Configuration Exchange
Settings → Configuration Exchange moves platform configuration in and out of Hegemony - as downloadable YAML or through Git repositories. Use it for backups, migrating between environments, and treating your platform config as code. It requires the platform admin role.
Export and import YAML (Platform<>YAML tab)
Download exports the platform's configuration into a single hegemony-export.yaml file - a reviewable backup you can re-import into another environment. It covers organizations and their memberships, sites, devices, flows and their attachments, variables, notification destinations and subscriptions, schedules, webhooks, Git repositories, file repositories, inventory providers, secret backends, route permission overrides, and the platform Git profiles themselves. Use Load Template for a commented example of every section.
Upload imports the same format. Paste YAML or choose a file, then:
- Preview Changes - a dry run. You get a per-section summary (created / updated / skipped / errors) and per-entity field diffs, with nothing applied yet. If the preview is clean, Apply Import commits it.
- Import - applies directly, skipping the preview.
Import rules worth knowing (the Load Template button fills the editor with a fully commented schema):
- Entities are upserted by name - existing entries are updated, new ones created; nothing is deleted by an import.
- Secrets are import-only: values go into the secrets backend and are never exported. A webhook endpoint carries its credential the way a Git repository does — as a
secret_refnaming the secret, never the value. Path tokens stay instance-local: the first import assigns one and later imports keep it, so an endpoint's URL survives updates. Read the URL from the UI after the first import. - Imported schedules arrive disabled for safety; enable them after review.
- Flows from bundles exported by earlier versions, whose steps carry
phase:/kind:fields or alabels:map (and whoseflow_defaults.nodehands every stepphase: null/kind: null), are upgraded on import: the values are folded into each step'stagsmap - an explicittagsentry wins, thenlabels, thenphase/kind- and the old keys are dropped, so re-importing such a bundle stays a no-op. The upgraded map must satisfy the step-tag rules (at most 12 tags, identifier keys, printable values); a bundle whose step breaks them is refused at import, naming the step. New bundles write them as tags (tags: {phase: VERIFY}); a step definition sent to the API withphase,kindorlabelsas a field is refused. Platform sync plans compare a flow file in its upgraded shape too, so a repository still holding the old shape plans asnooprather than as an update on every run.
Sync with Git (Platform<>Git tab)
Platform Git profiles keep platform configuration synchronized with a Git repository on a schedule. A profile picks one of your configured Git repositories (URL and credentials live there, not here), a branch and base path, and a Mode:
- Backup - the platform stays the source of truth; snapshots are exported to Git.
- Mirror - Git is applied to the platform, with review controls.
- Bidirectional - drift is detected in both directions and resolved through plans and conflict resolution.
You can scope a profile to specific resource families (flows, sites, devices, ...) and schedule it by interval. Each profile's detail page offers manual Export, Plan, and Apply actions, run history, and per-family conflict resolution (Prefer Git, Prefer Platform, or Manual Edit).
Destructive changes are guarded
A plan that would delete things is never applied casually: the profile's destructive policy can block it outright, require typing the confirmation phrase shown in the Apply dialog, or - for scheduled applies - require a time-bound destructive authorization with an expiry, a reason, and an optional delete cap. Create and revoke authorizations from the profile's detail page.
Flows<>Git tab
A read-only inventory of flows linked to Git repositories, with their sync mode, status, and last sync time. Pull, push, and detach live on each flow's own page - see building flows.
Operations History tab
Every export, import, plan, and apply - YAML and Git alike - is recorded with its scope, transport, status, actor, and duration. Use it to audit who moved configuration and when.
Related
- Instance bootstrap - importing configuration automatically when a fresh instance starts.
- Git integration - configuring the repositories profiles use.