> For the complete documentation index, see [llms.txt](https://docs.unitlab.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.unitlab.ai/api-sdk-cli/clis/cli-ontologies-and-cloud-storage.md).

# CLI: ontologies and cloud storage

{% hint style="info" %}
**Outcome:** Create or update ontology JSON, list compatible ontologies, and browse safe cloud metadata.
{% endhint %}

```bash
unitlab ontology list --data-type image --json
unitlab ontology detail ONTOLOGY_ID --json
unitlab ontology create "Road ontology" ontology.json --data-type image --json
unitlab ontology update ONTOLOGY_ID ontology.json --json

unitlab cloud list --json
unitlab cloud browse CLOUD_ID --prefix incoming/ --json
```

Treat ontology JSON as a versioned schema artifact and validate it in a pilot project. Cloud commands never return provider credentials; they expose safe integration and object metadata.

### Operating contract

| Concern           | Required behavior                                                           |
| ----------------- | --------------------------------------------------------------------------- |
| Execution surface | Pinned `unitlab==3.0.0` command in the intended Python 3.10+ environment.   |
| Machine contract  | Use `--json`; human-readable output is not an automation interface.         |
| Target resolution | Resolve stable IDs with a read command before a state-changing command.     |
| Success evidence  | Exit status, JSON result, returned IDs, and a read-after-write state check. |

### Failure and recovery boundary

| Condition                                       | Response                                                                                                     |
| ----------------------------------------------- | ------------------------------------------------------------------------------------------------------------ |
| Authentication or authorization fails           | Stop, correct the service identity or access model, rotate exposed credentials, and rerun a read-only check. |
| Validation or entitlement rejects the operation | Correct the input or entitlement; do not retry an unchanged request.                                         |
| A request times out                             | Inspect remote state before repeating a mutation because the server may have accepted it.                    |
| Asynchronous processing exceeds its deadline    | Preserve the Batch Queue or release ID, continue bounded monitoring, and inspect item-level failures.        |
| Only part of a batch succeeds                   | Keep successful identifiers, isolate failed rows, and retry only the corrected subset.                       |

{% hint style="warning" %}
Pin and test the production SDK version. Use stable IDs, keep secrets out of logs and command history, and record the correlation ID, target IDs, counts, final state, and redacted error details for material state changes.
{% endhint %}
