Skip to content

Repository files navigation

CloudForge CI

Maven Central License Java

CloudForge CI is an open-source Java framework, built on the AWS CDK, for deploying containerized applications to AWS. You describe a deployment in a small JSON file (deployment-context.json): which application, EC2 or Fargate, a security profile, and optional domain, authentication, and compliance settings. CloudForge synthesizes a CloudFormation stack with the VPC, load balancer, storage, database, logging, and IAM resources that application needs. The same template can be deployed to AWS or, without an AWS account, to a local MiniStack or LocalStack emulator.

CloudForge implements and validates infrastructure controls mapped to compliance frameworks. It is not compliance-certified and does not make a deployment compliant on its own. You remain responsible for your own assessments, audits, and organizational controls. The software is provided "AS IS" under the Business Source License 1.1.

Features

  • Application catalog: built-in specifications for CI/CD and code quality (Jenkins, GitLab, Drone, SonarQube), version control (Gitea), monitoring (Grafana, Prometheus), analytics (Metabase, Superset), databases (PostgreSQL, Redis), artifact registries (Nexus, Harbor), secrets (Vault), collaboration (Mattermost), and PHP CMS, commerce, forum, wiki, LMS, and CRM platforms (WordPress, WooCommerce, Drupal, Joomla, TYPO3, Concrete CMS, October CMS, Magento, PrestaShop, OpenCart, Sylius, Bagisto, phpBB, Flarum, MyBB, MediaWiki, Moodle, SuiteCRM, UNA). Additional applications can be added as plugins through Java ServiceLoader.
  • Runtimes: Amazon ECS on Fargate or EC2 Auto Scaling groups behind an Application Load Balancer.
  • Security profiles: dev, staging, and production profiles set defaults for networking, encryption, logging, backups, and compliance enforcement.
  • Authentication: ALB-level or application-level OIDC, depending on what each application supports, with Amazon Cognito (optionally auto-provisioned), an external OIDC provider, or IAM Identity Center.
  • Managed dependencies: Amazon RDS for applications that need a database, and S3 media storage, Redis, and a CloudFront distribution for the CMS topology.
  • Compliance validation: controls mapped to SOC 2, PCI DSS, HIPAA, and GDPR, checked at synthesis time (framework rules and cdk-nag), optionally with cfn-guard, and at runtime with AWS Config rules and remediation.
  • Local emulators: deploy the synthesized template to MiniStack or LocalStack for development and testing.

Published test, coverage, and compliance reports: https://cloudforgeci.github.io/cfc-core/

Prerequisites

  • Java 25 and Maven 3.9+
  • For AWS deployments: Node.js, the AWS CDK CLI (npm install -g aws-cdk), and AWS credentials
  • For local deployments: Docker; LOCALSTACK_AUTH_TOKEN when using LocalStack
  • Optional: cfn-guard for template validation when complianceMode is enforce

Quick Start

1. Install cloudforge-cli

cloudforge-cli deploys applications and manages local emulators. Install it from the CloudForgeCI Homebrew tap:

brew install CloudForgeCI/tap/cloudforge-cli

2. Build the sample application

git clone https://github.com/CloudForgeCI/cfc-core.git
cd cfc-core
mvn clean install                                      # tests are skipped by default
mvn -f cfc-testing/pom.xml package -Dmaven.test.skip=true

cfc-testing is the sample application in this repository: CloudForgeCommunitySample builds a stack from deployment-context.json.

3. Run locally without an AWS account

Start an emulator (ministack or localstack):

cloudforge-cli emulator start --target localstack

Then deploy an application against it:

cloudforge-cli deploy --context cfc-testing/deployment-contexts/Jenkins-Stack.json --target localstack

MiniStack and LocalStack share port 4566, so run one at a time. See the local emulator setup docs in cloudforge-localstack and cloudforge-ministack for details.

4. Deploy to AWS

cd cfc-testing
cdk bootstrap          # once per account and region

Write a deployment-context.json (see Minimal deployment context below), then use the CDK CLI directly. cdk.json runs CloudForgeCommunitySample, which synthesizes that file without prompting (and synthesizes nothing if the file does not exist):

cdk diff
cdk deploy
cdk destroy <stackName>

Use CloudForge in your own project

The cloudforge-sample repository is a standalone project with the same layout as cfc-testing. To add CloudForge to an existing Maven project, import the BOM and depend on cloudforge-api, using the latest version shown on Maven Central:

<dependencyManagement>
  <dependencies>
    <dependency>
      <groupId>com.cloudforgeci</groupId>
      <artifactId>cfc-core</artifactId>
      <version>${cloudforge.version}</version>
      <type>pom</type>
      <scope>import</scope>
    </dependency>
  </dependencies>
</dependencyManagement>

<dependencies>
  <dependency>
    <groupId>com.cloudforgeci</groupId>
    <artifactId>cloudforge-api</artifactId>
  </dependency>
</dependencies>

See the sample project BOM template for a complete POM and project layout.

Minimal deployment context

{
  "stackName": "jenkins-dev",
  "applicationId": "jenkins",
  "runtime": "fargate",
  "securityProfile": "dev"
}

This deploys Jenkins on Fargate with the dev profile, reachable through the load balancer's DNS name over HTTP. Fields you leave out take their defaults from the security profile and the application specification. Add a domain, TLS, and Cognito sign-in with:

{
  "domain": "example.com",
  "subdomain": "jenkins",
  "enableSsl": true,
  "authMode": "alb-oidc",
  "cognitoAutoProvision": true,
  "cognitoDomainPrefix": "example-jenkins-auth"
}

Documentation

Contributing

Contributions are welcome. See CONTRIBUTING.md for the development setup, build and test commands, and pull request process. Release history is in CHANGELOG.md.

Support

License

Business Source License 1.1. Free for production use, including managing your own infrastructure; offering CloudForge (or a derivative) to third parties as a hosted service or marketplace listing requires a commercial license. Converts to Apache License 2.0 on 2030-10-01. See LICENSE.

About

CloudForgeCI provides secure-by-default AWS infrastructure patterns, evaluates synthesized deployments against selected policy controls, and enforces the configured production baseline. It also surfaces actionable findings for environment- and workload-specific requirements that must be completed by the deploying organization.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages