Skip to main content
scripts/fireflo is the operator’s command line. It talks to three different things depending on the verb, and knowing which is most of knowing how to use it.
show reads the database, which is not the same as what the gateway is doing. In file mode it is not reading those tables at all; in database mode it holds a cached snapshot and re-reads on a poll.For what is actually in force — including whether whitelisting ever loaded — use health.

Database and offline

info and validate do not need the write-enabling flag. Reading the schema version changes nothing, and needing a flag before you may look would be a trap in the middle of an incident.

bootstrap

Writes the least a fresh database needs to start: a default routing table, an empty MESSAGE table for a vendor to go in, one listener on 27777, and one SMPP login whose password it generates and prints once. It writes nothing else on purpose — no vendor, because one needs a host and credentials nobody can guess; no rates, because an invented price bills silently where an absent one shows up unpriced. Both absences are named in its closing output.
bootstrap refuses the moment it finds a routing table, a worker or a login, so it cannot overwrite a running deployment. There is no flag that makes it.

import

Subjects are all (default), rates, routing, credentials. Flags: --dry-run, --replace, --replace-filters, --prune, --rates-file, --routing-file, --currency. Run the dry run and read it. It classifies every rate scope as a vendor cost or an account price and names the ones it can classify as neither — which is how a scope that will load and silently match nothing gets caught before it does.
Credentials have one refusal the others do not. An import yielding no usable credential is refused unconditionally, flag or no flag. An empty app_credential plus FIREFLO_CONFIG_SOURCE=db refuses every bind and every REST call at once, and nothing in the logs names the cause.
Exit codes: 0 fine, 1 the migration failed, 2 refused without touching anything — so a deploy pipeline can tell a missing flag from a broken migration.

show

whitelist prints the four gates in the order they apply, then what is approved. rejected is what was refused in the last 24 hours, and why.

Sending one message

Goes through the HTTP API exactly as a customer would. Needs FIREFLO_SEND_LOGIN and FIREFLO_SEND_PASSWORD.

Operational

version asks the gateway rather than the files on disk — an artefact that was built but never restarted into is the whole reason to ask. verify checks in the order that makes the first failure the informative one: the artefact is complete, Java is new enough, the message port answers, the operational port agrees with the configuration you chose, and the two tokens are genuinely separate. It ends by saying whether it can send yet, which is not the same question as whether it is running.
verify exit code 4 means the deployment is sound but this install’s own data is not — for example nothing is configured to route to. 0 is fine, 1 failed, 2 refused or misused.

Credit

Returns unspent RESERVED prepaid credit so the next message re-reads the balance.
This is the one piece of runtime state reload cannot rebuild. Credit is handed out in blocks and stays spendable until used, so correcting a balance by hand does not take effect until this runs. It takes nothing away — the block is reservable again immediately.

Queues

Lists the messages waiting, not just how many — account, product, destination, retry count and age. Answers “whose traffic is this” when a queue is deep. Read-only: nothing is taken off a queue and nothing is reordered. Default 20 per queue, maximum 500. There is no message text in the output, by the same rule that keeps it out of call records by default.

Usage and retention

usage purge refuses the whole run if any day it would delete has no rollup, and names the days. Not a warning — deleting an unsummarised day destroys the consumption record permanently, with nothing able to reconstruct it. Needs FIREFLO_CDR_PURGE=true.rollup is deliberately a separate command. A purge that quietly rolled up first would mean a rollup bug is discovered by the command that deletes the evidence.

Connections

Session ids come from fireflo health. They are the listener’s own counter, so they collide between listeners and restart with the gateway.
disconnect ends a connection; it does not withdraw permission. A healthy client rebinds within seconds unless you also disable its login.
Captures contain message content and destination numbers. They are bounded and held in memory only: the capture stops itself and is dropped fifteen minutes later, downloaded or not. This replaces turning on log.pdus for a whole worker, which wrote every session’s PDUs to a shared log file.

The seven control verbs

What each does per worker kind is set out in Controlling a worker.

Purging sample data

purge seed runs the paired down script and nothing else. There is no search for things that look like test data, because on a configuration database that is how you delete a customer. --reset-database empties every table, back to the state just after db migrate. It refuses unless FIREFLO_DB_RESET=true, refuses while the gateway is reachable, and asks you to type the database name.

Environment

See Environment variables for the full list, and The operational endpoint for the two tokens.