helmr computer
helmr computer create DECLARED_ID [--key KEY] [--idempotency-key KEY] [--json]
helmr computer get (--id UUID | --key KEY) [--json]
helmr computer delete (--id UUID | --key KEY) [--idempotency-key KEY] [--json]
helmr computer exec (--id UUID | --key KEY) --idempotency-key KEY -- COMMAND [ARG...]
All commands also accept project/environment scope.
exec accepts --cwd, repeated --set-env NAME=VALUE, --stdin FILE, and
--timeout (default 5m, maximum 15m). It returns bounded stdout/stderr and exits
with the remote process exit code. The -- separator is required before the
remote command.
Secret bindings at creation
Use one JSON binding array with --secrets-file; it contains names and placements,
never Secret values. The wire schema uses allowed_origins (SDK: allowedOrigins).
[
{"secret":"github-token","env":{"name":"GH_TOKEN","mode":"protected","allowed_origins":["https://api.github.com"]}},
{"secret":"database-password","env":{"name":"PGPASSWORD","mode":"raw"}},
{"secret":"client-key","file":{"path":"/run/secrets/client.key"}}
]
helmr computer create reviewer --secrets-file bindings.json --idempotency-key create-reviewer
Bindings are fixed at Computer creation. See Secrets for client support, upstream trust, rotation, and revocation limits. Console Computers → Create Computer offers the same choices; Computer detail shows modes and origins without values.