Eigon CLI

Deploy from your terminal.

Everything you can do in the dashboard, in one binary you can drop into a shell script. Trigger deploys, tail logs, flip feature flags and export Terraform with a single command.

The eigon CLI is the official command line tool for Eigon. It is a single statically linked Go binary. No Node, no Python, no runtime dependencies. It works exactly the same on your laptop and inside a CI runner.

Install

One line install (recommended)

curl -sSL https://eigon.io/install.sh | sh

The script detects your operating system and architecture, downloads the right binary from the latest GitHub release, and drops it into /usr/local/bin/eigon. It will ask for sudo if it cannot write to that directory.

You can pin to a specific version or change the install location with environment variables:

# Pin to a version
curl -sSL https://eigon.io/install.sh | EIGON_VERSION=v0.8.0 sh

# Install to a directory you own (no sudo needed)
curl -sSL https://eigon.io/install.sh | EIGON_INSTALL_DIR=$HOME/bin sh

Verify the install

eigon version

Authenticate

The CLI uses API tokens, not passwords. Each token is scoped, revocable and tied to a specific user. Tokens never expire unless you tell them to.

  1. Go to Account → Tokens in the dashboard.
  2. Click New token. Give it a name like laptop or github-actions.
  3. Pick the scopes you need (read, deploy, admin). Most workflows only need read and deploy.
  4. Copy the token immediately. It will never be shown again. Tokens look like eigon_ab12cd_....

Then run the login command and paste the token when prompted:

eigon login

Your token is saved at ~/.eigon/config.json with 0600 permissions. To check who you are signed in as:

eigon whoami

You can also skip eigon login entirely by exporting the token as an environment variable. This is the right pattern for CI:

export EIGON_TOKEN=eigon_ab12cd_xxxxxxxxxxxxxxxxxxxxxx

Which scope to pick

Tokens carry scopes and the API enforces them, so give a token the least it needs:

  • read — everything that only looks: status, logs, envs, env list, projects list, flags list, drift, compliance.
  • deploy — anything that changes something: deploy, env set, env unset, flags set, pause, resume. A CI token that deploys wants this one.
  • admin — creating and revoking other tokens. A deploy token deliberately cannot mint one, so it cannot widen its own access.

Use the wrong scope and the CLI tells you which one you are missing rather than failing vaguely:

$ eigon deploy --env prod
error: deploy failed: this token is read-only: it does not carry the 'deploy' scope needed to change anything

Your first deploy

Once you have a project with an environment, you can deploy from the terminal. Start by listing your projects:

$ eigon projects list
NAME                            SOURCE        REPO/BRANCH
heal-probe                      github        ayush/heal-probe @ main
landing-page                    zip           (uploaded ZIP)
api-service                     github        myorg/api @ main

Then list a project’s environments. This is where you find the name to pass to --env, along with each environment’s address:

$ eigon envs --project heal-probe
heal-probe

ENV             PROFILE   STATE     URL
dev             dev       running   https://heal-probe-e407-app.eigon.app
staging         staging   running   https://heal-probe-da94-app.eigon.app

Use the ENV value with --env, e.g. eigon deploy --env dev

--project and --env take names, not ids. If your organisation has one project and that project has one environment, you can leave both out entirely and just run eigon deploy.

$ eigon deploy --project heal-probe --env dev
✓ Deploy queued for heal-probe/dev: 91f79585-8da9-445d-b418-791976c3c31f
  Watch progress: https://eigon.io/dashboard/org/<org>/project/<project>/environments
  Or: eigon logs --env dev --tail

Tail the logs while it deploys:

eigon logs --project heal-probe --env dev --tail

When the deploy is done, check the address and what it costs:

$ eigon status --project heal-probe --env dev
Status:        SUCCEEDED
Monthly cost:  $31.63
App URL:       https://heal-probe-e407-app.eigon.app
Latest deploy: 91f79585-8da9-445d-b418-791976c3c31f (SUCCEEDED)

Command reference

Run eigon help at any time for the full list. The most useful ones:

eigon login

Prompts for an API token and saves it to ~/.eigon/config.json with owner-only permissions. There is no browser step: create the token in the dashboard, then paste it here. In CI, skip this and set EIGON_TOKEN instead.

eigon whoami

Calls the API and prints the user and organisation associated with the current token. Useful for confirming a CI token actually works.

eigon projects list

Lists every project the current token can see, with source type and repository or upload origin.

eigon envs --project <name>

Lists a project’s environments with their profile, whether they are running or asleep, and the address each one serves. This is how you find the value for --env.

eigon deploy --env <name>

Triggers a deploy on the given environment using the latest code. Returns the deployment ID immediately. The deploy continues in the background and you can follow it via eigon status or in the dashboard.

eigon status --env <name>

Shows the current status of an environment: state, month to date cost, live URL, and the latest deployment plus its status.

eigon logs --env <name> [--tail]

Prints the most recent application logs. With --tail, follows new log lines as they arrive (poll based, every 2 seconds). Press Ctrl+C to stop.

eigon flags list --env <name>

Lists every feature flag in an environment.

eigon flags set key=value --env <name>

Updates a feature flag value. Useful for dark launches and emergency kill switches you want to be able to flip from a script.

eigon export-tf --env <name> --org <id> --project <id>

Downloads a Terraform module covering the entire environment: network, compute, database, cache, CDN and WAF. The bundle is ready to apply against your own AWS account. This is how you take your infrastructure with you if you ever decide to leave Eigon.

eigon scan <repo-url>

Reads a public repository and reports what would break on deploy, plus what the infrastructure would cost. No account and no login required — this is the one command you can run before signing up. It exits non-zero when the repository would not deploy, so it works as a CI gate without parsing output.

eigon scan github.com/gothinkster/realworld

This repository looks production-ready. Nothing here would stop a deploy.
2 service(s) · about $38.88/month

eigon pause --env <envId>

Scales an environment to zero so it stops costing money. Your data is kept by default: databases are snapshotted before anything is removed, never destroyed. Pass --delete-data only if you also want the data gone. Bring it back with eigon resume --env <envId>, which restores from the snapshot and rewrites connection secrets to the new endpoint before redeploying.

eigon drift --env <envId>

Shows infrastructure that was changed outside Eigon — usually someone editing the AWS console during an incident. Add --check to run a fresh check rather than reading the last one. Exits non-zero when drift is found, because the next deploy resets those changes back to Eigon's configuration.

eigon compliance --env <envId>

Technical controls from SOC 2, GDPR and HIPAA, checked against the environment. Filter with --framework soc2|gdpr|hipaa. Each control says whether it was checked against your environment or is a statement about how Eigon builds every environment — a readiness report, not a certification, and it covers the infrastructure layer only.

eigon version

Prints the installed CLI version. Useful when filing bug reports.

Environment variables

Set a variable, list what is set, remove one. Values are written to AWS Parameter Store by the control plane, encrypted at rest, and injected into your containers at start-up.

$ eigon env set DATABASE_URL=postgres://user:pass@host:5432/db --env prod
✓ DATABASE_URL set on api-service/prod

Not live yet: running containers keep the values they started with.
Apply with `eigon deploy`, or re-run this with --deploy.

Add --deploy to set the variable and roll it out in one step, which is usually what you want:

eigon env set STRIPE_KEY=sk_live_... --env prod --deploy

Moving a whole file in is one command. Comments, blank lines, export prefixes and quoted values are all handled:

$ eigon env set --from-file .env.production --env prod --deploy
✓ API_KEY set on api-service/prod
✓ DATABASE_URL set on api-service/prod
✓ REDIS_URL set on api-service/prod
✓ Deploy queued: 91f79585-8da9-445d-b418-791976c3c31f

A pair given on the command line beats the same key in the file, so a single override next to --from-file behaves the way it reads.

$ eigon env list --env prod
api-service/prod

NAME                                STORE     DESCRIPTION
API_KEY                             ssm
DATABASE_URL                        ssm       primary read/write
REDIS_URL                           ssm

3 variable(s). Values are held in AWS Parameter Store and are never returned by the API,
so they cannot be printed here. Overwrite one with `eigon env set NAME=newvalue`.

eigon env list shows names, never values. Nothing in Eigon can read a value back out once it is stored, including this CLI and the dashboard. To change one, write over it.

eigon env unset OLD_FLAG STALE_KEY --env prod

Setting or removing a variable needs a token with the deploy scope. A read token can run eigon env list but not change anything.

Use it from CI

The official GitHub Action wraps the CLI with a single composite step. Drop this in .github/workflows/deploy.yml and add EIGON_TOKEN as a repository secret.

name: Deploy to Eigon
on:
  push:
    branches: [main]

jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Deploy
        env:
          EIGON_TOKEN: ${{ secrets.EIGON_TOKEN }}
        run: |
          curl -sSL https://eigon.io/install.sh | sh
          eigon deploy --project my-app --env prod

Two lines and a secret. There is no Eigon-specific action to install, so there is nothing extra to trust in your pipeline, and the same three lines work on any CI that can run a shell.

Prefer to call the CLI directly? Any other CI system works too. The shape is the same: install, set the token, run a command.

# GitLab CI / CircleCI / Buildkite / Bash one-liner
curl -sSL https://eigon.io/install.sh | sh
export EIGON_TOKEN=$EIGON_TOKEN
eigon deploy --project api-service --env prod

Configuration

Configuration is read from environment variables first, then from ~/.eigon/config.json as a fallback. Environment variables always win, which makes CI predictable.

VariableDescription
EIGON_TOKENAPI token. When set, login is skipped entirely.
EIGON_API_BASEAPI base URL. Defaults to https://api.eigon.io. Override only if you are pointing at a self hosted control plane.
EIGON_INSTALL_DIRUsed by the install script. Default /usr/local/bin.
EIGON_VERSIONUsed by the install script to pin a specific version. Default latest.

The config file at ~/.eigon/config.json looks like this:

{
  "token": "eigon_ab12cd_xxxxxxxxxxxxxxxxxxxxxx",
  "api_base": "https://api.eigon.io",
  "default_org": "d08b48d4-bf1c-43f1-b292-f99eeaa2ffc0"
}

Uninstall

Removing the CLI is the inverse of installing it. Delete the binary and drop the config directory.

sudo rm /usr/local/bin/eigon
rm -rf ~/.eigon

You should also revoke any API tokens you no longer want. Visit Account → Tokens and click Revoke.

Troubleshooting

eigon: command not found

The install directory is not on your PATH. Either add it (most shells already include /usr/local/bin) or reinstall with EIGON_INSTALL_DIR set to a directory that is.

not authenticated. Run `eigon login`.

Your token is missing or expired. Run eigon login again, or export EIGON_TOKEN in your shell.

invalid api token

The token has been revoked, or you copied the wrong one. Create a fresh token at Account → Tokens and run eigon login again.

Deploy fails with BLOCKED_BY_CAP

The environment has hit its monthly spending cap. Either raise the cap from the dashboard, or wait for the next month to roll over. Spending caps are a built in protection so you do not get a surprise bill.

eigon logs --tail stops after a few minutes

Tail mode polls every two seconds. If the underlying connection is dropped (idle CI runner, sleeping laptop) it stops. Restart the command and it will pick up from the most recent timestamp.

Still stuck?

Email info@eigon.io with the command you ran and the output you got. We answer every message and we keep CLI bug reports near the top of the queue.

Ready to deploy from your terminal?

Install the CLI in 30 seconds and trigger your first deploy.