- Concept
- Create
Command reference
Last updated: September 29, 2026
Detailed usage, flags, and examples for all Change Intelligence CLI commands.
All commands accept a --dir flag to specify the working directory containing docker-compose.yml. If omitted, the CLI looks in the current directory, then falls back to a default path.
install
Set up a new self-hosted Liquibase Secure server deployment. This is the primary first-run command that handles everything from secret generation to health verification.
What it does
Resolve working directory (must contain
docker-compose.yml)Check for existing
.env(prevents accidental reinstall)Pre-flight checks: Docker 24+, Compose v2
Verify registry authentication
Generate
.envfrom.env.samplewith auto-generated secretsInstall TLS certificates: the pair given by
--tls-certand--tls-key, or a generated self-signed certificatePull container images from registry
Start database containers (
db,secrets-db,redis)Wait for database health
Run Liquibase migrations (primary DB + secrets DB), then record the version tag
Start full stack
Wait for API and web health, display success message
Flags
Flag | Required | Default | Description |
|---|---|---|---|
| No |
| Container image registry URL |
| No |
| Image version tag |
| No |
| Hostname for the TLS certificate and application URLs |
| No |
| Overwrite existing |
| No | Value from | GitHub username for |
| No |
| Skip the registry-auth pre-flight. Use this when Docker is authenticated through a credential helper the CLI cannot detect |
| No | None | Path to a TLS certificate in PEM format. Without it, a self-signed certificate is generated. Requires |
| No | None | Path to the TLS private key in PEM format. Requires |
Examples
update
Upgrade an existing deployment to a new version in place. Pulls the new images, runs the new version's database migrations, and recreates the services, preserving your data and secrets (unlike install --force).
What it does
Verifies registry authentication. Skipped for Early Access preview installs (
LIQUIBASE_PLATFORM_IMAGE_SOURCE=preview).Pulls the new
liquibase-platform-api,liquibase-platform-web, andliquibase-platform-migrateimages. Also skipped for Early Access preview installs, which run from images already loaded locally. The images are pulled before the old containers are released, so a pull that fails leaves your existing deployment onestartaway.Updates
IMAGE_TAGin your existing.env(andIMAGE_REGISTRYif--registryis given). Secrets are never regenerated. The previous file is kept beside it as.env.bak, and the new one is written atomically, so.envis never left half-written. If registry authentication or the pull fails, nothing in.envchanges.Starts the
db,secrets-db, andrediscontainers and waits for both databases to report healthy.Runs the new version's migrations against the primary database, then against the secrets database.
Recreates the services with the new images.
Waits for the API to pass its health check, and exits non-zero if it does not become reachable.
If a migration or the final health check fails, the command stops and says so. Your data and volumes are left intact and the databases stay running, so you can inspect them before retrying. If any step after the .env update fails, .env already names the new version and .env.bak holds the previous file. Re-run update once the cause is fixed, or restore .env from .env.bak to stay on the version you had.
Flags
Flag | Required | Default | Description |
|---|---|---|---|
| Yes | None | Image version to upgrade to (letters, digits, |
| No |
| Override the image registry |
| No | Current directory, then a default path | Working directory containing |
| No | Value from | GitHub username for |
| No |
| Skip the registry-auth pre-flight. Use this when Docker is authenticated through a credential helper the CLI cannot detect |
Examples
start
Start the Liquibase Secure server stack.
Checks that .env exists (must be installed first), runs docker compose up -d, health checks the API and web services, and displays the access URL.
Example
liquibase-platform startstop
Stop the Liquibase Secure server stack.
Flags
Flag | Default | Description |
|---|---|---|
|
| Remove data volumes. Prompts for confirmation before proceeding. |
|
| Skip confirmation prompts (for scripting) |
Without --reset, data volumes are preserved and the stack can be restarted with liquibase-platform start.
Examples
status
Show deployment status.
liquibase-platform status [--json]Displays a table with service name, status, health, and image for each container. Runs a quick 5-second API health check.
Flags
Flag | Default | Description |
|---|---|---|
|
| Output as JSON (includes all metrics) |
Example output
logs
View or bundle logs from the stack.
Flags
Flag | Default | Description |
|---|---|---|
| all | One or more service names to filter (can repeat) |
|
| Number of lines to show from end |
|
| Stream logs in real time |
|
| Generate a support diagnostic bundle |
Diagnostic bundle
When filing a support ticket, use --bundle to generate a tarball containing:
Docker logs (last 1000 lines per service)
System info (Docker version, OS, disk usage)
Container status (JSON)
Redacted
.envfile (secrets replaced with***REDACTED***)
liquibase-platform logs --bundle
# Creates: liquibase-platform-support-<timestamp>.tar.gzExamples
migrate
Run database migrations independently. Primarily used during upgrades to apply schema changes before restarting services.
liquibase-platform migrate [--dry-run]What it does
Loads registry and tag from
.envEnsures databases are running (starts them if needed)
Runs Liquibase
updateagainst the primary database (liquibase-platform-api.yml)Runs Liquibase
updateagainst the secrets databaseTags the migration (skipped for dry-run)
Flags
Flag | Default | Description |
|---|---|---|
|
| Run |
Examples
uninstall
Remove the Liquibase Secure server deployment.
What it does
Prompts for confirmation (unless
--non-interactive)Stops and removes containers
Removes the data volumes by name (unless
--keep-data)Deletes generated files
.env,.env.bakandcerts/(unless--keep-data)Preserves template files (
.env.sample,docker-compose.yml,default.conf.template)
Flags
Flag | Default | Description |
|---|---|---|
|
| Preserve the data volumes, |
|
| Skip confirmation prompts |
Note: With --keep-data, the deployment's data stays on disk in the volumes insights_insights-db-data, insights_insights-secrets-db-data and insights_redis-data. Remove those yourself when you no longer need the data.