Fusion Infra CLI
When to use
Use when a Fusion service database needs to be provisioned or migrated — locally during development or inside CI/CD pipelines.
Typical triggers:
- "Provision the database for the context service"
- "Run migrations on the QA database"
- "Set up a PR database for this pull request"
- "What does the database provision config look like?"
- "The pipeline is failing on the database provision step"
- "Create a PR database that copies from CI"
When not to use
- Application code or service changes — use the service repo
- Role or permission management — use
fusion-roles-cli - Infrastructure other than databases (networking, storage, etc.)
- Kubernetes or container management
Prerequisites
Install finf as a .NET global tool:
Update to latest:
Auth uses DefaultAzureCredential automatically (picks up az login session). Pass -t <token> to override.
Core workflow — provision a database
1. Create the provisioning config file
The config file defines the database resource. Minimal example (db-config.json):
Full config with SQL permissions:
See references/db-config-schema.md [blocked] for the full schema.
2. Run provisioning
CI / non-production:
QA:
Production (add --production flag):
Pull Request (ephemeral database, copies from CI):
3. Run migrations
After provisioning, apply SQL migrations:
The -m flag accepts a directory of .sql files or a single .sql file.
Environments
Full reference
For complete flag reference, run:
Or see the source documentation:
Safety
- Always use
--verbosein pipelines to get diagnostic output - Always save output with
-o response.jsonso pipeline steps can reference the result - The
--productionflag is an explicit guard — never omit it forfprdprovisioning - Never pass raw tokens in pipeline YAML — use secret variables and pass via
-t database deleteis irreversible for non-PR databases — confirm with user before running


