Skip to content

CLI reference

Infrawise ships five commands, one per job: infrawise start to onboard (probe, generate config, analyze, connect your editor), infrawise analyze for an on-demand report, infrawise check as a CI/CD gate, infrawise serve to run the MCP server directly, and infrawise doctor to diagnose connectivity problems.

Probe the environment, generate infrawise.yaml if missing, analyze, write the MCP config file for your editor, then exit. This is the primary command — no config file is required on the first run.

Terminal window
infrawise start [options]
Flag Default Description
-c, --config <path> infrawise.yaml Path to config file
--claude Write .mcp.json and open Claude Code
--cursor Write .cursor/mcp.json and open Cursor
--vscode Write .vscode/mcp.json (merging with existing servers) and open VS Code
--interactive Run the guided setup wizard instead of auto-discovery
--rediscover Delete infrawise.yaml and the .infrawise/ directory, then re-probe and re-analyze from scratch

Running infrawise start without an editor flag writes .mcp.json only (no editor is opened). Re-run any time your infrastructure changes to refresh the graph, or use --rediscover for a clean slate.

Force a full re-scan and print findings to stdout. Does not start the MCP server. Use this for scripted audits or to inspect findings without opening an editor.

Terminal window
infrawise analyze [options]
Flag Default Description
-c, --config <path> infrawise.yaml Path to config file
-r, --repo <path> current dir Repository to scan for service usage
--no-cache Skip reading/writing the cache
-o, --output <path> Save findings as a markdown report, e.g. report.md
--severity <level> Only show findings at or above: high, medium, low

CI/CD gate. Runs a fresh analysis and exits with a non-zero code when findings reach the threshold severity, so it can block a deploy without an AI editor in the loop.

Terminal window
infrawise check [options]
Flag Default Description
-c, --config <path> infrawise.yaml Path to config file
-r, --repo <path> current dir Repository to scan for service usage
--fail-on <level> high Severity that fails the build: high, medium, low
Terminal window
# Block a deploy if any high-severity finding exists (exit 1)
infrawise check
# Stricter gate — fail on medium and above
infrawise check --fail-on medium

Start the MCP server directly. Defaults to HTTP transport; pass --stdio for the transport editors use. Keeps running in the foreground.

Terminal window
infrawise serve [options]
Flag Default Description
-c, --config <path> infrawise.yaml Path to config file
--stdio Use stdio transport (for editors via .mcp.json) instead of HTTP
-p, --port <n> 3000 HTTP port (HTTP only)

MCP endpoint (HTTP): POST http://localhost:<port>/mcp

Diagnostic escape hatch. Validates AWS credential resolution, tests connectivity to each configured service, and verifies the config file. Prints a pass/fail report per service and surfaces permission errors with the specific missing IAM action.

Terminal window
infrawise doctor

Run this when extraction comes up empty. No flags required beyond --config — it reads infrawise.yaml from the current directory.

Print the installed Infrawise version.

Terminal window
infrawise --version

What is the difference between infrawise start and infrawise serve?

Section titled “What is the difference between infrawise start and infrawise serve?”

infrawise start runs a one-time scan, writes the MCP config file for your editor, then exits. Your editor picks up the config and manages the Infrawise process from there. infrawise serve starts the MCP server in the foreground — HTTP by default, or --stdio — and stays running until you stop it. Use serve for direct HTTP calls or non-stdio MCP clients.

Use infrawise check. It runs a fresh analysis and exits 1 when any finding reaches --fail-on severity (default high), so it fails the pipeline step. Example: infrawise check --fail-on high.

When should I run infrawise analyze again?

Section titled “When should I run infrawise analyze again?”

Run infrawise analyze (or infrawise start) any time you add, remove, or significantly change AWS resources — new Lambda functions, new DynamoDB tables, new SQS queues, etc. The MCP tools your AI calls serve results from the in-memory graph built at startup; they do not re-scan on every call. For always-fresh data during active infrastructure work, use infrawise serve and restart it after changes.