Docs
Reference

Command line

Every 3am-core command.

The binary is /opt/3am/3am-core inside the 3AM container. See Running 3AM for how to run it on Podman, Docker or Kubernetes.

CommandWhat it does
serveStart the service and the console. Setup mode until a valid licence is installed. The container's default
fingerprintPrint this install's fingerprint, which you send to 3am.si to get a licence
versionPrint the version
healthExit 0 if the server answers. Used by container health checks; needs no curl
preflight [--deep] [--json]Check the host, the licence and the reach of every configured tool. --deep also checks each connector's credentials and permissions
connectors listEvery connector kind in this build, and its capabilities
connectors checkHealth of every configured connector
estate buildDiscover services, repositories, owners and dependencies; writes estate.json to the data directory
estate resolve ALERT [label=value …]Which service, repositories and owners an alert concerns
knowledge syncCheck out and index every repository the source connectors list (incremental)
knowledge search QUERY [--service NAME]Search across the indexed repositories
packs listThe check packs this licence opens
checks run [ALERT …]Run the root-cause checks for these alerts against live systems, read-only, and print the verdicts
digest [YYYY-MM-DD]Write the daily digest for a day (default: the last 24 hours)
ledger-verify [DIR]Verify the audit log (default /var/lib/3am/ledger). Exits 1 if anything was changed, removed or reordered

Examples

# Dry-run the diagnosis for an alert that is firing now, without opening an incident
3am-core checks run MySQLReadOnly

# Which team owns this alert?
3am-core estate resolve KubePodCrashLooping namespace=payments workload=checkout-api

Installer

The single-host installer (install.sh in the bundle) takes:

OptionDefaultMeaning
--profile auto|cpu|gpu|noneautoWhich model to run, or none. auto picks from the hardware
--port N8700Console port on the host
--bind ADDR127.0.0.1Address the console listens on. Use 0.0.0.0 or a host IP to reach it from other machines
--config DIRNoneHost directory holding the licence and configuration files, mounted read-only at /etc/3am. Without it, upload the licence and add connectors in the console
--runtime podman|dockerDetectedContainer runtime
--host-networkOffShare the host's network, for tools that listen only on the host's loopback
--yesOffDon't ask for confirmation
--uninstall [--purge]Remove 3AM; --purge also deletes its data (Uninstall)

On this page