Skip to content

sky provision ​

Provision missing public-state keys discovered by code analysis.

Synopsis ​

bash
sky provision --project <slug> [--env <env>] [--path <dir>] [--dry-run] [--yes]

Description ​

Scans a directory of source files for public-state reads made through the SkyState SDKs, collects the key and default value of each, and adds any key that does not yet exist at the top level of the environment's public state. Existing keys are never modified or removed.

Two call shapes are recognized:

  • usePublicState(key, default) imported from @skystate/react
  • client.publicState.get(key, default) where client was created with createSkyStateClient from @skystate/core

The key must be a string literal and the default must be a literal JSON-serializable value (string, number, boolean, null, array, or object literal). Calls that do not meet this are skipped with a warning. Files with the extensions .ts, .tsx, .js, .jsx, .mjs, .cjs, .mts, and .cts are scanned; the directories .cache, .git, .next, .skystate, .turbo, build, coverage, dist, and node_modules are skipped.

Keys are only added when the value is safe to determine: a key with no default, an invalid top-level name (empty, or containing / or ~), or different defaults in different places is skipped with a warning. Warnings are printed to stderr as Warning [<code>]: <file>:<line>:<column>: <message>.

If nothing is found, or every discovered key is already present, the command exits without writing. Otherwise it lists the keys it will add and asks for confirmation unless --yes or --dry-run is given. The write is a single new version of the environment's public state. If the environment changes between the check and the write, the command re-reads the state and retries once.

Authentication follows the CLI auth resolution rules.

Options ​

OptionDescription
--project <slug>Required. Project slug.
--env <env>Target environment (development, staging, production, or an alias). See Environments for how it resolves when omitted.
--path <dir>Directory to scan. Defaults to the current directory.
--dry-runShow keys without writing changes.
--yesSkip confirmation prompt.

Examples ​

bash
sky provision --project my-app --env development --path ./src --dry-run
sky provision --project my-app --env development --path ./src --yes

Output ​

All output goes to stderr. A run that adds keys prints:

text
Provisioning 2 missing key(s) to development:
  + banner = {"enabled":true}
  + maxItems = 10
Provisioned 2 key(s) (v3).

With --dry-run, the summary is followed by Dry run: no changes written. instead of a write.

Other outcomes print one of:

text
No provisionable keys found.
All discovered keys are already present.
Aborted.

--quiet suppresses all of the above, including warnings.

Errors ​

SituationMessage
--env cannot be resolvedMissing required option: --env
--env is not a known environmentInvalid environment "<env>". Must be one of: dev, stg, prod (or development, staging, production)
Project or environment does not existProject '<slug>' or environment '<env>' not found.
Non-interactive mode without --yes or --dry-runUse --force to skip confirmation in non-interactive mode
State changed again after the retryState changed during provision. Rerun the command.