an image (digest + size), from base to top |
image ls | List local images |
image sbom | The image's SBOM as an SPDX 2.3 document, not the table `scan --sbom` prints |
image scan | SBOM + CVE scan of an image |
image verify | Verify the cosign signature of a local image against a public key |
image login | Authenticate to an OCI registry |
image logout | Remove the stored credentials of a registry |
image sign | Sign an image with cosign-compatible ECDSA-P256, publishing the signature next to it in the registry |
image tag | Give another name/tag to a local image (copies nothing — it's just a new name for the same content) |
image export | Export an OCI runtime bundle (rootfs + config.json) for `runc`/`crun` |
image load | Load an image from an archive (the counterpart of `save`) |
image save | Save an image to a portable archive (`docker save`'s counterpart) |
image apply | Apply the `kind: Image` documents of a manifest |
image prune | Remove unused images and the CAS blobs nobody references any more |
image vm | Golden VM images (`<root>/vm-images/`): ls/pull/push/build/rm/describe |
delonix build
Constrói uma imagem a partir de um Dockerfile ou Delonixfile.
Builds an image from a Dockerfile or Delonixfile.
delonix secret
| ComandoCommand | O que fazWhat it does |
|---|---|
secret create | Create a secret from literals and/or a `.env` file |
secret rm | Remove a secret |
secret inspect | Show the keys of a secret (values redacted, unless `--reveal`) |
secret ls | List the secrets (name + number of keys; values NEVER shown) |
secret set | Set/update keys in a secret (creates it if it does not exist) |
secret unset | Remove a key from a secret (or the whole secret with `--all`) |
secret apply | Apply the `kind: Secret` documents from a manifest |
secret rotate | Rotate one key's VALUE to a fresh random one |
secret rotate-key | Rotate the host master key: re-encrypt ALL secrets with a new key. The values are preserved |
ArmazenamentoStorage
delonix volume
| ComandoCommand | O que fazWhat it does |
|---|---|
volume create | Create a named volume |
volume rm | Remove a volume |
volume describe | Readable detail of one or more volumes, `kubectl describe` style |
volume inspect | Details of a volume (includes real on-disk usage) |
volume ls | List the volumes |
volume apply | Apply the `kind: Volume` documents from a manifest (idempotent by name) |
volume prune | DESTROY every local volume that nothing references |
volume snapshot | Point-in-time snapshots of a volume (tar.gz under the volume; safe in rootless) |
RedeNetworking
delonix network
| ComandoCommand | O que fazWhat it does |
|---|---|
network connect | Connect a RUNNING container to an additional network, hot |
network create | Create a network |
network disconnect | Disconnect a container from an additional network, hot |
network rm | Remove a network |
network route | Open a DIRECTED path from one network to another (ADR-0013 tier B) |
network vlan | 802.1Q VLAN on a physical NIC — **the one command here that needs root** |
network describe | Readable detail of one or more networks, `kubectl describe` style |
network diagnose | The LIVE state of this node's network, and what disagrees with it |
network inspect | Detail of a network |
network ls | List the networks |
network apply | Apply the `kind: Network` documents of a manifest (idempotent by name) |
network ipam | The IP lease registry — the `/16` anti-collision allocator |
network node | WireGuard identity of THIS node, for the encrypted overlay between nodes |
delonix net
| ComandoCommand | O que fazWhat it does |
|---|---|
net capture | Raw packet capture on a container's SDN interface, via the host's own `tcpdump` |
net flow | Live per-container traffic (eBPF datapath; degrades to veth counters) |
net egress | OUTBOUND firewall (L4 rules + per-network egress policy) for a container |
net ingress | INBOUND firewall (L4 rules + DNAT publishes) for a container on the SDN |
net l4guard | Ingress-wide L4 DDoS guard (per-source connection rate + concurrent cap) |
net httproute | Embedded L7/HTTP reverse-proxy (`kind: HTTPRoute`): apply/rm |
net tunnel | Expose a local port to the public internet (`kind: Gateway`) |
net netns | Low-level management of the rootless ingress infra (up/status/attach/publish/firewall) |
delonix net netns
| ComandoCommand | O que fazWhat it does |
|---|---|
net netns down | Force tear-down of the ingress infra (kills slirp + holder, frees the netns) |
net netns gc | Reclaim infra left behind by state roots that no longer exist |
net netns up | Bring the ingress infra up (idempotent): holder netns + delonix0 + single slirp |
net netns status | Show the ingress infra status (holder/slirp pids, bridge, refcount) |
net netns exec | Run a command inside an attached netns (exercises the runtime join path) |
net netns attach | Attach a netns to delonix0 via veth (the holder is the netns/veth factory) |
net netns detach | Detach (and destroy) a previously attached netns |
net netns firewall | Apply (or clear) a container's parameterizable firewall AT THE INGRESS |
net netns publish | Publish a port through the ingress (add_hostfwd + DNAT) to a container |
net netns unpublish | Unpublish a host port from the ingress |
delonix net flow
Tráfego por-container ao vivo — datapath eBPF (degrada para contadores veth).
Live per-container traffic — eBPF datapath (degrades to veth counters).
delonix net capture
Captura de pacotes crua na interface SDN de um container — o tcpdump do próprio host.
Raw packet capture on a container's SDN interface — the host's own tcpdump.
delonix net l4guard
| ComandoCommand | O que fazWhat it does |
|---|---|
net l4guard status | Show whether the guard is active, with its drop counters |
net l4guard clear | Turn the guard off |
net l4guard set | Turn the guard on (or update it): new conns/s and concurrent conns, per source IP |
delonix net ingress
| ComandoCommand | O que fazWhat it does |
|---|---|
net ingress ls | Show the inbound firewall (policy + rules) and published ports |
net ingress allow | Allow inbound traffic to a container: `[proto/]port` from an optional CIDR |
net ingress deny | Deny inbound traffic to a container (same shape as `allow`) |
net ingress policy | Set the default inbound policy when no rule matches |
net ingress publish | Publish a host port to the container (DNAT through the ingress) |
net ingress unpublish | Remove a published host port |
net ingress clear | Remove all inbound rules (keeps published ports) |
net ingress rm | Remove inbound rule(s) matching `[proto/]port` (all protos if none given) |
delonix net egress
| ComandoCommand | O que fazWhat it does |
|---|---|
net egress ls | Show the outbound firewall (policy + rules) |
net egress show | Show a NETWORK's egress policy |
net egress allow | Allow outbound traffic from a container: `[proto/]port` to an optional CIDR |
net egress deny | Deny outbound traffic from a container (same shape as `allow`) |
net egress host | Allow a network's egress to a HOSTNAME (and `*.hostname`). Repeatable |
net egress net | Govern a whole network's egress to the Internet |
net egress policy | Set the default outbound policy when no rule matches |
net egress clear | Remove all outbound rules |
net egress rm | Remove outbound rule(s) matching `[proto/]port` (all protos if none given) |
delonix net httproute
| ComandoCommand | O que fazWhat it does |
|---|---|
net httproute apply | Apply the HTTPRoutes of a manifest (brings up/reloads the proxy) |
net httproute rm | Stop the proxy and unpublish the ports (teardown) |
delonix net tunnel
| ComandoCommand | O que fazWhat it does |
|---|---|
net tunnel expose | One-shot expose of a local port, no manifest needed |
net tunnel apply | Apply the `kind: Gateway` documents of a manifest (idempotent) |
delonix hosts
| ComandoCommand | O que fazWhat it does |
|---|---|
hosts sync | Publish the service names of exposed containers in `/etc/hosts` and keep them current |
ClustersClusters
delonix cluster
| ComandoCommand | O que fazWhat it does |
|---|---|
cluster create | Create a local Kubernetes cluster **without a manifest and without Docker** |
cluster destroy | Remove a kind-mode cluster entirely — nodes, network, kubeconfig, `~/.kube/config` entry |
cluster kubeadm | Provision VMs (golden VM image) + `kubeadm` bootstrap |
cluster start | Start every node of a stopped kind-mode cluster back up |
cluster stop | Stop every node of a kind-mode cluster at once — no rebuild, no state lost |
cluster upgrade | Upgrade a `mode: ssh` cluster to a newer Kubernetes version, kubeadm-style |
cluster init | Initialize a project with the cluster manifests (kind/vm/ssh) |
cluster drain | Cordon a node and evict its pods |
cluster health | Is the control-plane answering, and is every node `Ready`? |
cluster kubeconfig | Print a cluster's kubeconfig from the local cache (no live SSH) |
cluster load | Load local images into a kind-mode cluster's nodes, **without a registry** |
cluster ls | List this host's clusters — kind-mode AND VM-based |
cluster uncordon | Mark a drained node schedulable again |
cluster apply | Apply the `kind: KubernetesCluster` document(s) of a manifest |
cluster kube | Generate a Kubernetes manifest from a container/pod already running locally |
cluster prune | Reclaim the state of clusters that have no nodes left |
delonix cluster kube
| ComandoCommand | O que fazWhat it does |
|---|---|
cluster kube generate | Generates a `kind: Pod` from a container (or from every member of a pod) and prints it to stdout |
DeclarativoDeclarative
delonix explain
Referência de campos de um Kind, gerada do próprio código — `kubectl explain` style.
Field reference for a Kind, generated from the code — `kubectl explain` style.
delonix api-resources
Todos os Kinds que este motor serve: plural, nomes curtos, apiVersion e forma.
Every Kind this engine serves: plural, shortnames, apiVersion and form.
delonix apply
Converge um manifesto — a grafia canónica de `stack apply`.
Converge a manifest — the canonical spelling of `stack apply`.
delonix plan
Mostra o que um apply mudaria, e não muda nada.
Show what an apply would change, and change nothing.
delonix wait
Bloqueia até os recursos do manifesto estarem prontos.
Block until the manifest's resources are ready.
delonix manifest
| ComandoCommand | O que fazWhat it does |
|---|---|
manifest render | Print the manifest as the engine will read it, with defaults filled in |
manifest schema | The JSON Schema, generated from the Rust types (ADR-0007) |
manifest validate | Check a manifest against the schema, the references and the graph |
delonix diff
O manifesto, o last-applied e o observado de UM recurso, lado a lado.
The manifest, last-applied, and observed values for one resource — side by side.
delonix drift
O que a MÁQUINA mudou desde o último apply — a stack inteira.
What the MACHINE changed since the last apply — the whole stack.
delonix migrate
| ComandoCommand | O que fazWhat it does |
|---|---|
migrate assess | Score a `docker-compose.yml` against what this engine serves |
delonix stack
| ComandoCommand | O que fazWhat it does |
|---|---|
stack apply | Applies all the manifest Kinds (Network → Volume → Image → Vm → Container) |
stack destroy | Removes everything this stack owns (by the `delonix.io/stack` label) |
stack wait | Blocks until every declared resource is present and, where it has one, healthy |
stack init | Initializes a COMPLETE project: Delonixfile + manifest + cluster + README |
stack describe | Stack detail in `kubectl describe` style |
stack history | What this stack applied, and when (ADR-0019) |
stack ls | List the structure the manifest composes, and whether each resource exists |
stack plan | Shows what an `apply` WOULD change, without changing anything |
stack validate | Validates the manifest WITHOUT touching anything (dry-run) |
stack rollback | Re-apply a recorded revision (ADR-0019) |
stack prune | Remove what this stack owns and the manifest no longer declares |
delonix compose
| ComandoCommand | O que fazWhat it does |
|---|---|
compose down | Removes every container this project's `up` created |
compose up | Creates/starts every service |
compose config | Validates and prints the resolved project, without creating anything (`docker compose config` equivalent) |
compose logs | Logs of one service (default: every service, one after another) |
compose ps | Containers of this project (derived from labels) |
RecursosResources
delonix get
Lista recursos de um Kind — a forma genérica de dez `ls`s.
List resources of a Kind — the generic form of ten `ls` commands.
delonix describe
Detalhe de um recurso, em blocos — a forma genérica de dez `describe`s.
Detail of one resource, in blocks — the generic form of ten `describe`s.
delonix delete
Remove recursos por Kind e nome — a forma genérica de dez `rm`s.
Remove resources by Kind and name — the generic form of ten `rm`s.
ServirServe
delonix compatibility
| ComandoCommand | O que fazWhat it does |
|---|---|
compatibility compose | Compose Specification coverage, key by key |
compatibility docker | Docker Engine API coverage |
delonix serve
| ComandoCommand | O que fazWhat it does |
|---|---|
serve api | Serve the MANAGEMENT API (HTTP+JSON) on a unix socket |
serve cri | Serve the CRI endpoint (`runtime.v1`) on a unix socket — replaces containerd/CRI-O for a kubelet |
serve docker-api | Serve a slice of the Docker Engine API on a unix socket |
serve node-api | Serve the NODE API (gRPC + HTTP/JSON of `delonix.node.v1`) on a unix socket |
delonix serve cri
Serve o endpoint CRI (runtime.v1) num socket unix.
Serves the CRI endpoint (runtime.v1) on a unix socket.
delonix serve api
A API de gestão LOCAL (HTTP+JSON) num socket unix, para um control-plane externo.
The LOCAL management API (HTTP+JSON) on a unix socket, for an external control plane.
delonix serve docker-api
Fatia da API Docker Engine, num socket unix — ciclo de vida completo de um container, não só leitura.
A slice of the Docker Engine API, on a unix socket — full container lifecycle, not just reads.
delonix serve node-api
O contrato de nó (gRPC + HTTP/JSON do delonix.node.v1) num socket unix.
The node contract (gRPC + HTTP/JSON of delonix.node.v1) on a unix socket.
delonix mcp
| ComandoCommand | O que fazWhat it does |
|---|---|
mcp capabilities | Print the tool risk table (name, risk level, whether `confirm` is required) |
mcp doctor | Check that this node is ready to serve MCP tool calls |
mcp serve | Start the MCP server |
MotorEngine
delonix init
Começa o projecto CERTO para este directório — detecta, explica-se, e delega.
Start the RIGHT project for this directory — detect, explain, dispatch.
delonix version
Imprime a versão (o mesmo texto que `--version`).
Print the version (same output as `--version`).
delonix policy
| ComandoCommand | O que fazWhat it does |
|---|---|
policy unset | Remove the node's security ceiling (`<root>/policy.json`) |
delonix config
| ComandoCommand | O que fazWhat it does |
|---|---|
config get | Read one key, or every key set (with no argument) |
config set | Set a key. Refuses an unknown key or an invalid value by name — never accepted-and-ignored |
config unset | Remove a key — the command that reads it falls back to its built-in default again |
delonix system
| ComandoCommand | O que fazWhat it does |
|---|---|
system df | Disk usage by area (images, containers, volumes, VM images) |
system doctor | Check the HOST prerequisites this engine needs, and say how to fix each |
system events | Engine events (create/start/die/remove/…), from oldest to most recent |
system features | What each capability promises, and the EVIDENCE for it |
system info | Engine state: rootless?, cgroup delegation, network infra, counts |
system metrics | The raw counters: containers/VMs/networks/volumes/images, memory, network, disk |
system namespace | Isolation namespaces: ls/describe — a namespace exists while something is in it, so there is no create/rm |
system resources | How much this host has, how much the engine can actually enforce, and what is under pressure right now |
system regulate | Give the contended CPU back to the workloads that are waiting for it |
system setup | Diagnose — and, with `--delegate`, fix — cgroup delegation |
system snapshot | Point-in-time capture of this node's whole state — `create` saves it into one archive, `restore` puts it back |
system virt | Host virtualization: hypervisor, KVM, virtio — and what there is to tune |
system prune | Reclaim space taken by what nothing uses any more |
system thermal | Thermal governor for Delonix's CPU budget. Runs continuously (see `--once`) |
system monitor | Active network connections per container (via conntrack) |
system boot | Boot persistence: systemd units so containers come back up after a reboot |
delonix system boot
| ComandoCommand | O que fazWhat it does |
|---|---|
system boot status | Show boot-persistence status (installed units + mode) |
system boot disable | Disable + remove the generated boot units |
system boot enable | Install + enable systemd units so containers come back after a reboot |
delonix system namespace
| ComandoCommand | O que fazWhat it does |
|---|---|
system namespace describe | What is inside ONE namespace, by Kind, `kubectl describe` style |
system namespace ls | List the isolation namespaces IN USE, with what is in each |
delonix backup
| ComandoCommand | O que fazWhat it does |
|---|---|
backup inspect | What an archive holds, without unpacking it |
backup ls | The archives in a directory |
backup create | Write an archive of one resource, now |
backup remove | Delete an archive |
backup restore | Put a resource back from an archive |
backup schedule | Keep archiving this resource on a systemd user timer |
delonix provider
| ComandoCommand | O que fazWhat it does |
|---|---|
provider config | The node's providers file (ADR-0054): what it says, and whether it is valid |
provider describe | Every capability of ONE provider, with its state and the reason |
provider ls | Every provider this build knows, probed on this host |
provider matrix | The declared matrix, host-independent, as Markdown |
delonix dashboard
Dashboard de resumo/KPIs (TUI estilo htop) — RAM/rede/disco, uptime por-container, JSON e Prometheus.
Summary/KPI dashboard (htop-style TUI) — RAM/network/disk, per-container uptime, JSON and Prometheus.
delonix completion
| ComandoCommand | O que fazWhat it does |
|---|---|
completion editor | VMfile syntax highlighting for an editor (vim/vscode) |
completion shell | Print the shell autocompletion script (bash/zsh/fish/...) |
delonix man
Páginas de manual em roff, geradas a partir deste binário — uma por comando.
Manual pages in roff, generated from this binary — one per command.
GlobalGlobal
--l18n en|pt — idioma da saída (EN por omissão; pt para pt_AO). $DELONIX_ROOT — raiz do estado. delonix completion shell <shell> — autocompletion.
--l18n en|pt — output language (EN by default; pt for pt_AO). $DELONIX_ROOT — the state root. delonix completion shell <shell> — autocompletion.