Skip to main content

CLI Reference

This page is the fast orientation guide for si. For a full categorized list, use Command Reference.

Command discovery pattern

CLI color system

SI text output uses a small semantic palette instead of per-command ad hoc colors: Rules:
  • JSON output stays uncolored.
  • Text output uses the semantic palette above when color is enabled.
  • si --help and nested --help output use the same palette as runtime text output.
Color control:
  • SI_CLI_COLOR=always: force color even when stdout is not a TTY
  • SI_CLI_COLOR=auto: default behavior
  • SI_CLI_COLOR=never: disable CLI colors
  • NO_COLOR=1: disable CLI colors

Top-level command families

High-signal workflows

Runtime setup

Viva tunnel via SI wrapper

Integration readiness

Fort runtime secret check

Release preflight

  • si build self assets defaults to the canonical SI workspace version from root Cargo.toml.
  • For SI itself, release tags come from that same repo-wide version and only minor releases are tagged/published.
  • orbit github release create now verifies the remote tag first.
  • When the tag is missing, pass --target <sha> and SI will create the git tag ref before creating the release.
  • For draft releases, GitHub may still return an untagged-... HTML URL until publish; verify with tag_name and git ls-remote --tags.

Faster Rust iteration

  • si build self now reuses .artifacts/cargo-target/self-build by default for faster rebuilds.
  • si build self check runs cargo check against the SI CLI manifest without linking a release binary.
  • si build self and release-asset builds auto-use sccache when it is available on PATH.
  • Keep SI’s .artifacts/cargo-target warm during active development. Prune it only when artifacts are older than 14 days or when root disk pressure requires immediate recovery; clear repo target directories before clearing sccache so cross-repo Rust rebuilds stay fast.

Safety guidance

  • On host/admin flows, use si fort run -- <command> when secrets are required.
  • For SI runtime workers, use si fort ... for secret access.
  • si fort wrapper passes explicit Fort file-path auth flags for the managed Codex profile session under CODEX_HOME/fort/; caller-supplied FORT_TOKEN_PATH / FORT_REFRESH_TOKEN_PATH values are not normal runtime fallbacks.
  • Runtime secret commands fail loudly when no usable runtime Fort session exists; bootstrap/admin token files are only for explicit admin/provisioning commands.
  • If a flag belongs to the native fort CLI, pass it after -- (example: si fort -- --host https://fort.aureuma.ai doctor).
  • Prefer --json for automation and auditability.
  • Run doctor commands before mutating production systems.
  • Keep command docs aligned with si --help and si help --format json. orbit github release create now follows the checkout-first default path more closely:
  • omit the repo argument inside a GitHub checkout and SI infers it from origin
  • use -R, --repo <owner/repo> when you need an explicit override
  • omit --title to reuse the release tag as the title