--admin-email | string | — | v0.6 compatibility only: admin email for login accounts |
--api-version | string | stackkit/v2alpha2 | StackSpec contract (stackkit/v2alpha2; explicit legacy adapter: stackkit/v2alpha1) |
--candidate-spec | string | — | Native v2 only: preserve a complete CUE-valid StackSpec from a file or - for stdin; excludes authoring overrides |
--catalog-defaults | bool | — | Accept CUE catalog defaults for omitted native alternatives and compute profiles; persist explicit intent |
--cloud-oidc-client-id | string | — | v0.6 compatibility only: Cloud OIDC client ID |
--cloud-oidc-client-secret-ref | string | — | v0.6 compatibility only: Cloud OIDC client secret reference (e.g. secret://) |
--cloud-oidc-foreign-subject | string | — | v0.6 compatibility only: Cloud user’s foreign subject ID |
--cloud-oidc-issuer | string | — | v0.6 compatibility only: Cloud OIDC issuer URL for auto/cloud owner handoff |
--cluster-mode | string | first | v0.6 compatibility only: cluster mode (first|join) |
--compute-tier | string | — | Legacy v2alpha1 only: declared kit graph (low, standard, high) |
--domain | string | — | Domain override for the generated stack spec |
--enable | strings | — | Native v2 only: optional kit capabilities to enable (capabilities.enable, e.g. lan-dns,internal-pki) |
--expected-spec-hash | string | — | Native v2 only: exact current CUE-normalized spec hash required for replacement |
--force, -f | bool | — | v0.6 compatibility only: overwrite existing files |
--hardware-profile | string | — | Device class for nodes[0].hardware.profile (standard, pi, gpu, storage). pi is a constrained homelab device, not Raspberry-only. Not auto-detected from inventory |
--local-dns | bool | — | v0.6 compatibility only: use Kombify Point local DNS names |
--local-name | string | — | v0.6 compatibility only: local DNS short name for --local-dns |
--mode | string | — | v0.6 compatibility only: installation mode (bare, bootstrapped, advanced) |
--module-accelerator-profile | stringArray | — | Native v2alpha2: module-id=accelerator-profile for a declared accelerator dimension |
--module-compute-profile | stringArray | — | Native v2alpha2: module-id=profile; repeat for every selected workload module |
--module-storage-profile | stringArray | — | Native v2alpha2: module-id=storage-profile for a declared storage dimension |
--name | string | — | Deployment contract ID (defaults to a normalized working-directory name) |
--non-interactive | bool | — | Run in non-interactive mode (fail if input is required) |
--output, -o | string | deploy | v0.6 compatibility only: output directory for generated files |
--owner-bootstrap-mode | string | — | v0.6 compatibility only: owner bootstrap mode (auto|custom|none) |
--owner-display-name | string | — | Desired PocketID owner display name for --owner-source=local |
--owner-email | string | — | Desired PocketID owner email for --owner-source=local |
--owner-source | string | — | Owner custody source (native standalone: local; v0.6 compatibility: local|cloud) |
--owner-username | string | — | Desired PocketID owner username for --owner-source=local |
--platform | string | — | Native v2 only: selected-provider platform adapter (install.platform.providerRef, e.g. coolify or komodo) |
--recovery-material-ref | string | — | v0.6 compatibility only: reference to orchestrator-owned recovery material; plaintext recovery passphrases are never accepted in stack specs |
--recovery-passphrase-hash | string | — | v0.6 compatibility only: recovery passphrase hash (argon2id PHC); prompts when missing |
--service-profile | string | — | v0.6 compatibility only: BaseKit service profile |
--use-case | strings | — | Optional kit workloads to enable (e.g. photos,files,vault); v2alpha2 requires explicit alternatives |
--use-case-alternative | stringArray | — | Native v2alpha2: use-case-id=alternative; include required core workloads |