[!WARNING] Not a supported Solace product.
solace-utilwas created by Solace Professional Services and is supported only by Solace Professional Services – not by Solace Support. For help with this tool, contact your Solace Professional Services representative rather than opening a Solace Support case. This notice covers this tool only, not the Solace PubSub+ Event Broker or the EventBroker Operator that it deploys and operates.
Every command solace-util exposes, with its arguments and flags.
Generated from the command tree – do not edit by hand. Regenerate after any command, flag, or description change:
go test ./internal/cli -update
The test task fails while this file is stale, so it cannot drift from the code.
solace-util
auto-complete
bash
fish
powershell
zsh
broker
cli
configure
data-replication
default-users
default-vpn
domain-certs
product-keys
server-certs
copy
from files...
into files...
deploy
generate
logs
perform
assert-leader
cli-script <file>
data-replication
export-config
gather-diagnostics
import-config <file>
redundancy-test
semp-login-check
shell-script <file>
remove
restart
shell
start
status
stop
validate
convert <bash-env-file>
examples
operator
deploy
generate
logs
remove
restart
start
status
stop
validate
validate
version
--allow-command approves one extra binary for the env file’s platform command,
for that run only; it is repeatable and takes a bare name, never a path. It is listed
on every command that executes something, and refused with a named error by the ones
that only render.remove alone removes nothing.[role] is primary, backup or monitor, and the letters p, b, m work
everywhere the long names do. On Kubernetes it picks which pod a command targets,
defaulting to the primary. On docker and podman there is one container per host, so it
instead names which host in the redundancy group this invocation runs on – required
where the artifact is per-host, and detected from the host name where it may be
omitted. Passing one where it means nothing is refused with a named error.br and op ride under every verb that takes broker and operator. Every short
form the tool accepts, including the role letters and the --platform spellings, is
in abbreviation.md.Inherited by every command.
| Flag | Default | Meaning |
|---|---|---|
--base-dir |
(none) | directory searched for the env file, and holding env/ (default: current directory) |
-e, --env |
env.yaml |
env file name, searched in the base dir then <base-dir>/env; a value with a directory is used as-is |
--platform |
(none) | platform to drive: kubernetes (kube), docker (dk) or podman (pm). Default: the one the env file declares, or a prompt if it declares several |
-v, --verbose |
false |
announce every external command as it runs; by default the binaries this env file names are resolved and listed once, up front |
Deploy and operate Solace PubSub+ brokers on Kubernetes, Docker, or Podman
Deploy and operate Solace PubSub+ Event Brokers from one YAML env file, with the same commands on every platform. Name the thing, then the verb:
broker
Every command takes -e/–env
Exit status: 0 worked, 2 bad command line or env file, 1 anything else.
solace-util
Subcommands: auto-complete, broker, convert, examples, operator, validate, version
Print the shell auto-completion script for solace-util
Print a shell’s completion script on stdout. Load it to complete commands and flags, plus the values they take: env files for -e/–env, primary|backup|monitor for –pod, platform names for –platform, and directories for –base-dir and –dir.
To load it for every new shell:
bash solace-util auto-complete bash > /etc/bash_completion.d/solace-util zsh solace-util auto-complete zsh > “${fpath[1]}/_solace-util” fish solace-util auto-complete fish > ~/.config/fish/completions/solace-util.fish powershell solace-util auto-complete powershell > $HOME\solace-util.ps1 then add . $HOME\solace-util.ps1 to $PROFILE
Each shell’s own help has the one-liner for loading into the CURRENT shell instead, and the prerequisites where a shell has any.
Completion never reads the env file, so it stays inert – a TAB press cannot parse config or run anything.
solace-util auto-complete
Subcommands: bash, fish, powershell, zsh
Print the bash completion script
Load into the current shell:
source <(solace-util auto-complete bash)
Load for every session. With the bash-completion package installed, write it where that package looks:
solace-util auto-complete bash > /etc/bash_completion.d/solace-util
Without that package there is no such directory, so source it from ~/.bashrc instead – this script needs nothing but bash itself:
echo ‘source <(solace-util auto-complete bash)’ » ~/.bashrc
solace-util auto-complete bash [flags]
| Flag | Default | Meaning |
|---|---|---|
--descriptions |
false |
show the description beside each completion |
Print the fish completion script
Load into the current shell:
| solace-util auto-complete fish | source |
Load for every session:
solace-util auto-complete fish > ~/.config/fish/completions/solace-util.fish
solace-util auto-complete fish [flags]
| Flag | Default | Meaning |
|---|---|---|
--descriptions |
false |
show the description beside each completion |
Print the powershell completion script
Load into the current shell:
| solace-util auto-complete powershell | Out-String | Invoke-Expression |
Load for every session. Write the script once, then dot-source it from your profile – generating it once is what keeps shell start-up fast, since the alternative runs this binary on every new shell:
solace-util auto-complete powershell > $HOME\solace-util.ps1 Add-Content $PROFILE ‘. $HOME\solace-util.ps1’
If $PROFILE does not exist yet, create it first:
New-Item -ItemType File -Force $PROFILE
solace-util auto-complete powershell [flags]
| Flag | Default | Meaning |
|---|---|---|
--descriptions |
false |
show the description beside each completion |
Print the zsh completion script
Load into the current shell:
source <(solace-util auto-complete zsh)
Load for every session (compinit must be enabled in ~/.zshrc):
solace-util auto-complete zsh > “${fpath[1]}/_solace-util”
solace-util auto-complete zsh [flags]
| Flag | Default | Meaning |
|---|---|---|
--descriptions |
false |
show the description beside each completion |
Deploy and operate the broker
Everything that acts on the broker this env file describes.
broker validate check the env file and the cluster or host broker generate see exactly what would be applied broker deploy prerequisites + the broker, idempotent broker status watch it come up broker configure … settings the env file describes (certs, keys, hardening) broker perform … one-shot actions (diagnostics, failover test) broker stop / start pause it without removing it broker remove tear it down, prompting for each layer
solace-util broker
Runs nothing on its own. It names what solace-util broker can act on – cli, configure, copy, deploy, generate, logs, perform, remove, restart, shell, start, status, stop, validate – and given a word it does not know it fails rather than reporting success.
Also available as: br
Open an interactive Solace CLI in the broker
Interactive only; execs cli -A into the picked pod (Kubernetes) or this
host’s container (docker/podman).
To run a script instead of typing at a prompt, use
broker perform cli-script <file>.
solace-util broker cli [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Configure a deployed broker (certs, keys, hardening)
Settings the env file describes, applied to a deployed broker over its own CLI.
On a fresh HA broker, run in this order:
broker perform assert-leader config-sync leader FIRST broker configure server-certs broker configure domain-certs broker configure default-vpn hardening broker configure default-users broker configure product-keys last
broker configure data-replication a DR pair, when there is one
solace-util broker configure
Runs nothing on its own. It names what solace-util broker configure can act on – data-replication, default-users, default-vpn, domain-certs, product-keys, server-certs – and given a word it does not know it fails rather than reporting success.
Also available as: cfg
Converge this broker to the replication: block
Converges THIS broker to the env file’s replication: block – the mate addresses, which message-VPNs replicate, and each one’s active/standby role.
It never contacts the mate. Run it at BOTH sites with the same file.
Shuts down replication on any replicating VPN the file does not list, and can
leave a VPN active at both sites if the mate still holds it – move a role with
broker perform data-replication instead.
solace-util broker configure data-replication [flags]
Also available as: dr
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Shut down the default client-usernames in all VPNs
Shuts down the default client-username in every message-VPN found on the broker.
This blocks any client still relying on the default username to connect.
solace-util broker configure default-users [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--disable |
false |
shut it down (the default; accepted explicitly so a script can say so) |
--enable |
false |
start it back up instead of shutting it down |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Shut down the default message-VPN
Shuts down the broker’s default message-VPN.
This stops every client connection using it, and every service it fronts.
solace-util broker configure default-vpn [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--disable |
false |
shut it down (the default; accepted explicitly so a script can say so) |
--enable |
false |
start it back up instead of shutting it down |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Load the configured domain CA certificates
Uploads the domain CA certificates broker.domainCerts describes and creates a domain certificate authority for each.
–remove deletes those authorities from the broker; the certificate files themselves stay.
solace-util broker configure domain-certs [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--apply |
false |
apply what the env file configures (the default; accepted explicitly so a script can say so) |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
--remove |
false |
remove it from the broker instead of applying it |
Apply the configured product keys
Applies broker.productKeys to the primary node (and backup, in HA); fails loud rather than silently succeeding when none are configured.
–remove revokes those keys and can leave the broker unlicensed.
solace-util broker configure product-keys [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--apply |
false |
apply what the env file configures (the default; accepted explicitly so a script can say so) |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
--remove |
false |
remove it from the broker instead of applying it |
Load or update the TLS server certificate
Updates the stored certificate (the TLS Secret, or podman’s secret store), then hot-swaps it into the running broker over its CLI, on every node. Never restarts.
–remove takes TLS down immediately on every listener configured to present a certificate.
solace-util broker configure server-certs [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--apply |
false |
apply what the env file configures (the default; accepted explicitly so a script can say so) |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
--remove |
false |
remove it from the broker instead of applying it |
Copy files to or from the broker
Attempts every file in both directions and reports each one, rather than stopping at the first failure; a partial failure still exits non-zero.
solace-util broker copy
Runs nothing on its own. It names what solace-util broker copy can act on – from, into – and given a word it does not know it fails rather than reporting success.
Also available as: cp
Copy files from the broker to the host
Each file lands in the current directory under its base name. The base name is split on both separators, so a remote path written with backslashes cannot produce a local filename containing one.
solace-util broker copy from files... [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Copy files from the host into the broker
–dir is the destination inside the broker, defaulting to the exec’s working directory. The destination is not checked first: a copy into a path that does not exist fails for that file and says so.
solace-util broker copy into files... [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--dir |
(none) | destination directory inside the broker |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Deploy the broker and its prerequisites
Applies every prerequisite – namespace, secrets, TLS – then the broker, and is
safe to re-run. A running broker is restarted for a change only on consent or
–restart. Kubernetes readiness is not waited on; broker status watches it.
solace-util broker deploy [flags]
Also available as: dp
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (docker/podman only) |
--restart |
false |
restart an already-running broker when the deploy changed its artifact or its server certificate (otherwise you are asked, and a non-interactive run leaves it running) |
Render what deploy would apply, without applying it
Renders exactly what broker deploy would apply, without applying it.
Kubernetes output can be piped straight to kubectl apply -f -; prefer
-o/–out to > redirection, which PowerShell corrupts.
solace-util broker generate [flags]
Also available as: gen
Renders to stdout and changes nothing: it runs no external command, so it needs no cluster or runtime, runs no preflight, and refuses --allow-command – there is nothing here for it to approve.
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--no-prompt |
false |
answer yes to the –out overwrite question (no effect without –out) |
-o, --out |
(none) | write the artifact to this file instead of stdout |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (docker/podman only) |
Read the broker’s logs
Reads the picked pod’s log (Kubernetes) or this host’s container’s log (docker/podman).
solace-util broker logs [flags]
Also available as: lg
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
-f, --follow |
false |
keep streaming new lines instead of exiting |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
-p, --previous |
false |
read the PREVIOUS container’s logs instead of the current one (kubernetes only) |
--since |
(none) | read only lines newer than this duration (e.g. 30s, 5m, 2h) |
--tail |
(none) | print only this many trailing lines (a count, or all) |
--timestamps |
false |
prefix each line with its timestamp |
Run a one-shot action against the broker
One-shot actions against a running broker; not settings the env file describes.
assert-leader assert the primary as config-sync leader (HA)
redundancy-test exercise a real failover and fail back (HA, INVASIVE)
gather-diagnostics collect a support bundle into broker.hostDiagnosticDir
semp-login-check prove the admin credentials work over SEMP
export-config capture the broker’s configuration as one artifact
import-config
solace-util broker perform
Runs nothing on its own. It names what solace-util broker perform can act on – assert-leader, cli-script, data-replication, export-config, gather-diagnostics, import-config, redundancy-test, semp-login-check, shell-script – and given a word it does not know it fails rather than reporting success.
Also available as: pf
Assert the config-sync leader (HA only)
Asserts this node as config-sync leader for the router and every message-VPN, overwriting the mate’s configuration with its own; the node must report Local Active. Kubernetes uses the primary pod; on docker/podman a backup host asks first and the monitor is refused. A no-op on a standalone deployment.
solace-util broker perform assert-leader [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask (docker/podman only) |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (docker/podman only) |
Run a Solace CLI script in the broker
Uploads a Solace CLI script from broker.cliScriptsDir and runs it in the broker. Give the file’s name, not a path; a name not in that folder fails.
The broker stops at the first rejected line, which fails the run.
solace-util broker perform cli-script <file> [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Move replication roles across the DR pair
Moves each message-VPN’s replication role to the site the env file names, across BOTH brokers: demote at the losing site, confirm it, then promote.
It changes no configuration – run broker configure data-replication first.
Refuses unless both sites are on their primary HA node and name each other.
Interrupts message flow for every VPN it moves.
solace-util broker perform data-replication [flags]
Also available as: dr
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Capture the broker’s configuration as one artifact
Captures the broker’s configuration as a replayable Solace CLI script; it changes nothing on the broker.
–vpn NAME (repeatable) narrows to those VPNs; –broker-only excludes them instead – naming both is refused.
solace-util broker perform export-config [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--broker-only |
false |
capture only broker-level configuration, and no message-VPN at all |
--no-prompt |
false |
answer yes to the –out overwrite question (no effect without –out) |
-o, --out |
(none) | write the artifact to this file instead of stdout |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
--vpn |
[] |
capture only this message-VPN, repeatable for several; omit it and every VPN is captured |
Gather a support bundle into broker.hostDiagnosticDir
Runs the broker’s full diagnostic sweep and downloads the resulting bundle to broker.hostDiagnosticDir.
Kubernetes collects one bundle per role by default; –pod narrows to just one.
solace-util broker perform gather-diagnostics [flags]
Also available as: gd
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--days |
1 |
days of logs/diagnostics to gather |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Apply a captured configuration back to the broker
Applies a broker perform export-config artifact back to a running
broker. Only that command’s own output is accepted; to run any other script,
use broker perform cli-script.
Any message-VPN in the artifact that already exists on the target is torn down and rebuilt, destroying every message spooled in it.
solace-util broker perform import-config <file> [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Exercise a real failover and fail back (HA only)
Fails the broker over to its mate and back for real; a no-op on a standalone deployment.
A Ctrl-C partway through can leave the group failed over; see docs/operations.md to recover.
solace-util broker perform redundancy-test [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (docker/podman only) |
Test an authenticated SEMP request against the broker
Runs an authenticated SEMP request from inside the broker and reports whether the credentials were accepted. On Kubernetes without semp.adminPass it reads the password from the admin Secret the broker uses.
Run this after rotating the admin password.
solace-util broker perform semp-login-check [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Run a host shell script inside the broker
Uploads a shell script from broker.cliScriptsDir and runs it with bash inside the broker, as the broker’s own user. Give the file’s name, not a path.
Bash reports one exit status for the whole run, and the full output is shown.
solace-util broker perform shell-script <file> [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Remove the broker, prompting for each layer
Removes the deployed broker and its secrets on every platform.
This permanently deletes the broker; add –delete-data (with its own confirmation) to also destroy its persistent data.
solace-util broker remove [flags]
Also available as: rm
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--delete-data |
false |
delete the broker’s persistent data too (Kubernetes PVCs, or the contents of the container data directory). Without it the data is kept |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask. It does not RAISE a question – without –delete-data, persistent data is still kept |
Bounce the broker’s pod(s) or container
Restarts the broker’s pod(s) gracefully (Kubernetes), or the container (docker/podman).
With no –pod every pod is bounced in turn: monitor, then backup, then primary.
This drops in-flight messaging on whatever it bounces.
solace-util broker restart [flags]
Also available as: rs
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Open an interactive shell in the broker
Interactive only; execs bash into the picked pod (Kubernetes) or this
host’s container (docker/podman).
To run a script instead of typing at a prompt, use
broker perform shell-script <file>.
solace-util broker shell [flags]
Also available as: sh
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Start a broker that is deployed but not running
Starts what broker deploy already created; it does not create anything
itself.
Kubernetes starts primary, then backup, then monitor, waiting for each rollout.
solace-util broker start [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
Report the broker’s deployment status
Reports pod/container state, plus the operator’s CR conditions on Kubernetes.
–all is how to find a broker whose env file you have lost.
solace-util broker status [flags]
Also available as: sts
| Flag | Default | Meaning |
|---|---|---|
--all |
false |
report every Solace broker found, not just the one this env file describes (Kubernetes: across all namespaces; docker/podman: every Solace container on this host) |
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--detail |
false |
include the static artifacts, not just the running ones (Kubernetes: secrets, configmaps and PVCs; docker/podman: mounts, which is also where secrets appear) |
--pod |
(none) | role to act on: primary (p), backup (b) or monitor (m). Kubernetes: which pod. Docker/podman: which node THIS host is, detected from this host’s name or address when omitted (kubernetes only) |
Stop a running broker without removing it
Scales the broker to zero replicas, or stops the container, without deleting anything.
This takes messaging down until broker start brings it back.
solace-util broker stop [flags]
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
Check the env file and what this broker needs
Read-only, and safe to run against a system you don’t want to disturb.
Reports every problem it finds in one pass, rather than stopping at the first.
solace-util broker validate [flags]
Also available as: vld
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
Convert a legacy bash env file into a YAML env file
Convert a legacy bash env file – the pre-Go format sourced by bash/000-env.sh – into the YAML env file this CLI reads.
The target platform section is detected from the variables present; pass –platform to choose it yourself. Variables with no YAML equivalent are reported on stderr rather than dropped silently.
The output carries every secret from the source file verbatim, so treat it like the source: write it with -o rather than through a shared terminal, and never commit it.
solace-util convert bash/env/prod -o prod.yaml solace-util convert bash/env/prod –platform podman -o prod.yaml solace-util check deploy -e prod.yaml
solace-util convert <bash-env-file> [flags]
Also available as: cv
| Flag | Default | Meaning |
|---|---|---|
--no-prompt |
false |
answer yes to the –out overwrite question (no effect without –out) |
-o, --out |
(none) | write the artifact to this file instead of stdout |
Print a sample env file to start from
Bare examples prints the FULL annotated schema: every key the loader accepts and
the default each omitted one takes.
–platform writes a minimal STARTER instead – only the keys that platform cannot default, declaring only its own section, so the file it writes needs no –platform afterwards. It reads no env file and contacts nothing.
Every secret is a CHANGE-ME placeholder the broker refuses until you edit it. Each has a sibling *Env key naming a variable to read instead, which is what keeps a committed env file secret-free.
solace-util examples –platform docker -o env/dev.yaml solace-util examples | less solace-util eg –platform kube -o env/prod.yaml && solace-util validate -e env/prod.yaml
solace-util examples [flags]
Also available as: eg
| Flag | Default | Meaning |
|---|---|---|
--no-prompt |
false |
answer yes to the –out overwrite question (no effect without –out) |
-o, --out |
(none) | write the artifact to this file instead of stdout |
Install and operate the cluster-scoped EventBroker Operator (kubernetes only)
Installs and operates the operator, which is shared across every broker it watches.
operator deploy adds this env file’s namespaces to the watch list;
operator remove removes them, deleting the install only when nothing
else needs it.
solace-util operator
Runs nothing on its own. It names what solace-util operator can act on – deploy, generate, logs, remove, restart, start, status, stop, validate – and given a word it does not know it fails rather than reporting success.
Also available as: op
Applies to: kubernetes. On any other platform this command fails rather than doing nothing.
Install the operator, or add this env file’s namespaces to it (kubernetes only)
Installs the operator, or unions this env file’s namespaces into an already-running one’s watch list.
Widening the watch to all namespaces, or installing an older version, needs an interactive confirmation with no unattended override.
solace-util operator deploy [flags]
Also available as: dp
Applies to: kubernetes. On any other platform this command fails rather than doing nothing.
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
Render the operator install bundle (kubernetes only)
Renders everything operator deploy would apply, in apply order, without
applying it.
The watch list shown is only this env file’s; a real deploy unions it with whatever the running operator already watches.
solace-util operator generate [flags]
Also available as: gen
Applies to: kubernetes. On any other platform this command fails rather than doing nothing.
Renders to stdout and changes nothing: it runs no external command, so it needs no cluster or runtime, runs no preflight, and refuses --allow-command – there is nothing here for it to approve.
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--no-prompt |
false |
answer yes to the –out overwrite question (no effect without –out) |
-o, --out |
(none) | write the artifact to this file instead of stdout |
Read the operator’s controller logs (kubernetes only)
Runs kubectl logs against the controller Deployment, showing
reconciliation for every broker it watches, not just this env file’s.
solace-util operator logs [flags]
Also available as: lg
Applies to: kubernetes. On any other platform this command fails rather than doing nothing.
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
-f, --follow |
false |
keep streaming new lines instead of exiting |
--since |
(none) | read only lines newer than this duration (e.g. 30s, 5m, 2h) |
--tail |
(none) | print only this many trailing lines (a count, or all) |
--timestamps |
false |
prefix each line with its timestamp |
Release this env file’s claim on the operator (kubernetes only)
Removes this env file’s namespaces from the operator’s watch list, deleting the operator itself only when nothing else is left watching.
–delete-crd additionally deletes every PubSubPlusEventBroker in the cluster, and is refused while any broker resource still exists.
solace-util operator remove [flags]
Also available as: rm
Applies to: kubernetes. On any other platform this command fails rather than doing nothing.
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--delete-crd |
false |
delete the operator’s CustomResourceDefinitions too. Without it they are kept, so existing brokers survive |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask. It does not RAISE a question – without –delete-crd, the operator CRDs is still kept |
Bounce the operator’s controller (kubernetes only)
Runs a rollout restart on the operator’s controller Deployment; it does not change what is installed.
This briefly interrupts reconciliation for every broker the operator watches.
solace-util operator restart [flags]
Also available as: rs
Applies to: kubernetes. On any other platform this command fails rather than doing nothing.
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
Start the operator’s controller (kubernetes only)
Scales the controller Deployment back to one replica and waits for the rollout.
Reconciliation resumes for every namespace the operator watches.
solace-util operator start [flags]
Applies to: kubernetes. On any other platform this command fails rather than doing nothing.
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
Report the operator’s controller status (kubernetes only)
Reads the controller Deployment and its pods to report the running version and the namespaces it watches.
solace-util operator status [flags]
Also available as: sts
Applies to: kubernetes. On any other platform this command fails rather than doing nothing.
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--detail |
false |
include the full description of the operator deployment |
Stop the operator’s controller, freezing reconciliation (kubernetes only)
Scales the controller Deployment to zero.
This freezes reconciliation for every broker in every watched namespace,
not just this env file’s, until operator start.
solace-util operator stop [flags]
Applies to: kubernetes. On any other platform this command fails rather than doing nothing.
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
--no-prompt |
false |
do not ask: answer yes to every question this command would ask |
Check the operator’s install state and watch scope (kubernetes only)
Says whether an operator install is required for this env file’s broker namespace, and compares the running version with this env file’s.
Every value is read live from the cluster, since the operator is shared and may already watch namespaces this env file never named.
solace-util operator validate [flags]
Also available as: vld
Applies to: kubernetes. On any other platform this command fails rather than doing nothing.
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
Check the whole env file and what it needs
Reports both the broker and operator halves of the env file together;
broker validate and operator validate are the same rows, scoped.
Read-only; a [WARN] (such as an operator not installed yet) does not fail it, only a [FAIL] does.
solace-util validate [flags]
Also available as: vld
| Flag | Default | Meaning |
|---|---|---|
--allow-command |
[] |
approve one extra binary for the config’s platform command, for this run only (repeatable; a bare name, never a path). The env file cannot grant this |
Print the solace-util version
Print the version this binary was built at, plus the Go toolchain and platform that built it – useful to paste alongside a support request.
A release binary (built by scripts/dev.sh or dev.ps1) reports the git tag
it shipped as, e.g. v1.2.3 – matching the GitHub release exactly. A plain
go build . with no version stamped reports “dev”.
solace-util version
Also available as: ver