Command line
evergreen extend
Builds a TTL extension and simulates it. Submitting is a separate, explicit decision that needs a flag, a named secret variable and a fee cap — and it is testnet only.
It simulates unless you insist
Running extend with no submission flags builds the operation, simulates it against the network and tells you what would happen. Nothing is signed and nothing is sent. --dry-run exists so a script can state that intention rather than rely on the absence of a flag, and it is mutually exclusive with --submit.
Simulation success does not mean the TTL changed. It means the network accepted the shape of the operation. Until you submit, nothing on chain has moved.
The guards
| Guard | What it prevents |
|---|---|
| simulate by default | A command that submits because a flag was forgotten. |
| --submit required | Submission as a side effect of any other option. |
| --secret-env NAME | A secret in shell history, in a process list, or in a committed script. The value is never an argument, and there is no .env auto-loading. |
| --max-fee-stroops N | An unbounded fee. The cap is an aggregate in integer stroops and it is mandatory with --submit. |
| explicit payer | Silent use of some default account. Supply --source-account or EVERGREEN_SOURCE_ACCOUNT; there is no fallback payer. |
| testnet passphrase check | A mainnet submission from a mislabelled config. The passphrase is compared, not a label trusted. |
| --include-code opt-in | Extending Wasm shared with contracts you cannot see, without meaning to. |
| no auto restore or funding | The tool quietly spending more than the operation you asked for. |
| no replacement send | A double submission after an uncertain result. An unconfirmed result is reported, not retried. |
Usage
Printed by evergreen extend --help, read from packages/cli/src/extend.ts at build time.
What gets extended
The instance entry by default. A keys file adds explicit data keys, in the same shape the scanner takes — { "dataKeys": ["base64 XDR LedgerKey", ...] }. Storage is never enumerated, so what you do not name is not touched.
--ledgers N adds N to each selected entry’s current remaining TTL. The protocol wants an absolute target, so the CLI computes it for you and caps it at max_entry_ttl - 1, saying so when it does.
What the exit code means here
0 is a complete simulation, a no-op, or a verified live result. 2 is an error, or a partial or unconfirmed result. There is no exit code that means “probably worked”. Exit codes
Next