Cheatsheet

Todos os grupos de comandos e subcomandos, num só sítio. Gerado do --help real do binário.

All command groups and subcommands, in one place. Generated from the real --help of the binary.

Tarefas comunsCommon tasks

Serviço web, sem root, sem daemon
Web service, no root, no daemon
delonix container run -d --name web -p 8080:80 nginx
Shell descartável
Disposable shell
delonix container run --rm -it alpine sh
Rede própria + publicar pelo ingress
Own network + publish via ingress
delonix network create backend
delonix container run -d --net backend -p 8443:443 caddy
Trocar uma porta a QUENTE (sem reiniciar)
Hot-swap a port (no restart)
delonix container update web --publish-add 9090:80
Firewall: só deixar entrar Postgres da SDN
Firewall: only let Postgres in from the SDN
delonix net ingress allow db tcp/5432 --from 10.219.0.0/16
delonix net ingress policy db deny
Firewall: egress da rede só p/ DNS + CIDRs
Firewall: network egress to DNS + CIDRs only
delonix net egress net backend allowlist --to 10.0.0.0/8
Tráfego por container ao vivo (eBPF)
Live per-container traffic (eBPF)
sudo delonix net flow --watch
Volume de rede de um NAS (NFS)
Network volume from a NAS (NFS)
delonix volume create media --driver nfs --opt server=10.0.0.5 --opt share=/mnt/pool/media
Segredo no cofre (não no argv)
Secret in the vault (not in argv)
printf 'password=s3nha' | delonix secret create db-pass --from-env-file -
Expor um container à internet pública (sem conta, sem router)
Expose a container to the public internet (no account, no router)
delonix container run -d --name web --expose 80 nginx
delonix net tunnel expose 8080
tunnel/tunnel-8080: running — https://oxipg-197-148-40-67.free.pinggy.net
NAS partilhado por vários tenants, cada um com a sua quota
NAS shared by several tenants, each with its own quota
delonix volume create nas --driver nfs --opt server=10.0.0.5 --opt share=/pool/data
delonix volume create tenant-a --parent nas --quota 5G
microVM com cloud-init
microVM with cloud-init
delonix vm create node1 --disk base.qcow2 --ssh-key @~/.ssh/id_ed25519.pub
Cluster Kubernetes do zero
Kubernetes cluster from scratch
delonix cluster kubeadm --name lab --control-plane 1 --workers 2
Aplicar um manifesto inteiro
Apply a whole manifest
delonix stack apply -f delonix-manifest.yaml
Persistir os containers no arranque
Persist containers on boot
delonix system boot enable
Recuperar espaço (GC)
Reclaim space (GC)
delonix system prune

Todos os gruposAll groups

Cargas de trabalhoWorkloads

delonix container

ComandoCommandO que fazWhat it does
container killSend a signal to one or more containers (default SIGKILL)
container pauseSuspend a container's processes (cgroup v2 freezer)
container restartStop then start one or more containers
container rmRemove one or more containers
container runRun a container from an image (pulls it if missing)
container start(Re)start stopped/crashed containers. Always detached
container stopStop one or more containers (SIGTERM, then SIGKILL)
container unpauseResume a container suspended with `pause`
container waitBlock until one or more containers exit, then print their exit code (one per line, in the order given)
container describeHuman-readable detail of one or more containers, `kubectl describe`-style
container diffFiles changed relative to the image: `A` = created/changed, `D` = deleted
container healthcheckRun the image's `HEALTHCHECK` inside the container. Exits with 1 if `unhealthy` — usable in a script/CI
container inspectShow the full spec of one or more containers (Store JSON)
container logsShow the logs (detached containers)
container portPublished ports of a container (`hostPort/proto -> containerPort`)
container psList containers [alias: ls]
container statsResource usage (CPU/memory/PIDs) of the running containers
container topProcesses running inside a container (read from `cgroup.procs`)
container attachRe-attach to a running container's output stream (output only)
container commitCreate an image from a container's CURRENT rootfs state (whatever was written inside becomes a new layer)
container cpCopy files between the host and a container
container execExecute a command inside a running container
container renameGive a container a new name
container update**Reconfigure a RUNNING container without stopping it** — ports, volumes, and bandwidth cap
container applyApply the `kind: Container` documents of a manifest (idempotent by name)
container initInitialize a project with a Delonixfile + manifest
container pruneRemove every stopped container and the rootfs debris they left behind

delonix pod

ComandoCommandO que fazWhat it does
pod createCreate a pod (N containers sharing a netns) from a manifest (`kind: Pod`)
pod logsLogs of a pod's container (defaults to the first member)
pod attachRe-attach to a pod member's output stream (output only)
pod cpCopy files between the host and one member of a pod
pod execExecute a command inside one member of a pod (defaults to the first)
pod port-forwardForward one or more host ports to ports inside the pod's netns

delonix vm

ComandoCommandO que fazWhat it does
vm cloud-initChange a STOPPED VM's cloud-init — hostname, user, SSH keys — for its next boot
vm createCreate (or auto-recover) a VM
vm destroyDestroy VMs and everything they own — provider-side VM, disks, snapshots
vm migrateMove a VM to another `delonix` host — real downtime, no shared storage
vm moveMove a VM to another node of its cluster — same VM, same record
vm pauseSuspend a running VM's vCPUs — guest memory stays intact, unlike `stop`
vm resizeChange a STOPPED VM's vCPUs and/or memory for its next boot
vm restartStop (if running) then start — always a real reboot, unlike `start`. Same recovered-fields limits as `start`
vm startStart an existing, stopped VM — idempotent (already running = no-op)
vm stopStop the VM (preserves disk, record and snapshots)
vm unpauseResume a VM suspended with `pause`. Refuses a VM that is not paused
vm lsList the VMs
vm consoleAttach to the VM's serial console (interactive terminal)
vm sshSSH into a VM by NAME, or straight to an address
vm vncPrint the VNC address of a graphical VM (created with `--vnc`, libvirt)
vm default-backendGet or set the default VM backend
vm bridgeEXPERIMENTAL (root): give a libvirt VM DIRECT IP reachability to a container SDN network
vm reachWhich published ports a VM can actually reach, and how to fix the rest
vm unbridgeTear down a `vm bridge` (dry-run without `--apply`)
vm buildBuild a VM image (qcow2) from a `vm.yaml`, a `VMfile`, or the golden recipe
vm convertConvert a VM disk to the format another ecosystem imports
vm ls-remoteList the tags available in a remote OCI repository
vm pullPull a golden VM image from an OCI registry
vm pushPush a local golden VM image to an OCI registry (`vm push <name> <target>`)
vm applyApply the `kind: VirtualMachine` documents of a manifest
vm initBootstrap a project with a VM manifest
vm pruneReclaim the VM state directory: everything in it no VM record accounts for
vm snapshotPoint-in-time snapshots of a VM (checkpoints in the VM's own disk)

delonix systemcontainer

ComandoCommandO que fazWhat it does
systemcontainer cloneA full copy of a system container under a new name, registered here
systemcontainer moveMove a system container to another node of its provider's cluster
systemcontainer snapshotSnapshots of a system container's root volume

delonix workload

ComandoCommandO que fazWhat it does
workload rmRemove a workload by name
workload stopStop a workload by name (routed to the owning backend)
workload describeDescribe a workload by name (routed to the owning backend, kubectl-style)
workload lsList all workloads — containers AND VMs — in one table (or `-o json`)

ArtefactosArtifacts

delonix image

ComandoCommandO que fazWhat it does
image pullPull an image from a registry
image pushPublish a local image to an OCI registry
image removeRemove a local image
image describeHuman-readable detail of one or more images, `kubectl describe`-style
image historyLayers of an image (digest + size), from base to top
image lsList local images
image sbomThe image's SBOM as an SPDX 2.3 document, not the table `scan --sbom` prints
image scanSBOM + CVE scan of an image
image verifyVerify the cosign signature of a local image against a public key
image loginAuthenticate to an OCI registry
image logoutRemove the stored credentials of a registry
image signSign an image with cosign-compatible ECDSA-P256, publishing the signature next to it in the registry
image tagGive another name/tag to a local image (copies nothing — it's just a new name for the same content)
image exportExport an OCI runtime bundle (rootfs + config.json) for `runc`/`crun`
image loadLoad an image from an archive (the counterpart of `save`)
image saveSave an image to a portable archive (`docker save`'s counterpart)
image applyApply the `kind: Image` documents of a manifest
image pruneRemove unused images and the CAS blobs nobody references any more
image vmGolden VM images (`<root>/vm-images/`): ls/pull/push/build/rm/describe

delonix build

Constrói uma imagem a partir de um Dockerfile ou Delonixfile.

Builds an image from a Dockerfile or Delonixfile.

delonix secret

ComandoCommandO que fazWhat it does
secret createCreate a secret from literals and/or a `.env` file
secret rmRemove a secret
secret inspectShow the keys of a secret (values redacted, unless `--reveal`)
secret lsList the secrets (name + number of keys; values NEVER shown)
secret setSet/update keys in a secret (creates it if it does not exist)
secret unsetRemove a key from a secret (or the whole secret with `--all`)
secret applyApply the `kind: Secret` documents from a manifest
secret rotateRotate one key's VALUE to a fresh random one
secret rotate-keyRotate the host master key: re-encrypt ALL secrets with a new key. The values are preserved

ArmazenamentoStorage

delonix volume

ComandoCommandO que fazWhat it does
volume createCreate a named volume
volume rmRemove a volume
volume describeReadable detail of one or more volumes, `kubectl describe` style
volume inspectDetails of a volume (includes real on-disk usage)
volume lsList the volumes
volume applyApply the `kind: Volume` documents from a manifest (idempotent by name)
volume pruneDESTROY every local volume that nothing references
volume snapshotPoint-in-time snapshots of a volume (tar.gz under the volume; safe in rootless)

RedeNetworking

delonix network

ComandoCommandO que fazWhat it does
network connectConnect a RUNNING container to an additional network, hot
network createCreate a network
network disconnectDisconnect a container from an additional network, hot
network rmRemove a network
network routeOpen a DIRECTED path from one network to another (ADR-0013 tier B)
network vlan802.1Q VLAN on a physical NIC — **the one command here that needs root**
network describeReadable detail of one or more networks, `kubectl describe` style
network diagnoseThe LIVE state of this node's network, and what disagrees with it
network inspectDetail of a network
network lsList the networks
network applyApply the `kind: Network` documents of a manifest (idempotent by name)
network ipamThe IP lease registry — the `/16` anti-collision allocator
network nodeWireGuard identity of THIS node, for the encrypted overlay between nodes

delonix net

ComandoCommandO que fazWhat it does
net captureRaw packet capture on a container's SDN interface, via the host's own `tcpdump`
net flowLive per-container traffic (eBPF datapath; degrades to veth counters)
net egressOUTBOUND firewall (L4 rules + per-network egress policy) for a container
net ingressINBOUND firewall (L4 rules + DNAT publishes) for a container on the SDN
net l4guardIngress-wide L4 DDoS guard (per-source connection rate + concurrent cap)
net httprouteEmbedded L7/HTTP reverse-proxy (`kind: HTTPRoute`): apply/rm
net tunnelExpose a local port to the public internet (`kind: Gateway`)
net netnsLow-level management of the rootless ingress infra (up/status/attach/publish/firewall)

delonix net netns

ComandoCommandO que fazWhat it does
net netns downForce tear-down of the ingress infra (kills slirp + holder, frees the netns)
net netns gcReclaim infra left behind by state roots that no longer exist
net netns upBring the ingress infra up (idempotent): holder netns + delonix0 + single slirp
net netns statusShow the ingress infra status (holder/slirp pids, bridge, refcount)
net netns execRun a command inside an attached netns (exercises the runtime join path)
net netns attachAttach a netns to delonix0 via veth (the holder is the netns/veth factory)
net netns detachDetach (and destroy) a previously attached netns
net netns firewallApply (or clear) a container's parameterizable firewall AT THE INGRESS
net netns publishPublish a port through the ingress (add_hostfwd + DNAT) to a container
net netns unpublishUnpublish a host port from the ingress

delonix net flow

Tráfego por-container ao vivo — datapath eBPF (degrada para contadores veth).

Live per-container traffic — eBPF datapath (degrades to veth counters).

delonix net capture

Captura de pacotes crua na interface SDN de um container — o tcpdump do próprio host.

Raw packet capture on a container's SDN interface — the host's own tcpdump.

delonix net l4guard

ComandoCommandO que fazWhat it does
net l4guard statusShow whether the guard is active, with its drop counters
net l4guard clearTurn the guard off
net l4guard setTurn the guard on (or update it): new conns/s and concurrent conns, per source IP

delonix net ingress

ComandoCommandO que fazWhat it does
net ingress lsShow the inbound firewall (policy + rules) and published ports
net ingress allowAllow inbound traffic to a container: `[proto/]port` from an optional CIDR
net ingress denyDeny inbound traffic to a container (same shape as `allow`)
net ingress policySet the default inbound policy when no rule matches
net ingress publishPublish a host port to the container (DNAT through the ingress)
net ingress unpublishRemove a published host port
net ingress clearRemove all inbound rules (keeps published ports)
net ingress rmRemove inbound rule(s) matching `[proto/]port` (all protos if none given)

delonix net egress

ComandoCommandO que fazWhat it does
net egress lsShow the outbound firewall (policy + rules)
net egress showShow a NETWORK's egress policy
net egress allowAllow outbound traffic from a container: `[proto/]port` to an optional CIDR
net egress denyDeny outbound traffic from a container (same shape as `allow`)
net egress hostAllow a network's egress to a HOSTNAME (and `*.hostname`). Repeatable
net egress netGovern a whole network's egress to the Internet
net egress policySet the default outbound policy when no rule matches
net egress clearRemove all outbound rules
net egress rmRemove outbound rule(s) matching `[proto/]port` (all protos if none given)

delonix net httproute

ComandoCommandO que fazWhat it does
net httproute applyApply the HTTPRoutes of a manifest (brings up/reloads the proxy)
net httproute rmStop the proxy and unpublish the ports (teardown)

delonix net tunnel

ComandoCommandO que fazWhat it does
net tunnel exposeOne-shot expose of a local port, no manifest needed
net tunnel applyApply the `kind: Gateway` documents of a manifest (idempotent)

delonix hosts

ComandoCommandO que fazWhat it does
hosts syncPublish the service names of exposed containers in `/etc/hosts` and keep them current

ClustersClusters

delonix cluster

ComandoCommandO que fazWhat it does
cluster createCreate a local Kubernetes cluster **without a manifest and without Docker**
cluster destroyRemove a kind-mode cluster entirely — nodes, network, kubeconfig, `~/.kube/config` entry
cluster kubeadmProvision VMs (golden VM image) + `kubeadm` bootstrap
cluster startStart every node of a stopped kind-mode cluster back up
cluster stopStop every node of a kind-mode cluster at once — no rebuild, no state lost
cluster upgradeUpgrade a `mode: ssh` cluster to a newer Kubernetes version, kubeadm-style
cluster initInitialize a project with the cluster manifests (kind/vm/ssh)
cluster drainCordon a node and evict its pods
cluster healthIs the control-plane answering, and is every node `Ready`?
cluster kubeconfigPrint a cluster's kubeconfig from the local cache (no live SSH)
cluster loadLoad local images into a kind-mode cluster's nodes, **without a registry**
cluster lsList this host's clusters — kind-mode AND VM-based
cluster uncordonMark a drained node schedulable again
cluster applyApply the `kind: KubernetesCluster` document(s) of a manifest
cluster kubeGenerate a Kubernetes manifest from a container/pod already running locally
cluster pruneReclaim the state of clusters that have no nodes left

delonix cluster kube

ComandoCommandO que fazWhat it does
cluster kube generateGenerates a `kind: Pod` from a container (or from every member of a pod) and prints it to stdout

DeclarativoDeclarative

delonix explain

Referência de campos de um Kind, gerada do próprio código — `kubectl explain` style.

Field reference for a Kind, generated from the code — `kubectl explain` style.

delonix api-resources

Todos os Kinds que este motor serve: plural, nomes curtos, apiVersion e forma.

Every Kind this engine serves: plural, shortnames, apiVersion and form.

delonix apply

Converge um manifesto — a grafia canónica de `stack apply`.

Converge a manifest — the canonical spelling of `stack apply`.

delonix plan

Mostra o que um apply mudaria, e não muda nada.

Show what an apply would change, and change nothing.

delonix wait

Bloqueia até os recursos do manifesto estarem prontos.

Block until the manifest's resources are ready.

delonix manifest

ComandoCommandO que fazWhat it does
manifest renderPrint the manifest as the engine will read it, with defaults filled in
manifest schemaThe JSON Schema, generated from the Rust types (ADR-0007)
manifest validateCheck a manifest against the schema, the references and the graph

delonix diff

O manifesto, o last-applied e o observado de UM recurso, lado a lado.

The manifest, last-applied, and observed values for one resource — side by side.

delonix drift

O que a MÁQUINA mudou desde o último apply — a stack inteira.

What the MACHINE changed since the last apply — the whole stack.

delonix migrate

ComandoCommandO que fazWhat it does
migrate assessScore a `docker-compose.yml` against what this engine serves

delonix stack

ComandoCommandO que fazWhat it does
stack applyApplies all the manifest Kinds (Network → Volume → Image → Vm → Container)
stack destroyRemoves everything this stack owns (by the `delonix.io/stack` label)
stack waitBlocks until every declared resource is present and, where it has one, healthy
stack initInitializes a COMPLETE project: Delonixfile + manifest + cluster + README
stack describeStack detail in `kubectl describe` style
stack historyWhat this stack applied, and when (ADR-0019)
stack lsList the structure the manifest composes, and whether each resource exists
stack planShows what an `apply` WOULD change, without changing anything
stack validateValidates the manifest WITHOUT touching anything (dry-run)
stack rollbackRe-apply a recorded revision (ADR-0019)
stack pruneRemove what this stack owns and the manifest no longer declares

delonix compose

ComandoCommandO que fazWhat it does
compose downRemoves every container this project's `up` created
compose upCreates/starts every service
compose configValidates and prints the resolved project, without creating anything (`docker compose config` equivalent)
compose logsLogs of one service (default: every service, one after another)
compose psContainers of this project (derived from labels)

RecursosResources

delonix get

Lista recursos de um Kind — a forma genérica de dez `ls`s.

List resources of a Kind — the generic form of ten `ls` commands.

delonix describe

Detalhe de um recurso, em blocos — a forma genérica de dez `describe`s.

Detail of one resource, in blocks — the generic form of ten `describe`s.

delonix delete

Remove recursos por Kind e nome — a forma genérica de dez `rm`s.

Remove resources by Kind and name — the generic form of ten `rm`s.

ServirServe

delonix compatibility

ComandoCommandO que fazWhat it does
compatibility composeCompose Specification coverage, key by key
compatibility dockerDocker Engine API coverage

delonix serve

ComandoCommandO que fazWhat it does
serve apiServe the MANAGEMENT API (HTTP+JSON) on a unix socket
serve criServe the CRI endpoint (`runtime.v1`) on a unix socket — replaces containerd/CRI-O for a kubelet
serve docker-apiServe a slice of the Docker Engine API on a unix socket
serve node-apiServe the NODE API (gRPC + HTTP/JSON of `delonix.node.v1`) on a unix socket

delonix serve cri

Serve o endpoint CRI (runtime.v1) num socket unix.

Serves the CRI endpoint (runtime.v1) on a unix socket.

delonix serve api

A API de gestão LOCAL (HTTP+JSON) num socket unix, para um control-plane externo.

The LOCAL management API (HTTP+JSON) on a unix socket, for an external control plane.

delonix serve docker-api

Fatia da API Docker Engine, num socket unix — ciclo de vida completo de um container, não só leitura.

A slice of the Docker Engine API, on a unix socket — full container lifecycle, not just reads.

delonix serve node-api

O contrato de nó (gRPC + HTTP/JSON do delonix.node.v1) num socket unix.

The node contract (gRPC + HTTP/JSON of delonix.node.v1) on a unix socket.

delonix mcp

ComandoCommandO que fazWhat it does
mcp capabilitiesPrint the tool risk table (name, risk level, whether `confirm` is required)
mcp doctorCheck that this node is ready to serve MCP tool calls
mcp serveStart the MCP server

MotorEngine

delonix init

Começa o projecto CERTO para este directório — detecta, explica-se, e delega.

Start the RIGHT project for this directory — detect, explain, dispatch.

delonix version

Imprime a versão (o mesmo texto que `--version`).

Print the version (same output as `--version`).

delonix policy

ComandoCommandO que fazWhat it does
policy unsetRemove the node's security ceiling (`<root>/policy.json`)

delonix config

ComandoCommandO que fazWhat it does
config getRead one key, or every key set (with no argument)
config setSet a key. Refuses an unknown key or an invalid value by name — never accepted-and-ignored
config unsetRemove a key — the command that reads it falls back to its built-in default again

delonix system

ComandoCommandO que fazWhat it does
system dfDisk usage by area (images, containers, volumes, VM images)
system doctorCheck the HOST prerequisites this engine needs, and say how to fix each
system eventsEngine events (create/start/die/remove/…), from oldest to most recent
system featuresWhat each capability promises, and the EVIDENCE for it
system infoEngine state: rootless?, cgroup delegation, network infra, counts
system metricsThe raw counters: containers/VMs/networks/volumes/images, memory, network, disk
system namespaceIsolation namespaces: ls/describe — a namespace exists while something is in it, so there is no create/rm
system resourcesHow much this host has, how much the engine can actually enforce, and what is under pressure right now
system regulateGive the contended CPU back to the workloads that are waiting for it
system setupDiagnose — and, with `--delegate`, fix — cgroup delegation
system snapshotPoint-in-time capture of this node's whole state — `create` saves it into one archive, `restore` puts it back
system virtHost virtualization: hypervisor, KVM, virtio — and what there is to tune
system pruneReclaim space taken by what nothing uses any more
system thermalThermal governor for Delonix's CPU budget. Runs continuously (see `--once`)
system monitorActive network connections per container (via conntrack)
system bootBoot persistence: systemd units so containers come back up after a reboot

delonix system boot

ComandoCommandO que fazWhat it does
system boot statusShow boot-persistence status (installed units + mode)
system boot disableDisable + remove the generated boot units
system boot enableInstall + enable systemd units so containers come back after a reboot

delonix system namespace

ComandoCommandO que fazWhat it does
system namespace describeWhat is inside ONE namespace, by Kind, `kubectl describe` style
system namespace lsList the isolation namespaces IN USE, with what is in each

delonix backup

ComandoCommandO que fazWhat it does
backup inspectWhat an archive holds, without unpacking it
backup lsThe archives in a directory
backup createWrite an archive of one resource, now
backup removeDelete an archive
backup restorePut a resource back from an archive
backup scheduleKeep archiving this resource on a systemd user timer

delonix provider

ComandoCommandO que fazWhat it does
provider configThe node's providers file (ADR-0054): what it says, and whether it is valid
provider describeEvery capability of ONE provider, with its state and the reason
provider lsEvery provider this build knows, probed on this host
provider matrixThe declared matrix, host-independent, as Markdown

delonix dashboard

Dashboard de resumo/KPIs (TUI estilo htop) — RAM/rede/disco, uptime por-container, JSON e Prometheus.

Summary/KPI dashboard (htop-style TUI) — RAM/network/disk, per-container uptime, JSON and Prometheus.

delonix completion

ComandoCommandO que fazWhat it does
completion editorVMfile syntax highlighting for an editor (vim/vscode)
completion shellPrint the shell autocompletion script (bash/zsh/fish/...)

delonix man

Páginas de manual em roff, geradas a partir deste binário — uma por comando.

Manual pages in roff, generated from this binary — one per command.

GlobalGlobal

--l18n en|pt — idioma da saída (EN por omissão; pt para pt_AO). $DELONIX_ROOT — raiz do estado. delonix completion shell <shell> — autocompletion.

--l18n en|pt — output language (EN by default; pt for pt_AO). $DELONIX_ROOT — the state root. delonix completion shell <shell> — autocompletion.