AppViewX Utility Reference
appviewx.sh is the primary CLI for AppViewX platform administration. It is located at <INSTALL_PATH>/appviewx_kubernetes/scripts/appviewx.sh.
Note: EXECUTION RULES:
- Run from the scripts/ directory only.
- Most operations require: kubectl config current-context > kubernetes-admin@kubernetes.
- Run as the AppViewX installation user (not root).
Note: EXCLUDED OPERATIONS: Log collection and auto-remediation are managed
exclusively through the Interactive UI (options 4 and 8 in ./install.sh).
Basic Usage
cd <INSTALL PATH>/appviewx kubernetes/scripts/
_ _ ./appviewx.sh <option> [arguments]
# Display usage
./appviewx.sh --help
# Check version
./appviewx.sh --version
Platform Lifecycle
| Command | Purpose | Syntax | Notes |
|---|---|---|---|
| --version | Display the installed AppViewX version. | ./appviewx.sh --version | Reads VERSION from appviewx.conf. No kube context required. |
| --stop | Gracefully stop all AppViewX services (drain nodes). | ./appviewx.sh --stop [<nodename> | -all] | Drain order: workers → secondary masters → primary master. |
| --start | Resume pod scheduling by uncordoning all nodes. | ./appviewx.sh --start [<nodename> | -all] | Reverse of --stop. |
| --conf-merge | Merge incremental config | ./appviewx.sh --conf-merge into active appviewx.conf. | No kube context required. |
| --rollback | Roll back to the previous version or patch state. | ./appviewx.sh --rollback | Restores previous scripts backup. Does NOT restore DB. |
| --enable-pods- | Enable the graceful OS | ./appviewx.sh --enable-pods- | |
| graceful-restart | reboot process | graceful-restart | |
| --implement- priority-class | Apply Kubernetes PriorityClass to platform pods. | ./appviewx.sh --implement-priority- class |
Cluster Operations
| Command | Purpose | Syntax | Notes |
|---|---|---|---|
| --run-on-all | Execute a shell command on all cluster nodes. | ./appviewx.sh --run-on-all '<cmd>' | Requires SSH via secure-ssh.sh. |
| --run-on-master-nodes | Execute a command on master nodes only. | ./appviewx.sh --run-on-master-nodes '<cmd>' | Targets MASTER NODE _ IPs. |
| --sync | Sync scripts directory to a specific remote node. | ./appviewx.sh --sync <target ip> | MULTINODE must be True. |
| --sync-all | Sync scripts directory to all cluster nodes. | ./appviewx.sh --sync-all | MULTINODE must be True. |
| --time-setup | Configure time synchronisation across nodes. | ./appviewx.sh --time-setup | |
| --image-import | Import container | ./appviewx.sh --image-import images into the local registry. | For air-gapped/offline environments. |
| --generate service accounts | Generate Kubernetes service accounts. | ./appviewx.sh -- generate service accounts |
Configuration Management
| Command | Purpose | Syntax | Notes |
|---|---|---|---|
| --apply-all | Apply all pending custom configuration changes. | ./appviewx.sh --apply-all | Executes all --apply-* via custom changes applier.py. |
| --apply-affinities | Apply node affinity rules to deployments. | ./appviewx.sh --apply-affinities | Edit custom changes.yaml →_ affinities section first. |
| --apply-labels | Apply node label configurations. | ./appviewx.sh --apply-labels | Edit custom changes.yaml → _ node labels section. |
| --apply-allocate-memory | Apply memory resource limits to deployments. | ./appviewx.sh --apply-allocate-memory | xms/xmx are mandatory incustom changes.yaml. |
| --apply- logstashCustoms | Apply custom Logstash pipeline configuration. | ./appviewx.sh --apply- logstashCustoms | Edit custom changes.yaml → _ logstash customs section. |
| --apply-replicas | Apply configured replica counts to deployments. | ./appviewx.sh --apply-replicas | Edit custom changes.yaml → replica section. |
| --apply-hpa | Apply HPA configurations to eligible workloads. | ./appviewx.sh --apply-hpa | Edit custom changes.yaml → _ horizontalPodAutoScalling section. |
| --apply-host-aliases | Inject custom host alias entries into pod specs. | ./appviewx.sh --apply-host-aliases | Edit custom changes.yaml _ -> hostAliases section |
| --latency-tuning | Apply latency/resiliency optimisation settings. | ./appviewx.sh --latency-tuning | Apply latency/resiliency optimisation settings. |
| --enable strict routing | Enable Istio strict DC traffic routing. | ./appviewx.sh --enable strict routing | Set STRICT ROUTING DC in appviewx.conf first. |
| --setup-redis-dc- priority | Configure Redis Sentinel DC failover priority. | ./appviewx.sh --setup-redis-dc- priority | Set DC REDIS PRIORITY in appviewx.conf first. |
| --whitelist-ingress-hosts | Manage allowed ingress hostnames whitelist. | ./appviewx.sh --whitelist-ingress-hosts | No kube context required. |
| --calico-conversion | Convert Calico network policy config format. | ./appviewx.sh --calico-conversion [args] |
Database Operations
| Command | Purpose | Syntax | Notes |
|---|---|---|---|
| --db-backup | Create a MongoDB database backup. | ./appviewx.sh --db-backup | Stored at BACKUP HOSTPATH. SFTP transferred if SFTP TRANSFER=True. |
| --db-restore | Restore MongoDB from a backup archive. | ./appviewx.sh --db-restore <BACKUP LOCATION> | Full path to decrypted backup archive. |
| --db-shell | Open an interactive MongoDB shell inside the DB pod. | ./appviewx.sh --db-shell | Reads credentials from avx- common-config ConfigMap. |
| --db-execution | Execute a non-interactive MongoDB command. | ./appviewx.sh --db-execution '<mongo cmd>' | For scripted DB operations. |
| --set-db-cache-size | Set MongoDB WiredTiger cache size. | ./appviewx.sh --set-db-cache-size <SIZE GB> | ~50% of available RAM recommended. |
| --export-mongo- collections | Export MongoDB collections to files. | ./appviewx.sh --export-mongo- collections | |
| --isolate-database | Isolate MongoDB to a specific node. | ./appviewx.sh --isolate-database [<NODE IDENTIFIER>] | |
| --mongo-replicaset- reconfiguration | Reconfigure the MongoDB replica set. | ./appviewx.sh --mongo-replicaset-reconfiguration | Run after adding/removing replica set members. |
| --seed-restore | Restore from a seed backup. | ./appviewx.sh --seed-restore | |
| --kek enable | Enable the Key Encryption Key. | ./appviewx.sh --kek enable | |
| --kek disable | Disable the Key Encryption Key. | ./appviewx.sh --kek disable | Use only with approved change request and backup available. |
Vault and Secrets
| Command | Purpose | Syntax | Notes |
|---|---|---|---|
| --vault-backup | Create a backup of the OpenBao/Vault secret store. | ./appviewx.sh --vault-backup | Stored at BACKUP HOSTPATH. |
| --vault-restore | Restore OpenBao/Vault from a backup. | ./appviewx.sh --vault-restore <BACKUP LOCATION> | |
| --sync-vaults | Synchronise vault data across all nodes. | ./appviewx.sh --sync-vaults | |
| --vault-sync-status | Check vault synchronisation status across nodes. | ./appviewx.sh --vault-sync-status | |
| --vault-key-version- validate | Validate vault key version consistency. | ./appviewx.sh --vault-key-version- validate [--backup] | |
| --update-secret-ttl | Update the TTL for secrets. | ./appviewx.sh --update-secret-ttl |
Certificate and TLS
| Command | Purpose | Syntax | Notes |
|---|---|---|---|
| --renew-kube- certificate | Renew Kubernetes cluster TLS certificates. | ./appviewx.sh --renew-kube- certificate | No kube context required. Run before cert expiry. |
| --update-web-cert | Update the AppViewX web | ./appviewx.sh --update-web-cert SSL certificate. | New certificate must be present locally. |
| --enable-kube- external-ca | Configure external CA for Kubernetes kubeadm. | ./appviewx.sh --enable-kube- external-ca | Set all cert paths in appviewx.conf first. |
| --add-custom-ca-trustore | Add a custom CA to the platform trust store. | ./appviewx.sh --add-custom-ca- trustore | CA cert file must be available locally. |
User, Password, and Licensing
| Command | Purpose | Syntax | Notes |
|---|---|---|---|
| --password-encrypt | Encrypt a plaintext password for configuration. | ./appviewx.sh --password-encrypt '<plaintext>' | |
| --change-db-password | Change the MongoDB access password. | ./appviewx.sh --change-db- password | Updates both MongoDB user and platform config. |
| --license host-fetch | Fetch current license host binding. | ./appviewx.sh --license host-fetch | |
| --license host-update | Update the license hostbinding. | ./appviewx.sh --license host-update | |
| --restrict-script- update | Restrict end-user workflow script modification. | ./appviewx.sh --restrict-script- update | |
| --remove-import-workflow | Remove import workflowcapability. | ./appviewx.sh --remove-import- workflow | |
| --add-import- workflow | Re-enable import workflow capability. | ./appviewx.sh --add-import- workflow |
Maintenance and Backup
| Command | Purpose | Syntax | Notes |
|---|---|---|---|
| --config-log-rotation | Configure log rotation policies. | ./appviewx.sh --config-log-rotation | |
| --setup sftp | Set up SFTP connectivity for remote backup transfer. | ./appviewx.sh --setup sftp | Configure SFTP params in appviewx.conf first. |
