Rover config Commands

Create and manage configuration profiles


Rover enables you to create multiple configuration profiles. A profile can hold a credential, which determines its GraphOS identity and permissions: an OAuth login from rover auth login or a personal API key from rover config auth. A profile can also hold settings, with or without a credential. You manage your configuration profiles with the rover config set of commands. To learn where profiles are stored, see Where Rover stores configuration.

Displaying configuration profiles

config list

The config list command lists all of your stored configuration profiles:

Text
1rover config list
2
3Profiles:
4
5staging
6default

This includes settings-only profiles created by config set. If there are none, it prints No profiles found.

config whoami

The config whoami command checks the credential Rover uses against GraphOS and displays its identity:

Text
1rover config whoami
2
3note: `rover config whoami` is being replaced by `rover auth whoami` - consider switching over.
4Checking identity of your API key against the registry.
5note: OAuth authentication is now available - consider running `rover auth login` instead of a Personal API Key.
6┌──────────┬───────────────────┐
7│ Key Type ┆ User              │
8├╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
9│ User ID  ┆ gh.example-user   │
10├╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
11│ Origin   ┆ --profile default │
12├╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
13│ API Key  ┆ user********-key  │
14└──────────┴───────────────────┘

Key Type is User, Graph, or Service Account. A graph API key shows Graph ID and Graph Title rows instead of User ID. Origin shows where the credential came from: $APOLLO_KEY, $APOLLO_CLIENT_ID, --profile <name> (OAuth), or --profile <name>. See Which credential Rover uses. The OAuth note appears only when the credential is an API key. rover auth whoami reports the same identity and also covers OAuth logins in detail.

If the profile holds settings but no credential, and no credential is set in the environment, config whoami and every other command that needs a credential fail:

Text
1error[E055]: Profile `staging` has settings but no credential. Run `rover auth login --profile staging`, or set `APOLLO_KEY` in the environment.

Creating configuration profiles

config auth

The config auth command stores a personal API key on a configuration profile, creating the profile if it doesn't exist. For local development, rover auth login is recommended instead, and config auth says so before it prompts for the key:

Text
1rover config auth
2
3warning: OAuth authentication is now available - consider running `rover auth login` instead of storing a Personal API Key.
4Go to https://go.apollo.dev/r/auth and create a new Personal API Key.
5Copy the key and paste it into the prompt below.
6>

After you paste the key, Rover stores it in your operating system's credential store and confirms:

Text
1Successfully saved API key. Consider running `rover config whoami` to verify your API authentication.

The key replaces any credential already on the profile, including an OAuth login. Rover keeps the profile's settings.

By default, your configuration profile is saved with the name default. You can specify a different name with the --profile option:

Text
1rover config auth --profile sso

Managing settings

A configuration profile can also store non-secret settings, with or without a credential, such as the registry URL or request timeouts. See Settings in a profile for which settings can be stored and how they rank against flags, environment variables, and the project file.

config show

The config show command reports every setting's effective value and which source supplied it: flag, environment, profile (explicit) for a profile named with --profile, project file, profile (default), or built-in default. Run it inside your project to include the project's rover.yaml. In this example, the staging profile sets the registry URL, your project's rover.yaml sets the checks timeout (and a registry URL that the profile outranks), and APOLLO_TELEMETRY_DISABLED is set in the environment:

Text
1rover config show --profile staging
2
3Profile: staging (explicit)
4Credential: none
5
6┌───────────────────────────────────────┬────────────────────────────────────────────────────────────┬────────────────────┐
7│ Setting                               ┆ Value                                                      ┆ Source             │
8╞═══════════════════════════════════════╪════════════════════════════════════════════════════════════╪════════════════════╡
9│ APOLLO_REGISTRY_URL                   ┆ https://registry.staging.example.com                       ┆ profile (explicit) │
10├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
11│ APOLLO_TELEMETRY_URL                  ┆ https://rover.apollo.dev/telemetry                         ┆ built-in default   │
12├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
13│ APOLLO_TELEMETRY_DISABLED             ┆ true                                                       ┆ environment        │
14├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
15│ APOLLO_CHECKS_TIMEOUT_SECONDS         ┆ 600                                                        ┆ project file       │
16├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
17│ APOLLO_CLIENT_TIMEOUT                 ┆ 30                                                         ┆ built-in default   │
18├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
19│ APOLLO_ROVER_DOWNLOAD_HOST            ┆ https://rover.apollo.dev                                   ┆ built-in default   │
20├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
21│ APOLLO_TEMPLATES_API                  ┆ https://rover.apollo.dev/templates                         ┆ built-in default   │
22├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
23│ APOLLO_GRAPH_REF                      ┆ none                                                       ┆ built-in default   │
24├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
25│ APOLLO_ROVER_ALLOW_AUTOMATIC_DOWNLOAD ┆ true                                                       ┆ built-in default   │
26├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
27│ APOLLO_OAUTH_AUTHORIZATION_URL        ┆ https://auth.apollographql.com/oauth2/authorize            ┆ built-in default   │
28├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
29│ APOLLO_OAUTH_TOKEN_URL                ┆ https://auth.apollographql.com/oauth2/token                ┆ built-in default   │
30├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
31│ APOLLO_OAUTH_DEVICE_AUTHORIZATION_URL ┆ https://auth.apollographql.com/oauth2/device_authorization ┆ built-in default   │
32├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
33│ APOLLO_OAUTH_REVOCATION_URL           ┆ https://auth.apollographql.com/oauth2/revoke               ┆ built-in default   │
34├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
35│ APOLLO_OAUTH_WHOAMI_URL               ┆ https://auth.apollographql.com/oauth2/userinfo             ┆ built-in default   │
36├╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┼╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌╌┤
37│ APOLLO_OAUTH_CLIENT_ID                ┆ UOsTLIgQb6eFevYcnQewoCDJZagFswCfESvr1hdIU8w                ┆ built-in default   │
38└───────────────────────────────────────┴────────────────────────────────────────────────────────────┴────────────────────┘

The Credential line reads none, present (environment), or present (profile). config show never prints an API key or other credential value, only whether one is present and where it came from. It doesn't create a profile or store any credential or setting.

Pass --format json for a machine-readable version. The data object has these fields:

  • profile: the name of the profile in use.

  • profile_selection: explicit if you named the profile with --profile, otherwise default.

  • credential: an object with present (true or false) and origin (environment, profile, or null).

  • settings: one entry per setting, in the same order as the table. Each entry has name, value (null when the setting has no value), source, and overridden, which lists every lower-precedence source that set it too, highest first.

JSON
1{
2  "json_version": "1",
3  "data": {
4    "profile": "staging",
5    "profile_selection": "explicit",
6    "credential": {
7      "present": false,
8      "origin": null
9    },
10    "settings": [
11      {
12        "name": "APOLLO_REGISTRY_URL",
13        "value": "https://registry.staging.example.com",
14        "source": "explicit_profile",
15        "overridden": [
16          {
17            "source": "project_file",
18            "value": "https://registry.example.com"
19          }
20        ]
21      },
22      {
23        "name": "APOLLO_TELEMETRY_URL",
24        "value": "https://rover.apollo.dev/telemetry",
25        "source": "builtin",
26        "overridden": []
27      },
28      {
29        "name": "APOLLO_TELEMETRY_DISABLED",
30        "value": "true",
31        "source": "environment",
32        "overridden": []
33      },
34      {
35        "name": "APOLLO_CHECKS_TIMEOUT_SECONDS",
36        "value": "600",
37        "source": "project_file",
38        "overridden": []
39      },
40      {
41        "name": "APOLLO_CLIENT_TIMEOUT",
42        "value": "30",
43        "source": "builtin",
44        "overridden": []
45      },
46      {
47        "name": "APOLLO_ROVER_DOWNLOAD_HOST",
48        "value": "https://rover.apollo.dev",
49        "source": "builtin",
50        "overridden": []
51      },
52      {
53        "name": "APOLLO_TEMPLATES_API",
54        "value": "https://rover.apollo.dev/templates",
55        "source": "builtin",
56        "overridden": []
57      },
58      {
59        "name": "APOLLO_GRAPH_REF",
60        "value": null,
61        "source": "builtin",
62        "overridden": []
63      },
64      {
65        "name": "APOLLO_ROVER_ALLOW_AUTOMATIC_DOWNLOAD",
66        "value": "true",
67        "source": "builtin",
68        "overridden": []
69      },
70      {
71        "name": "APOLLO_OAUTH_AUTHORIZATION_URL",
72        "value": "https://auth.apollographql.com/oauth2/authorize",
73        "source": "builtin",
74        "overridden": []
75      },
76      {
77        "name": "APOLLO_OAUTH_TOKEN_URL",
78        "value": "https://auth.apollographql.com/oauth2/token",
79        "source": "builtin",
80        "overridden": []
81      },
82      {
83        "name": "APOLLO_OAUTH_DEVICE_AUTHORIZATION_URL",
84        "value": "https://auth.apollographql.com/oauth2/device_authorization",
85        "source": "builtin",
86        "overridden": []
87      },
88      {
89        "name": "APOLLO_OAUTH_REVOCATION_URL",
90        "value": "https://auth.apollographql.com/oauth2/revoke",
91        "source": "builtin",
92        "overridden": []
93      },
94      {
95        "name": "APOLLO_OAUTH_WHOAMI_URL",
96        "value": "https://auth.apollographql.com/oauth2/userinfo",
97        "source": "builtin",
98        "overridden": []
99      },
100      {
101        "name": "APOLLO_OAUTH_CLIENT_ID",
102        "value": "UOsTLIgQb6eFevYcnQewoCDJZagFswCfESvr1hdIU8w",
103        "source": "builtin",
104        "overridden": []
105      }
106    ],
107    "success": true
108  },
109  "error": null
110}

The source values in JSON output are flag, environment, explicit_profile, project_file, default_profile, and builtin.

config set

The config set command stores a value for one setting on a profile:

Text
1rover config set APOLLO_REGISTRY_URL https://registry.staging.example.com --profile staging
2
3Set `APOLLO_REGISTRY_URL` to `https://registry.staging.example.com` in profile `staging`.

<SETTING> is the setting's environment variable name, spelled exactly, such as APOLLO_REGISTRY_URL. Rover validates the value before storing it. For example, Rover rejects a URL that doesn't use http or https rather than saving it:

Text
1rover config set APOLLO_REGISTRY_URL ftp://registry.example.com --profile staging
2
3error[E054]: `ftp://registry.example.com` isn't a valid URL. Rover only accepts `http`/`https` URLs for this setting.

Only the settings marked in the Profile column of the environment variables table can be stored. config set and config unset refuse any other name and say why. For example:

Text
1rover config set APOLLO_LOG_LEVEL debug --profile staging
2
3error: invalid value 'APOLLO_LOG_LEVEL' for '<SETTING>': `APOLLO_LOG_LEVEL` can't be stored in a profile. It's a property of you and your terminal rather than an environment. Pass `--log`, or set `APOLLO_LOG_LEVEL` in the environment.
4
5For more information, try '--help'.

Credentials such as APOLLO_KEY can't be stored with config set either. Rover refuses them as names it doesn't recognize, for example "APOLLO_KEY isn't a Rover setting". To store a credential, use rover auth login or config auth.

If the named profile doesn't already exist, config set creates it without a credential. A later command that needs that profile's credential fails with error E055, which tells you how to add one; see config whoami.

With --format json, config set reports the setting, the value it stored, and the profile:

JSON
1{
2  "json_version": "1",
3  "data": {
4    "setting": "APOLLO_REGISTRY_URL",
5    "value": "https://registry.staging.example.com",
6    "profile": "staging",
7    "success": true
8  },
9  "error": null
10}

config unset

The config unset command removes a stored setting from a profile:

Text
1rover config unset APOLLO_REGISTRY_URL --profile staging
2
3Removed `APOLLO_REGISTRY_URL` from profile `staging`.

Unsetting a setting that isn't stored on the profile isn't an error:

Text
1rover config unset APOLLO_CHECKS_TIMEOUT_SECONDS --profile staging
2
3`APOLLO_CHECKS_TIMEOUT_SECONDS` isn't set in profile `staging`. Nothing to remove.

With --format json, config unset reports setting, profile, and removed, which is false when there was nothing to remove.

Deleting configuration profiles

config delete

The config delete command deletes a single configuration profile, specified by its name, including its stored credential and settings:

Text
1rover config delete sso
2
3Successfully deleted profile "sso"

config clear

The config clear command deletes all of your stored configuration profiles, including their credentials and settings:

Text
1rover config clear
2
3Successfully cleared all configuration.