Skip to main content
Version: Next

lhc instance

Show information about the connected Lakehousecat instance, and rotate its encryption key.

Commands​

instance info​

Fetches instance metadata including the license state, expiry, and seat count.

lhc instance info
lhc instance info --output json
lhc instance info --output yaml

Example output (table):

INSTANCE_ID                            EXPIRES_AT   SUBSCRIPTION_STATE   USER_SEAT_COUNT
eb0e938e-ff73-4e53-b20e-e74d1e021541 2027-01-01 active 10

Example output (JSON):

{
"instance_id": "eb0e938e-ff73-4e53-b20e-e74d1e021541",
"expires_at": "2027-01-01",
"subscription_state": "active",
"user_seat_count": 10
}

Use instance info as a connectivity check after configuring a new profile.


instance rotate-encryption-key​

Rotate the instance's encryption key (ENCRYPT_KEY). Requires Admin permissions.

Runs as a background job on the backend — this command returns immediately with a run ID; poll its progress with instance rotate-encryption-key-status. Defaults to a dry run, which only counts rows pending rotation and writes nothing:

lhc instance rotate-encryption-key
lhc instance rotate-encryption-key --apply
lhc instance rotate-encryption-key --apply --table user --table model
FlagDefaultDescription
--applyfalseActually rewrite rows. Without it, the command only counts what would change
--table—Limit the run to this table (repeatable). Omit to rotate every table that holds encrypted content

Example output:

{ "run_id": 3 }

Before running this: the old key must already be reachable by the backend as a read fallback, alongside the new key that is already active. See Encryption Key Rotation for the full, ordered procedure — running this command out of order can make encrypted data unreadable.


instance rotate-encryption-key-status <run-id>​

Check the progress of a rotation run started with instance rotate-encryption-key:

lhc instance rotate-encryption-key-status 3

Example output (JSON):

{
"run_id": 3,
"status": "completed",
"mode": "apply",
"primary_key_fingerprint": "60e202ae",
"tables": {
"chart": { "scanned": 42, "pending": 42, "rewritten": 42 },
"datasource": { "scanned": 5, "pending": 0, "rewritten": 0 }
},
"error": null,
"created_at": 1787931801,
"updated_at": 1787931825
}

status is one of pending, running, completed, or failed. Each table's tally reports scanned (rows read), pending (rows not yet encrypted with the current key), and rewritten (rows actually rewritten — always 0 for a dry run). If status is failed, error names the row and reason — most commonly a row encrypted with a key that isn't available as a read fallback. The run stops immediately rather than skip the row silently; re-running is safe once the missing key is back in place, since already-rotated rows are skipped automatically.