Fusion Infra Cli

equinor/fusion-skills/skills/fusion-infra-cli

作者 equinore8fd6cfaf8edMIT2 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Provision and migrate Fusion databases using the fusion-infra-cli (finf). USE FOR: provision a database for a service, run SQL migrations, provision PR-specific ephemeral databases, check database state. DO NOT USE FOR: application code changes, service deployments, role management, or infrastructure other than databases.

仅含说明DevOps & Cloud
AI 生成的概览

使用 finf CLI 为 Fusion 服务数据库执行预配与迁移,包括 PR 临时数据库。

功能
指导代理使用 fusion-infra-cli(finf)预配 Fusion 服务数据库并执行 SQL 迁移。内容涵盖创建预配配置文件、针对 ci、fqa、fprd 和拉取请求环境运行预配命令,以及从目录或单个 .sql 文件运行迁移。还说明了环境键、身份验证,以及使用 --verbose 和保存输出等安全做法。
适用场景
适用于需要在本地开发或 CI/CD 流水线中预配或迁移 Fusion 服务数据库的场景。典型情况包括为拉取请求创建临时数据库、在 QA 或生产环境运行迁移,或排查数据库预配步骤失败的问题。
运行要求
需要将 finf 作为 .NET 全局工具从 Fusion-Public NuGet 源安装,并需要 Azure CLI 登录(az login)或通过 -t 传入显式令牌。需要访问 NuGet 源和 Azure 的网络。不附带脚本,仅为说明文档。

Fusion Infra CLI

When to use

Use when a Fusion service database needs to be provisioned or migrated — locally during development or inside CI/CD pipelines.

Typical triggers:

  • "Provision the database for the context service"
  • "Run migrations on the QA database"
  • "Set up a PR database for this pull request"
  • "What does the database provision config look like?"
  • "The pipeline is failing on the database provision step"
  • "Create a PR database that copies from CI"

When not to use

  • Application code or service changes — use the service repo
  • Role or permission management — use fusion-roles-cli
  • Infrastructure other than databases (networking, storage, etc.)
  • Kubernetes or container management

Prerequisites

Install finf as a .NET global tool:

bash
dotnet tool install --global \  --add-source "https://statoil-proview.pkgs.visualstudio.com/Fusion%20-%20Packages/_packaging/Fusion-Public/nuget/v3/index.json" \  Fusion.Infra.Cli

Update to latest:

bash
dotnet tool update --global \  --add-source "https://statoil-proview.pkgs.visualstudio.com/Fusion%20-%20Packages/_packaging/Fusion-Public/nuget/v3/index.json" \  Fusion.Infra.Cli

Auth uses DefaultAzureCredential automatically (picks up az login session). Pass -t <token> to override.

Core workflow — provision a database

1. Create the provisioning config file

The config file defines the database resource. Minimal example (db-config.json):

json
{  "name": "my-service",  "environment": "ci"}

Full config with SQL permissions:

json
{  "name": "my-service",  "environment": "fqa",  "sqlPermission": {    "owners": [      { "clientId": "<app-registration-client-id>" }    ],    "contributors": [      { "clientId": "<app-registration-client-id>" }    ]  }}

See references/db-config-schema.md [blocked] for the full schema.

2. Run provisioning

CI / non-production:

bash
finf database provision -f db-config.json -e ci \  --sql-owner-client-id <client-id> \  --sql-contributor-client-id <client-id> \  -o response.json --verbose

QA:

bash
finf database provision -f db-config.json -e fqa \  --sql-owner-client-id <client-id> \  --sql-contributor-client-id <client-id> \  -o response.json --verbose

Production (add --production flag):

bash
finf database provision -f db-config.json -e fprd \  --production \  --sql-owner-client-id <client-id> \  --sql-contributor-client-id <client-id> \  -o response.json --verbose

Pull Request (ephemeral database, copies from CI):

bash
finf database provision -f db-config.json \  -e pr -pr <pr-number> -ghr "equinor/my-repo" -c ci \  --sql-owner-client-id <client-id> \  --sql-contributor-client-id <client-id> \  --timeout 500 -o response.json --verbose

3. Run migrations

After provisioning, apply SQL migrations:

bash
# Non-productionfinf database migrate -d sql-myservice-fqa -m migrations/ \  -o migrations.json --verbose
# Productionfinf database migrate -d sql-myservice-fprd -m migrations/ \  --production -o migrations.json --verbose

The -m flag accepts a directory of .sql files or a single .sql file.

Environments

KeyPurpose
ciContinuous integration
fqaQA / pre-production
fprdProduction (requires --production flag)
prPull request ephemeral (requires -pr and -ghr)

Full reference

For complete flag reference, run:

bash
finf database provision --helpfinf database migrate --help

Or see the source documentation:

Safety

  • Always use --verbose in pipelines to get diagnostic output
  • Always save output with -o response.json so pipeline steps can reference the result
  • The --production flag is an explicit guard — never omit it for fprd provisioning
  • Never pass raw tokens in pipeline YAML — use secret variables and pass via -t
  • database delete is irreversible for non-PR databases — confirm with user before running

来源与署名

来源:equinor/fusion-skills位于skills/fusion-infra-cli提交e8fd6cf

许可证: MIT

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架