Imperative create

kubectl-style generators that build a canonical object from flags and apply it.

Every kind carries a minimal rl <kind> create <name>. A few also have a rich generator, where rl <kind> create builds a complete object from flags and applies it, so you do not have to write the manifest by hand for the common case. There is no bespoke server endpoint behind this; the CLI generates an ordinary object and applies it like any other.

Add --dry-run -o yaml to print the generated object instead of applying it, which is a quick way to turn a command into a manifest you keep.

rl namespace create <name>

Create a Namespace. Alias: ns.

rl namespace create dev
rl ns create dev -l team=platform
rl ns create dev --dry-run -o yaml
FlagDescription
-l, --labels <name=value>Labels (repeatable or comma-separated).
--dry-runPrint the generated object instead of applying it.
-o, --output <format>With --dry-run, output format (yaml).
--as <subject>Impersonate a subject.
--home <dir>Data directory.

rl secret create <name>

Create a Secret. Values are never printed unmasked, and a Secret is broadcast to every origin of its namespace.

rl secret create db \
  --from-string password=s3cret \
  --from-file ca.crt=./ca.pem \
  -n dev
FlagDescription
--from-string <name=value>Literal data (repeatable).
--from-file <name=path>File content as data (repeatable).
-l, --labels <name=value>Labels (repeatable or comma-separated).
--dry-runPrint the generated object instead of applying it.
-o, --output <format>With --dry-run, output format (yaml).
-n, --namespace <ns>Namespace.
--as <subject>Impersonate a subject.
--home <dir>Data directory.

Note

--from-file reads the file content client-side and stores it as Secret data, so secret material never lands on disk in a manifest.

rl workstation create <name>

Create a Workstation. Alias: ws.

rl workstation create my-box
rl ws create my-box --config ide --provider gcp -l tier=dev
rl ws create my-box --dry-run -o yaml   # print, don't apply
FlagDescription
--config <name>WorkstationConfig to apply (repeatable).
--provider <name>Pin a provider (adds a provider:<x> requirement; omit for automatic placement).
--image <distribution>Base image distribution (e.g. debian).
-l, --labels <name=value>Labels (repeatable or comma-separated).
--dry-runPrint the generated object instead of applying it.
-o, --output <format>With --dry-run, output format (yaml).
-n, --namespace <ns>Namespace.
--as <subject>Impersonate a subject.
--home <dir>Data directory.

rl configmap create <name>

Create a ConfigMap: text that a config’s scripts and files can reference. Alias: cm.

rl configmap create bootstrap --from-file setup.sh=./setup.sh

It takes --from-file, --from-string and -l the way secret create does, and its values are not masked. The flags are listed in the ConfigMap reference.

rl sshkey create <name>

Create an SSHKey, which forwards a local private key into matching workstations.

rl sshkey create github --path ~/.ssh/id_ed25519

The flags are listed in the SSHKey reference.