COMMAND REFERENCE
Midnight CLI
Deploy and operate applications from a terminal with the same tenant boundaries as the console. Interactive work uses a human session; unattended deploys use a credential bound to one project.
midnightHuman sessionsProject linksCI tokens
On this page
INSTALL
Use a reviewed binary on your PATH.
Protected tag archives contain the binary, checksum manifest and Sigstore bundle, license, CLI documentation, and shell completions. Verify the bundle against the release workflow identity before trusting the checksum. Workflow-dispatch smoke artifacts are unsigned.
MIDNIGHT_COMMIT=replace-with-reviewed-commit-sha
git clone https://github.com/packetloss404/midnight.git
cd midnight
git checkout --detach "$MIDNIGHT_COMMIT"
go build -o "$HOME/.local/bin/midnight" ./cmd/midnight
midnight versionDEVELOPER LOOP
Login, link, deploy, inspect.
midnight login --api-base https://your-midnight.example --email you@example.com
midnight whoami
cd path/to/your/application
midnight link
midnight status
midnight up
midnight logs -f --build- login
- Reads the password without terminal echo and requests TOTP only when the server returns MFA_REQUIRED. Remote endpoints must use HTTPS.
- link
- Selects a project, environment, and service, then atomically writes .midnight/project.json.
- up
- Packages the current directory, uploads it, queues the build/deploy operation, and follows events unless --detach is set.
- logs
- Follows runtime logs by default. Use -f --build for tenant-safe build operation events.
CREDENTIAL RESOLUTION
Keep interactive and automation authority separate.
- Human session
- Created by midnight login and stored per API server. Use it for console/CLI tenant work.
- Project automation
- A midn_sa_ credential shown once by midnight token create. It can deploy and inspect only its bound project.
- Runtime agent
- A per-agent credential used only for registration, heartbeat, desired state, and signed status routes.
- Recovery
- Installation-wide break-glass compatibility under explicit admin flows. Developer commands never silently fall back to it.
midnight token create --name ci-deploy
MIDNIGHT_API_BASE=https://your-midnight.example MIDNIGHT_TOKEN=midn_sa_... midnight up --detachDISCOVERY
Command families in the current binary.
- login · logout · whoami
- Create, revoke, and inspect a durable human session.
- link · unlink · status · open
- Manage the current directory's project, environment, and service context.
- up · logs · redeploy · rollback
- Upload source, follow logs, or create a release from an immutable deployment.
- restart · stop · remove · cancel
- Control deployment work in the linked context.
- project · service · environment
- Create and discover tenant resources; service also owns config and GitHub source commands.
- variable · domain · tcp-proxy
- Manage exact service variables, HTTP domains, and TCP endpoints.
- deploy · observability
- Deploy an immutable image and inspect operation events, logs, and metrics.
- usage
- Inspect workspace usage, policy limits, evidence coverage, and source freshness.
- volume · template
- Manage persistent volumes and deploy official data-service templates.
- token · invitation
- Manage project automation credentials and workspace invitations.
- monitor · cron
- Manage checks, channels, deliveries, and scheduled occurrences.
- config
- Validate, diff, apply, or synchronize an ID-bound environment configuration document.
- changeset
- Review, revalidate, atomically apply, or discard a durable environment draft.
- audit · admin
- Verify evidence or perform explicitly installation-scoped recovery and maintenance.
midnight usage --workspace-id wrk_01H...
midnight usage --workspace-id wrk_01H... --since 2026-08-01T00:00:00Z --until 2026-09-01T00:00:00Z --jsonAUTOMATION
Make output and prompting explicit.
- --output, -o
- Choose table (default), json, jsonl, or name.
- --quiet, -q
- Print only the primary result.
- --no-input
- Never prompt. Pair it with complete flags in CI.
- --yes, -y
- Approve confirmation prompts explicitly.
- --timeout
- Set the maximum command duration; zero uses the command default.
- --debug
- Enable diagnostic output. Review it for sensitive context before sharing.
- --no-color
- Remove terminal color sequences for logs and CI artifacts.
- completion
- Generate Bash, Zsh, Fish, or PowerShell completion scripts.