Skip to content

Latest commit

 

History

History
279 lines (194 loc) · 4.59 KB

File metadata and controls

279 lines (194 loc) · 4.59 KB

Loam CLI Reference

The complete command surface of the Loam substrate.

This reference lists:

  • every subsystem
  • every subcommand
  • required/optional arguments
  • one-line descriptions

It is mechanical, not conceptual. For architecture and mental models, see the Architecture Overview.

Store Identifiers

Anywhere the CLI expects a argument, you may supply any of the following:

Human‑friendly name — the name you assigned with identity issue --name or identity name

Store UUID — the directory name under ~/.loam/stores/

Identity fingerprint — the cryptographic fingerprint shown in identity show

All three forms resolve to the same identity store. If a command requires a specific form (rare), it is noted explicitly.

Top-Level Structure

loam <system> <action> [args...]

Systems

  • identity
  • logs
  • secret
  • state
  • ops
  • run
  • exec

1. identity — Manage identity stores

identity issue

Issue a new identity store.

loam identity issue [--name <name>] [--plaintext] [--passphrase <pw>]

Arguments:

  • --name — human-friendly name
  • --plaintext — issue unencrypted (insecure)
  • --passphrase — non-interactive encrypted issuance

identity list

List all identity stores.

loam identity list

identity show

Show identity metadata.

loam identity show <store>

identity verify

Verify continuity and store integrity.

loam identity verify <store>

identity name

Get or set a store’s human-friendly name.

loam identity name <store> [new_name]

identity rename

Rename a store.

loam identity rename <store> <new_name>

identity revoke

Revoke an identity by fingerprint.

loam identity revoke <fingerprint> [--note <text>]

identity unrevoke

Remove an identity from the revocation list.

loam identity unrevoke <fingerprint>

identity revoked

List all revoked identities.

loam identity revoked

identity encrypt

Encrypt an existing identity store.

loam identity encrypt <identity>

identity decrypt

Decrypt an existing identity store.

loam identity decrypt <identity>

identity unlock

Unlock an encrypted identity for this session.

loam identity unlock <identity>

identity lock

Lock an identity for this session.

loam identity lock <identity>

identity lock-all

Lock all identities for this session.

loam identity lock-all

2. logs — Inspect continuity and chronicle

logs show

Show continuity or chronicle log.

loam logs show <continuity|chronicle> <store>

logs verify

Verify continuity and chronicle logs.

loam logs verify <store>

logs interlaced

Show continuity and chronicle interwoven.

loam logs interlaced <store>

3. secret — Manage identity-scoped secrets

secret create

Create a secret.

loam secret create <store> <secret_name> [--value <value>]

secret list

List secrets.

loam secret list <store>

secret load

Load a secret (temporary command).

loam secret load <store> <secret_name>

secret rotate

Rotate a secret.

loam secret rotate <store> <secret_name> [--value <value>]

secret delete

Delete a secret.

loam secret delete <store> <secret_name>

4. state — Manage deterministic state hashing

state enable

Enable state hashing.

loam state enable <store> [--path <abs-path>]

state disable

Disable state hashing.

loam state disable <store>

state show

Show state hashing status.

loam state show <store>

state set-path

Set a state path without enabling hashing.

loam state set-path <store> --path <abs-path>

state unset-path

Remove state path and disable hashing.

loam state unset-path <store>

5. ops — Operational tools

ops verifyartifact

Verify an artifact envelope against an identity’s public key.

loam ops verifyartifact <store> <artifact>

ops export

Export a sealed identity store.

loam ops export <store> --out <dir> [--passphrase <pw>]

ops import

Import a sealed identity store.

loam ops import <store-dir> [--passphrase <pw>]

6. run — Run a Loam-native agent

loam run [--python-driver] [--legacy-python] <store> <exec_path> [--passphrase <pw>] [args...]

7. exec — Execute a program inside an identity

loam exec <store> <program> [--passphrase <pw>] [args...]