DESIRED STATE
Configure deliberately. Deploy explicitly.
Service settings, variables, and storage live at an exact project, environment, and service boundary. Midnight stores the intended state, redacts sensitive reads, and requires a separate deployment to apply runtime changes.
On this page
SERVICE SETTINGS
Keep environment-specific runtime intent together.
Use the console for focused edits. For a reviewable CLI change, read the exact service/environment configuration, turn its version and editable fields into a PUT request document, edit that file, and submit it with compare-and-swap protection.
midnight service config get --environment-id env_example --json svc_example |
jq '{
expected_version: .version,
root_directory, builder, dockerfile_path, build_command,
start_command, predeploy_command, target_port,
health_kind, health_path, health_port,
health_timeout_seconds, health_interval_seconds,
restart_policy, restart_retries, replicas,
overlap_enabled, drain_grace_seconds, runtime_kind,
cron_schedule, cron_timeout_seconds,
cron_max_attempts, cron_retry_delay_seconds
}' > service-config.json
$EDITOR service-config.json
midnight service config put --environment-id env_example --file service-config.json --idempotency-key service-config-v2 svc_exampleSENSITIVE VALUES
Choose the scope and keep the value out of argv.
- plain
- Non-sensitive configuration. The value is still stored as application state; do not use it for credentials.
- secret
- A sensitive value encrypted in Postgres and returned only as redaction-safe metadata.
- sealed
- A write-only sensitive value intended for the narrowest handling path.
printf %s 'postgres://user:password@db/app' |
midnight variable set --service-id svc_api --environment-id env_prod --scope sealed --stdin DATABASE_URLCONCURRENCY
Refresh before replacing a newer value.
Variable list and create responses include an opaque variable ID and current version. Update and delete require that version so a stale editor cannot win silently.
midnight variable list --service-id svc_api --environment-id env_prod
printf %s 'new-secret-value' |
midnight variable update --service-id svc_api --environment-id env_prod --expected-version 1 --stdin sealed_database_url
midnight variable delete --service-id svc_api --environment-id env_prod --expected-version 2 sealed_database_urlPERSISTENCE
Attach storage with an explicit recovery plan.
- 1
Create and attach
Create a volume for the exact service and environment, then set the workload mount path.
- 2
Set a backup policy
Configure a real off-host destination before describing the workload as recoverable.
- 3
Run and inspect backups
Keep backup operation IDs, destination evidence, and failure reason codes.
- 4
Plan before restore
A restore stages a replacement volume and then performs an immutable redeploy. Review the plan before applying it.
midnight volume create --project-id prj_example --environment-id env_example --service-id svc_example --name app-data --mount-path /data --size-bytes 10737418240
midnight volume policy create --schedule daily --retention-days 14 vol_example
midnight volume backup create --retention-days 14 vol_example
midnight volume backup list vol_example
# Creating a restore stages a plan; applying it is a separate action.
midnight volume backup restore bak_example
midnight volume restore list vol_example
midnight volume restore apply rst_example