fusion-infra-cli
Provision and migrate Fusion databases using the fusion-infra-cli (finf). USE FOR: provision a database for a service, run SQL migrations, provision PR-specific ephemeral databases, check database state. DO NOT USE FOR: application code changes, service deployments, role management, or infrastructure other than databases.
How do I install this agent skill?
npx skills add https://github.com/equinor/fusion-skills --skill fusion-infra-cliIs this agent skill safe to install?
- Gen Agent Trust Hubpass
This skill facilitates database provisioning and migrations using the Fusion Infra CLI (finf). It handles sensitive infrastructure tasks and processes user-provided configuration and SQL files, which represents an indirect prompt injection surface. The tool is downloaded from a vendor-owned NuGet feed, which is a standard procedure for Equinor tooling.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Fusion Infra CLI
When to use
Use when a Fusion service database needs to be provisioned or migrated — locally during development or inside CI/CD pipelines.
Typical triggers:
- "Provision the database for the context service"
- "Run migrations on the QA database"
- "Set up a PR database for this pull request"
- "What does the database provision config look like?"
- "The pipeline is failing on the database provision step"
- "Create a PR database that copies from CI"
When not to use
- Application code or service changes — use the service repo
- Role or permission management — use
fusion-roles-cli - Infrastructure other than databases (networking, storage, etc.)
- Kubernetes or container management
Prerequisites
Install finf as a .NET global tool:
dotnet tool install --global \
--add-source "https://statoil-proview.pkgs.visualstudio.com/Fusion%20-%20Packages/_packaging/Fusion-Public/nuget/v3/index.json" \
Fusion.Infra.Cli
Update to latest:
dotnet tool update --global \
--add-source "https://statoil-proview.pkgs.visualstudio.com/Fusion%20-%20Packages/_packaging/Fusion-Public/nuget/v3/index.json" \
Fusion.Infra.Cli
Auth uses DefaultAzureCredential automatically (picks up az login session). Pass -t <token> to override.
Core workflow — provision a database
1. Create the provisioning config file
The config file defines the database resource. Minimal example (db-config.json):
{
"name": "my-service",
"environment": "ci"
}
Full config with SQL permissions:
{
"name": "my-service",
"environment": "fqa",
"sqlPermission": {
"owners": [
{ "clientId": "<app-registration-client-id>" }
],
"contributors": [
{ "clientId": "<app-registration-client-id>" }
]
}
}
See references/db-config-schema.md for the full schema.
2. Run provisioning
CI / non-production:
finf database provision -f db-config.json -e ci \
--sql-owner-client-id <client-id> \
--sql-contributor-client-id <client-id> \
-o response.json --verbose
QA:
finf database provision -f db-config.json -e fqa \
--sql-owner-client-id <client-id> \
--sql-contributor-client-id <client-id> \
-o response.json --verbose
Production (add --production flag):
finf database provision -f db-config.json -e fprd \
--production \
--sql-owner-client-id <client-id> \
--sql-contributor-client-id <client-id> \
-o response.json --verbose
Pull Request (ephemeral database, copies from CI):
finf database provision -f db-config.json \
-e pr -pr <pr-number> -ghr "equinor/my-repo" -c ci \
--sql-owner-client-id <client-id> \
--sql-contributor-client-id <client-id> \
--timeout 500 -o response.json --verbose
3. Run migrations
After provisioning, apply SQL migrations:
# Non-production
finf database migrate -d sql-myservice-fqa -m migrations/ \
-o migrations.json --verbose
# Production
finf database migrate -d sql-myservice-fprd -m migrations/ \
--production -o migrations.json --verbose
The -m flag accepts a directory of .sql files or a single .sql file.
Environments
| Key | Purpose |
|---|---|
ci | Continuous integration |
fqa | QA / pre-production |
fprd | Production (requires --production flag) |
pr | Pull request ephemeral (requires -pr and -ghr) |
Full reference
For complete flag reference, run:
finf database provision --help
finf database migrate --help
Or see the source documentation:
Safety
- Always use
--verbosein pipelines to get diagnostic output - Always save output with
-o response.jsonso pipeline steps can reference the result - The
--productionflag is an explicit guard — never omit it forfprdprovisioning - Never pass raw tokens in pipeline YAML — use secret variables and pass via
-t database deleteis irreversible for non-PR databases — confirm with user before running
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/equinor/fusion-skills/fusion-infra-cli">View fusion-infra-cli on skillZs</a>