drift slice
Create, resize and operate the slice itself: the environment your project lives in.
| Command | Description |
|---|---|
drift slice create [name] | Draw the slice's shape in the terminal. You pick resources there, see the price update as you type, and apply; the new slice becomes the active one. |
drift slice create <name> --free | Create a free Hacker slice with no form, usable in CI, scripts, and SSH sessions. --headless is an alias. |
drift slice list | List your slices (* marks the active one) |
drift slice use <name> | Set the active slice for the commands that follow |
drift slice info | What the active slice's scheduler is holding and refusing right now |
drift slice resize [name] | Draw the slice's shape opened on what it already is. Defaults to the active slice. |
drift slice shrink | Deprecated: resizes the active slice, exactly as resize does. |
drift slice restart | Restart your slice |
drift slice auth | Put an HTTP Basic-auth gate in front of the slice's Canvas site |
drift slice delete <name> [--yes] | Delete a slice and everything in it (irreversible) |
What a slice is doing right now
The runtime admits work against a per-function memory pool, learns each pool's booking from the peak memory of every invocation it reaps, and stops an invocation that overruns rather than letting it take the slice down with it. drift slice info is the read on all of that:
$ drift slice info
my-slice
compute 340MB of 512MB held (66%)
in flight 2 invocation(s)
warm workers 3 parked
pools
post:webhook 12MB of 32MB held (37%)
get:report 190MB of 256MB held (74%)A limit reported as unbounded means no ceiling could be read, not a generous one. Read this when something is slow; drift file benchmark answers the other question, what a function has actually cost and what it should book.
Changing a slice's shape
drift slice create and drift slice resize own a slice's shape, and they are the only things that write one. Every resource, every limit and the price of the lot are chosen there. A Driftfile declares what runs on a slice; it does not say what the slice is.
The default path for either is a form that recomputes the total as you type. It is a tree you move around in: arrows move, space folds a section, and typing edits the row you are on directly, a function's row is its route, so you highlight it and start spelling. ^D removes an item, Esc discards a half-typed one. Everything is collapsed to begin with, so the parts you never open stay at the platform's own defaults. The price comes from the server on every edit; the CLI ships no rates of its own, so the figure above Apply is the figure you are charged.
For a resize, that gives one path for a change in any direction, up or down:
drift slice resize # the active slice
drift slice resize my-slice # or a named onedrift slice shrink still works and resizes the active slice. It says once that it is deprecated: a reduction is chosen and confirmed where the shape lives, so there is no longer a destructive spelling of resize for it to be.
A resize is refused twice on purpose, and each refusal is answered on the form itself rather than by starting again. Booking memory per function for the first time reprices the whole slice, so it is refused until you agree to the new figure: the button changes to say what it now costs, and pressing it again is the agreement. A change that takes something away is refused until you confirm it, after the form has listed what would go.
Resizing without a terminal
The form needs a TTY, which used to mean no script, CI job or SDK consumer could resize a slice at all. --dump and --config answer the platform's same two questions from flags instead of from the form:
drift slice resize my-slice --dump > shape.json # what it is now
$EDITOR shape.json # what it should be
drift slice resize my-slice --config shape.json \
--acknowledge-monthly-cents 1200 # yes, at that price--dump writes the slice's current shape as JSON to stdout; edit it and feed it back with --config. A resize that changes what the slice costs is refused until --acknowledge-monthly-cents sends back the new figure in cents; one that takes something away is refused until --confirm <slice-name> names the slice. Each refusal states the figure or lists what would be lost, the same information the form's own row shows, so a second attempt can answer it exactly. drift slice create has no such flag pair: a slice that does not exist yet has nothing to dump, and --free is its own no-form path for creating one.
drift file apply neither creates a slice nor resizes one.
drift slice create. Growing and shrinking are the same act now, and both happen at the resize form, or through --dump/--config, which is also where a reduction that would strand data is refused, with each offending resource named against its current usage.The interactive form needs a terminal.
create, --free is the path that asks nothing and works anywhere; for resize, --dump/--config is.Linking
Let the active slice call another slice you own, without the call leaving Drift (e.g. an app calling your own observability slice). From code, reach the linked slice with drift.Slice("<name>").
| Command | Description |
|---|---|
drift slice link add <slice> | Allow the active slice to call <slice> (same owner) |
drift slice link list | List the slices the active slice can call, and who can call it |
drift slice link remove <slice> | Remove a link |
Site gate
Guard the slice's Canvas site with HTTP Basic auth: anyone without the credential gets a 401 and never reaches the site. This gates the site itself, not the API; drift atomic auth guards a function separately.
| Command | Description |
|---|---|
drift slice auth set --user <name> [--realm R] | Enable the gate for the users named, replacing any credentials already set. Repeat --user for more than one. |
drift slice auth list | Show whether the gate is on, and who can sign in |
drift slice auth disable | Remove the gate; the site becomes publicly reachable again |
set replaces the whole credential set rather than adding to it, so naming one user leaves exactly that user able to get in, which is what makes removing someone a single predictable command. Passwords are read from the terminal, or from stdin in order with --password-stdin (one line per --user); there is no --password flag, since the credential would land in ps output and shell history. disable asks for confirmation, being the one direction that exposes something.
Snapshots
Portable backups of a whole slice: source code, data, secrets, and sites. Your source comes back as you wrote it, with every Drift-generated wrapper stripped out; the only Drift files in the archive are two manifests that sit beside the tree rather than inside it.
| Command | Description |
|---|---|
drift slice snapshot create [--name label] [--passphrase] | Snapshot the active slice (polls until ready) |
drift slice snapshot list | List snapshots with id, name, size, and status |
drift slice snapshot download <id> [-o path] | Download a snapshot archive |
drift slice snapshot restore <id> | Restore a snapshot into the active slice |
drift slice snapshot delete <id> [--yes] | Delete a snapshot |
Cache and locks are not in the archive.
Encryption, and your own passphrase
Snapshots are stored encrypted. Each archive gets a key of its own, and that key is held wrapped by the platform, so the object store holds ciphertext and a restore can run without you present. The file you download is a plain .tar.gz, and it holds this slice's secrets in cleartext. The CLI writes it 0600 and says so every time.
--passphrase changes who can open the archive. Drift prompts for one, derives the archive's key from it, and uses that instead of the platform's key. Downloading or restoring that snapshot asks for the same passphrase.
A passphrase you forget cannot be recovered, by you or by us.
drift slice snapshot list marks the protected ones, so you can see which those are before you need them.--passphrase-stdin reads the passphrase from stdin instead of prompting, on create, download and restore, for scripts. There is deliberately no flag that takes the passphrase as a value: it would land in ps and in your shell history, and unlike a password this one can never be reset.
What the passphrase protects is the archive at rest, in the object store and on whatever holds a copy of it. Drift builds the archive from your slice, so the contents pass through the platform when you create one and again when you open one. Encrypting in the CLI instead would change that, at the cost of an archive an older CLI could not read.
Custom domains
Point your own hostname at a slice; Drift verifies ownership and issues the TLS certificate. See Getting started for the full flow.
| Command | Description |
|---|---|
drift slice domain add <host> | Register a custom hostname (prints the DNS records to create) |
drift slice domain add <host> --wildcard | Route every subdomain of host to this slice as well |
drift slice domain verify <host> | Re-check the TXT record and, on success, issue the certificate |
drift slice domain list | List custom hostnames for the active slice |
drift slice domain remove <host> | Remove a hostname, its certificate, and its routing |
--wildcard is routing only. Every subdomain reaches the slice, and each one gets its own certificate issued on demand, and there is no wildcard certificate. Telling alice.example.com from bob.example.com is your app's job; the platform hands both to the same slice.
Hostnames can also be declared in the Driftfile under domains:, which the deploy reconciles.