# lizard ssh

Execute a command inside a running service's container, streaming its output and returning the remote exit code.

## run vs. ssh

`lizard run` and `lizard ssh` both execute a command with a service's context, but they run in different places — know which one you want.

| Command | Runs where | Use for |
|---------|-----------|---------|
| `lizard run` | **Locally**, with the service's project + service secrets injected | Migrations, seed scripts, local tooling that needs prod config |
| `lizard ssh` | **Inside the running service container** | Inspecting the live container, one-off remote commands, debugging |

`lizard run` shows your local injected copy of the environment, which is usually the same as production — but `lizard ssh` is authoritative for what the live container actually sees.

## Usage

```bash
lizard ssh --service <name> -- <command>
```

## Examples

### Inspect the environment the running app sees

```bash
lizard ssh --service api -- env
```

### List files in the deployed image

```bash
lizard ssh --service api -- ls -la /app
```

### Check the OS in the container

```bash
lizard ssh --service api -- cat /etc/os-release
```

### Confirm a secret landed in the live container

```bash
lizard ssh --service api -- env | grep DATABASE_URL
```

## See also

- [lizard run](https://lizard.build/docs/cli/run) — run a command locally with the service's env injected instead
- [Variables](https://lizard.build/docs/variables) — how secrets and references reach a service
- [Deploy from Claude Code](https://lizard.build/blog/deploy-from-claude-code#claude-code-deployment-compared-with-the-alternatives) — why an agent needs a shell into the running container, and which platforms don't give one
