--artifact-key-provider string key sealed artifacts are protected by (env: KUBOX_ARTIFACT_KEY_PROVIDER)
--cluster-document string the cluster document the plane was built from (default: <name>.cluster.yaml beside the deployment)
--context string context within it
--database-url string record store connection string (env: KUBOX_DATABASE_URL, KUBOX_ARTIFACT_DSN)
-f, --file string the PlaneDeployment naming the release
-h, --help help for upgrade
--kubeconfig string path to the plane's kubeconfig
--plan say what would move and what would not, and do nothing
--settle duration how long to wait for the plane to report the new release (default 3m0s)
--stack-key-provider string key Pulumi state is encrypted with; must be a DIFFERENT key (env: KUBOX_STACK_KEY_PROVIDER)
--state-backend string Pulumi state backend (env: PULUMI_BACKEND_URL)
--tenant stringArray a tenant this plane builds for: the cloud connection's namespace (kubox-system for Kubox's own); repeatable. Read from the plane's cloud connections when not given