Skip to main content
Everything you do after your secure environment is running. The Helm and kubectl commands below use <namespace>: your secure environment’s namespace. The one-line installer names it after your client and gives the Helm release the same name, so <namespace> is both. tracebloc cluster info shows it. For a manual Helm install, it’s the namespace and release name you chose.
Day-to-day management — inspecting the cluster, ingesting and removing data — is easiest with the tracebloc CLI. The Helm/kubectl commands here cover the lifecycle bits the CLI doesn’t (upgrade, stop/start, uninstall) and deeper debugging.

Which version am I on?

The install summary also prints the version, and --diagnose reports it on its first line.

Health & status

For deeper debugging:
Then check your clients page — your secure environment should read Online.

Logs

Stop & start (local / k3d)

Free up your machine without losing anything — data persists between stops.

Upgrade

The auto-upgrade CronJob keeps your secure environment current by default: every hour it checks for a new release and upgrades the services. To update the CLI now:
It re-runs the official installer (signature-verified) and brings the CLI to the latest release. On a healthy secure environment it leaves the services to the hourly auto-upgrade. If the installer finds something it has to repair, or your CLI is older than the oldest it supports, it runs the full install, which also brings the services up to date. On Windows it prints the command to run in a new PowerShell window. Safe to re-run. To upgrade the services right away, use Helm:
--reset-then-reuse-values preserves the values the installer applied. Append --version <x.y.z> to pin a specific release.

Roll back

Move to another machine

The client’s identity is its Client ID, not the machine. To relocate: run the installer on the new host with the same Client ID, then re-ingest your datasets (or copy ~/.tracebloc). The old host can be uninstalled once the new one shows Online.

Uninstall

To remove tracebloc from this machine, run:
It shows what it will remove and keep, then asks you to type the name of your secure environment to confirm. --yes skips the confirmation (for automation).
  • Removed from this machine: the machine credential is revoked, the Helm release is uninstalled, the local cluster is deleted, the tracebloc container images are reclaimed, ~/.tracebloc is cleared, and the tracebloc CLI removes itself.
  • Kept on tracebloc: your use cases, the catalog entries of your datasets, and the models trained here.
  • Left in place: Docker, kubectl, k3d, helm and NVIDIA drivers. Remove them yourself if nothing else uses them.
This can’t be undone. Datasets stored on this machine are erased. tracebloc delete --keep-data keeps ~/.tracebloc (local config and any datasets stored there on the host), but datasets kept inside the cluster go with it. On a macOS or Linux local install, that’s where datasets live by default.
tracebloc delete refuses while experiments are still running. Wait for them to finish, or pass --force to stop them. It targets kubectl’s current context; if you’ve switched to another cluster since installing, add --context k3d-tracebloc.
k3d cluster delete tracebloc (local) or helm uninstall <namespace> -n <namespace> (any cluster) removes only the cluster or the release. The machine credential stays live, so your secure environment stays registered on your dashboard, and the tracebloc CLI and ~/.tracebloc stay on disk. Prefer tracebloc delete.After a helm uninstall, PVCs are annotated helm.sh/resource-policy: keep, so your data survives. To remove it too: kubectl delete pvc --all -n <namespace>.

Back up

Your data lives in the data PVCs (or ~/.tracebloc on a local install). Back up that directory / those volumes on your normal schedule — tracebloc keeps nothing of yours off your infrastructure.