stado credentials vault
Invocation
stado credentials vault [OPTIONS] [COMMAND]Purpose
Report which vault this machine's credential operations resolve to, and why. Every write and every authoritative read here goes through one file, and until this command existed nothing said which — the answer lived in a discovery rule and one environment variable, and it surfaced only as a refusal from whatever command hit it. On 2026-09-05 that was `stado repair stado --step release-verifier`, after two vaults on this machine had been claiming one owner for long enough to close the fleet's release publication boundary. Exits non-zero when nothing resolves, so a script can gate on it.
Required inputs and options
| Input or option | Contract |
|---|---|
--json | Emit JSON instead of a table |
Output and state effect
This command group selects one of the subcommands listed below; use its exact child invocation to perform an operation.
Refusals
- Before dispatch, Stado refuses a missing required token shown in the invocation, an unknown option, or a value outside a listed value set; argument-usage failures exit with code 2.
Subcommands
sync— Pull a host's Skarbiec mirror into its declared live vault