Skip to content
CLI Configuration

CLI Configuration

The DCM CLI (dcm) connects to the DCM control plane to manage resources. It can be configured through command-line flags, environment variables, or a configuration file.

For installation instructions, see Setting Up the CLI.

Configuration File

The CLI reads its configuration from ~/.dcm/config.yaml by default. Here is an example with all available fields:

control-plane-url: http://localhost:8080
output-format: table
timeout: 30
tls-ca-cert: ""
tls-client-cert: ""
tls-client-key: ""
tls-skip-verify: false
issuer-url: ""

When the control plane requires authentication, set issuer-url or use dcm login (see Authentication).

Configuration Priority

Settings are resolved in the following order (highest priority first):

  1. Command-line flags
  2. Environment variables (prefixed with DCM_)
  3. Configuration file
  4. Built-in defaults

Global Flags

The following flags are available on all commands:

FlagShortDefaultDescription
--control-plane-urlhttp://localhost:8080URL of the DCM control plane
--output-otableOutput format (table, json, yaml)
--timeout30Request timeout in seconds
--config~/.dcm/config.yamlPath to configuration file
--issuer-url(empty)OIDC issuer URL for authentication
--token(empty)Bearer token (skips interactive login)

Authentication

When the control plane has authentication enabled, the CLI must send a JWT bearer token on each request. Use one of the following approaches:

Interactive login

Run dcm login after setting the issuer URL. The command runs the OIDC device authorization flow in your browser and stores tokens locally.

For the reference compose stack, map the hostname keycloak on your host before login (see Local compose: host access to Keycloak).

dcm login --issuer-url http://keycloak:8080/realms/dcm \
  --control-plane-url http://localhost:8080

On success, issuer-url is saved in the config file. Use dcm logout to revoke stored refresh tokens and clear credentials.

Static token

For scripts and CI, pass a bearer access token without using the device flow:

Flag / variableDescription
--tokenBearer access token for this invocation
DCM_TOKENSame as --token, via environment variable

When --token or DCM_TOKEN is set, the CLI does not read the token store. If both a static token and issuer-url are configured, the static token is used for API requests (--token and DCM_TOKEN follow the usual flag-over-env precedence). Stored login sessions and dcm logout still use issuer-url.

Auth-related settings

Flag / variableConfig keyDescription
--issuer-urlissuer-urlOIDC issuer URL (required for dcm login / dcm logout)
DCM_ISSUER_URLissuer-urlEnvironment override for issuer URL

If issuer-url is set (and no static token is configured), the CLI loads tokens from the OS keyring or ~/.dcm/tokens.json and refreshes access tokens before they expire.

Full workflows, control-plane settings, and troubleshooting are in Authentication.

TLS Configuration

To connect to a TLS-secured control plane, use the following flags:

FlagDescription
--tls-ca-certPath to CA certificate file for TLS verification
--tls-client-certPath to client certificate file for mutual TLS
--tls-client-keyPath to client private key file for mutual TLS
--tls-skip-verifySkip TLS certificate verification (not recommended for production)

Output Formats

All commands support three output formats via the -o flag:

  • table (default) — Human-readable tabular output.
  • json — Structured JSON output, useful for scripting and automation.
  • yaml — YAML output.

For example, to list catalog items as JSON:

dcm catalog item list -o json

Shell Completion

Generate shell completion scripts with the dcm completion command:

# Bash
source <(dcm completion bash)

# Zsh
source <(dcm completion zsh)

# Fish
dcm completion fish | source

# PowerShell
dcm completion powershell | Out-String | Invoke-Expression

To make completion persistent, add the appropriate command to your shell profile (e.g., ~/.bashrc, ~/.zshrc).