• Concept
  • Create

Command reference

Last updated: September 29, 2026

Detailed usage, flags, and examples for all Change Intelligence CLI commands.

All commands accept a --dir flag to specify the working directory containing docker-compose.yml. If omitted, the CLI looks in the current directory, then falls back to a default path.

install

Set up a new self-hosted Liquibase Secure server deployment. This is the primary first-run command that handles everything from secret generation to health verification.

loading

What it does

  1. Resolve working directory (must contain docker-compose.yml)

  2. Check for existing .env (prevents accidental reinstall)

  3. Pre-flight checks: Docker 24+, Compose v2

  4. Verify registry authentication

  5. Generate .env from .env.sample with auto-generated secrets

  6. Install TLS certificates: the pair given by --tls-cert and --tls-key, or a generated self-signed certificate

  7. Pull container images from registry

  8. Start database containers (db, secrets-db, redis)

  9. Wait for database health

  10. Run Liquibase migrations (primary DB + secrets DB), then record the version tag

  11. Start full stack

  12. Wait for API and web health, display success message

Flags

Flag

Required

Default

Description

--registry

No

ghcr.io/liquibase

Container image registry URL

--tag

No

latest

Image version tag

--domain

No

localhost

Hostname for the TLS certificate and application URLs

--force

No

false

Overwrite existing .env (for reinstall)

--github-user

No

Value from gh api user

GitHub username for ghcr.io auto-login

--skip-registry-auth

No

false

Skip the registry-auth pre-flight. Use this when Docker is authenticated through a credential helper the CLI cannot detect

--tls-cert

No

None

Path to a TLS certificate in PEM format. Without it, a self-signed certificate is generated. Requires --tls-key

--tls-key

No

None

Path to the TLS private key in PEM format. Requires --tls-cert

Examples

loading

update

Upgrade an existing deployment to a new version in place. Pulls the new images, runs the new version's database migrations, and recreates the services, preserving your data and secrets (unlike install --force).

loading

What it does

  1. Verifies registry authentication. Skipped for Early Access preview installs (LIQUIBASE_PLATFORM_IMAGE_SOURCE=preview).

  2. Pulls the new liquibase-platform-api, liquibase-platform-web, and liquibase-platform-migrate images. Also skipped for Early Access preview installs, which run from images already loaded locally. The images are pulled before the old containers are released, so a pull that fails leaves your existing deployment one start away.

  3. Updates IMAGE_TAG in your existing .env (and IMAGE_REGISTRY if --registry is given). Secrets are never regenerated. The previous file is kept beside it as .env.bak, and the new one is written atomically, so .env is never left half-written. If registry authentication or the pull fails, nothing in .env changes.

  4. Starts the db, secrets-db, and redis containers and waits for both databases to report healthy.

  5. Runs the new version's migrations against the primary database, then against the secrets database.

  6. Recreates the services with the new images.

  7. Waits for the API to pass its health check, and exits non-zero if it does not become reachable.

If a migration or the final health check fails, the command stops and says so. Your data and volumes are left intact and the databases stay running, so you can inspect them before retrying. If any step after the .env update fails, .env already names the new version and .env.bak holds the previous file. Re-run update once the cause is fixed, or restore .env from .env.bak to stay on the version you had.

Flags

Flag

Required

Default

Description

--tag

Yes

None

Image version to upgrade to (letters, digits, _, . or -)

--registry

No

IMAGE_REGISTRY from .env

Override the image registry

--dir

No

Current directory, then a default path

Working directory containing docker-compose.yml

--github-user

No

Value from gh api user

GitHub username for ghcr.io auto-login

--skip-registry-auth

No

false

Skip the registry-auth pre-flight. Use this when Docker is authenticated through a credential helper the CLI cannot detect

Examples

loading

start

Start the Liquibase Secure server stack.

loading

Checks that .env exists (must be installed first), runs docker compose up -d, health checks the API and web services, and displays the access URL.

Example

liquibase-platform start

stop

Stop the Liquibase Secure server stack.

loading

Flags

Flag

Default

Description

--reset

false

Remove data volumes. Prompts for confirmation before proceeding.

--non-interactive

false

Skip confirmation prompts (for scripting)

Without --reset, data volumes are preserved and the stack can be restarted with liquibase-platform start.

Examples

loading

status

Show deployment status.

liquibase-platform status [--json]

Displays a table with service name, status, health, and image for each container. Runs a quick 5-second API health check.

Flags

Flag

Default

Description

--json

false

Output as JSON (includes all metrics)

Example output

loading

logs

View or bundle logs from the stack.

loading

Flags

Flag

Default

Description

--service

all

One or more service names to filter (can repeat)

--tail

100

Number of lines to show from end

--follow / -f

false

Stream logs in real time

--bundle

false

Generate a support diagnostic bundle

Diagnostic bundle

When filing a support ticket, use --bundle to generate a tarball containing:

  • Docker logs (last 1000 lines per service)

  • System info (Docker version, OS, disk usage)

  • Container status (JSON)

  • Redacted .env file (secrets replaced with ***REDACTED***)

liquibase-platform logs --bundle
# Creates: liquibase-platform-support-<timestamp>.tar.gz

Examples

loading

migrate

Run database migrations independently. Primarily used during upgrades to apply schema changes before restarting services.

liquibase-platform migrate [--dry-run]

What it does

  1. Loads registry and tag from .env

  2. Ensures databases are running (starts them if needed)

  3. Runs Liquibase update against the primary database (liquibase-platform-api.yml)

  4. Runs Liquibase update against the secrets database

  5. Tags the migration (skipped for dry-run)

Flags

Flag

Default

Description

--dry-run

false

Run updateSQL to preview migration SQL without applying

Examples

loading

uninstall

Remove the Liquibase Secure server deployment.

loading

What it does

  1. Prompts for confirmation (unless --non-interactive)

  2. Stops and removes containers

  3. Removes the data volumes by name (unless --keep-data)

  4. Deletes generated files .env, .env.bak and certs/ (unless --keep-data)

  5. Preserves template files (.env.sample, docker-compose.yml, default.conf.template)

Flags

Flag

Default

Description

--keep-data

false

Preserve the data volumes, .env, .env.bak and certificates, so the deployment can be brought back with update

--non-interactive

false

Skip confirmation prompts

Note: With --keep-data, the deployment's data stays on disk in the volumes insights_insights-db-data, insights_insights-secrets-db-data and insights_redis-data. Remove those yourself when you no longer need the data.

Examples

loading