Eigon CLI
Deploy from your terminal.
Everything you can do in the dashboard, in one binary you can drop into a shell script. Trigger deploys, tail logs, flip feature flags and export Terraform with a single command.
The eigon CLI is the official command line tool for Eigon. It is a single statically linked Go binary. No Node, no Python, no runtime dependencies. It works exactly the same on your laptop and inside a CI runner.
Install
One line install (recommended)
curl -sSL https://eigon.io/install.sh | shThe script detects your operating system and architecture, downloads the right binary from the latest GitHub release, and drops it into /usr/local/bin/eigon. It will ask for sudo if it cannot write to that directory.
You can pin to a specific version or change the install location with environment variables:
# Pin to a version
curl -sSL https://eigon.io/install.sh | EIGON_VERSION=v0.8.0 sh
# Install to a directory you own (no sudo needed)
curl -sSL https://eigon.io/install.sh | EIGON_INSTALL_DIR=$HOME/bin shVerify the install
eigon versionAuthenticate
The CLI uses API tokens, not passwords. Each token is scoped, revocable and tied to a specific user. Tokens never expire unless you tell them to.
- Go to Account → Tokens in the dashboard.
- Click New token. Give it a name like
laptoporgithub-actions. - Pick the scopes you need (read, deploy, admin). Most workflows only need read and deploy.
- Copy the token immediately. It will never be shown again. Tokens look like
eigon_ab12cd_....
Then run the login command and paste the token when prompted:
eigon loginYour token is saved at ~/.eigon/config.json with 0600 permissions. To check who you are signed in as:
eigon whoamiYou can also skip eigon login entirely by exporting the token as an environment variable. This is the right pattern for CI:
export EIGON_TOKEN=eigon_ab12cd_xxxxxxxxxxxxxxxxxxxxxxWhich scope to pick
Tokens carry scopes and the API enforces them, so give a token the least it needs:
read— everything that only looks:status,logs,envs,env list,projects list,flags list,drift,compliance.deploy— anything that changes something:deploy,env set,env unset,flags set,pause,resume. A CI token that deploys wants this one.admin— creating and revoking other tokens. Adeploytoken deliberately cannot mint one, so it cannot widen its own access.
Use the wrong scope and the CLI tells you which one you are missing rather than failing vaguely:
$ eigon deploy --env prod
error: deploy failed: this token is read-only: it does not carry the 'deploy' scope needed to change anythingYour first deploy
Once you have a project with an environment, you can deploy from the terminal. Start by listing your projects:
$ eigon projects list
NAME SOURCE REPO/BRANCH
heal-probe github ayush/heal-probe @ main
landing-page zip (uploaded ZIP)
api-service github myorg/api @ mainThen list a project’s environments. This is where you find the name to pass to --env, along with each environment’s address:
$ eigon envs --project heal-probe
heal-probe
ENV PROFILE STATE URL
dev dev running https://heal-probe-e407-app.eigon.app
staging staging running https://heal-probe-da94-app.eigon.app
Use the ENV value with --env, e.g. eigon deploy --env dev--project and --env take names, not ids. If your organisation has one project and that project has one environment, you can leave both out entirely and just run eigon deploy.
$ eigon deploy --project heal-probe --env dev
✓ Deploy queued for heal-probe/dev: 91f79585-8da9-445d-b418-791976c3c31f
Watch progress: https://eigon.io/dashboard/org/<org>/project/<project>/environments
Or: eigon logs --env dev --tailTail the logs while it deploys:
eigon logs --project heal-probe --env dev --tailWhen the deploy is done, check the address and what it costs:
$ eigon status --project heal-probe --env dev
Status: SUCCEEDED
Monthly cost: $31.63
App URL: https://heal-probe-e407-app.eigon.app
Latest deploy: 91f79585-8da9-445d-b418-791976c3c31f (SUCCEEDED)Command reference
Run eigon help at any time for the full list. The most useful ones:
eigon login
Prompts for an API token and saves it to ~/.eigon/config.json with owner-only permissions. There is no browser step: create the token in the dashboard, then paste it here. In CI, skip this and set EIGON_TOKEN instead.
eigon whoami
Calls the API and prints the user and organisation associated with the current token. Useful for confirming a CI token actually works.
eigon projects list
Lists every project the current token can see, with source type and repository or upload origin.
eigon envs --project <name>
Lists a project’s environments with their profile, whether they are running or asleep, and the address each one serves. This is how you find the value for --env.
eigon deploy --env <name>
Triggers a deploy on the given environment using the latest code. Returns the deployment ID immediately. The deploy continues in the background and you can follow it via eigon status or in the dashboard.
eigon status --env <name>
Shows the current status of an environment: state, month to date cost, live URL, and the latest deployment plus its status.
eigon logs --env <name> [--tail]
Prints the most recent application logs. With --tail, follows new log lines as they arrive (poll based, every 2 seconds). Press Ctrl+C to stop.
eigon flags list --env <name>
Lists every feature flag in an environment.
eigon flags set key=value --env <name>
Updates a feature flag value. Useful for dark launches and emergency kill switches you want to be able to flip from a script.
eigon export-tf --env <name> --org <id> --project <id>
Downloads a Terraform module covering the entire environment: network, compute, database, cache, CDN and WAF. The bundle is ready to apply against your own AWS account. This is how you take your infrastructure with you if you ever decide to leave Eigon.
eigon scan <repo-url>
Reads a public repository and reports what would break on deploy, plus what the infrastructure would cost. No account and no login required — this is the one command you can run before signing up. It exits non-zero when the repository would not deploy, so it works as a CI gate without parsing output.
eigon scan github.com/gothinkster/realworld
This repository looks production-ready. Nothing here would stop a deploy.
2 service(s) · about $38.88/montheigon pause --env <envId>
Scales an environment to zero so it stops costing money. Your data is kept by default: databases are snapshotted before anything is removed, never destroyed. Pass --delete-data only if you also want the data gone. Bring it back with eigon resume --env <envId>, which restores from the snapshot and rewrites connection secrets to the new endpoint before redeploying.
eigon drift --env <envId>
Shows infrastructure that was changed outside Eigon — usually someone editing the AWS console during an incident. Add --check to run a fresh check rather than reading the last one. Exits non-zero when drift is found, because the next deploy resets those changes back to Eigon's configuration.
eigon compliance --env <envId>
Technical controls from SOC 2, GDPR and HIPAA, checked against the environment. Filter with --framework soc2|gdpr|hipaa. Each control says whether it was checked against your environment or is a statement about how Eigon builds every environment — a readiness report, not a certification, and it covers the infrastructure layer only.
eigon version
Prints the installed CLI version. Useful when filing bug reports.
Environment variables
Set a variable, list what is set, remove one. Values are written to AWS Parameter Store by the control plane, encrypted at rest, and injected into your containers at start-up.
$ eigon env set DATABASE_URL=postgres://user:pass@host:5432/db --env prod
✓ DATABASE_URL set on api-service/prod
Not live yet: running containers keep the values they started with.
Apply with `eigon deploy`, or re-run this with --deploy.Add --deploy to set the variable and roll it out in one step, which is usually what you want:
eigon env set STRIPE_KEY=sk_live_... --env prod --deployMoving a whole file in is one command. Comments, blank lines, export prefixes and quoted values are all handled:
$ eigon env set --from-file .env.production --env prod --deploy
✓ API_KEY set on api-service/prod
✓ DATABASE_URL set on api-service/prod
✓ REDIS_URL set on api-service/prod
✓ Deploy queued: 91f79585-8da9-445d-b418-791976c3c31fA pair given on the command line beats the same key in the file, so a single override next to --from-file behaves the way it reads.
$ eigon env list --env prod
api-service/prod
NAME STORE DESCRIPTION
API_KEY ssm
DATABASE_URL ssm primary read/write
REDIS_URL ssm
3 variable(s). Values are held in AWS Parameter Store and are never returned by the API,
so they cannot be printed here. Overwrite one with `eigon env set NAME=newvalue`.eigon env list shows names, never values. Nothing in Eigon can read a value back out once it is stored, including this CLI and the dashboard. To change one, write over it.
eigon env unset OLD_FLAG STALE_KEY --env prodSetting or removing a variable needs a token with the deploy scope. A read token can run eigon env list but not change anything.
Use it from CI
The official GitHub Action wraps the CLI with a single composite step. Drop this in .github/workflows/deploy.yml and add EIGON_TOKEN as a repository secret.
name: Deploy to Eigon
on:
push:
branches: [main]
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Deploy
env:
EIGON_TOKEN: ${{ secrets.EIGON_TOKEN }}
run: |
curl -sSL https://eigon.io/install.sh | sh
eigon deploy --project my-app --env prodTwo lines and a secret. There is no Eigon-specific action to install, so there is nothing extra to trust in your pipeline, and the same three lines work on any CI that can run a shell.
Prefer to call the CLI directly? Any other CI system works too. The shape is the same: install, set the token, run a command.
# GitLab CI / CircleCI / Buildkite / Bash one-liner
curl -sSL https://eigon.io/install.sh | sh
export EIGON_TOKEN=$EIGON_TOKEN
eigon deploy --project api-service --env prodConfiguration
Configuration is read from environment variables first, then from ~/.eigon/config.json as a fallback. Environment variables always win, which makes CI predictable.
| Variable | Description |
|---|---|
| EIGON_TOKEN | API token. When set, login is skipped entirely. |
| EIGON_API_BASE | API base URL. Defaults to https://api.eigon.io. Override only if you are pointing at a self hosted control plane. |
| EIGON_INSTALL_DIR | Used by the install script. Default /usr/local/bin. |
| EIGON_VERSION | Used by the install script to pin a specific version. Default latest. |
The config file at ~/.eigon/config.json looks like this:
{
"token": "eigon_ab12cd_xxxxxxxxxxxxxxxxxxxxxx",
"api_base": "https://api.eigon.io",
"default_org": "d08b48d4-bf1c-43f1-b292-f99eeaa2ffc0"
}Uninstall
Removing the CLI is the inverse of installing it. Delete the binary and drop the config directory.
sudo rm /usr/local/bin/eigon
rm -rf ~/.eigonYou should also revoke any API tokens you no longer want. Visit Account → Tokens and click Revoke.
Troubleshooting
eigon: command not found
The install directory is not on your PATH. Either add it (most shells already include /usr/local/bin) or reinstall with EIGON_INSTALL_DIR set to a directory that is.
not authenticated. Run `eigon login`.
Your token is missing or expired. Run eigon login again, or export EIGON_TOKEN in your shell.
invalid api token
The token has been revoked, or you copied the wrong one. Create a fresh token at Account → Tokens and run eigon login again.
Deploy fails with BLOCKED_BY_CAP
The environment has hit its monthly spending cap. Either raise the cap from the dashboard, or wait for the next month to roll over. Spending caps are a built in protection so you do not get a surprise bill.
eigon logs --tail stops after a few minutes
Tail mode polls every two seconds. If the underlying connection is dropped (idle CI runner, sleeping laptop) it stops. Restart the command and it will pick up from the most recent timestamp.
Still stuck?
Email info@eigon.io with the command you ran and the output you got. We answer every message and we keep CLI bug reports near the top of the queue.
Ready to deploy from your terminal?
Install the CLI in 30 seconds and trigger your first deploy.
