Fly.io
Arcade tools designed for LLMs to interact with Fly.io
1.0.1Fly.io Toolkit
Arcade's Fly.io toolkit lets LLMs manage Fly.io infrastructure programmatically — apps, Machines, volumes, networking, secrets, certificates, and deployments — using the Fly.io API.
Capabilities
- App & release management: list, inspect, and deploy apps; roll new container images to all Machines; browse paginated release history scoped to any organization.
- Machine lifecycle: create, start, stop, restart, and permanently destroy Machines; scale app Machine count up or down; change VM size or memory allocation.
- Persistent storage: create, extend (grow only), list, and destroy volumes attached to an app.
- Networking & TLS: allocate or release dedicated IP addresses; list all assigned IPs; add, check, and remove custom-domain TLS certificates with DNS record guidance.
- Secrets management: list secret names (values are never returned by Fly.io), set new secrets, and unset existing ones — each with an optional immediate rollout flag.
- Observability & metadata: read recent app logs (requires a token with explicit log-read access; returns a
no_accessstatus rather than an error when that permission is absent); list organizations, regions, and per-Machine configuration and health.
Secrets
FLYIO_ACCESS_TOKEN — A Fly.io personal access token or deploy token used to authenticate every API call. To obtain one, log in to the Fly.io dashboard, open Account → Access Tokens, and create a new token. For production use, prefer a scoped deploy token created with fly tokens create deploy -a <app-name> (Fly CLI) or via the dashboard's app-level token page; for log access (Flyio.GetLogs), the token must additionally be granted log-read permission, which a standard deploy token does not include — create a token via fly tokens create org or use a personal access token with full org access if log reading is required. See Fly.io access token docs for full scope details.
Add this secret in Arcade at https://api.arcade.dev/dashboard/auth/secrets. For general guidance on configuring secrets in Arcade tools, see https://docs.arcade.dev/en/guides/create-tools/tool-basics/create-tool-secrets.
Available tools(30)
| Tool name | Description | Secrets | |
|---|---|---|---|
Add a TLS certificate for a hostname and return the DNS records to set. | 1 | ||
Allocate a new IP address for an app. | 1 | ||
Check a certificate's validation status and any pending DNS records. | 1 | ||
Create a new Machine for an app from a container image. | 1 | ||
Create a new persistent volume for an app. | 1 | ||
Roll a new container image out to all of an app's Machines. | 1 | ||
Permanently destroy a Machine. Stop it first unless force is set. | 1 | ||
Permanently destroy a volume and the data it holds. | 1 | ||
Grow a volume to a larger size. Volumes cannot be shrunk. | 1 | ||
Get the current status of a single Fly.io app. | 1 | ||
Read recent historical log entries for an app, optionally filtered.
Reading logs requires a token granted log-read access, which is a capability
separate from app management; a token without it cannot read logs at all. When
that access is missing this returns a ``no_access`` result rather than raising,
so prefer branching on the result's ``status`` over assuming logs are present. | 1 | ||
Get the configuration, state, and health of a single Machine. | 1 | ||
List Fly.io apps, optionally scoped to a single organization.
Apps are returned in Fly.io's own ordering, with pagination metadata so a
caller can tell when more apps exist beyond the returned window. | 1 | ||
List the custom-domain TLS certificates configured on an app. | 1 | ||
List the IP addresses assigned to an app, including the shared IPv4. | 1 | ||
List the Machines that belong to an app. | 1 | ||
List the Fly.io organizations the configured token can access. | 1 | ||
List the Fly.io regions available for deploying apps and volumes. | 1 | ||
List an app's release history, newest first. | 1 | ||
List an app's secret names. Secret values are never returned by Fly.io. | 1 | ||
List the persistent volumes that belong to an app. | 1 | ||
Release a dedicated IP address so it is no longer assigned to the app. | 1 | ||
Remove a custom-domain TLS certificate from an app. | 1 | ||
Restart a Machine and report its settled state. | 1 | ||
Scale an app to a target Machine count by adding or removing Machines. | 1 |