Running Unified AHF CLI Administration Commands
Currently, the unified AHF CLI is supported only for Linux platforms.
ahf
The ahf command provides a unified CLI for generating diagnostic and AHF Balance reports, querying AHF software and MRP information, managing configuration and repositories, monitoring component status, and administering users and security. Its categories include analysis, configuration, observer, software, data, and security, with common options for help, version information, debugging, local-node scope, and JSON output. Supported operations include Insights and impact analysis, configuration updates, component status checks, software updates and rollbacks, repository management, data relocation, and user administration.
Read More: ahf
ahf analysis
The ahf analysis command generates AHF Insights, AHF Balance impact reports, and activity-specific Alert History reports. Insights supports bounded time-based analysis, refresh, tagging, and optional cell data; AHF Balance supports fleet, cluster, and database scopes, EM groups or cluster lists, output files, and limits on recommended database changes. Since AHF 25.11, Alert History consolidates component logs into activity timelines and supports ASM scenarios such as mount, dismount, forced dismount, and offline events, with filtering by instance, disk group, disk, severity, scenario, and time range limited to the previous 30 days. The deprecated exploratory Scope function should be replaced with Insights.
Read More: ahf analysis
ahf configuration
The ahf configuration command sets, retrieves, validates, and removes AHF settings for repositories, uploads, cells, SMTP, updates, upgrades, resource limits, switches, GoldenGate, fleet insights, and AHF Balance. Recent capabilities include securely storing and checking switch and Exadata infrastructure details in the AHF wallet, automated propagation of excluded compliance-check IDs, and CLI management of update and upgrade parameters while legacy ahfctl commands transition to SDK CLI equivalents. Configuration supports interactive and property-based operations, JSON output, node-wide or targeted scope, repository connection details, upload endpoints, resource controls, and Exadata best-practice configuration.
Read More: ahf configuration
ahf observer
The ahf observer command reports the status of AHF components through ahf observer status. It supports optional JSON output and identifies each component, host, and current state, such as whether Compliance is running or not running.
Read More: ahf observer
ahf software
The ahf software command provides AHF, TFA, and Compliance version details; queries installed MRP levels; compares Oracle homes with specified MRP levels to show installed and missing patches; identifies the latest applicable MRP; and manages update, upgrade, rollback, downgrade, backup deletion, and AHF Home relocation operations. It also exposes downgrade targets, validates downgrade installers, and retrieves update or upgrade histories. Several commands support JSON output, while software movement can optionally include the data directory.
Read More: ahf software
ahf data
The ahf data command retrieves AHF repository information for TFA, Compliance, or all components, optionally restricted to the local installation and formatted as JSON. It can move the AHF Data directory to a specified destination and retrieve the latest Compliance reports by report type, including location, collection time, full-report status, and Compliance version.
Read More: ahf data
ahf security
The ahf security command manages AHF users, roles, access states, credentials, and certificates. User operations include adding, removing, promoting, demoting, blocking, unblocking, listing, resetting, and granting or revoking roles. Credential operations securely store, retrieve, validate, and remove passwords and SSH keys for nodes, cells, databases, ASM, CDBs, and PDBs, with SSH keys protected in the AHF wallet and database credentials restricted from root users. AHF 26.8 adds customer CA-signed certificate support for root and non-root connections and certificate import, listing, updating, and removal for self-signed upload servers; certificates are distributed across cluster nodes and used for TLS validation.
Read More: ahf security
ahf schedule
The ahf schedule advise-time command identifies a minimum-duration low-load window for running Exachk. It currently supports the Compliance component and can exclude specified busy periods using start and end times in HH:MM format. The required --window value defines the minimum available duration in minutes, enabling scheduling around production or maintenance activity.
Read More: ahf schedule