Skip to content

Commit e042607

Browse files
authored
Merge branch 'main' into hypeship/stagehand-v4
2 parents 7f77948 + c64f4b5 commit e042607

35 files changed

Lines changed: 2994 additions & 467 deletions

‎README.md‎

Lines changed: 75 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -103,7 +103,7 @@ Create an API key from the [Kernel dashboard](https://dashboard.onkernel.com).
103103
- `--version`, `-v` - Print the CLI version
104104
- `--no-color` - Disable color output
105105
- `--log-level <level>` - Set log level (trace, debug, info, warn, error, fatal, print)
106-
- `--project <project-id>` - Scope requests to a project ID (or set `KERNEL_PROJECT` to a project ID). Project-scoped OAuth tokens cannot switch projects.
106+
- `--project <id-or-name>` - Scope requests to a project by ID or exact name (or set `KERNEL_PROJECT`). Project-scoped OAuth tokens cannot switch projects.
107107

108108
## JSON Output
109109

@@ -210,25 +210,28 @@ Commands with JSON output support:
210210

211211
- `kernel browsers list` - List running browsers
212212
- `--query <q>` - Search by name, session ID, profile ID, proxy ID, or pool name
213-
- `--region <region>` - Filter sessions by region (us-east or eu-west); omit to list sessions in all regions
213+
- `--region us-east|eu-west` - Filter by geographic region; omit to list sessions in all regions
214214
- `--tag <KEY=VALUE>` - Filter by tag, repeatable; a session must match every pair
215215
- `--output json`, `-o json` - Output raw JSON array
216216
- `kernel browsers create` - Create a new browser session
217217
- `-s, --stealth` - Launch browser in stealth mode to avoid detection
218218
- `-H, --headless` - Launch browser without GUI access
219219
- `--kiosk` - Launch browser in kiosk mode
220-
- `--region <region>` - Region for the session (us-east or eu-west); fixed once created, defaults to us-east. Requires a Start-Up or Enterprise plan.
220+
- `--region us-east|eu-west` - Geographic region for the session. Fixed once the session is created; requires a Start-Up or Enterprise plan and defaults to `us-east`.
221+
- `--private-host <host>` - Destination the browser reaches directly through the session's own network instead of Kernel-managed egress, for private hosts on a VPN or tunnel the session joins (repeatable or comma-separated, max 32). Accepts hostname patterns (`*.example.ts.net`), IPs (`10.1.30.63`, `[fd00::1]`), and private CIDRs (`100.64.0.0/10`). Replaces the default private ranges (RFC1918, `100.64.0.0/10`, `fc00::/7`); omit to keep them. Fixed once the session is created. Unrelated to a proxy's `--bypass-host`, which only chooses between upstream proxy and Kernel-managed direct egress.
221222
- `--start-url <url>` - Initial page to open on launch
223+
- `--proxy-id <id>` / `--proxy-name <name>` - Use that proxy for the session regardless of stealth (mutually exclusive with each other and with `--proxy-mode`)
224+
- `--proxy-mode direct|default` - Egress mode instead of a selected proxy: `direct` for no proxy regardless of stealth, `default` for the stealth-derived default (Kernel's stealth proxy with `--stealth`, direct egress otherwise). Omit all proxy flags to get the default.
222225
- `--name <name>` - Optional unique name for the session (used to find it later by name; can be changed with `browsers update --name`)
223226
- `--tag <KEY=VALUE>` - Set a tag on the session, repeatable; up to 50 pairs
224227
- `--pool-id <id>` - Acquire a browser from the specified pool (mutually exclusive with --pool-name; ignores other session flags). `--name`/`--tag` still apply to the acquired session.
225228
- `--pool-name <name>` - Acquire a browser from the pool name (mutually exclusive with --pool-id; ignores other session flags)
226229
- `--telemetry=all` - Enable telemetry for all categories
227230
- `--telemetry=off` - Disable telemetry
228231
- `--telemetry=<list>` - Per-category config, e.g. `--telemetry=network=on,page=off`
232+
- `--telemetry-export-otlp <id-or-name>` - Export captured telemetry over OTLP to one of the org's configured destinations. Implies `--telemetry=all` when `--telemetry` is not set, since export requires capture. Use `--telemetry-export-otlp=off` to disable export.
229233
- `--chrome-policy <json>` - Custom Chrome enterprise policy as a JSON object. Kernel-managed policies (extensions, proxy, automation) are rejected server-side.
230234
- `--chrome-policy-file <path>` - Read the Chrome enterprise policy from a file (use `-` for stdin). Mutually exclusive with `--chrome-policy`.
231-
- `--private-host <host>` - Route a private hostname, IP, or CIDR through the session network instead of Kernel-managed egress. Repeatable or comma-separated; replaces the default private IP ranges.
232235
- `--output json`, `-o json` - Output raw JSON object
233236
- _Note: When a pool is specified, omit other session configuration flags—pool settings determine profile, proxy, viewport, etc._
234237
- `kernel browsers delete <id-or-name>` - Delete a browser by ID or name
@@ -244,7 +247,10 @@ Commands with JSON output support:
244247
- `--telemetry=all` - Enable telemetry for all categories
245248
- `--telemetry=off` - Disable telemetry
246249
- `--telemetry=<list>` - Per-category config, e.g. `--telemetry=network=on,page=off`
247-
- `--disable-default-proxy` - Disable the default stealth proxy so the browser connects directly; use `--disable-default-proxy=false` to re-enable it
250+
- `--proxy-id <id>` / `--proxy-name <name>` - Switch the session to that proxy regardless of stealth (mutually exclusive with each other and with `--proxy-mode`)
251+
- `--proxy-mode direct|default` - Change egress mode: `direct` for no proxy regardless of stealth, `default` to restore the browser default after using a selected proxy. Changing the proxy does not change stealth or CAPTCHA solver behavior.
252+
- `--clear-proxy` - Drop the selected proxy and restore the browser default (same as `--proxy-mode=default`)
253+
- `--disable-default-proxy` - Connect directly instead of through the default stealth proxy (same as `--proxy-mode=direct`); use `--disable-default-proxy=false` to restore the default
248254
- `--output json`, `-o json` - Output raw JSON object
249255
- `kernel browsers curl <id> <url>` - Make HTTP requests through a browser session's Chrome network stack
250256
- `-X, --request <method>` - HTTP method (default: GET; defaults to POST when `--data` is set)
@@ -264,7 +270,7 @@ Commands with JSON output support:
264270
### Browser Pools
265271

266272
- `kernel browser-pools list` - List browser pools
267-
- `--region <region>` - Filter pools by region (us-east or eu-west); omit to list pools in all regions
273+
- `--region us-east|eu-west` - Filter by geographic region; omit to list pools in all regions
268274
- `--output json`, `-o json` - Output raw JSON array
269275
- `kernel browser-pools create` - Create a browser pool
270276
- `--name <name>` - Optional unique name for the pool
@@ -325,6 +331,37 @@ Telemetry config is a sub-field of the browser session. Use `browsers create` or
325331

326332
Per-category updates are partial — only categories you name are changed; others retain their current state. `--telemetry=all` and `--telemetry=off` reset the entire config.
327333

334+
#### Exporting telemetry
335+
336+
Captured telemetry can be exported over OTLP to one of the org's configured destinations with `--telemetry-export-otlp <id-or-name>`. A value that looks like an ID is sent as one; anything else is resolved as a destination name, which must match exactly one destination in the org.
337+
338+
- Capture and export: `kernel browsers create --telemetry-export-otlp my-collector`
339+
- Capture without exporting: `kernel browsers create --telemetry=all`
340+
- Stop exporting: `--telemetry-export-otlp=off`
341+
342+
Export is bound at session creation, so it is available on `browsers create` and on the managed-auth commands that create a browser (`auth connections create`, `update`, and `login`). A browser session keeps the destination it was created with — `browsers update` cannot change it — and browser pools do not support export.
343+
344+
#### Telemetry destinations
345+
346+
Destinations are the OTLP/HTTP endpoints sessions export to, managed per project.
347+
348+
- `kernel telemetry destinations list` - List OTLP destinations
349+
- `--page <n>` / `--per-page <n>` - Page number (1-based) and items per page (default 20)
350+
- `--name <name>` - Filter by exact destination name
351+
- `--query <text>` - Substring match against name or endpoint; IDs match by exact value
352+
- `kernel telemetry destinations get <id-or-name>` - Get an OTLP destination
353+
- `kernel telemetry destinations create --name <name> --endpoint <url>` - Create an OTLP destination
354+
- `--endpoint <url>` - Base OTLP/HTTP endpoint without a signal path: pass `https://api.honeycomb.io`, not `https://api.honeycomb.io/v1/logs` (required)
355+
- `--name <name>` - Destination name, unique within the project (required)
356+
- `--description <text>` - Optional description
357+
- `--header NAME=VALUE` - Header sent with each export request, typically an ingestion key (repeatable). Values are encrypted at rest and always returned redacted, so only header names are shown
358+
- `kernel telemetry destinations update <id-or-name>` - Update an OTLP destination. Sessions already exporting pick up the new values without restarting, which makes this the way to rotate credentials without interrupting export
359+
- `--name <name>` / `--endpoint <url>` / `--description <text>` - Update those fields; pass `--description ""` to clear it
360+
- `--header NAME=VALUE` - Add or replace a header (repeatable). Headers you do not name are left as they are
361+
- `--remove-header NAME` - Delete a header (repeatable). Removals are applied before `--header` is merged, so a header given to both keeps its new value
362+
- `kernel telemetry destinations delete <id-or-name>` - Delete an OTLP destination. Refused while sessions are still exporting to it, or while a managed auth connection still selects it
363+
- `-y, --yes` - Skip confirmation prompt
364+
328365
- `kernel browsers telemetry stream <id>` - Stream live telemetry events (NDJSON with `-o json`)
329366
- `--categories <list>` - Filter by event category (`console`, `network`, `page`, `interaction`, `control`, `connection`, `system`, `screenshot`, `captcha`, `monitor`)
330367
- `--types <list>` - Filter by event type (e.g. `network_response`, `console_error`)
@@ -482,10 +519,22 @@ Per-category updates are partial — only categories you name are changed; other
482519
- `--offset <n>` - Number of projects to skip; table indexes match this offset
483520
- `--output json`, `-o json` - Output `{ "projects": [...], "next_offset": <n> }`; `next_offset` is omitted on the last page
484521
- When more projects are available, the CLI prints the exact command to fetch the next page
522+
- `kernel projects get <id-or-name>` - Show a project's details
485523
- `kernel projects update <id-or-name>` - Update a project's name or status
486-
- `--name <name>` - New project name (1-255 characters)
524+
- `--name <name>` - New project name (1-255 characters; cannot contain `/` or `%`)
487525
- `--status <status>` - New project status: `active` or `archived`
488526
- `--output json`, `-o json` - Output raw JSON object
527+
- `kernel projects delete <id-or-name>` - Soft-delete a project (must have no active resources)
528+
- `kernel projects limits get <id-or-name>` - Show a project's resource limit overrides
529+
- `--output json`, `-o json` - Output raw JSON object
530+
- `kernel projects limits set <id-or-name>` - Update a project's resource limit overrides
531+
- `--max-concurrent-sessions <n>` - Cap on concurrent browser sessions (0 removes the cap)
532+
- `--max-concurrent-invocations <n>` - Cap on concurrent invocations (0 removes the cap)
533+
- `--max-pooled-sessions <n>` - Cap on pooled browser sessions (0 removes the cap)
534+
- `--output json`, `-o json` - Output raw JSON object
535+
536+
Every `<id-or-name>` above is resolved by the API, so a project name works
537+
anywhere a project ID does.
489538

490539
### Extension Management
491540

@@ -538,6 +587,11 @@ Per-category updates are partial — only categories you name are changed; other
538587
- `kernel proxies delete <id>` - Delete a proxy configuration
539588
- `-y, --yes` - Skip confirmation prompt
540589

590+
### Auth Context
591+
592+
- `kernel auth context` - Show the identity and authorization context resolved for the current credentials: the authenticated principal, organization, credential scope, and the effective scope for the request. Credential secrets are never returned. Pass `--project <id>` to see the effective scope a project-scoped request would get.
593+
- `--output json`, `-o json` - Output raw JSON object
594+
541595
### Auth Connections
542596

543597
Managed auth connections (`kernel auth connections`). The commands below are new or gained new flags; run `kernel auth connections --help` for the full command list.
@@ -547,16 +601,27 @@ Managed auth connections (`kernel auth connections`). The commands below are new
547601
- `--page <n>` - Page number (1-based, default: 1)
548602
- `--per-page <n>` - Items per page (default: 20)
549603
- `--output json`, `-o json` - Output raw JSON array
550-
- `kernel auth connections create` - New flag:
604+
- `kernel auth connections create` - New flags:
605+
- `--proxy-id <id>` / `--proxy-name <name>` / `--proxy-mode direct|default` - Proxy configuration for this connection's login, reauth, and health-check browser sessions (mutually exclusive). Omit to derive the default from stealth.
606+
- `--stealth` - Whether those browser sessions run in stealth mode (default: true); use `--stealth=false` to disable
551607
- `--telemetry=all` / `--telemetry=off` / `--telemetry=<categories>` - Default telemetry for this connection's browser sessions. Same semantics as `kernel browsers create`
552-
- `kernel auth connections update <id>` - New flag:
608+
- `--telemetry-export-otlp <id-or-name>` - Export this connection's captured telemetry over OTLP to one of the org's configured destinations. Implies `--telemetry=all` when `--telemetry` is not set. Use `=off` to disable export.
609+
- `kernel auth connections update <id>` - New flags:
610+
- `--proxy-id <id>` / `--proxy-name <name>` / `--proxy-mode direct|default` - Proxy configuration for future browser sessions (mutually exclusive). Use `--proxy-mode=default` to drop a selected proxy rather than passing an empty value.
611+
- `--stealth` - Set whether future browser sessions run in stealth mode; use `--stealth=false` to disable
553612
- `--telemetry=all` / `--telemetry=off` / `--telemetry=<categories>` - Update telemetry for future browser sessions
554-
- `kernel auth connections login <id>` - New flag:
613+
- `--telemetry-export-otlp <id-or-name>` - Update where future sessions export captured telemetry. Naming a destination requires passing `--telemetry` in the same command, since the API validates capture and export together and enabling capture here would replace the connection's current category selection. Use `=off` to disable export.
614+
- `kernel auth connections login <id>` - New flags:
615+
- `--proxy-id <id>` / `--proxy-name <name>` / `--proxy-mode direct|default` - Proxy override for this login's browser session (mutually exclusive); omitted properties inherit the connection defaults
616+
- `--stealth` - Stealth override for this login's browser session; use `--stealth=false` to disable
555617
- `--telemetry=all` / `--telemetry=off` / `--telemetry=<categories>` - Telemetry override for this login only, merged onto the connection's config
618+
- `--telemetry-export-otlp <id-or-name>` - Export override for this login only. Naming a destination requires passing `--telemetry` in the same command. Use `=off` to disable export.
556619
- `kernel auth connections submit <id>` - New flags:
557620
- `--field-value <id=value>` - Canonical field-id=value pair from the connection's `fields` list (repeatable); preferred over the legacy `--field`
558621
- `--choice-id <id>` - Canonical choice ID from the connection's `choices` list
559622

623+
`kernel auth connections get` and `follow` list those IDs alongside the metadata the API captured for them, so you can tell the options apart before submitting. Fields show their type, ref, and any hint (which names the masked destination a one-time code was sent to); choices show their type, semantic MFA method (`sms`, `totp`, `push`, …), and masked destination.
624+
560625
### Agent Auth
561626

562627
Automated authentication for web services. The `run` command orchestrates the full auth flow automatically.

0 commit comments

Comments
 (0)