init (write the config) → generate (preview the change) → provision (apply it) — see the walkthroughs for the full setup.
init
Interactive wizard — writes the infrastructure config (_infra/synthetiq.yaml):
--yes (non-interactive) there are no prompts, so --domain is required and the certificates must be discoverable in the account or passed via --api-cert-arn / --cdn-cert-arn.
generate
Compute the CloudFormation change sets from the config and write a reviewable changeset file — nothing is executed:terraform plan -detailed-exitcode: 0 when nothing changed, 2 when changes are pending, 1 on error.
provision
Apply the pending changeset — executes exactly the reviewed change sets, prints the app DNS records (including one per load balancer shard), seeds the deploy key, and registers the account as your organization’s deployment target:infra:provision scope (your login locally, a service account in CI) — init and generate need no Synthetiq identity at all. Refuses to apply when the config changed since generate, when the stack moved underneath the change set, or when the changeset was generated by a different CLI version.
status
Show your organization’s registered deployment target — the result of the most recentprovision — and its load balancer capacity:
status (ready, provisioning, failed, …) along with the AWS account, domain, and deploy role. Prints No deployment target registered when the organization has never provisioned.
When run inside an infra repo with AWS credentials for the registered account, it also lists each load balancer shard with its app count (out of 100), flags shards whose DNS record doesn’t point at them yet, and warns once every shard holds more than 80 apps. Without credentials it skips that section.
permissions
Print the IAM policy required for provisioning (JSON):
See Permissions for what each stage’s policy contains.

