MidnightDocumentation

COMMAND REFERENCE

Midnight CLI

Deploy and operate applications from a terminal with the same tenant boundaries as the console. Interactive work uses a human session; unattended deploys use a credential bound to one project.

midnightHuman sessionsProject linksCI tokens
On this page

INSTALL

Use a reviewed binary on your PATH.

Protected tag archives contain the binary, checksum manifest and Sigstore bundle, license, CLI documentation, and shell completions. Verify the bundle against the release workflow identity before trusting the checksum. Workflow-dispatch smoke artifacts are unsigned.

Build the CLI from a reviewed checkoutbash
MIDNIGHT_COMMIT=replace-with-reviewed-commit-sha
git clone https://github.com/packetloss404/midnight.git
cd midnight
git checkout --detach "$MIDNIGHT_COMMIT"
go build -o "$HOME/.local/bin/midnight" ./cmd/midnight
midnight version

DEVELOPER LOOP

Login, link, deploy, inspect.

First deploybash
midnight login --api-base https://your-midnight.example --email you@example.com
midnight whoami

cd path/to/your/application
midnight link
midnight status
midnight up
midnight logs -f --build
login
Reads the password without terminal echo and requests TOTP only when the server returns MFA_REQUIRED. Remote endpoints must use HTTPS.
link
Selects a project, environment, and service, then atomically writes .midnight/project.json.
up
Packages the current directory, uploads it, queues the build/deploy operation, and follows events unless --detach is set.
logs
Follows runtime logs by default. Use -f --build for tenant-safe build operation events.

CREDENTIAL RESOLUTION

Keep interactive and automation authority separate.

Human session
Created by midnight login and stored per API server. Use it for console/CLI tenant work.
Project automation
A midn_sa_ credential shown once by midnight token create. It can deploy and inspect only its bound project.
Runtime agent
A per-agent credential used only for registration, heartbeat, desired state, and signed status routes.
Recovery
Installation-wide break-glass compatibility under explicit admin flows. Developer commands never silently fall back to it.
Project-scoped CI deploybash
midnight token create --name ci-deploy

MIDNIGHT_API_BASE=https://your-midnight.example MIDNIGHT_TOKEN=midn_sa_... midnight up --detach

DISCOVERY

Command families in the current binary.

login · logout · whoami
Create, revoke, and inspect a durable human session.
link · unlink · status · open
Manage the current directory's project, environment, and service context.
up · logs · redeploy · rollback
Upload source, follow logs, or create a release from an immutable deployment.
restart · stop · remove · cancel
Control deployment work in the linked context.
project · service · environment
Create and discover tenant resources; service also owns config and GitHub source commands.
variable · domain · tcp-proxy
Manage exact service variables, HTTP domains, and TCP endpoints.
deploy · observability
Deploy an immutable image and inspect operation events, logs, and metrics.
usage
Inspect workspace usage, policy limits, evidence coverage, and source freshness.
volume · template
Manage persistent volumes and deploy official data-service templates.
token · invitation
Manage project automation credentials and workspace invitations.
monitor · cron
Manage checks, channels, deliveries, and scheduled occurrences.
config
Validate, diff, apply, or synchronize an ID-bound environment configuration document.
changeset
Review, revalidate, atomically apply, or discard a durable environment draft.
audit · admin
Verify evidence or perform explicitly installation-scoped recovery and maintenance.
Usage evidencebash
midnight usage --workspace-id wrk_01H...
midnight usage --workspace-id wrk_01H...   --since 2026-08-01T00:00:00Z --until 2026-09-01T00:00:00Z --json

AUTOMATION

Make output and prompting explicit.

--output, -o
Choose table (default), json, jsonl, or name.
--quiet, -q
Print only the primary result.
--no-input
Never prompt. Pair it with complete flags in CI.
--yes, -y
Approve confirmation prompts explicitly.
--timeout
Set the maximum command duration; zero uses the command default.
--debug
Enable diagnostic output. Review it for sensitive context before sharing.
--no-color
Remove terminal color sequences for logs and CI artifacts.
completion
Generate Bash, Zsh, Fish, or PowerShell completion scripts.