Skip to Content
ResourcesIntegrationsDeveloper ToolsFly.io

Fly.io

Service domainCODE SANDBOX
Fly.io icon
Arcade OptimizedBYOC

Arcade tools designed for LLMs to interact with Fly.io

Author:Arcade
Version:1.0.1
Auth:No authentication required
30tools
30require secrets

Fly.io toolkit for Arcade enables LLMs to manage the full Fly.io application lifecycle — machines, volumes, networking, secrets, certificates, and deployments — via the Fly.io API.

Capabilities

  • App & release management: list apps and organizations, inspect app status, view release history, and deploy new container images across all machines.
  • Machine lifecycle: create, start, stop, restart, and destroy machines; scale machine count; resize VM size and memory.
  • Storage & volumes: create, extend, list, and destroy persistent volumes (note: volumes cannot be shrunk).
  • Networking & TLS: allocate and release dedicated IP addresses, list assigned IPs (including shared IPv4), and manage custom-domain TLS certificates with DNS validation support.
  • Secrets management: list secret names, set new secrets, and unset existing ones — with optional immediate rollout; secret values are never returned by Fly.io.
  • Observability: read recent app logs with optional filtering; log access requires a token with explicit log-read permission — tools return a no_access status (rather than raising) when this permission is absent.

Secrets

FLYIO_ACCESS_TOKEN

A Fly.io personal access token or deploy token used to authenticate all API requests. To obtain one:

  1. Log in to the Fly.io dashboard.
  2. Navigate to Account → Access Tokens (or go directly to https://fly.io/user/personal_access_tokens).
  3. Click Create token, give it a name, and copy the value immediately — it is not shown again.

If you need log-read access (required for Flyio.GetLogs), ensure the token is granted that capability. Organization-scoped deploy tokens (created per-app or per-org) can be used instead of a personal token but may have restricted access; confirm the token covers all orgs and apps your agent needs to reach. See Fly.io token documentation for full details on token types and permissions.

Add this secret to Arcade via the Arcade secrets config docs or directly at https://api.arcade.dev/dashboard/auth/secrets.

Available tools(30)

30 of 30 tools
Operations
Behavior
Tool nameDescriptionSecrets
Add a TLS certificate for a hostname and return the DNS records to set.
1
Allocate a new IP address for an app.
1
Check a certificate's validation status and any pending DNS records.
1
Create a new Machine for an app from a container image.
1
Create a new persistent volume for an app.
1
Roll a new container image out to all of an app's Machines.
1
Permanently destroy a Machine. Stop it first unless force is set.
1
Permanently destroy a volume and the data it holds.
1
Grow a volume to a larger size. Volumes cannot be shrunk.
1
Get the current status of a single Fly.io app.
1
Read recent historical log entries for an app, optionally filtered. Reading logs requires a token granted log-read access, which is a capability separate from app management; a token without it cannot read logs at all. When that access is missing this returns a ``no_access`` result rather than raising, so prefer branching on the result's ``status`` over assuming logs are present.
1
Get the configuration, state, and health of a single Machine.
1
List Fly.io apps, optionally scoped to a single organization. Apps are returned in Fly.io's own ordering, with pagination metadata so a caller can tell when more apps exist beyond the returned window.
1
List the custom-domain TLS certificates configured on an app.
1
List the IP addresses assigned to an app, including the shared IPv4.
1
List the Machines that belong to an app.
1
List the Fly.io organizations the configured token can access.
1
List the Fly.io regions available for deploying apps and volumes.
1
List an app's release history, newest first.
1
List an app's secret names. Secret values are never returned by Fly.io.
1
List the persistent volumes that belong to an app.
1
Release a dedicated IP address so it is no longer assigned to the app.
1
Remove a custom-domain TLS certificate from an app.
1
Restart a Machine and report its settled state.
1
Scale an app to a target Machine count by adding or removing Machines.
1
Page 1 of 2(25 of 30)
Last updated on