ForgeFlow
From a local change to a verified server revision.
Product tour · Features · Get started · Deployment model
ForgeFlow is a Windows desktop application for teams that use Git, Gitea and self-hosted Docker or Unraid servers. It brings local changes, remote commits and the exact revision running on a server into one workspace, then guides review, commit, push, deployment and verification.
Public-source edition: This repository contains reviewed source files from a private canonical repository. It does not yet host signed Windows releases.
PUBLIC_SOURCE_MANIFEST.jsonidentifies the exact source revision and file hashes; private Git history is not included.
Downloads: Existing signed Windows releases remain at the legacy ForgeFlow release page during the public-repository transition. The curated public source is separate; it will become the release destination only after signing and update compatibility are verified.
See the workflow
| Review local work | Reconcile deployments |
|---|---|
![]() |
![]() |
The captures use example repositories and demo state; they are not a live infrastructure dashboard.
Key capabilities
| Area | What ForgeFlow helps you do |
|---|---|
| Action queue | See which repositories need review, a push, deployment or health attention. |
| Git review | Inspect diffs, stage files or hunks, commit, push and recover from common sync problems. |
| Gitea awareness | Compare local and remote revisions, review branch protection and open a pull request. |
| Server inventory | Discover Docker, Compose and DockerMan workloads and link them only when repository evidence matches. |
| Exact-commit deployment | Dispatch a reviewed revision and compare the full local, Gitea and live commit SHAs. |
| Git Validator | Inspect repository identity, protection, documentation, secret hygiene and oversized files. |
| Diagnostics | Keep configuration local and redact sensitive values in support exports. |
ForgeFlow distinguishes a matching commit from a healthy deployment. It keeps incomplete evidence visible instead of claiming that a server is current when its live SHA is unknown.
Get started
Install the Windows app
- Download an installer or portable executable from the published release page.
- Launch ForgeFlow and complete the setup wizard.
- Add your Gitea URL, a token with the required repository permissions, and the local folders to scan.
- Optionally add a Docker or Unraid host, then use Scan servers to review detected workloads.
The packaged updater checks a release against the exact remote commit, its SHA-256 checksum and the embedded Ed25519 publisher key. Existing installations continue to use the legacy release endpoint until the migration is qualified.
Explore with example data
Requirements: Node.js 22, npm and Git.
npm ci
npm run demo
Open http://127.0.0.1:41737. The browser demo uses example repositories and server state; it does not mutate your Git checkouts or deploy a workload. To run the full desktop application from source, use npm start after npm ci.
Deployment model
flowchart LR
Desktop[ForgeFlow desktop] --> Git[Local Git worktree]
Desktop --> Gitea[Gitea repository and Actions]
Gitea --> Runner[Approved deployment workflow]
Runner --> Server[Docker or Unraid host]
Server --> Evidence[Live revision and health evidence]
Evidence --> Desktop
For server-pull deployments, the host fetches the exact approved commit with a repository-scoped read-only deploy key and a pinned SSH host key. ForgeFlow validates Compose configuration and checks post-deployment health. A direct copy remains an explicit fallback, never an implicit replacement for the verified pull path.
Start with the setup guide, deployment setup, SSH and Unraid deployment, and migration example. Keep runtime data and credentials outside Git. The diagnostics guide explains safe support bundles.
Develop and verify
npm ci
npm run check
npm run acceptance
npm run check performs source verification, linting and tests. Browser acceptance and Windows packaging are separate release gates. src/main/ contains desktop services and IPC, src/renderer/ contains the UI, src/shared/ holds shared policies, scripts/ contains validation and release tooling, and tests/ covers core behavior.
The private canonical repository publishes a reviewed, content-only snapshot to ForgeFlow-Public. Its manifest records the source revision; private Git history and operational evidence are excluded. Binary release publication remains manual during the endpoint transition.
ForgeFlow is available under the MIT License. Report security issues through SECURITY.md.


