Skip to Content
ResourcesIntegrationsDeveloper ToolsFly.io

Fly.io

Service domainCODE SANDBOX
Fly.io icon
Arcade OptimizedBYOC

Arcade tools designed for LLMs to interact with Fly.io

Author:Arcade
Version:1.0.1
Auth:No authentication required
30tools
30require secrets

Fly.io Toolkit

Arcade's Fly.io toolkit lets LLMs manage the full lifecycle of Fly.io apps, machines, volumes, networking, secrets, and certificates via the Fly.io API.

Capabilities

  • App & release management: list, inspect, and deploy apps; roll new container images to all machines; browse release history scoped per app or organization.
  • Machine control: create, start, stop, restart, and destroy individual machines; scale machine count up or down; resize VM size or memory across an app's fleet.
  • Volume management: create, extend, and destroy persistent volumes; list volumes per app. Note: volumes cannot be shrunk.
  • Networking & TLS: allocate and release dedicated IP addresses; add, check, and remove custom-domain TLS certificates; retrieve required DNS validation records.
  • Secrets: set and unset app secrets with optional immediate rollout; list secret names (Fly.io never exposes secret values through the API).
  • Observability & discovery: read recent app logs (requires a token with explicit log-read access; returns a no_access status when that permission is absent), list available regions, and enumerate organizations accessible to the configured token.

Secrets

FLYIO_ACCESS_TOKEN — A Fly.io personal access token or deploy token used to authenticate every API call. To obtain one, log in to the Fly.io dashboard and navigate to Account → Access Tokens, or run flyctl tokens create in the Fly.io CLI. For log access via Flyio.GetLogs, the token must have the log-read capability in addition to standard app management permissions; a token lacking this permission causes log reads to return a no_access result rather than raising an error. Scope the token to the minimum required organizations and capabilities for your use case.

For general guidance on configuring secrets in Arcade, see the Arcade secrets documentation. You can manage secret values at https://api.arcade.dev/dashboard/auth/secrets.

Available tools(30)

30 of 30 tools
Operations
Behavior
Tool nameDescriptionSecrets
Add a TLS certificate for a hostname and return the DNS records to set.
1
Allocate a new IP address for an app.
1
Check a certificate's validation status and any pending DNS records.
1
Create a new Machine for an app from a container image.
1
Create a new persistent volume for an app.
1
Roll a new container image out to all of an app's Machines.
1
Permanently destroy a Machine. Stop it first unless force is set.
1
Permanently destroy a volume and the data it holds.
1
Grow a volume to a larger size. Volumes cannot be shrunk.
1
Get the current status of a single Fly.io app.
1
Read recent historical log entries for an app, optionally filtered. Reading logs requires a token granted log-read access, which is a capability separate from app management; a token without it cannot read logs at all. When that access is missing this returns a ``no_access`` result rather than raising, so prefer branching on the result's ``status`` over assuming logs are present.
1
Get the configuration, state, and health of a single Machine.
1
List Fly.io apps, optionally scoped to a single organization. Apps are returned in Fly.io's own ordering, with pagination metadata so a caller can tell when more apps exist beyond the returned window.
1
List the custom-domain TLS certificates configured on an app.
1
List the IP addresses assigned to an app, including the shared IPv4.
1
List the Machines that belong to an app.
1
List the Fly.io organizations the configured token can access.
1
List the Fly.io regions available for deploying apps and volumes.
1
List an app's release history, newest first.
1
List an app's secret names. Secret values are never returned by Fly.io.
1
List the persistent volumes that belong to an app.
1
Release a dedicated IP address so it is no longer assigned to the app.
1
Remove a custom-domain TLS certificate from an app.
1
Restart a Machine and report its settled state.
1
Scale an app to a target Machine count by adding or removing Machines.
1
Page 1 of 2(25 of 30)
Last updated on