CloudForge Plugin Ecosystem
Overview
CloudForge provides two extensible plugin systems that enable organizations to:
- Application Plugins - Describe application deployment requirements for supported AWS runtimes
- Compliance Framework Plugins - Add custom compliance validators for industry standards
Both systems use Java ServiceLoader for automatic plugin discovery and loading.
Included Applications (33 Applications)
CloudForge includes 33 application specifications across two plugin types: general ApplicationSpec plugins and specialized CmsSpec plugins for PHP-based platforms. Validate each specification against your workload before production use.
CI/CD (3)
- Jenkins - Automation server with OIDC support
- GitLab - Complete DevOps platform with OIDC support
- Drone - Container-native CI/CD
Version Control (1)
- Gitea - Lightweight self-hosted Git service with OIDC support
Monitoring (2)
- Grafana - Observability platform with OIDC support
- Prometheus - Metrics collection and alerting
Analytics (2)
- Metabase - BI and analytics platform
- Apache Superset - Modern data exploration platform
Databases (2)
- PostgreSQL - Relational database
- Redis - In-memory data store
Artifact Registries (2)
- Nexus Repository - Universal artifact manager
- Harbor - Container registry
Secrets Management (1)
- HashiCorp Vault - Secrets and encryption management
Collaboration (1)
- Mattermost - Team collaboration platform
CMS / E-commerce (19 Platforms — cms-service topology)
CMS plugins use the @CmsPlugin annotation and CmsSpec interface, which extends ApplicationSpec with PHP runtime, media storage, CDN, object cache, and cron capabilities. Deploy any of these by setting topology: "cms-service" and applicationId: "<id>".
Content Management (7)
- WordPress (
wordpress) — OIDC, S3 media, Redis, and multisite configuration - WooCommerce (
woocommerce) — WordPress-based e-commerce; inherits WordPress capabilities - Drupal (
drupal) — Enterprise CMS with native OIDC module; S3FS, Redis - Joomla (
joomla) — Flexible CMS; Redis, S3 media - TYPO3 (
typo3) — Enterprise CMS for large organisations - Concrete CMS (
concrete-cms) — Block-based CMS - October CMS (
october-cms) — Laravel-based CMS
E-commerce (5)
- Magento 2 / Adobe Commerce (
magento) — 3-database Redis, S3 media, and PCI DSS-related infrastructure configuration - PrestaShop (
prestashop) — Open-source online store; S3 media, Redis - OpenCart (
opencart) — Lightweight e-commerce - Sylius (
sylius) — Symfony-based e-commerce framework - Bagisto (
bagisto) — Laravel-based headless commerce
Forum / Community (3)
- phpBB (
phpbb) — Classic bulletin board - Flarum (
flarum) — Modern discussion platform - MyBB (
mybb) — Free bulletin board
CRM (1)
- SuiteCRM (
suitecrm) — Open-source CRM
Wiki (1)
- MediaWiki (
mediawiki) — Powers Wikipedia
LMS (1)
- Moodle (
moodle) — Learning management system; FERPA-related requirements remain workload-specific
Social Networking (1)
- UNA / Dolphin (
dolphin-una) — Social platform framework; ALB OIDC
All applications support:
- ✅ Docker/ECS (Fargate) deployment
- ✅ EC2 deployment
- ✅ Automatic infrastructure (VPC, ALB, EFS, monitoring)
- ✅ Security profiles (DEV, STAGING, PRODUCTION)
- ✅ OIDC integration (where supported)
CMS applications additionally support (where declared by the spec):
- ✅ Automatic S3 media bucket + CloudFront CDN wiring
- ✅ Automatic ElastiCache Redis provisioning
- ✅ CMS-specific Redis and DB environment variable injection
- ✅ CloudFront path behaviors (media S3 origin, static cache, admin bypass)
- ✅ System cron registration
- ✅ PHP-FPM + NGINX configuration generation
Included Compliance Frameworks (12 Frameworks)
Always-Load Cross-Framework Validators (5)
These run for ALL deployments:
| Framework | Priority | Purpose |
|---|---|---|
| KeyManagement | -10 | KMS rotation, secrets management, certificates |
| DatabaseSecurity | -5 | RDS/DynamoDB security controls |
| AdvancedMonitoring | -5 | Security Hub, Inspector, Macie integration |
| ThreatProtection | 0 | Malware protection, IDS, file integrity monitoring |
| IncidentResponse | 0 | Disaster recovery, backup, forensics |
Conditional Industry-Specific Frameworks (7)
These run when explicitly enabled via complianceFrameworks:
| Framework | Priority | Standard |
|---|---|---|
| HIPAA | 10 | Healthcare technical safeguards |
| HIPAA-Organizational | 15 | Healthcare administrative safeguards |
| PCI-DSS | 20 | Payment card industry security |
| GDPR | 30 | EU privacy regulation (technical) |
| GDPR-Organizational | 35 | EU privacy regulation (organizational) |
| SOC 2 | 40 | Service organization controls |
| ISO 27001 | 50 | Information security management |
Framework plugins can provide:
- Infrastructure validation
- Runtime-specific checks (Docker/ECS versus EC2)
- Security-profile checks (PRODUCTION versus STAGING)
- Findings for compliance reports
Creating Custom Plugins
Application Plugin Example
Deploy SonarQube as a custom application:
package com.example.applications;
import com.cloudforge.core.interfaces.ApplicationSpec;
import com.cloudforge.core.interfaces.Ec2Context;
import com.cloudforge.core.interfaces.UserDataBuilder;
public class SonarQubeApplicationSpec implements ApplicationSpec {
@Override
public String applicationId() {
return "sonarqube";
}
@Override
public String defaultContainerImage() {
return "sonarqube:lts-community";
}
@Override
public int applicationPort() {
return 9000;
}
@Override
public String healthCheckPath() {
return "/api/system/health";
}
// ... implement other required methods
}
Register: META-INF/services/com.cloudforge.core.interfaces.ApplicationSpec
Compliance Plugin Example
Add NIST 800-53 compliance validation:
package com.example.compliance;
import com.cloudforge.core.annotation.ComplianceFramework;
import com.cloudforge.core.interfaces.FrameworkRules;
import com.cloudforgeci.api.core.SystemContext;
@ComplianceFramework(
value = "NIST-800-53",
priority = 25,
displayName = "NIST 800-53 Rev 5",
description = "Federal information system security controls"
)
public class Nist80053Rules implements FrameworkRules<SystemContext> {
@Override
public void install(SystemContext ctx) {
ctx.getNode().addValidation(() -> {
List<ComplianceRule> rules = new ArrayList<>();
// AC-6: Least Privilege
rules.addAll(validateAccessControl(ctx));
// AU-2: Event Logging
rules.addAll(validateAuditLogging(ctx));
return rules;
});
}
}
Register: META-INF/services/com.cloudforge.core.interfaces.FrameworkRules
Documentation
- Plugin System Overview: PLUGIN-SYSTEM.md
- Application Plugin Guide: APPLICATION-PLUGIN-GUIDE.md
- Compliance Plugin Guide: COMPLIANCE-PLUGIN-GUIDE.md
Use Cases
For Enterprises
- Standardize deployments across all teams
- Enforce compliance at infrastructure-as-code level
- Distribute best practices as reusable plugins
- Reduce duplicated infrastructure code
For ISVs
- Package your application as a CloudForge plugin
- Reuse infrastructure patterns
- Provide an AWS deployment configuration for customers
- Support multiple deployment modes (container/VM)
For Compliance Teams
- Codify internal policies as validators
- Prevent non-compliant infrastructure from deploying
- Generate compliance reports automatically
- Track control effectiveness over time
Plugin Discovery
CloudForge discovers plugins automatically using Java ServiceLoader:
your-application.jar
├── META-INF/
│ └── services/
│ ├── com.cloudforge.core.interfaces.ApplicationSpec
│ └── com.cloudforge.core.interfaces.FrameworkRules
├── com/example/
│ ├── MyApplicationSpec.class
│ └── MyComplianceRules.class
- Add your JAR to the classpath
- CloudForge discovers it automatically
- Use it like any built-in application/framework
Included Plugin Counts
| Category | Built-in | Priorities | Always-Load |
|---|---|---|---|
| Applications | 33 | N/A | N/A |
| Compliance Frameworks | 12 | -10 to 50 | 5 frameworks |
Application Coverage
- CI/CD: 3 applications
- Databases: 2 applications
- Monitoring: 2 applications
- Analytics: 2 applications
- Artifact Registries: 2 applications
- Collaboration: 1 application
- Secrets Management: 1 application
- Version Control: 1 application
- CMS (cms-service topology): 19 platforms
- Content Management: 7 (WordPress, WooCommerce, Drupal, Joomla, TYPO3, Concrete CMS, October CMS)
- E-commerce: 5 (Magento, PrestaShop, OpenCart, Sylius, Bagisto)
- Forum: 3 (phpBB, Flarum, MyBB)
- CRM: 1 (SuiteCRM)
- Wiki: 1 (MediaWiki)
- LMS: 1 (Moodle)
- Social: 1 (UNA/Dolphin)
Compliance Coverage
- Healthcare: HIPAA (2 frameworks)
- Finance: PCI-DSS (1 framework)
- Privacy: GDPR (2 frameworks)
- Enterprise: SOC 2, ISO 27001 (2 frameworks)
- Cross-Framework: 5 always-load frameworks
Community Plugins
cloudforge-sample
cloudforge-sample is a reference plugin repository demonstrating both plugin types:
| Plugin | Type | ID | Notes |
|---|---|---|---|
CraftCmsApplicationSpec | CmsSpec + DatabaseSpec | craft-cms | Craft CMS on Fargate; non-root document root (web/), queue cron, ALB-OIDC |
CustomSecurityPolicyRules | FrameworkRules | — | Example custom compliance validator |
OpenSourceSecurityPolicyRules | FrameworkRules | — | Open-source license compliance checks |
Use cloudforge-sample as the starting point for building your own CMS plugin. See CMS Deployment Guide for the full Craft CMS deployment reference.
Contributing
We welcome community contributions!
- Report issues: https://github.com/cloudforgeci/cfc-core/issues
- Submit plugins: https://github.com/cloudforgeci/cfc-core/pulls
- Share examples: https://github.com/cloudforgeci/cfc-core/tree/main/examples
Planned Plugin Registry
The roadmap includes a central plugin registry where developers could:
- ✅ Publish application and compliance plugins
- ✅ Browse community-contributed plugins
- ✅ Review and rate plugins
- ✅ Track plugin versions and compatibility
Quick Start
Deploy a Built-in Application
# Create a Jenkins deployment
cdk deploy -c applicationId=jenkins -c runtimeType=FARGATE
# Create a GitLab deployment with OIDC
cdk deploy -c applicationId=gitlab -c runtimeType=EC2 -c authMode=application-oidc
Enable Compliance Frameworks
{
"context": {
"complianceFrameworks": "HIPAA,PCI-DSS",
"securityProfile": "PRODUCTION"
}
}
Add a Custom Plugin
# Build your plugin
mvn clean package
# Add to your project
cp target/my-plugin-1.0.0.jar lib/
# Deploy (plugin discovered automatically)
cdk deploy