CLI reference / credentials / vault

stado credentials vault

Invocation

stado credentials vault [OPTIONS] [COMMAND]

Purpose

Report which vault this machine's credential operations resolve to, and why. Every write and every authoritative read here goes through one file, and until this command existed nothing said which — the answer lived in a discovery rule and one environment variable, and it surfaced only as a refusal from whatever command hit it. On 2026-09-05 that was `stado repair stado --step release-verifier`, after two vaults on this machine had been claiming one owner for long enough to close the fleet's release publication boundary. Exits non-zero when nothing resolves, so a script can gate on it.

Required inputs and options

Input or optionContract
--jsonEmit JSON instead of a table

Output and state effect

This command group selects one of the subcommands listed below; use its exact child invocation to perform an operation.

Refusals

  • Before dispatch, Stado refuses a missing required token shown in the invocation, an unknown option, or a value outside a listed value set; argument-usage failures exit with code 2.

Subcommands

  • sync Pull a host's Skarbiec mirror into its declared live vault