Command Reference

The command reference follows the same operational grouping used by the One-Click help and interactive menus, so commands are organised by what they operate rather than presented as one flat list.

Aligned to the current public one-click.sh --help structure

Global Entry Points

Start here for system-wide tools and the top-level One-Click entry points.

one-click backupBackup or restore system data using rsync with optional remote targets.
one-click bench <version>Run the One-Click benchmark workflow for CPU, disk and network testing.
one-click bench-sysRun the Geekbench/sysbench-focused benchmark path.
one-click cronCreate or modify scheduled cron jobs.
one-click engine | one-click rule-engineOpen the human-readable firewall and security engine.
one-click helpDisplay the current CLI help menu.
one-click logs | one-click log-browserBrowse and inspect system logs.
one-click menuOpen the grouped interactive control-plane menu.
one-click recoveryBackup and restore boot partitions and bootloader state.
one-click fleet …Operate the controller-driven Fleet engine.
one-click reinstallPerform the guided operating-system reinstall workflow.
one-click net-repairDiagnose and repair network configuration.
one-click netView network statistics.
one-click system | one-click sys-infoDisplay detailed system information.
one-click uninstallRemove One-Click and associated files.
one-click --versionDisplay the installed One-Click version.

Fleet Orchestration

Controller-driven server orchestration. Fleet uses Ansible as its foundational execution engine.

one-click fleet initInitialise Fleet configuration, directory trees and SSH keys.
one-click fleet add <ip> <host> [port]Register a server in Fleet.
one-click fleet remove <host> | one-click fleet rm <host>Remove a Fleet member.
one-click fleet verifyTest Fleet SSH connectivity through Ansible.
one-click fleet update-keysRotate Fleet SSH keys.
one-click fleet updateRun One-Click update across active Fleet members.
one-click fleet auditCollect hardware/system profiles from Fleet members.
one-click fleet listList Fleet members and addresses.
one-click fleet statusView status of recent distributed benchmarks.
one-click fleet migrate-masterMove the Fleet controller role to another member.
one-click fleet --syncSynchronise Fleet nodes with controller authority.
one-click fleet rule-engine | one-click fleet engineRun Fleet firewall management through Rule Engine.
one-click fleet dir <host> <directory>List a directory on a Fleet member.
one-click fleet put <host> <src> <dest>Upload files/directories to a Fleet member.
one-click fleet get <host> <src> <dest>Download files/directories from a Fleet member.
one-click fleet raw <host> '<command>'Execute a direct remote shell command on a Fleet member.
one-click clone-site <site> <peer>Clone a supported site/application to a Fleet peer.
one-click restore-site <site> <peer>Restore a supported site/application from a Fleet peer.
one-click mv <directory> <peer>Move directory content to a Fleet member.
one-click fleet verify
one-click fleet audit
one-click fleet raw web01 "systemctl status nginx"

Benchmarking

Local and Fleet-wide benchmark commands are separate so you can compare one host or orchestrate many.

one-click bench <version>Run a local benchmark workflow.
one-click bench-sysRun only Geekbench/sysbench-focused tests.
one-click fleet bench <version>Run a benchmark asynchronously across Fleet members.
one-click fleet bench --exclude <server>Exclude a Fleet member from a distributed benchmark.
one-click fleet bench --summary [vm]View benchmark history for the Fleet or a selected VM.
one-click fleet statusTrack the most recent Fleet benchmark run.
one-click fleet auditCollect current hardware architecture information alongside benchmark data.

KVM / VPS Lifecycle

Create and operate NAT or public KVM guests on the controller or Fleet hypervisors.

one-click --vps createCreate a KVM instance on a selected hypervisor.
one-click --vps deleteDelete a VPS from its hypervisor.
one-click --vps editEdit VPS configuration.
one-click --vps consoleAccess the serial console workflow.
one-click --vps reinstallReinstall the guest operating system.
one-click --vps snapshotCreate, delete or restore snapshots.
one-click --vps backupCreate, delete or restore VPS backups.
one-click --vps patchPatch one VM or the supported fleet scope.
one-click --vps migrateMigrate an existing KVM VPS between trusted Fleet hypervisors by moving the VM disk and libvirt definition.
one-click --vps importImport a complete external Linux VPS into a newly built, like-for-like Fleet replacement.
one-click --vps export --name <vps_name>Export a Fleet VPS into a fresh external Linux replacement while retaining the original Fleet VPS for validation.
one-click --vps startStart a VPS.
one-click --vps stopStop a VPS.
one-click --vps info <vps_name>Show storage, memory and resource information.
one-click --vps viewView available snapshots.
one-click --vps list | one-click --vps menuList VPS instances, mapped IPs and owning hypervisors.
-n | --nameVPS instance name.
-t | --targetTarget Fleet hypervisor.
-m | --modeNetwork mode: NAT or public.
-i | --imageGuest image/profile.
-d | --diskGuest storage size.
-c | --cpuvCPU count.
-r | --ramGuest RAM.
-p | --ipPublic IP option for public-mode deployments.
-w | --passwordPassword for the guest oneclick administrator.
-l | --languageWindows installation language when applicable.
one-click --vps create --target hypervisor1 --name db1 --image ubuntu24 --cpu 1 --ram 1G --disk 6G --mode nat --password <password>

VM Console, VNC and Edge Publishing

Out-of-band guest access and HAProxy edge publishing for private/NAT workloads.

one-click --console <vm_name> [host]Attach directly to the libvirt serial console.
one-click --vnc <vm_name> [duration]Create a temporary, token-protected noVNC recovery session.
one-click --proxy --target <vm> --source <port> --port <public-port>Publish a TCP service through the hypervisor edge.
one-click --proxy --target <vm> --website <fqdn> --proto <http|https>Publish web traffic through the HAProxy edge.
one-click --ssh <peer_name>Connect to a Fleet/NAT peer using the managed SSH path.

Firewall, Audit and IDS

Human-readable firewall operations plus auditing, ban management, AbuseIPDB lookup and filesystem scanning.

one-click engine --dry-run "…"Preview generated firewall changes without applying them.
one-click engine open [table|all]Display firewall rules in a readable table.
one-click engine flush <table> | flush allFlush one firewall table or all supported tables.
one-click engine backup | saveBack up the current firewall configuration.
one-click engine restoreRestore a saved firewall configuration.
one-click engine raw <iptables cmd>Run an advanced raw iptables command.
one-click engine chain create <chain>Create a custom firewall chain.
one-click engine allow <arg>Accept matching traffic.
one-click engine deny <arg> | drop <arg>Drop matching traffic.
one-click engine reject <arg> | decline <arg>Reject matching traffic with a response.
one-click engine delete <arg> | remove <arg>Delete rules, aliases or firewall backups.
one-click engine mask | hideEnable NAT masquerading.
one-click engine "allow ssh from office"Use a source IP/CIDR/alias in a readable rule.
one-click engine "allow 443 to 10.0.0.5"Target a destination address/interface.
one-click engine enable icmp | echoEnable ICMP echo requests.
one-click engine disable icmp | echoDisable ICMP echo requests.
one-click engine "allow udp port 100"Select UDP instead of default TCP.
one-click engine "… multiport 50 556 4000"Apply one rule to multiple ports.
one-click engine "range 1000-2000"Use a port range.
one-click engine alias-create <name> <ips…>Create a named IP group.
one-click engine alias-append <name> <ips…>Append addresses to an alias.
one-click engine alias-prune <name> <ips…>Remove addresses from an alias.
one-click engine sensitive <ports…>Mark ports that require extra confirmation.
one-click engine sensitive-listList sensitive ports.
one-click engine sensitive-remove <ports…>Remove ports from the sensitive list.
one-click engine auditInspect firewall rules, drops and security activity.
one-click engine audit sshReview detected SSH brute-force attempts.
one-click engine audit block <ID> [dur=N|perm]Block an audited attacker temporarily or permanently.
one-click engine audit unblock <ID>Remove an audit block.
one-click engine audit historyReview historic mitigation actions.
one-click engine audit banlistShow the combined Rule Engine and Fail2Ban ban list.
one-click engine 'audit jail <name> port <port> retry <count>'Create an additional Fail2Ban jail.
one-click engine audit key <APIKEY>Configure AbuseIPDB integration.
one-click engine audit lookup <IP>Look up an IP reputation through AbuseIPDB.
one-click engine audit scan --initInitialise the IDS baseline.
one-click engine audit scanRun the lightweight integrity/malware scan.
one-click engine audit scan --deepRun deeper filesystem inspection.
one-click engine audit scan --remediateAuthorise supported IDS auto-remediation.
one-click engine --dry-run "allow https"
one-click engine "allow ssh from office and deny ssh from blacklist"

Websites and Application Hosting

Provision and operate isolated web/application environments using native Linux web servers and services.

one-click --web-createCreate a blank static HTML or PHP website.
one-click --web-adminManage/backup an existing static site.
one-click --wp-createInstall WordPress with Nginx or Apache.
one-click --wpOpen basic WordPress and cron management.
one-click --wp-adminManage WordPress staging, backups, SSL and lifecycle operations.
one-click --nodejs-createInstall a Node.js application with Nginx or Apache.
one-click --nodejs-adminStart, stop and manage Node.js applications.
one-click --nextcloud-createCreate an isolated Nextcloud instance.
one-click --nextcloud-adminManage Nextcloud instances.
one-click --db-adminManage databases and create temporary web administration access.
one-click --sslInstall TLS for WordPress or another virtual host.
one-click --phpManage system-wide or per-site PHP settings.
one-click --permission-repairRepair hosting permissions across sites, PHP, databases and backups.

For step-by-step site administration, see Node.js management, Nextcloud hosting and WordPress hosting.

Networking, DNS and Private Mesh

Network diagnostics, DNS provider workflows, WireGuard device profiles and private Fleet access.

one-click netView network statistics.
one-click net-repairDiagnose and repair network configuration.
one-click --dnsManage DNS through BIND, Cloudflare and supported provider workflows.
one-click --wireguard add-userCreate a new external-device profile for the private mesh.
one-click --wireguard delete-userRemove a WireGuard device profile.
one-click --wireguard viewView active WireGuard profiles.
one-click --proxy …Publish NAT/private services through a Fleet hypervisor.
one-click --ssh <peer_name>Connect to a managed private/NAT peer.

Backup and Recovery

Local data protection, boot recovery, operating-system recovery and workload-level continuity.

one-click backupOpen rsync/rclone backup and restore workflows.
one-click recoveryBack up or restore BIOS/UEFI/GRUB boot state.
one-click reinstallRun the full OS reinstall workflow.
one-click net-repairRecover broken network configuration.
one-click clone-site <site> <peer>Clone a supported workload to a Fleet peer.
one-click restore-site <site> <peer>Restore a supported workload from a Fleet peer.