Forgeplane private beta quickstart
Use make dev for source development. Use the packaged Docker path to validate release-style coordinator and worker images. Use make quickstart-smoke when you need to prove the queue-to-worker path with a real, provider-free run.
Get private beta access
Section titled “Get private beta access”Forgeplane is in private beta. The coordinator source, release images, Helm chart, and Terraform provider are not anonymous public downloads. Request access by email before following this guide.
The commands below assume your GitHub identity can read the private Forgeplane repositories and that you have any distribution credentials required by the beta program. A public visitor cannot clone the source repository. The Terraform provider is currently source-only and unreleased, so repository access alone does not provide a supported installable artifact or resolver contract.
Choose a local path
Section titled “Choose a local path”| Goal | Start here |
|---|---|
| Develop the coordinator, UI, or worker | Source development and make dev |
| Validate release-style images | Packaged validation and make deploy-test |
| Execute a bounded OpenTofu run | OpenTofu validation and make quickstart-smoke |
Source development after access
Section titled “Source development after access”Use this path for coordinator, UI, and worker development.
Prerequisites
Section titled “Prerequisites”- Go at the version declared in
go.mod; - Docker with Docker Compose;
- Make; and
- Node.js 22 with npm.
After access is confirmed, clone the private repository and start the development loop:
git clone https://github.com/Forgeplane-io/forgeplane.gitcd forgeplanemake devmake dev starts local dependencies, initializes the database schema, prepares frontend assets, starts the coordinator and worker, and runs the frontend/reload watchers.
Open these local services:
| Service | URL |
|---|---|
| Live-reload UI | http://127.0.0.1:7331 |
| Coordinator API | http://127.0.0.1:8080 |
| Jaeger | http://127.0.0.1:16686 |
| NATS monitoring | http://127.0.0.1:8222 |
The development bootstrap account is admin@forgeplane.local with password admin12345. Override it with FORGEPLANE_DEV_BOOTSTRAP_ADMIN_EMAIL and FORGEPLANE_DEV_BOOTSTRAP_ADMIN_PASSWORD, or disable automatic creation with FORGEPLANE_DEV_BOOTSTRAP_ADMIN=0 before running make dev. These credentials are for a disposable local environment only; never reuse them elsewhere. Packaged installations use the separate administrator bootstrap procedure.
make dev proves the source development loop. An IaC run still requires a worker that advertises the requested tool capability.
Packaged validation
Section titled “Packaged validation”Use this path to validate release-style coordinator and worker images:
make docker-buildmake docker-upmake deploy-testmake deploy-test checks health, readiness, and authenticated control-plane access. It does not execute IaC: the default/production worker image contains no IaC tools and advertises [].
OpenTofu validation
Section titled “OpenTofu validation”To run an OpenTofu-capable local stack, opt in explicitly:
make docker-up-opentofuThis profile uses the repository’s checksum-verified OpenTofu 1.10.6 image and advertises only tofu. It does not change the default worker image.
For a provider-free, no-change queue-to-worker test, run:
make quickstart-smokeThe smoke test waits for the real run to succeed and verifies 0 add / 0 change / 0 destroy. It is the executable IaC validation path; make deploy-test validates the control plane only.
Queue the first governed run
Section titled “Queue the first governed run”After signing in:
- Create an organization, team, and project.
- Register a template, publish a template version, and select its tool.
- Create an environment and an instance bound to that published version.
- Supply ordinary inputs and bind secret-marked fields through the secret catalog.
- Confirm that a worker pool advertises the required capability, then queue a plan.
- Review the plan and, when policy permits, approve and apply it.
Forgeplane validates run inputs against the selected published template-version snapshot at creation. Declare catalog-bound secret slots with x-forgeplane-secret: true on direct top-level input properties; inline values are rejected for these slots. Redaction-only annotations such as writeOnly and x-secret do not declare secret slots. See Input schema for annotation and placement rules.
See Onboarding for the permission-aware setup hub, Run operations for the execution lifecycle, and the Terraform provider guide for managing available Forgeplane resources as code after beta access is granted.
Before production
Section titled “Before production”Local Compose data and credentials are disposable. Before production, configure the Helm chart with capability-specific worker images, TLS and authentication, durable PostgreSQL and object storage, NetworkPolicies, and a tested managed-state backup and restore procedure.