CLI Commands and Flags
Use this page as a quick index of the SRA-related CLI command families. This page is intentionally concise and links to the full command reference.
For complete syntax and flag behavior, use the Gateway CLI reference area and the SRA command page:
Command Families
gateway-update-remote-access: Configure core SRA bastion behavior, such as allowed URLs, session TTL, username claim mapping, and SSH key exchange settings.gateway-update-remote-access-rdp-recording: Configure RDP session recording storage, quality, compression, and encryption.gateway-update-remote-access-desktop-app: Configure Secure Remote Access Desktop Application defaults and control-path settings.gateway-update-remote-access-session-forwarding-*: Configure session log forwarding providers.list-sra-sessions: List SRA sessions. Default behavior is scoped to active statuses and own-user scope unless explicit filters and permissions expand visibility.list-sra-bastions: List bastion clusters and instances for operational inventory and health-oriented review.
Notes
- Include closed session states (
failed,completed,terminated) by applyinglist-sra-sessionsfilters when needed. - When reviewing bastion URL hardening configuration, run
list-sra-bastions --allowed-urls-only true. - The CLI reference page is the source of truth for accepted aliases and parameter names.
