Anyone with a fleet of three or more servers has typed an rsync command, paused, and wondered: was it -a or -r? do I need --delete? where does the trailing slash go? The trailing slash alone has cost more outages than people would like to admit.
1. Sync excluding common ignores
$ clai rsync this folder to staging:/srv/app/ excluding node_modules and .git→ rsync -avz --delete --exclude='node_modules' --exclude='.git' \ ./ staging:/srv/app/
The trailing slash on ./ matters. CliAI gets it right. Notice the --delete flag is included because a "sync" implies the destination should mirror the source — but it's the kind of flag worth confirming you actually want before pressing Enter.
2. SSH with a forwarded local port
$ clai ssh into prod-db and forward local port 5432 to its postgres→ ssh -L 5432:localhost:5432 prod-db
Forward syntax (-L local:remote_host:remote_port) is one of those things you don't internalize until you've used it weekly for a year.
3. SCP a directory
$ clai scp the whole reports directory from staging:/srv/reports to ./reports→ scp -r staging:/srv/reports ./reports
-r is required for directories; without it scp silently does nothing useful. CliAI knows; you don't have to.
4. Preserve permissions and timestamps
$ clai copy /etc/nginx from prod to here, preserving permissions and timestamps→ rsync -avz --rsync-path='sudo rsync' prod:/etc/nginx/ ./nginx-backup/
--rsync-path='sudo rsync' is the right pattern when the source path needs root to read but you ssh as a regular user. Hard to recall, easy to ask for.
A reminder about authentication
CliAI generates the command; it does not configure your SSH keys or hosts. If ssh staging doesn't work in your terminal, the generated command won't either. Invest once in your ~/.ssh/config and ssh-agent, and these one-liners pay off forever.
See also
- Compress and upload to S3 — when "remote" means object storage rather than another machine.
- Network triage — when the remote command fails because of the network, not the syntax.