CEDAR CLI Cheat Sheet¶
cedarcli is CEDAR's command-line interface for building, publishing, starting, stopping, and
checking the installation. Make it available and select a persistent deployment mode before the
first native or Docker operation:
export CEDAR_HOME=$HOME/CEDAR_DOCKER
alias cedarcli='source "$CEDAR_HOME/cedar-cli/cli.sh"'
cedarcli mode docker
Mode selection starts nothing. The choices are native, hybrid, and docker. A second selection
is rejected; stop the current deployment and run cedarcli mode --clear before changing it. Clear
refuses while the selected topology still owns processes or Compose projects. If the optional admin
project is running, stop it separately with cedarcli docker stop admin.
If Docker has already been deliberately shut down and therefore cannot confirm teardown, use
cedarcli mode --clear --force to discard the inactive deployment record.
Use cedarcli env status to see the selected mode and effective profile. env list and env filter
read that effective profile and redact credentials. In hybrid mode, append native or docker to
select the environment being inspected.
Normal Docker Workflow¶
cedarcli docker validate
cedarcli docker setup one-time-setup
cedarcli docker start all --pull missing --timeout 1800
cedarcli docker status
cedarcli docker stop all
one-time-setup recreates the private Docker network, so run it only while the stack is stopped.
The three lower-level setup commands are available separately as
cedarcli docker setup create-network, create-certificates-volume, and copy-certificates when
repairing one resource. In normal use, run the aggregate command above.
Ordinary stop and start operations preserve the named volumes that hold CEDAR data.
Keep Docker running until stop completes. When the daemon is unavailable, aggregate stop reports one
error without attempting each stack. mode --clear --force clears CLI state only; it does not stop
or remove Docker resources.
Start or Stop One Target¶
Use a target when you need to operate on less than the complete deployment:
cedarcli docker start infra
cedarcli docker start keycloak
cedarcli docker start frontend workspace
cedarcli docker stop microservice resource
kk is the short spelling of keycloak. frontend all and microservice all are accepted, but
the clearer group spellings are frontends and microservices.
Deployment Modes¶
| Mode | Runtime selected by the CLI |
|---|---|
docker |
All 29 core containers, including the seven frontend applications |
hybrid |
The 22-container Docker backend, with Docker nginx routing to seven native frontend servers |
native |
The complete host-based deployment; Docker commands are unavailable |
Image Selection and Pulling¶
An ordinary start selects the latest completed and verified Docker train. The options change that selection or control how it reaches this machine:
--pull missingdownloads only absent images. This is the normal first-start choice.--pull alwayschecks the registry even when a local image is present.--pull neverrequires every selected image to exist locally.--train <TRAIN_ID>selects a particular older, completed train.--localselects locally built development tags rather than a published train.
The timeout covers the complete start, including image downloads. A cold pull is several gigabytes, so the example gives it 30 minutes. Later starts normally finish much sooner.
Build Images from Checked-out Source¶
Most installations do not need to build images. Developers can build the complete local image set from checked-out source:
cedarcli build java
cedarcli docker build infra --local
cedarcli docker build microservices --local
cedarcli docker build frontends --local
cedarcli docker start all --local --pull never
cedarcli build runs Java tests by default. Use cedarcli build java --skip-tests for an explicit
compile/install-only pass; --tests is the paired explicit spelling of the default. The option is
available on this, parent, libraries, project, clients, java, and all, but not
on frontend-only build commands.
Docker build targets are infra, microservices, frontends, admin, all, or one
image name. all builds every image, including the four optional administration images.
--no-deps skips required CEDAR base images and should be used only when the exact bases are
already present.
If the local Maven cache is demonstrably inconsistent, remove only CEDAR artifacts before rebuilding. A complete cache reset also removes third-party dependencies and is deliberately broader:
cedarcli build maven clean cedar
cedarcli build maven clean all
Split Workspace and Designer¶
Workspace and Template Designer have explicit routes while their split deployment is being stabilized:
cedarcli build split-frontends
cedarcli build split-frontends --server-payload
cedarcli publish split-frontends --dry-run
cedarcli publish split-frontends
The ordinary build installs only their locked dependencies. --server-payload creates the static
trees used by native staging/production nginx. Publication creates immutable commit-derived
development packages in CEDAR Nexus without changing either checkout; the generic frontend and
all publication selectors intentionally exclude them.
Immutable Development Trains¶
CEDAR maintainers publish one internally consistent Maven, npm, and Docker set with:
cedarcli publish train --dry-run
cedarcli publish train
cedarcli publish train-status <TRAIN_ID>
cedarcli publish train-status <TRAIN_ID> --watch
cedarcli publish train --resume <TRAIN_ID> --dry-run
cedarcli publish train --resume <TRAIN_ID>
The first command rehearses dispatch without creating state; its displayed ID is prospective and
not reserved. The real dispatch allocates an
identifier such as <NEXT>-dev.YYYYMMDD.HHMM; operators do not choose it. train-status reduces
the workflow to its Maven, npm, and Docker stages, names a failed subcheck, and prints whether to
start a new ID, resume, or do nothing; --watch follows compact matrix counts and emits a quiet
one-minute active-step heartbeat during unchanged stages. Local dry-run also checks CI for each
exact remote develop commit, giving only GitHub indexing delay and transient 502/503/504 failures
a bounded retry, and validates npmrc key names without printing values. It
performs the live read-only publication probe using environment credentials or
~/.m2/settings.xml. Resume uses the exact source manifest already recorded for that train; preview
it with --dry-run when diagnosing an interruption.
Create a new train when newer source commits must be included.
Formal Release¶
A formal release consumes a completed train and requires all four inputs explicitly:
cedarcli release plan \
--version <VER> \
--next-version <NEXT>-SNAPSHOT \
--from-train <TRAIN_ID> \
--cee-version <PUBLIC_CEE_VERSION>
cedarcli release start \
--version <VER> \
--next-version <NEXT>-SNAPSHOT \
--from-train <TRAIN_ID> \
--cee-version <PUBLIC_CEE_VERSION>
cedarcli release status --watch
cedarcli release resume # compact, retained task logs
cedarcli release resume --verbose # stream raw task output
cedarcli release abandon --version <VER> --reason "<WHY>"
plan is the complete read-only release gate. start reruns that gate and advances the
manifest-owned ledger. It requires exact package/version decisions for every npm install script and
runs release installs in strict mode. Compact progress is the default; --verbose streams the raw
output that is otherwise retained in task logs, and status --watch follows the ledger with a
one-minute heartbeat. Transient transport retries are automatic; after a hard failure, fix the
cause and use resume. If a corrected train must replace an attempt that has not
begun snapshot publication, abandon retains its evidence and frees the release slot. It is refused
after external publication may have begun. Only an accepted status means the release is complete.
Diagnose a Docker Service¶
cedarcli docker status
cd $CEDAR_HOME/cedar-docker-deploy/cedar-microservices
docker compose ps
docker compose logs --tail 200 server-resource
The grouped status table reports Health, Image, Ports, and Restarts for each service. A healthy
container marked MISMATCH is still a failure because it is not running the selected image set.
The summary reports container readiness, acceptance checks, and the active train or local tag.
If the CLI says no mode is configured, run cedarcli mode docker. If another mode is configured,
stop it, clear it with cedarcli mode --clear, and then select Docker mode.
Cleanup Commands¶
cedarcli docker remove containers
cedarcli docker remove images
cedarcli docker remove network
cedarcli docker remove volumes
cedarcli docker remove all
Containers, images, and the network are recreatable. remove volumes deletes databases,
certificates, logs, and other persistent state. remove all deletes the complete local Docker
installation, including those volumes.
Use cedarcli <command> --help at every level for the authoritative options.