Skip to content
downpipes docs

Drive the console from the keyboard

The console has a keyboard spine: a command palette, a shortcut cheat sheet and thirteen go-to chords. If you click through the rail, this is the shorter route.

The four keys that matter

KeyWhat it does
Cmd-K or Ctrl-KOpens the command palette, from anywhere
/Also opens the command palette, except when focus is in the Downpipes or Runs list, where it focuses the list filter
?Opens the shortcut cheat sheet
g then a letterJumps straight to a screen

Escape closes the palette. It closes whichever overlay is on top, so with a confirmation open over a panel it dismisses the confirmation first rather than everything at once.

The go-to chords

Press g, release it, then press the letter. There are thirteen.

ChordScreenChordScreen
g oOverviewg mTopology map
g dDownpipesg cCost calculator
g rRunsg nNotifications
g sRestoreg eSecurity centre
g kKeysg pReports
g aAccessg vCredentials and expiry
g lAudit log

The letter is not always the initial, because several screens start with the same one. g s is Restore (Security centre is g e), and g v is Credentials and expiry. The cheat sheet on ? is built from the same registry as the chords, so it matches the console you are running.

What the palette will and will not do

The palette is a fuzzy command line over one registry of actions, and the same registry feeds the go-to chords and the cheat sheet. That matters for a reason beyond tidiness: the palette never offers you an action you are not allowed to run. Every command is filtered by your role and by the engine’s current state, so a command that would come back 403 is not listed rather than listed-and-refused. The engine remains the enforcement point; the palette only lists what the engine would allow.

Dangerous actions do not execute from the palette. Request a restore and apply a restore are both in there. Choosing one takes you to the review-then-confirm flow on its own screen rather than firing anything from the palette itself. The palette is how you get to the confirmation, never a way around it. Some benign things do run inline: toggling the theme, switching the console view, and signing out. Others, such as Go to Keys (the key ceremony makes the recovery sheet), only open the screen that hosts the action.

The palette also searches your own account through one index that spans five entity providers: downpipes by name, runs by run id, destinations by label or id, credentials by label, and the audit log by entry sequence number. From console 0.2.7, the audit log is also found by downpipe name: the “Audit log for” row opens the audit log filtered to that downpipe. Each of the five is gated by the same read capability the owning screen reads, so a role that cannot see a kind of entity gets no rows for it and its list is never fetched in the first place. An audit row found by downpipe name needs the downpipe read capability as well.

What the index holds is names, labels and ids, and nothing else. No secret, no key fingerprint and no credential value passes through the palette, and it talks only to your own in-account engine. A credential is findable by the label you gave it, never by its value.

Turning the single-key shortcuts off

A single-key shortcut is a problem for anyone using speech input or an on-screen keyboard, where a stray character can fire a navigation. So the single-key layer, meaning /, ? and the g chords, can be switched off in Settings, under Accessibility. This is WCAG 2.1.4 Character Key Shortcuts. The switch does not affect the / that focuses the Downpipes or Runs filter, because that key acts only while focus is in the list.

Cmd-K and Ctrl-K keep working when that switch is off, because a chord with a modifier cannot be triggered by dictation. So turning the single-key shortcuts off costs you the jumps, not the palette.

The shortcuts are also inert while you are typing in a field, and while a modal owns the keyboard, so pressing g in a search box types a g.

Last updated .