[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"docs:\u002Fdocs\u002Fguides\u002Fstacks":3,"docs:nav":568,"docs:surround:\u002Fdocs\u002Fguides\u002Fstacks":780},{"id":4,"title":5,"body":6,"description":558,"extension":559,"launchGate":560,"meta":561,"navigation":562,"path":563,"seo":564,"stem":565,"stub":566,"__hash__":567},"docs_en\u002Fdocs\u002F3.guides\u002F4.stacks.md","Stacks: OpenTofu with approvals",{"type":7,"value":8,"toc":546},"minimark",[9,18,21,26,60,64,75,141,147,151,165,176,180,195,198,204,208,215,236,247,257,261,272,276,283,402,415,451,469,473,476,491,498,502,509,530,534,542],[10,11,12,13,17],"p",{},"A ",[14,15,16],"strong",{},"stack"," is an OpenTofu (or Ansible) configuration that Velrix runs for you. Its state is kept in Velrix, sealed, with every version. Each run plans in a sandbox first; you look at what it would change, and only then does it apply, exactly the plan you saw. With four eyes, someone other than the person who started the run must approve it.",[10,19,20],{},"This guide sets up an OpenTofu stack for an organisation. Personal stacks work the same way, without the approval step.",[22,23,25],"h2",{"id":24},"what-you-get","What you get",[27,28,29,36,42,48,54],"ul",{},[30,31,32,35],"li",{},[14,33,34],{},"No state on laptops."," The state lives in Velrix, encrypted, with its history. A run locks it, so two applies never race.",[30,37,38,41],{},[14,39,40],{},"No long-lived keys."," Each run gets a short-lived key that acts as the person who started it, with only the scopes the stack allows. It is dropped the moment the run ends.",[30,43,44,47],{},[14,45,46],{},"Four eyes and an audit trail."," Who started a run, who approved it, and what it changed, are kept on the stack.",[30,49,50,53],{},[14,51,52],{},"Secrets stay secret."," Secret variables are sealed, handed to runs only as secrets, and masked in every log line.",[30,55,56,59],{},[14,57,58],{},"Works offline."," Runs take providers from your installation’s own mirror, never from the internet.",[22,61,63],{"id":62},"_1-create-the-stack","1. Create the stack",[10,65,66,67,70,71,74],{},"Open ",[14,68,69],{},"Stacks"," and choose ",[14,72,73],{},"New stack",".",[76,77,78,88,97,123,131],"ol",{},[30,79,80,83,84,74],{},[14,81,82],{},"Name",": for example ",[85,86,87],"code",{},"network",[30,89,90,93,94,74],{},[14,91,92],{},"Kind",": ",[14,95,96],{},"OpenTofu",[30,98,99,102,103,106,107,110,111,114,115,118,119,122],{},[14,100,101],{},"Source",": the ",[14,104,105],{},"Repository"," as an https git URL, with a ",[14,108,109],{},"Branch, tag or commit"," and the ",[14,112,113],{},"Directory"," the configuration lives in. For a private repository, add a ",[14,116,117],{},"Deploy token","; it is sealed and never shown again. You can also upload a ",[85,120,121],{},".tar.gz"," of the source instead.",[30,124,125,93,128,74],{},[14,126,127],{},"Approval",[14,129,130],{},"Another person",[30,132,133,136,137,140],{},[14,134,135],{},"What runs may call",": the API scopes a run needs, words apart, such as ",[85,138,139],{},"machines ssh-keys",". A run can never do more than the person who started it may.",[10,142,143,144,74],{},"Choose ",[14,145,146],{},"Create stack",[22,148,150],{"id":149},"_2-add-variables","2. Add variables",[10,152,153,154,157,158,161,162,74],{},"On the stack’s ",[14,155,156],{},"Settings"," tab, under ",[14,159,160],{},"Variables",", add what the configuration needs. Runs get each one as ",[85,163,164],{},"var.\u003Cname>",[10,166,167,168,171,172,175],{},"Tick ",[14,169,170],{},"Secret"," for passwords and tokens. A secret is sealed in Velrix, handed to runs only as a secret, never shown again, and masked in the output: a line that would print it shows ",[85,173,174],{},"••••••"," instead.",[22,177,179],{"id":178},"_3-plan","3. Plan",[10,181,182,183,186,187,190,191,194],{},"On the ",[14,184,185],{},"Runs"," tab, choose ",[14,188,189],{},"Plan",". Velrix starts a sandboxed run that fetches the source, runs ",[85,192,193],{},"tofu plan",", and keeps the plan file sealed.",[10,196,197],{},"The run’s page shows what the plan changes, as counts and resource by resource: what it creates, updates, replaces and destroys. Destroys and replacements stand out. The output’s last lines are there too, masked.",[10,199,200,201,74],{},"If nothing differs, the run ends as ",[14,202,203],{},"No changes",[22,205,207],{"id":206},"_4-approve-and-apply","4. Approve and apply",[10,209,210,211,214],{},"The run now says ",[14,212,213],{},"Waiting for approval",", with who started it.",[27,216,217,227],{},[30,218,219,222,223,226],{},[14,220,221],{},"You cannot approve your own run."," Ask a colleague who holds ",[14,224,225],{},"Approve plans"," in the organisation. Organisation admins and owners do.",[30,228,229,232,233,74],{},[14,230,231],{},"The approver"," opens the run, reviews the plan and the source it came from, and chooses ",[14,234,235],{},"Approve and apply",[10,237,238,239,242,243,246],{},"Velrix then applies ",[14,240,241],{},"exactly the plan that was approved",", in a new sandbox, still acting as the person who started it. Approving lends no rights of its own. If the state moved on since the plan, OpenTofu refuses it and the run ends as ",[14,244,245],{},"Stale plan",": plan again.",[10,248,249,250,253,254,74],{},"To throw a plan away, choose ",[14,251,252],{},"Discard",". To stop a running one, ",[14,255,256],{},"Cancel run",[22,258,260],{"id":259},"_5-watch-for-drift","5. Watch for drift",[10,262,263,264,267,268,271],{},"Set ",[14,265,266],{},"Drift check every (hours)"," on the Settings tab. Velrix then plans on that schedule, never applies, and posts a notice when something changed outside the stack. The run ends as ",[14,269,270],{},"Drifted",", and the notice opens it.",[22,273,275],{"id":274},"use-the-state-from-a-laptop-or-ci","Use the state from a laptop or CI",[10,277,278,279,282],{},"A stack’s state also works on its own, for OpenTofu runs you start elsewhere. The ",[14,280,281],{},"State"," tab shows the snippet to paste into your configuration:",[284,285,290],"pre",{"className":286,"code":287,"language":288,"meta":289,"style":289},"language-hcl shiki shiki-themes github-light-high-contrast github-light-high-contrast github-dark-high-contrast","terraform {\n  backend \"http\" {\n    address        = \"https:\u002F\u002Fvelrix.example.com\u002Fstacks\u002F\u003Cstack>\u002Fstate\"\n    lock_address   = \"https:\u002F\u002Fvelrix.example.com\u002Fstacks\u002F\u003Cstack>\u002Flock\"\n    unlock_address = \"https:\u002F\u002Fvelrix.example.com\u002Fstacks\u002F\u003Cstack>\u002Funlock\"\n    lock_method    = \"POST\"\n    unlock_method  = \"POST\"\n    username       = \"velrix\"\n  }\n}\n","hcl","",[85,291,292,305,317,331,343,355,367,378,390,396],{"__ignoreMap":289},[293,294,297,301],"span",{"class":295,"line":296},"line",1,[293,298,300],{"class":299},"szw1H","terraform",[293,302,304],{"class":303},"s7iLA"," {\n",[293,306,308,311,315],{"class":295,"line":307},2,[293,309,310],{"class":299},"  backend",[293,312,314],{"class":313},"ssYy9"," \"http\"",[293,316,304],{"class":303},[293,318,320,323,327],{"class":295,"line":319},3,[293,321,322],{"class":303},"    address",[293,324,326],{"class":325},"sklAV","        =",[293,328,330],{"class":329},"semJd"," \"https:\u002F\u002Fvelrix.example.com\u002Fstacks\u002F\u003Cstack>\u002Fstate\"\n",[293,332,334,337,340],{"class":295,"line":333},4,[293,335,336],{"class":303},"    lock_address",[293,338,339],{"class":325},"   =",[293,341,342],{"class":329}," \"https:\u002F\u002Fvelrix.example.com\u002Fstacks\u002F\u003Cstack>\u002Flock\"\n",[293,344,346,349,352],{"class":295,"line":345},5,[293,347,348],{"class":303},"    unlock_address",[293,350,351],{"class":325}," =",[293,353,354],{"class":329}," \"https:\u002F\u002Fvelrix.example.com\u002Fstacks\u002F\u003Cstack>\u002Funlock\"\n",[293,356,358,361,364],{"class":295,"line":357},6,[293,359,360],{"class":303},"    lock_method",[293,362,363],{"class":325},"    =",[293,365,366],{"class":329}," \"POST\"\n",[293,368,370,373,376],{"class":295,"line":369},7,[293,371,372],{"class":303},"    unlock_method",[293,374,375],{"class":325},"  =",[293,377,366],{"class":329},[293,379,381,384,387],{"class":295,"line":380},8,[293,382,383],{"class":303},"    username",[293,385,386],{"class":325},"       =",[293,388,389],{"class":329}," \"velrix\"\n",[293,391,393],{"class":295,"line":392},9,[293,394,395],{"class":303},"  }\n",[293,397,399],{"class":295,"line":398},10,[293,400,401],{"class":303},"}\n",[10,403,404,405,408,409,414],{},"The password is an API key with the ",[85,406,407],{},"stacks:state"," scope (",[410,411,413],"a",{"href":412},"\u002Fdocs\u002Freference\u002Fin-your-realm","the API reference"," is in your realm’s Docs window):",[284,416,420],{"className":417,"code":418,"language":419,"meta":289,"style":289},"language-bash shiki shiki-themes github-light-high-contrast github-light-high-contrast github-dark-high-contrast","export TF_HTTP_PASSWORD=vlxk_…\ntofu init\ntofu apply\n","bash",[85,421,422,436,444],{"__ignoreMap":289},[293,423,424,427,430,433],{"class":295,"line":296},[293,425,426],{"class":325},"export",[293,428,429],{"class":303}," TF_HTTP_PASSWORD",[293,431,432],{"class":325},"=",[293,434,435],{"class":303},"vlxk_…\n",[293,437,438,441],{"class":295,"line":307},[293,439,440],{"class":299},"tofu",[293,442,443],{"class":329}," init\n",[293,445,446,448],{"class":295,"line":319},[293,447,440],{"class":299},[293,449,450],{"class":329}," apply\n",[10,452,453,454,456,457,460,461,464,465,468],{},"The ",[14,455,281],{}," tab lists every kept version. You can ",[14,458,459],{},"Restore"," an older one (it becomes the current state, with the next serial) or ",[14,462,463],{},"Download"," it. A state holds secrets in the clear, so every download is recorded with your name. ",[14,466,467],{},"Force unlock"," opens a lock whose holder is gone, also recorded.",[22,470,472],{"id":471},"providers-in-an-installation-without-internet","Providers in an installation without internet",[10,474,475],{},"Runs fetch nothing from the internet. The Velrix provider is always there. Any other provider must be in your installation’s mirror first:",[76,477,478,488],{},[30,479,480,481,484,485,74],{},"Under ",[14,482,483],{},"Mirror"," on the Stacks list, import the provider by name and version, such as ",[85,486,487],{},"hashicorp\u002Frandom 3.6.3",[30,489,490],{},"Velrix downloads it once, checks its signed checksums, and keeps it in your registry. This one step needs a way out to the provider’s own registry.",[10,492,493,494,74],{},"A run that needs a provider not in the mirror fails and names it: ",[495,496,497],"em",{},"not in the realm’s mirror: hashicorp\u002Frandom",[22,499,501],{"id":500},"ansible","Ansible",[10,503,504,505,508],{},"An Ansible stack works the same way. The plan is ",[85,506,507],{},"ansible-playbook --check --diff",", the summary is each host’s changed, ok, failed and unreachable counts, and the apply is the real run of the same commit.",[27,510,511,518,524,527],{},[30,512,513,514,517],{},"Each Ansible stack has its own SSH key pair. Its Settings tab shows the public half, with ",[14,515,516],{},"Add to SSH keys",", so your machines can let it in.",[30,519,520,523],{},[14,521,522],{},"Join the project network"," lets runs reach the private addresses of your machines on the server the run lands on. Without it, runs reach only public addresses.",[30,525,526],{},"With no inventory file, the inventory is your machines.",[30,528,529],{},"SSH host keys are checked on every run. Velrix machines’ keys are known before they boot; other hosts’ keys are pinned on first use, and a run against a changed key stops before it connects.",[22,531,533],{"id":532},"next","Next",[27,535,536],{},[30,537,538,539],{},"The OpenTofu and Terraform provider and the Ansible collection, in ",[410,540,541],{"href":412},"your realm’s Docs window",[543,544,545],"style",{},"html pre.shiki code .szw1H, html code.shiki .szw1H{--shiki-light:#702C00;--shiki-default:#702C00;--shiki-dark:#FFB757}html pre.shiki code .s7iLA, html code.shiki .s7iLA{--shiki-light:#0E1116;--shiki-default:#0E1116;--shiki-dark:#F0F3F6}html pre.shiki code .ssYy9, html code.shiki .ssYy9{--shiki-light:#023B95;--shiki-default:#023B95;--shiki-dark:#91CBFF}html pre.shiki code .sklAV, html code.shiki .sklAV{--shiki-light:#A0111F;--shiki-default:#A0111F;--shiki-dark:#FF9492}html pre.shiki code .semJd, html code.shiki .semJd{--shiki-light:#032563;--shiki-default:#032563;--shiki-dark:#ADDCFF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":289,"searchDepth":307,"depth":319,"links":547},[548,549,550,551,552,553,554,555,556,557],{"id":24,"depth":307,"text":25},{"id":62,"depth":307,"text":63},{"id":149,"depth":307,"text":150},{"id":178,"depth":307,"text":179},{"id":206,"depth":307,"text":207},{"id":259,"depth":307,"text":260},{"id":274,"depth":307,"text":275},{"id":471,"depth":307,"text":472},{"id":500,"depth":307,"text":501},{"id":532,"depth":307,"text":533},"Keep your OpenTofu state in Velrix, run plans in a sandbox, and let a second person approve before anything is applied.","md",null,{},{"title":69},"\u002Fdocs\u002Fguides\u002Fstacks",{"title":5,"description":558},"docs\u002F3.guides\u002F4.stacks",false,"-bKl0oDhpW_Dgegg32ivz1F63AVRNBrQLXRcKN2Q64o",[569],{"title":570,"path":571,"stem":572,"children":573,"page":-1},"Docs","\u002Fdocs","docs",[574,578,608,636,667,738,751,773],{"title":575,"path":571,"stem":576,"stub":566,"launchGate":560,"icon":577},"Overview","docs\u002Findex","i-lucide-house",{"title":579,"stub":566,"launchGate":560,"icon":580,"path":581,"stem":582,"children":583,"page":566},"Get started","i-lucide-rocket","\u002Fdocs\u002Fget-started","docs\u002F1.get-started",[584,588,592,596,600,604],{"title":585,"path":586,"stem":587,"stub":566,"launchGate":560},"What Velrix is","\u002Fdocs\u002Fget-started\u002Fwhat-is-velrix","docs\u002F1.get-started\u002F1.what-is-velrix",{"title":589,"path":590,"stem":591,"stub":566,"launchGate":560},"Ways to run Velrix","\u002Fdocs\u002Fget-started\u002Fways-to-run","docs\u002F1.get-started\u002F2.ways-to-run",{"title":593,"path":594,"stem":595,"stub":566,"launchGate":560},"Install from USB","\u002Fdocs\u002Fget-started\u002Finstall","docs\u002F1.get-started\u002F3.install",{"title":597,"path":598,"stem":599,"stub":566,"launchGate":560},"The setup wizard","\u002Fdocs\u002Fget-started\u002Fsetup-wizard","docs\u002F1.get-started\u002F4.setup-wizard",{"title":601,"path":602,"stem":603,"stub":566,"launchGate":560},"Your first app","\u002Fdocs\u002Fget-started\u002Ffirst-app","docs\u002F1.get-started\u002F5.first-app",{"title":605,"path":606,"stem":607,"stub":566,"launchGate":560},"Your first VM","\u002Fdocs\u002Fget-started\u002Ffirst-vm","docs\u002F1.get-started\u002F6.first-vm",{"title":609,"stub":566,"launchGate":560,"icon":610,"path":611,"stem":612,"children":613,"page":566},"Concepts","i-lucide-lightbulb","\u002Fdocs\u002Fconcepts","docs\u002F2.concepts",[614,619,623,627,631],{"title":615,"path":616,"stem":617,"stub":618,"launchGate":560},"Realms","\u002Fdocs\u002Fconcepts\u002Frealms","docs\u002F2.concepts\u002F1.realms",true,{"title":620,"path":621,"stem":622,"stub":618,"launchGate":560},"Instances and hosts","\u002Fdocs\u002Fconcepts\u002Finstances-and-hosts","docs\u002F2.concepts\u002F2.instances-and-hosts",{"title":624,"path":625,"stem":626,"stub":618,"launchGate":560},"Modules and the mesh","\u002Fdocs\u002Fconcepts\u002Fmodules-and-the-mesh","docs\u002F2.concepts\u002F3.modules-and-the-mesh",{"title":628,"path":629,"stem":630,"stub":618,"launchGate":560},"Organisations, projects and permissions","\u002Fdocs\u002Fconcepts\u002Forgs-projects-permissions","docs\u002F2.concepts\u002F4.orgs-projects-permissions",{"title":632,"path":633,"stem":634,"stub":618,"launchGate":635},"Host pools","\u002Fdocs\u002Fconcepts\u002Fhost-pools","docs\u002F2.concepts\u002F5.host-pools","A1",{"title":637,"stub":566,"launchGate":560,"icon":638,"path":639,"stem":640,"children":641,"page":566},"Guides for users","i-lucide-book-open","\u002Fdocs\u002Fguides","docs\u002F3.guides",[642,646,650,654,655,659,663],{"title":643,"path":644,"stem":645,"stub":566,"launchGate":560},"Apps","\u002Fdocs\u002Fguides\u002Fapps","docs\u002F3.guides\u002F1.apps",{"title":647,"path":648,"stem":649,"stub":618,"launchGate":560},"Machines","\u002Fdocs\u002Fguides\u002Fmachines","docs\u002F3.guides\u002F2.machines",{"title":651,"path":652,"stem":653,"stub":618,"launchGate":560},"Volumes","\u002Fdocs\u002Fguides\u002Fvolumes","docs\u002F3.guides\u002F3.volumes",{"title":69,"path":563,"stem":565,"stub":566,"launchGate":560},{"title":656,"path":657,"stem":658,"stub":618,"launchGate":560},"Terminal and cloud shells","\u002Fdocs\u002Fguides\u002Fterminal","docs\u002F3.guides\u002F5.terminal",{"title":660,"path":661,"stem":662,"stub":566,"launchGate":560},"Registry","\u002Fdocs\u002Fguides\u002Fregistry","docs\u002F3.guides\u002F6.registry",{"title":664,"path":665,"stem":666,"stub":618,"launchGate":560},"Kubernetes","\u002Fdocs\u002Fguides\u002Fkubernetes","docs\u002F3.guides\u002F7.kubernetes",{"title":668,"stub":566,"launchGate":560,"icon":669,"path":670,"stem":671,"children":672,"page":566},"Guides for operators","i-lucide-server-cog","\u002Fdocs\u002Foperators","docs\u002F4.operators",[673,677,681,685,689,693,697,701,705,709,714,718,722,726,730,734],{"title":674,"path":675,"stem":676,"stub":566,"launchGate":560},"Updates and maintenance windows","\u002Fdocs\u002Foperators\u002Fupdates","docs\u002F4.operators\u002F1.updates",{"title":678,"path":679,"stem":680,"stub":566,"launchGate":560},"Migrate: moving VMs from VMware","\u002Fdocs\u002Foperators\u002Fmigrate","docs\u002F4.operators\u002F10.migrate",{"title":682,"path":683,"stem":684,"stub":566,"launchGate":560},"Hardware","\u002Fdocs\u002Foperators\u002Fhardware","docs\u002F4.operators\u002F11.hardware",{"title":686,"path":687,"stem":688,"stub":566,"launchGate":560},"Billing","\u002Fdocs\u002Foperators\u002Fbilling","docs\u002F4.operators\u002F12.billing",{"title":690,"path":691,"stem":692,"stub":566,"launchGate":560},"Policies","\u002Fdocs\u002Foperators\u002Fpolicies","docs\u002F4.operators\u002F13.policies",{"title":694,"path":695,"stem":696,"stub":566,"launchGate":560},"Running the realm","\u002Fdocs\u002Foperators\u002Frealm-ops","docs\u002F4.operators\u002F14.realm-ops",{"title":698,"path":699,"stem":700,"stub":566,"launchGate":560},"Public address and app hostnames","\u002Fdocs\u002Foperators\u002Fpublic-address","docs\u002F4.operators\u002F15.public-address",{"title":702,"path":703,"stem":704,"stub":566,"launchGate":560},"Library","\u002Fdocs\u002Foperators\u002Flibrary","docs\u002F4.operators\u002F16.library",{"title":706,"path":707,"stem":708,"stub":566,"launchGate":560},"Backups","\u002Fdocs\u002Foperators\u002Fbackups","docs\u002F4.operators\u002F2.backups",{"title":710,"path":711,"stem":712,"stub":618,"launchGate":713},"Availability and drain","\u002Fdocs\u002Foperators\u002Favailability","docs\u002F4.operators\u002F3.availability","A1, A2, A3",{"title":715,"path":716,"stem":717,"stub":618,"launchGate":560},"Federation","\u002Fdocs\u002Foperators\u002Ffederation","docs\u002F4.operators\u002F4.federation",{"title":719,"path":720,"stem":721,"stub":618,"launchGate":560},"Licensing","\u002Fdocs\u002Foperators\u002Flicensing","docs\u002F4.operators\u002F5.licensing",{"title":723,"path":724,"stem":725,"stub":618,"launchGate":560},"Branding: look and design","\u002Fdocs\u002Foperators\u002Fbranding","docs\u002F4.operators\u002F6.branding",{"title":727,"path":728,"stem":729,"stub":618,"launchGate":560},"Connectivity","\u002Fdocs\u002Foperators\u002Fconnectivity","docs\u002F4.operators\u002F7.connectivity",{"title":731,"path":732,"stem":733,"stub":618,"launchGate":560},"Logs","\u002Fdocs\u002Foperators\u002Flogs","docs\u002F4.operators\u002F8.logs",{"title":735,"path":736,"stem":737,"stub":566,"launchGate":560},"Directory sync: Entra ID and Okta","\u002Fdocs\u002Foperators\u002Fdirectory-sync","docs\u002F4.operators\u002F9.directory-sync",{"title":739,"stub":566,"launchGate":560,"icon":740,"path":741,"stem":742,"children":743,"page":566},"Reference","i-lucide-library","\u002Fdocs\u002Freference","docs\u002F5.reference",[744,747],{"title":745,"path":412,"stem":746,"stub":566,"launchGate":560},"The API reference in your realm","docs\u002F5.reference\u002F1.in-your-realm",{"title":748,"path":749,"stem":750,"stub":566,"launchGate":560},"The velrix command","\u002Fdocs\u002Freference\u002Fcli","docs\u002F5.reference\u002F2.cli",{"title":752,"stub":566,"launchGate":560,"icon":753,"path":754,"stem":755,"children":756,"page":566},"Security and compliance","i-lucide-shield-check","\u002Fdocs\u002Fsecurity","docs\u002F6.security",[757,761,765,769],{"title":758,"path":759,"stem":760,"stub":618,"launchGate":560},"Post-quantum","\u002Fdocs\u002Fsecurity\u002Fpost-quantum","docs\u002F6.security\u002F1.post-quantum",{"title":762,"path":763,"stem":764,"stub":618,"launchGate":560},"GDPR","\u002Fdocs\u002Fsecurity\u002Fgdpr","docs\u002F6.security\u002F2.gdpr",{"title":766,"path":767,"stem":768,"stub":618,"launchGate":560},"NIS2 support","\u002Fdocs\u002Fsecurity\u002Fnis2","docs\u002F6.security\u002F3.nis2",{"title":770,"path":771,"stem":772,"stub":618,"launchGate":560},"Data residency","\u002Fdocs\u002Fsecurity\u002Fdata-residency","docs\u002F6.security\u002F4.data-residency",{"title":774,"path":775,"stem":776,"children":777,"stub":566,"launchGate":560,"icon":779},"Release notes","\u002Fdocs\u002Frelease-notes","docs\u002F7.release-notes\u002Findex",[778],{"title":774,"path":775,"stem":776,"stub":566,"launchGate":560},"i-lucide-scroll-text",[781,783],{"title":651,"path":652,"stem":653,"description":782,"children":-1},"Disks for apps and machines: sizes, attaching, resizing and snapshots.",{"title":656,"path":657,"stem":658,"description":784,"children":-1},"Shells in the browser: into your apps and machines, or a cloud shell already signed in to Velrix."]