CLI Reference¶
Canonical repository reference: docs/CLI_REFERENCE.md
First-run commands:
boundary version
boundary selftest
boundary doctor --json
boundary demo action-boundary
boundary demo github-lethal-trifecta
boundary demo command-secret-exfil
boundary evidence bundle --include-demo
boundary evidence verify boundary-evidence
Firewall commands:
boundary inventory --help
boundary graph --help
boundary policy generate --help
boundary inventory ingest --help
boundary dashboard --help
Secure GitHub commands:
boundary secure github --help
boundary secure github conformance --help
BOUNDARY_GITHUB_CONFORMANCE=true boundary secure github conformance denied-write
boundary redteam --pack github-lethal-trifecta
Command Boundary preview commands:
boundary command classify --help
boundary command run --help
boundary command install --project
boundary shell --help
boundary demo command-secret-exfil
Decision-record commands:
Availability - current release
boundary explain, boundary replay, and schema_version "2" (route-context)
decision records shipped by v0.9.0 and remain included in the current
published v0.13.0 release. boundary verify-record on a schema_version "1" or
"2" record is included as well.
boundary verify-record record.json
boundary explain record.json
boundary explain --json docs/examples/decision-record-v2.example.json
boundary replay record.json --request request.json --policies ./policies/
boundary explain is local-only and read-only: it describes a decision record
(schema_version 1 or 2) and does not verify its hashes. Run
boundary verify-record to recompute them.
boundary replay is local-only and fixture-safe: it re-evaluates the recorded
request against the recorded policy bundle and compares the decision-defining
fields (action, reason, decision_mode, matched_rule, policy_file) —
not action alone. It reproduces the decision, not enforcement, and does not
prove that no upstream bytes moved.
Policy test commands:
Availability - current release
boundary test shipped in v0.9.0 and remains included in the current
published v0.13.0 release. The historical @v0.8.0 install does not include it.
boundary test --path tests/fixtures/policy-test/cases
boundary test --path tests/fixtures/policy-test/cases --format json
boundary test is local-only and fixture-safe. It reports policy verdicts for
routed request fixtures only; it does not prove production route enforcement or
deployment bypass resistance.
Release verification commands:
make selftest
make demo-github
make release-check
boundary test --path tests/fixtures/policy-test/cases
boundary evidence bundle --include-demo --out /tmp/boundary-evidence
boundary evidence verify /tmp/boundary-evidence
go test ./claims/... -count=1
go test ./... -count=1 -timeout 5m