Skip to content

Developer Commands ​

Hegemony uses Task as the canonical command runner: if CI or pre-commit runs a check, it is runnable through a task listed here. Descriptions come from the Taskfiles' desc: fields.

Root tasks ​

CommandDescription
task check:file-permissionsVerify source file permissions (canonical entrypoint for pre-commit/CI)
task py:formatFormat Python (ruff)
task py:lintLint Python (ruff)
task py:lint:fixLint+fix Python (ruff)
task py:typecheckCheck Python types (ty)
task py:typecheck:strictCheck Python types strictly (fail on warnings)
task py:allPython format + lint + typecheck (ty)
task ui:installInstall UI dependencies (npm ci)
task ui:formatFormat UI (oxfmt)
task ui:format:checkCheck UI formatting (oxfmt)
task ui:lintLint UI (oxlint)
task ui:lint:fixLint+fix UI (oxlint)
task ui:lint:cssLint CSS (stylelint)
task ui:lint:css:fixLint+fix CSS (stylelint)
task ui:lint:tailwindLint Tailwind classes (eslint-plugin-tailwindcss)
task md:lintLint Markdown (markdownlint-cli2)
task md:lint:fixLint+fix Markdown (markdownlint-cli2)
task docs:check-linksVerify local doc links and docs/*.md references from code resolve
task docs:screenshotsRegenerate documentation screenshots (docs/assets/screenshots/) from the docs-shots manifest
task docs:generateRegenerate the docs index, docs/reference/ pages, and the UI help-content module
task docs:verify-syncVerify generated reference docs are in sync (fails if out of date)
task docs:verify-claimsVerify factual claims in Markdown docs against sources of truth
task docs:fixtures:refreshRefresh the step-handler catalog fixture from the installed plugin wheels
task docs:verify-fixturesVerify the step-handler fixture matches the installed plugin wheels
task docs:allRun every documentation check (lint, links, sync, claims, fixtures, meta-tests)
task ui:typecheckTypecheck UI (tsc)
task ui:e2e:installInstall Playwright browsers using the locked UI dependency
task ui:e2e:install:depsInstall Playwright Chromium browser and Linux OS dependencies (may prompt for sudo)
task ui:e2eRun all UI E2E tests
task ui:e2e:smokeRun UI E2E smoke tests only (@smoke, chromium)
task ui:e2e:coverageRun UI E2E tests with V8 coverage and generate reports
task ui:allUI format check + lint + CSS lint + Tailwind lint + typecheck + api-headers + contract-types + page-docs
task ui:check:api-headersCheck UI API client includes Authorization headers
task ui:check:contract-typesCheck contract.ts has no manually defined types (must re-export from generated api-types)
task ui:check:page-docsCheck every page component under apps/ui/src/pages carries a doc block
task ui:regenerate-types-from-apiGenerate TypeScript types from API OpenAPI spec
task ui:verifyVerify UI (lint/typecheck + build + Playwright smoke E2E)
task precommitRun pre-commit on all files
task precommit:hookRun a specific pre-commit hook by id (usage: task precommit:hook -- <hook-id>)
task commit:lintLint the last commit message with commitlint (mirrors CI commit-lint job)
task testRun Python tests in parallel (pytest-xdist, loadfile)
task test:serialRun Python tests serially (debug-friendly)
task test:authRun auth tests (route coverage, role matrix, security audit)
task test:auth:route-coverageVerify all API routes require auth
task test:auditRun audit-log tests (vocabulary, coverage registry, emitter reachability, write path)
task test:audit:coverageVerify every mutating route carries an audit decision and reaches an audit emitter
task test:schemaRun schema alignment tests only
task test:covRun Python tests with coverage in parallel (pytest-xdist, loadfile)
task test:cron-compatTest cron expression compatibility between cronsim (backend) and cronstrue (frontend)
task test:cron-compat:strictTest cron compatibility (fail on validation mismatches)
task py:vultureFind dead Python code (vulture)
task api:openapi:lintLint OpenAPI schema (Spectral)
task docker:lintLint Dockerfiles (hadolint via Docker)
task py:licensesCheck Python dependency licenses
task py:licenses:checkVerify Python licenses against allowlist
task ui:licensesCheck UI dependency licenses
task ui:licenses:checkVerify UI licenses against allowlist
task licenses:imagesVerify every container image in deploy/ is licence-reviewed
task licenses:pluginsVerify the pinned plugin repositories' own licences and run their image licence gates
task licenses:noticesRegenerate the per-package third-party attribution list
task licenses:pythonRefresh the declared licence of every PyPI distribution uv.lock pins
task licenses:python:verifyVerify the licence map still covers every distribution uv.lock pins
task sbom:generateRegenerate the CycloneDX bills of materials and licence summary under sbom/
task sbom:verifyVerify the committed bills of materials and licence summary are in sync
task sbom:refresh-spdxRefresh the vendored SPDX licence identifiers from the CycloneDX schema
task licenses:allVerify all dependency licenses
task reuse:lintVerify REUSE 3.3 (SPDX) compliance for source files
task reuse:annotateAdd SPDX header to file(s). Usage: task reuse:annotate -- path/to/file [more...]
task py:securitySecurity scan Python (bandit)
task py:auditAudit Python dependencies for vulnerabilities
task ui:auditAudit UI dependencies for high/critical vulnerabilities
task ui:audit:fixFix UI audit vulnerabilities and normalize lockfile
task security:allRun all security checks (bandit + pip-audit + npm audit + trivy)
task security:trivy:iacScan IaC (Dockerfiles, compose) for misconfigurations (trivy via Docker)
task security:trivy:imagesScan Docker images for vulnerabilities (trivy via Docker, requires built images)
task security:semgrepRun Semgrep security analysis (via Docker)
task api:export-openapiExport OpenAPI spec to deterministic JSON file (requires API container running on port 8000)
task api:export-openapi-localExport OpenAPI spec without running containers (uses uv, no DB/Temporal needed)
task api:regenerateExport OpenAPI spec locally, lint, and regenerate TypeScript types (no containers needed)
task api:verify-openapi-syncVerify openapi.json is in sync with API code (fails if out of date)
task api:verify-types-syncVerify generated TypeScript API types/defaults are in sync (fails if out of date)
task db:migrateRun database migrations (alembic upgrade head)
task db:migrate:prodRun database migrations in prod compose
task db:revisionCreate a new migration revision
task db:currentShow current migration revision
task db:historyShow migration history
task db:headsShow current migration head(s)
task db:downgradeDowngrade one migration
task lintRun all linters + typechecks (Python + UI + Markdown)
task fmtRun all formatters (Python + UI)
task checkFull local check (pre-commit + pytest)
task smoke:apiSmoke test API /health (with retry)
task smoke:uiSmoke test UI is reachable (with retry)
task smoke:otelSmoke test OTel collector health endpoint (with retry)
task dev:upRebuild dev stack and run smoke tests
task dev:up:nocacheRebuild dev stack and run smoke tests (no cache)
task dev:downStop dev stack
task prod:upStart production stack (shorthand for compose:prod:up)
task prod:downStop production stack (shorthand for compose:prod:down)
task prod:psShow production stack status
task prod:logsFollow production logs
task vault:upForward to hegemony-demo-data: compose:vault:up
task vault:downForward to hegemony-demo-data: compose:vault:down
task vault:logsForward to hegemony-demo-data: compose:vault:logs
task vault:statusForward to hegemony-demo-data: compose:vault:status
task vault:resetForward to hegemony-demo-data: compose:vault:reset
task release:cutCreate a release branch from develop (usage: task release:cut -- X.Y.Z)
task release:finishBack-merge main into develop after a release
task release:verify-version-syncVerify release/runtime/OpenAPI/UI version metadata are in sync
task release:manifest:checkVerify the plugin pins, sibling checkouts and pyproject version floors are consistent (offline)
task release:manifest:buildBuild hegemony-release.json from the pins and the plugin release tags (strict; needs the plugin repos)
task release:floors:syncMove the hegemony-* version floors in pyproject.toml to the pinned plugin versions and refresh uv.lock

Compose stack tasks ​

Compose tasks live in deploy/compose/Taskfile.yml and are invoked through the compose: namespace.

CommandDescription
task compose:dev:upRun migrations and start dev stack. Use SERVICES=core|auth,s3,otel,https,openbao-internal
task compose:dev:downStop dev stack
task compose:dev:psShow dev stack status
task compose:dev:logsFollow dev logs (all or specific service)
task compose:dev:buildBuild dev images
task compose:dev:rebuildRebuild dev images and restart
task compose:dev:rebuild:nocacheRebuild dev images (no cache) and restart
task compose:dev:restartRestart dev services
task compose:dev:execExecute command in a dev container
task compose:dev:resetDANGER: Stop dev stack and remove volumes (wipes DBs; a bind-mounted HEGEMONY_S3_DATA_HOST_DIR is left in place)
task compose:dev:configShow resolved dev compose config (useful for debugging overlays)
task compose:prod:upRun migrations and start prod stack. Use SERVICES=core|auth,s3,otel,https,openbao-internal|...,prod-local
task compose:prod:downStop prod stack
task compose:prod:psShow prod stack status
task compose:prod:logsFollow prod logs (all or specific service)
task compose:prod:buildBuild prod images (requires prod-local overlay)
task compose:prod:rebuildRebuild prod images from source and restart
task compose:prod:execExecute a command in a prod container (e.g. -- temporal tctl ... )
task compose:prod:restartRestart prod services
task compose:prod:configShow resolved prod compose config (useful for debugging overlays)
task compose:prod:resetDANGER: Stop prod stack and remove volumes (wipes DBs; a bind-mounted HEGEMONY_S3_DATA_HOST_DIR is left in place)
task compose:objectstoreBackup/restore the bundled object store + related DB metadata (xattr-preserving). Usage: ACTION=backup|restore ENV=dev|prod DB_SCOPE=storage|full BACKUP=/path/file.tar.gz CONFIRM=restore, plus the SERVICES, BUILD and EXTRA_FILES the stack runs with
task compose:dev:rebuild:apiRebuild API image and restart it
task compose:dev:rebuild:uiRebuild UI image and restart it
task compose:dev:rebuild:workerRebuild worker image and restart it
task compose:dev:rebuild:schedulerRebuild scheduler image and restart it
task compose:dev:ui:cleanClean UI node_modules volume and rebuild
task compose:dev:auth:disableDisable authentication (modify .env.dev and restart API)
task compose:dev:auth:enableEnable authentication (modify .env.dev and restart API)
task compose:dev:auth:statusShow current authentication status from running API container
task compose:demo:plugins:fetchForward to hegemony-demo-data: compose:demo:plugins:fetch
task compose:demo:plugins:pinForward to hegemony-demo-data: compose:demo:plugins:pin
task compose:demo:plugins:buildForward to hegemony-demo-data: compose:demo:plugins:build
task compose:demo:upForward to hegemony-demo-data: compose:demo:up
task compose:demo:local:upForward to hegemony-demo-data: compose:demo:local:up
task compose:demo:execForward to hegemony-demo-data: compose:demo:exec
task compose:registry:ui:devOpen the dev platform registry console on 127.0.0.1 (Ctrl-C closes it)
task compose:registry:ui:prodOpen the prod platform registry console on 127.0.0.1 (Ctrl-C closes it)
task compose:objectstore:ui:devOpen the dev object store browser on 127.0.0.1 (Ctrl-C closes it)
task compose:objectstore:ui:prodOpen the prod object store browser on 127.0.0.1 (Ctrl-C closes it)
task compose:objectstore:ui:demoForward to hegemony-demo-data: compose:objectstore:ui:demo
task compose:openbao:ui:devOpen the dev OpenBao UI on 127.0.0.1 (needs a token; Ctrl-C closes it)
task compose:openbao:ui:demoForward to hegemony-demo-data: compose:openbao:ui:demo
task compose:openbao:token:devPrint a short-lived OpenBao UI token for the dev stack (hegemony-api policy)
task compose:openbao:token:demoForward to hegemony-demo-data: compose:openbao:token:demo
task compose:temporal:ui:devOpen the dev Temporal console on 127.0.0.1 (unauthenticated, every org; Ctrl-C closes it)
task compose:temporal:ui:prodOpen the prod Temporal console on 127.0.0.1 (unauthenticated, every org; Ctrl-C closes it)
task compose:temporal:ui:demoForward to hegemony-demo-data: compose:temporal:ui:demo
task compose:demo:downForward to hegemony-demo-data: compose:demo:down
task compose:demo:resetForward to hegemony-demo-data: compose:demo:reset
task compose:demo:logsForward to hegemony-demo-data: compose:demo:logs
task compose:demo:psForward to hegemony-demo-data: compose:demo:ps
task compose:vault:upForward to hegemony-demo-data: compose:vault:up
task compose:vault:downForward to hegemony-demo-data: compose:vault:down
task compose:vault:logsForward to hegemony-demo-data: compose:vault:logs
task compose:vault:statusForward to hegemony-demo-data: compose:vault:status
task compose:vault:resetForward to hegemony-demo-data: compose:vault:reset

Released as open source under the AGPL-3.0-or-later license. Development is sponsored by Rexonix s.r.o.. Contact — [email protected].