Multiple clients and profile management
A profile stores one API endpoint, credential, user identity, selected organization, and namespace. Keep application shape in satusky.toml; never put a token or profile credential in a project file.
Profile storage
Section titled “Profile storage”~/.satusky/context.json~/.satusky/profiles/<profile-name>.jsonThe context file records the active profile. Each profile file contains its own sensitive authentication state. Do not commit either location.
Create one profile per target
Section titled “Create one profile per target”1ctl profile create client-a-staging \ --url https://api.satusky.com/v1/cli1ctl profile create client-a-production \ --url https://api.satusky.com/v1/cli
1ctl profile list1ctl profile currentCreation does not copy another profile’s credential. The active profile is marked with * in the table output.
Authenticate without shell-history exposure
Section titled “Authenticate without shell-history exposure”read -rs SATUSKY_API_KEYprintf '\n'export SATUSKY_API_KEY1ctl --profile client-a-staging auth loginunset SATUSKY_API_KEY
1ctl --profile client-a-staging auth status1ctl --profile client-a-staging org currentRepeat with the token intended for each target. If a user belongs to several organizations, select the intended organization once in that profile:
1ctl --profile client-a-staging org switch ORGANIZATION_NAME_OR_IDOrganization switching persists in the selected profile. Do not run it concurrently from jobs that share the same profile files.
Interactive and one-shot selection
Section titled “Interactive and one-shot selection”Change the active profile explicitly:
1ctl profile use client-a-staging1ctl profile current1ctl auth statusRun one command against another profile without changing the active selection:
1ctl --profile client-a-production org current1ctl --profile client-a-production -o json app listThe environment-variable equivalent is:
SATUSKY_PROFILE=client-a-production 1ctl -o json app list--profile is a global flag and appears before the command name.
Deploy to an explicit target
Section titled “Deploy to an explicit target”Verify the organization and existing applications first:
TARGET=client-a-staging1ctl --profile "$TARGET" org current1ctl --profile "$TARGET" -o json app list | jq '.[] | {app_label, status}'Then deploy from the project directory:
1ctl --profile "$TARGET" deploy \ --config satusky.staging.toml \ --waitThe profile selects the endpoint, identity, and organization. The config file selects the application settings.
Recover from the wrong target
Section titled “Recover from the wrong target”Do not redeploy or delete until you confirm the owning profile:
1ctl profile current1ctl org current1ctl -o json app list
1ctl --profile client-a-production org current1ctl --profile client-a-production -o json app listInspect and delete through the same owning profile:
1ctl --profile client-a-staging app get unintended-app1ctl --profile client-a-staging app delete unintended-app --yesRetire a local profile
Section titled “Retire a local profile”Switch away from the profile before deleting it:
1ctl profile use client-a-production1ctl profile delete client-a-stagingDeleting a profile removes local state only. It does not delete applications, organizations, or server-side API tokens. Disable or delete an obsolete token separately after confirming no client still uses it.
Command summary
Section titled “Command summary”| Task | Command |
|---|---|
| Create | 1ctl profile create NAME --url API_URL |
| List | 1ctl profile list |
| Show active | 1ctl profile current |
| Switch active | 1ctl profile use NAME |
| One-shot target | 1ctl --profile NAME COMMAND |
| Environment target | SATUSKY_PROFILE=NAME 1ctl COMMAND |
| Delete inactive | 1ctl profile delete NAME |