init
scaffold a project, or mint a new UI password
genctl init [dir] [--eval-node] [--auth] [--postgres] [--version <tag>] [-y]
genctl init password [email]
Writes a project that applies and runs: definitions/, a .genroc naming them, optionally
a compose.yaml. It asks which parts you want; -y takes the defaults, as does a pipe or a
CI job. init password mints a replacement for the UI login init printed.
config
read and write ~/.config/genroc/config.yaml
genctl config get <key> | set <key> <value> | unset <key>
Keys (the file is mode 0600):
server genroc server base URL ($GENROC_SERVER wins) token API credential, a genroc_sk_* value ($GENROC_TOKEN wins)
—server on a command overrides both.
token
manage API credentials
genctl token create --perms <list> [--label <name>] [-q]
genctl token generate | token list [--json] | token revoke <id>...
Perms: admin, deploy, operate, read, worker.
create registers a credential over the API and so needs an admin one of its own.
generate mints a secret OFFLINE — no server, no credential — which is how the first
one can exist at all. Break-glass equivalent: genroc token, run against the database.
lsp
run the language server an editor talks to over stdio
genctl lsp [--stdio]
Speaks LSP on stdin/stdout, so it is spawned by an editor rather than run by hand.
It publishes diagnostics for *.genroc.yaml — the same failures apply reports, from
the same two calls, so what is underlined is what a registration would refuse.
—stdio is accepted and ignored: it is the transport every client names on the command line, and it is the only one spoken here.
VS Code: install the extension in editors/vscode. Neovim: pass genctl lsp as the
cmd of a client started for the yaml filetype.