Command Reference
The command reference follows the same operational grouping used by the One-Click help and interactive menus, so commands are organised by what they operate rather than presented as one flat list.
one-click.sh --help structureGlobal Entry Points
Start here for system-wide tools and the top-level One-Click entry points.
one-click backupBackup or restore system data using rsync with optional remote targets.one-click bench <version>Run the One-Click benchmark workflow for CPU, disk and network testing.one-click bench-sysRun the Geekbench/sysbench-focused benchmark path.one-click cronCreate or modify scheduled cron jobs.one-click engine | one-click rule-engineOpen the human-readable firewall and security engine.one-click helpDisplay the current CLI help menu.one-click logs | one-click log-browserBrowse and inspect system logs.one-click menuOpen the grouped interactive control-plane menu.one-click recoveryBackup and restore boot partitions and bootloader state.one-click fleet …Operate the controller-driven Fleet engine.one-click reinstallPerform the guided operating-system reinstall workflow.one-click net-repairDiagnose and repair network configuration.one-click netView network statistics.one-click system | one-click sys-infoDisplay detailed system information.one-click uninstallRemove One-Click and associated files.one-click --versionDisplay the installed One-Click version.Fleet Orchestration
Controller-driven server orchestration. Fleet uses Ansible as its foundational execution engine.
one-click fleet initInitialise Fleet configuration, directory trees and SSH keys.one-click fleet add <ip> <host> [port]Register a server in Fleet.one-click fleet remove <host> | one-click fleet rm <host>Remove a Fleet member.one-click fleet verifyTest Fleet SSH connectivity through Ansible.one-click fleet update-keysRotate Fleet SSH keys.one-click fleet updateRun One-Click update across active Fleet members.one-click fleet auditCollect hardware/system profiles from Fleet members.one-click fleet listList Fleet members and addresses.one-click fleet statusView status of recent distributed benchmarks.one-click fleet migrate-masterMove the Fleet controller role to another member.one-click fleet --syncSynchronise Fleet nodes with controller authority.one-click fleet rule-engine | one-click fleet engineRun Fleet firewall management through Rule Engine.one-click fleet dir <host> <directory>List a directory on a Fleet member.one-click fleet put <host> <src> <dest>Upload files/directories to a Fleet member.one-click fleet get <host> <src> <dest>Download files/directories from a Fleet member.one-click fleet raw <host> '<command>'Execute a direct remote shell command on a Fleet member.one-click clone-site <site> <peer>Clone a supported site/application to a Fleet peer.one-click restore-site <site> <peer>Restore a supported site/application from a Fleet peer.one-click mv <directory> <peer>Move directory content to a Fleet member.one-click fleet verify one-click fleet audit one-click fleet raw web01 "systemctl status nginx"
Benchmarking
Local and Fleet-wide benchmark commands are separate so you can compare one host or orchestrate many.
one-click bench <version>Run a local benchmark workflow.one-click bench-sysRun only Geekbench/sysbench-focused tests.one-click fleet bench <version>Run a benchmark asynchronously across Fleet members.one-click fleet bench --exclude <server>Exclude a Fleet member from a distributed benchmark.one-click fleet bench --summary [vm]View benchmark history for the Fleet or a selected VM.one-click fleet statusTrack the most recent Fleet benchmark run.one-click fleet auditCollect current hardware architecture information alongside benchmark data.KVM / VPS Lifecycle
Create and operate NAT or public KVM guests on the controller or Fleet hypervisors.
one-click --vps createCreate a KVM instance on a selected hypervisor.one-click --vps deleteDelete a VPS from its hypervisor.one-click --vps editEdit VPS configuration.one-click --vps consoleAccess the serial console workflow.one-click --vps reinstallReinstall the guest operating system.one-click --vps snapshotCreate, delete or restore snapshots.one-click --vps backupCreate, delete or restore VPS backups.one-click --vps patchPatch one VM or the supported fleet scope.one-click --vps migrateMigrate an existing KVM VPS between trusted Fleet hypervisors by moving the VM disk and libvirt definition.one-click --vps importImport a complete external Linux VPS into a newly built, like-for-like Fleet replacement.one-click --vps export --name <vps_name>Export a Fleet VPS into a fresh external Linux replacement while retaining the original Fleet VPS for validation.one-click --vps startStart a VPS.one-click --vps stopStop a VPS.one-click --vps info <vps_name>Show storage, memory and resource information.one-click --vps viewView available snapshots.one-click --vps list | one-click --vps menuList VPS instances, mapped IPs and owning hypervisors.-n | --nameVPS instance name.-t | --targetTarget Fleet hypervisor.-m | --modeNetwork mode: NAT or public.-i | --imageGuest image/profile.-d | --diskGuest storage size.-c | --cpuvCPU count.-r | --ramGuest RAM.-p | --ipPublic IP option for public-mode deployments.-w | --passwordPassword for the guest oneclick administrator.-l | --languageWindows installation language when applicable.one-click --vps create --target hypervisor1 --name db1 --image ubuntu24 --cpu 1 --ram 1G --disk 6G --mode nat --password <password>
VM Console, VNC and Edge Publishing
Out-of-band guest access and HAProxy edge publishing for private/NAT workloads.
one-click --console <vm_name> [host]Attach directly to the libvirt serial console.one-click --vnc <vm_name> [duration]Create a temporary, token-protected noVNC recovery session.one-click --proxy --target <vm> --source <port> --port <public-port>Publish a TCP service through the hypervisor edge.one-click --proxy --target <vm> --website <fqdn> --proto <http|https>Publish web traffic through the HAProxy edge.one-click --ssh <peer_name>Connect to a Fleet/NAT peer using the managed SSH path.Firewall, Audit and IDS
Human-readable firewall operations plus auditing, ban management, AbuseIPDB lookup and filesystem scanning.
one-click engine --dry-run "…"Preview generated firewall changes without applying them.one-click engine open [table|all]Display firewall rules in a readable table.one-click engine flush <table> | flush allFlush one firewall table or all supported tables.one-click engine backup | saveBack up the current firewall configuration.one-click engine restoreRestore a saved firewall configuration.one-click engine raw <iptables cmd>Run an advanced raw iptables command.one-click engine chain create <chain>Create a custom firewall chain.one-click engine allow <arg>Accept matching traffic.one-click engine deny <arg> | drop <arg>Drop matching traffic.one-click engine reject <arg> | decline <arg>Reject matching traffic with a response.one-click engine delete <arg> | remove <arg>Delete rules, aliases or firewall backups.one-click engine mask | hideEnable NAT masquerading.one-click engine "allow ssh from office"Use a source IP/CIDR/alias in a readable rule.one-click engine "allow 443 to 10.0.0.5"Target a destination address/interface.one-click engine enable icmp | echoEnable ICMP echo requests.one-click engine disable icmp | echoDisable ICMP echo requests.one-click engine "allow udp port 100"Select UDP instead of default TCP.one-click engine "… multiport 50 556 4000"Apply one rule to multiple ports.one-click engine "range 1000-2000"Use a port range.one-click engine alias-create <name> <ips…>Create a named IP group.one-click engine alias-append <name> <ips…>Append addresses to an alias.one-click engine alias-prune <name> <ips…>Remove addresses from an alias.one-click engine sensitive <ports…>Mark ports that require extra confirmation.one-click engine sensitive-listList sensitive ports.one-click engine sensitive-remove <ports…>Remove ports from the sensitive list.one-click engine auditInspect firewall rules, drops and security activity.one-click engine audit sshReview detected SSH brute-force attempts.one-click engine audit block <ID> [dur=N|perm]Block an audited attacker temporarily or permanently.one-click engine audit unblock <ID>Remove an audit block.one-click engine audit historyReview historic mitigation actions.one-click engine audit banlistShow the combined Rule Engine and Fail2Ban ban list.one-click engine 'audit jail <name> port <port> retry <count>'Create an additional Fail2Ban jail.one-click engine audit key <APIKEY>Configure AbuseIPDB integration.one-click engine audit lookup <IP>Look up an IP reputation through AbuseIPDB.one-click engine audit scan --initInitialise the IDS baseline.one-click engine audit scanRun the lightweight integrity/malware scan.one-click engine audit scan --deepRun deeper filesystem inspection.one-click engine audit scan --remediateAuthorise supported IDS auto-remediation.one-click engine --dry-run "allow https" one-click engine "allow ssh from office and deny ssh from blacklist"
Websites and Application Hosting
Provision and operate isolated web/application environments using native Linux web servers and services.
one-click --web-createCreate a blank static HTML or PHP website.one-click --web-adminManage/backup an existing static site.one-click --wp-createInstall WordPress with Nginx or Apache.one-click --wpOpen basic WordPress and cron management.one-click --wp-adminManage WordPress staging, backups, SSL and lifecycle operations.one-click --nodejs-createInstall a Node.js application with Nginx or Apache.one-click --nodejs-adminStart, stop and manage Node.js applications.one-click --nextcloud-createCreate an isolated Nextcloud instance.one-click --nextcloud-adminManage Nextcloud instances.one-click --db-adminManage databases and create temporary web administration access.one-click --sslInstall TLS for WordPress or another virtual host.one-click --phpManage system-wide or per-site PHP settings.one-click --permission-repairRepair hosting permissions across sites, PHP, databases and backups.For step-by-step site administration, see Node.js management, Nextcloud hosting and WordPress hosting.
Networking, DNS and Private Mesh
Network diagnostics, DNS provider workflows, WireGuard device profiles and private Fleet access.
one-click netView network statistics.one-click net-repairDiagnose and repair network configuration.one-click --dnsManage DNS through BIND, Cloudflare and supported provider workflows.one-click --wireguard add-userCreate a new external-device profile for the private mesh.one-click --wireguard delete-userRemove a WireGuard device profile.one-click --wireguard viewView active WireGuard profiles.one-click --proxy …Publish NAT/private services through a Fleet hypervisor.one-click --ssh <peer_name>Connect to a managed private/NAT peer.Backup and Recovery
Local data protection, boot recovery, operating-system recovery and workload-level continuity.
one-click backupOpen rsync/rclone backup and restore workflows.one-click recoveryBack up or restore BIOS/UEFI/GRUB boot state.one-click reinstallRun the full OS reinstall workflow.one-click net-repairRecover broken network configuration.one-click clone-site <site> <peer>Clone a supported workload to a Fleet peer.one-click restore-site <site> <peer>Restore a supported workload from a Fleet peer.