Skip to main content

Build from the CLI

Everything the console's guided flow does can be driven from the orun CLI, and the build itself is the same: the platform provisions the sandbox, enforces every gate, and runs the baseline's blueprint. The CLI's part is short — pick a workspace, connect the provider, check, start — and this page covers only that. The engine documents the commands in full: the worked guide Create a workspace and build it from a baseline and the orun baseline reference.

Sign in and pick a workspace​

orun auth login              # browser approval
orun auth login --device # device code, for a terminal with no browser

Create a workspace, or use one you have, and select it — creating one does not select it:

orun workspace create "Acme Cloud" --slug acme
orun workspace use acme
orun workspace list

The selection is the last rung of the CLI's workspace resolution, so --workspace <ws_…|slug> on any command, or a repository's own intent.yaml, always wins over it.

Headless machines and CI

Set ORUN_TOKEN to a workspace API key instead of logging in. If a runner hands you a file it keeps refreshed, set ORUN_TOKEN_FILE to its path; the file wins over the variable, because an exported copy of a rotating token stops working at the first rotation. See CLI and CI auth.

Connect the provider​

Cirrus needs one connection, Cloudflare. Connect it in the console under Integrations (OAuth, recommended), or from the CLI by token paste — the token is read from standard input only, so it never lands in your shell history:

orun integrations cloudflare connect --workspace acme < cloudflare-token.txt
orun integrations list

GitHub is not a connection you make here: it arrives as the GitHub App installation and the repository link below.

A platform build writes into a repository the workspace has linked — a repository link (repl_…), created in the console from the repository's Git tab under Settings → Git repos, or by the guided flow's Repository step. This is the one step the CLI cannot do: orun cloud link creates a different record, the allow-list link used for remote state, and it is not enough here. See State plane for the two kinds of link.

Check, then build​

orun baseline show prints the row and one line per required provider; orun baseline check gives the same answer as an exit code, writing nothing:

orun baseline check cirrus && echo ready

Start the build on the platform. Name the repository, and pass the inputs the card asks for with --set; anything the card derives from the repository (reponame, githuborg) or from another value (apibaseurl) is filled for you:

orun baseline new cirrus --via-platform \
--repo acme/storefront \
--set productname="Acme Cloud" \
--set productdomain=acme.dev \
--set subdomain=acme
building cirrus@baseline-v12 into acme/storefront (repl_01J8…)
as_8f3c2d1e9b7a4c6d

The target is resolved and printed on standard error before anything starts; a repository with more than one link is refused rather than guessed (--repo-link repl_… chooses). The session id is the only thing on standard output.

Every rule is the server's and is reported verbatim: the admin role (403), the paid tier (412, naming the free baselines), readiness (412), required inputs (422, naming the keys), one build per repository (409, naming the running build), and the admission fee (412 credits_exhausted). See Baselines.

Watch it in the console

The CLI prints the session id and returns. Open the workspace at app.orunbase.com: the Overview shows the build panel with its phases, and the session transcript is under Agents. Retry, the blocked-phase acknowledgement, and the verify links are all in the panel.

Build on your own machine instead​

orun baseline new <id> --local --out <dir> runs the same build where you stand: it fetches the source repository at the registry's tag, reads the card, and places the build document's phases into --out. Without --run-hooks it places files and stops, which is the way to read a baseline or start a fork by hand; with --run-hooks it bootstraps the product — repositories, installs, secrets minted from the workspace's connection, Terraform, pull requests, deploys — and needs the same things the platform sandbox has: git, gh, Node.js 20+, pnpm, python3, an admin session or ORUN_TOKEN, and the providers connected. The readiness check is a hard gate for a local build too. Flags, phases, and resume are in the orun baseline reference.