Skip to content

Repository files navigation

Revelara CLI

Connect your codebase to the Revelara reliability risk platform. Scan for risks, get remediation guidance, and manage your reliability posture from the terminal or your AI coding agent.

Install

Homebrew (macOS, recommended):

brew tap revelara-ai/tap
brew trust revelara-ai/tap
brew install --cask rvl

Upgrade later with brew upgrade --cask rvl. No Go toolchain required.

From release binary (Linux/macOS/Windows):

Download the archive for your platform from Releases, extract it, and put rvl on your PATH.

From source (requires Go 1.25+):

go install github.com/revelara-ai/rvl-cli/cmd/rvl@latest

Quick Start

# Authenticate with your Revelara account
rvl login

# Initialize a project and install the AI coding agent plugin
rvl init

# Verify connection and plugin status
rvl status

AI Coding Agent Skills

After rvl init (or rvl plugin install), the following slash commands are available in Claude Code and other supported agents.

Command Description
/rvl:scan Multi-agent scan — detects risks, correlates with incidents, saves to register
/rvl:fix R-XXX Guided remediation for a specific risk with expert consultation
/rvl:ask <question> Reliability Q&A with automatic expert routing
/rvl:risks View risk register (posture overview, ready-to-fix, or full list)
/rvl:review Reliability-focused review of your current code changes
/rvl:evidence Submit evidence that a control has been implemented
/rvl:status Check CLI connectivity and plugin health

When run inside a git repository, rvl plugin install (any agent, or --all) also maintains a managed Revelara block in the repo's AGENTS.md — read natively by most agent runtimes — with the rvl context-tool cheat sheet and skill reference. Claude Code installs additionally maintain a managed block in CLAUDE.md. The two blocks are intentionally different: the AGENTS.md block is agent-neutral, while the CLAUDE.md block adds Claude-specific content such as expert-agent routing via the Task tool. Each file is created if it doesn't exist; otherwise the marker-delimited block is appended or updated in place on reinstall/update, leaving the rest of the file untouched. Pass --no-context-files to rvl plugin install/update to skip them. (Avoid symlinking one file to the other — both writers manage the same marker pair, so the last one to run would replace the other's block.)

CLI Commands

Command Description
rvl login Authenticate with your Revelara account
rvl logout Remove stored credentials
rvl init Initialize project and install AI coding agent plugin
rvl status Check connection and plugin status
rvl plugin Manage agent plugins (install, update, list, remove)
rvl risk Manage risks (list, show, resolve)
rvl control Query the 61-control reliability catalog
rvl knowledge Search your organization's knowledge base
rvl evidence Submit and manage control implementation evidence
rvl config View and edit configuration
rvl version Show version info

Change-scoped agent scan

rvl scan --agent runs a change-scoped reliability review over just your staged or pushed change set, using headless coding-agent lenses, and gates the commit/push on findings above a severity threshold. It's built to run as a pre-commit or pre-push git hook:

rvl hook install --pre-commit    # gate commits on the staged change set
rvl hook install --pre-push      # gate pushes
rvl scan --agent --staged        # run it manually

Configure it under scanner.agent in .revelara.yaml. See the agent scan hooks guide for installation, the enforce vs eval modes, waivers, and CI usage.

Feature maturity

Not every command and feature is equally mature. Most of the CLI is production-ready; a few features are still beta or alpha. Notably, rvl scan --agent and its .revelara.yaml scanner: section are beta, and rvl scan --auto-infer is alpha. See the feature maturity reference for the full breakdown and tier definitions.

Configuration

Credentials are stored in ~/.revelara/config.yaml (mode 0600). The CLI never exposes credentials to LLM contexts.

Project configuration lives in .revelara.yaml at your repo root; see the .revelara.yaml reference for every field.

Environment Variables

For headless and CI environments with no config file, credentials can be supplied as environment variables. They take precedence over ~/.revelara/config.yaml:

Variable Purpose
RVL_API_KEY API key (equivalent to config api_key)
RVL_API_URL API endpoint (equivalent to config api_url)
RVL_ORG_NAME Organization name (equivalent to config org_name)
# CI example: no `rvl login` needed
export RVL_API_KEY="$REVELARA_API_KEY_SECRET"
rvl scan --agent --changed-only --base main --format json

Exit Codes

Code Meaning
0 Success, including help output (help, -h, --help)
1 Runtime failure (API error, authentication failure, network problem)
2 Usage error (unknown command, unknown flag, invalid argument)

Exceptions: rvl scan --agent uses its own gate exit codes (0 = pass, eval mode, skip, or infra fail-open; 1 = blocked by a finding at or above --fail-on in enforce mode, a secret detection, or a strict_errors infra failure; 2 = config/usage error; 130 = interrupted), and rvl review follows its --enforce / --fail-closed contract (advisory mode always exits 0). rvl knowledge enrich degrades gracefully: it exits 1 only when every parallel fetch fails; partial failures print warnings on stderr and exit 0.

License

Apache License 2.0 - see LICENSE and NOTICE for details.

About

Revelara CLI — connect your codebase to the Revelara reliability risk platform

Topics

Resources

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages