Fusion Infra Cli

equinor/fusion-skills/skills/fusion-infra-cli

by equinore8fd6cfaf8edMIT2 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Provision and migrate Fusion databases using the fusion-infra-cli (finf). USE FOR: provision a database for a service, run SQL migrations, provision PR-specific ephemeral databases, check database state. DO NOT USE FOR: application code changes, service deployments, role management, or infrastructure other than databases.

Instructions onlyDevOps & Cloud
AI-generated overview

Provisions and migrates Fusion service databases with the finf CLI, including ephemeral PR databases.

What it does
Guides an agent through using the fusion-infra-cli (finf) to provision Fusion service databases and apply SQL migrations. It covers creating a provisioning config file, running provision commands for ci, fqa, fprd and pull-request environments, and running migrations from a directory or single .sql file. It also documents environment keys, authentication, and safety practices such as using --verbose and saving output.
When to use it
Use when a Fusion service database must be provisioned or migrated, locally during development or inside CI/CD pipelines. Typical cases include setting up a PR-specific ephemeral database, running migrations on QA or production, or diagnosing a failing database provision step.
Requirements
Requires the finf tool installed as a .NET global tool from the Fusion-Public NuGet feed, plus Azure CLI login (az login) or an explicit token passed with -t. Network access to the NuGet feed and Azure is needed. Ships no scripts; it is instructions only.

Fusion Infra CLI

When to use

Use when a Fusion service database needs to be provisioned or migrated — locally during development or inside CI/CD pipelines.

Typical triggers:

  • "Provision the database for the context service"
  • "Run migrations on the QA database"
  • "Set up a PR database for this pull request"
  • "What does the database provision config look like?"
  • "The pipeline is failing on the database provision step"
  • "Create a PR database that copies from CI"

When not to use

  • Application code or service changes — use the service repo
  • Role or permission management — use fusion-roles-cli
  • Infrastructure other than databases (networking, storage, etc.)
  • Kubernetes or container management

Prerequisites

Install finf as a .NET global tool:

bash
dotnet tool install --global \  --add-source "https://statoil-proview.pkgs.visualstudio.com/Fusion%20-%20Packages/_packaging/Fusion-Public/nuget/v3/index.json" \  Fusion.Infra.Cli

Update to latest:

bash
dotnet tool update --global \  --add-source "https://statoil-proview.pkgs.visualstudio.com/Fusion%20-%20Packages/_packaging/Fusion-Public/nuget/v3/index.json" \  Fusion.Infra.Cli

Auth uses DefaultAzureCredential automatically (picks up az login session). Pass -t <token> to override.

Core workflow — provision a database

1. Create the provisioning config file

The config file defines the database resource. Minimal example (db-config.json):

json
{  "name": "my-service",  "environment": "ci"}

Full config with SQL permissions:

json
{  "name": "my-service",  "environment": "fqa",  "sqlPermission": {    "owners": [      { "clientId": "<app-registration-client-id>" }    ],    "contributors": [      { "clientId": "<app-registration-client-id>" }    ]  }}

See references/db-config-schema.md [blocked] for the full schema.

2. Run provisioning

CI / non-production:

bash
finf database provision -f db-config.json -e ci \  --sql-owner-client-id <client-id> \  --sql-contributor-client-id <client-id> \  -o response.json --verbose

QA:

bash
finf database provision -f db-config.json -e fqa \  --sql-owner-client-id <client-id> \  --sql-contributor-client-id <client-id> \  -o response.json --verbose

Production (add --production flag):

bash
finf database provision -f db-config.json -e fprd \  --production \  --sql-owner-client-id <client-id> \  --sql-contributor-client-id <client-id> \  -o response.json --verbose

Pull Request (ephemeral database, copies from CI):

bash
finf database provision -f db-config.json \  -e pr -pr <pr-number> -ghr "equinor/my-repo" -c ci \  --sql-owner-client-id <client-id> \  --sql-contributor-client-id <client-id> \  --timeout 500 -o response.json --verbose

3. Run migrations

After provisioning, apply SQL migrations:

bash
# Non-productionfinf database migrate -d sql-myservice-fqa -m migrations/ \  -o migrations.json --verbose
# Productionfinf database migrate -d sql-myservice-fprd -m migrations/ \  --production -o migrations.json --verbose

The -m flag accepts a directory of .sql files or a single .sql file.

Environments

KeyPurpose
ciContinuous integration
fqaQA / pre-production
fprdProduction (requires --production flag)
prPull request ephemeral (requires -pr and -ghr)

Full reference

For complete flag reference, run:

bash
finf database provision --helpfinf database migrate --help

Or see the source documentation:

Safety

  • Always use --verbose in pipelines to get diagnostic output
  • Always save output with -o response.json so pipeline steps can reference the result
  • The --production flag is an explicit guard — never omit it for fprd provisioning
  • Never pass raw tokens in pipeline YAML — use secret variables and pass via -t
  • database delete is irreversible for non-PR databases — confirm with user before running

Source and attribution

Source:equinor/fusion-skillsinskills/fusion-infra-cliat commite8fd6cf

License: MIT

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal