Fusion Infra Cli

equinor/fusion-skills/skills/fusion-infra-cli

作者 equinore8fd6cfaf8edMIT2 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Provision and migrate Fusion databases using the fusion-infra-cli (finf). USE FOR: provision a database for a service, run SQL migrations, provision PR-specific ephemeral databases, check database state. DO NOT USE FOR: application code changes, service deployments, role management, or infrastructure other than databases.

僅含說明DevOps & Cloud
AI 產生的概覽

使用 finf CLI 為 Fusion 服務資料庫執行佈建與移轉,包括 PR 臨時資料庫。

功能
指導代理使用 fusion-infra-cli(finf)佈建 Fusion 服務資料庫並執行 SQL 移轉。內容涵蓋建立佈建設定檔、針對 ci、fqa、fprd 與拉取請求環境執行佈建命令,以及從目錄或單一 .sql 檔案執行移轉。也說明了環境鍵、身分驗證,以及使用 --verbose 和儲存輸出等安全做法。
適用情境
適用於需要在本地開發或 CI/CD 流程中佈建或移轉 Fusion 服務資料庫的情境。典型情況包括為拉取請求建立臨時資料庫、在 QA 或正式環境執行移轉,或排查資料庫佈建步驟失敗的問題。
執行需求
需要將 finf 以 .NET 全域工具從 Fusion-Public NuGet 來源安裝,並需要 Azure CLI 登入(az login)或透過 -t 傳入明確權杖。需要存取 NuGet 來源與 Azure 的網路。不附帶指令碼,僅為說明文件。

Fusion Infra CLI

When to use

Use when a Fusion service database needs to be provisioned or migrated — locally during development or inside CI/CD pipelines.

Typical triggers:

  • "Provision the database for the context service"
  • "Run migrations on the QA database"
  • "Set up a PR database for this pull request"
  • "What does the database provision config look like?"
  • "The pipeline is failing on the database provision step"
  • "Create a PR database that copies from CI"

When not to use

  • Application code or service changes — use the service repo
  • Role or permission management — use fusion-roles-cli
  • Infrastructure other than databases (networking, storage, etc.)
  • Kubernetes or container management

Prerequisites

Install finf as a .NET global tool:

bash
dotnet tool install --global \  --add-source "https://statoil-proview.pkgs.visualstudio.com/Fusion%20-%20Packages/_packaging/Fusion-Public/nuget/v3/index.json" \  Fusion.Infra.Cli

Update to latest:

bash
dotnet tool update --global \  --add-source "https://statoil-proview.pkgs.visualstudio.com/Fusion%20-%20Packages/_packaging/Fusion-Public/nuget/v3/index.json" \  Fusion.Infra.Cli

Auth uses DefaultAzureCredential automatically (picks up az login session). Pass -t <token> to override.

Core workflow — provision a database

1. Create the provisioning config file

The config file defines the database resource. Minimal example (db-config.json):

json
{  "name": "my-service",  "environment": "ci"}

Full config with SQL permissions:

json
{  "name": "my-service",  "environment": "fqa",  "sqlPermission": {    "owners": [      { "clientId": "<app-registration-client-id>" }    ],    "contributors": [      { "clientId": "<app-registration-client-id>" }    ]  }}

See references/db-config-schema.md [blocked] for the full schema.

2. Run provisioning

CI / non-production:

bash
finf database provision -f db-config.json -e ci \  --sql-owner-client-id <client-id> \  --sql-contributor-client-id <client-id> \  -o response.json --verbose

QA:

bash
finf database provision -f db-config.json -e fqa \  --sql-owner-client-id <client-id> \  --sql-contributor-client-id <client-id> \  -o response.json --verbose

Production (add --production flag):

bash
finf database provision -f db-config.json -e fprd \  --production \  --sql-owner-client-id <client-id> \  --sql-contributor-client-id <client-id> \  -o response.json --verbose

Pull Request (ephemeral database, copies from CI):

bash
finf database provision -f db-config.json \  -e pr -pr <pr-number> -ghr "equinor/my-repo" -c ci \  --sql-owner-client-id <client-id> \  --sql-contributor-client-id <client-id> \  --timeout 500 -o response.json --verbose

3. Run migrations

After provisioning, apply SQL migrations:

bash
# Non-productionfinf database migrate -d sql-myservice-fqa -m migrations/ \  -o migrations.json --verbose
# Productionfinf database migrate -d sql-myservice-fprd -m migrations/ \  --production -o migrations.json --verbose

The -m flag accepts a directory of .sql files or a single .sql file.

Environments

KeyPurpose
ciContinuous integration
fqaQA / pre-production
fprdProduction (requires --production flag)
prPull request ephemeral (requires -pr and -ghr)

Full reference

For complete flag reference, run:

bash
finf database provision --helpfinf database migrate --help

Or see the source documentation:

Safety

  • Always use --verbose in pipelines to get diagnostic output
  • Always save output with -o response.json so pipeline steps can reference the result
  • The --production flag is an explicit guard — never omit it for fprd provisioning
  • Never pass raw tokens in pipeline YAML — use secret variables and pass via -t
  • database delete is irreversible for non-PR databases — confirm with user before running

來源與署名

來源:equinor/fusion-skills位於skills/fusion-infra-cli提交e8fd6cf

授權條款: MIT

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架