Skip to main content

Connecting

The four permission flags

Each one exists because the command it guards is destructive in a way that is not obvious from its name. None of them has a command-line equivalent, on purpose: a flag you have to export is a flag you cannot pass by accident from shell history.
FIREFLO_DB_MIGRATE and FIREFLO_CONFIG_IMPORT are separate deliberately. One applies schema changes; the other replaces pricing and credentials. A deployment that is happy to auto-migrate is not necessarily happy to have its tariffs overwritten.

Exit codes

The 1 / 2 split is what lets a deploy pipeline tell a missing flag from a broken migration.