Skip to main content

CLI

๐Ÿ“„๏ธerun init

Initialize ERun configuration for a tenant and environment. On a local environment, init creates the per-user tenant/env files and prepares the local Kubernetes context. On a remote environment, it deploys the runtime pod โ€” straight from the published erun-devops chart โ€” and writes the in-pod bootstrap marker. init does not generate any files into your project beyond .erun/config.yaml; the runtime chart and image ship as release artifacts, and projects that need a custom toolchain extend the published image instead (see --runtime-image below).

๐Ÿ“„๏ธerun terraform

Run a hosted platform's per-environment Terraform without hand-running terraform or cd-ing into a folder. erun terraform is for platform deployments whose Terraform is laid out per environment โ€” one folder per env under terraform-/, scaffolded by the erun-blueprint-platform skill. erun resolves the env's root from the current scope โ€” terraform-// at the project root, or -devops/terraform-// when the tenant keeps its whole devops footprint (docker/, k8s/, terraform-/) under -devops/ (the same -devops convention build/deploy use) โ€” picks up the symlinked common.tf, and runs that env's own main.tf with its .tfvars. The terraform- base is the default; relocate it with paths.terraform in .erun/config.yaml (erun still appends /).

๐Ÿ“„๏ธerun upgrade

Redeploy every environment opted into Upgrade all to the latest version for its release channel. erun upgrade is the one-command way to roll a fleet of environments forward without running erun deploy for each โ€” it resolves the latest version per channel, then redeploys only the environments whose current version lags. It is an orchestrator over erun deploy --version: it never builds or pushes, it resolves a version per environment and installs it by reference. The versions it picks were minted by build and published by push (or by a release) ahead of time.

๐Ÿ“„๏ธerun cloud

Set up and manage cloud provider aliases โ€” the cloud credentials that managed cloud contexts and remote environments use. AWS aliases carry an IAM Identity Center profile and the OIDC issuer the deployed ERun APIs trust; Cloudflare aliases carry a delegated, account-scoped API token. An AWS alias is named +@aws; a Cloudflare alias is named +@cloudflare. Aliases are stored in your root ERun config โ€” except the Cloudflare token itself, which is held in a local secret store referenced from config (never written into erun-config.yaml).

๐Ÿ“„๏ธerun platform

Talk to a hosted erun platform's own control-plane API (erun-backend-api) directly โ€” the same API the hosted console drives โ€” using the erun-type cloud alias erun cloud init erun and erun cloud login set up. It exists so an Operator or Agent can exercise or smoke-test a deployed control plane without a browser-obtained token: registering tenants and users, listing and managing hosted environments, bootstrapping or reusing cloud contexts, and previewing a full provisioning plan before running it.

๐Ÿ“„๏ธerun review

Review code on a hosted erun platform from a terminal or an Agent โ€” the client for the collaboration API โ€” using the erun-type cloud alias erun cloud init erun and erun cloud login set up. List reviews, open one, comment on a line (or reply to an existing comment), resolve or reopen a comment thread, record a build against a review (or report one MERGED once its promoted environment has gate-built and pushed it), close a review, requeue one stuck at MERGE, assign or remove reviewers, and inspect or advance a target branch's merge queue.

๐Ÿ“„๏ธerun exec

Repository helpers that run from the project root. Fourteen subcommands: diff (a structured git diff), raw (run an arbitrary command), write (write file content), commit (commit every change), push (push a branch to a remote), merge (merge a branch into the current one), gate-merge (build the prospective squash merge a merge queue promotion gates), report-commit-status (report a GitHub commit status for a merge queue gate result), close-pr (close the GitHub pull request a merge queue gate actually shipped), gate-run start/gate-run report (make one gate attempt visible on erun gate list, independent of whether an erun review exists for the change), reconcile-bypass (check every ruleset-bypassed push against a real passed gate run), plan-ruleset-bypass (plan narrowing a ruleset's bypass grant to one non-human queue identity), and route-check (prove every registered API route is reachable on a deployed plane).