<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Flow on Jahvon Dockery</title>
    <link>https://jahvon.dev/tags/flow/</link>
    <description>Recent content in Flow on Jahvon Dockery</description>
    <image>
      <title>Jahvon Dockery</title>
      <url>https://jahvon.dev/images/og-default.png</url>
      <link>https://jahvon.dev/images/og-default.png</link>
    </image>
    <generator>Hugo -- 0.153.4</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 06 May 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://jahvon.dev/tags/flow/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Organization and References</title>
      <link>https://jahvon.dev/architecture/flow/organization/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://jahvon.dev/architecture/flow/organization/</guid>
      <description>Workspaces, namespaces, and the URI-like reference system. How flow finds the right workspace, and why registration is an optimization rather than a requirement.</description>
      <content:encoded><![CDATA[<h2 id="organizational-model">Organizational Model</h2>
<p>Flow&rsquo;s organizational system creates a hierarchical structure that scales from individual projects to complex multi-project ecosystems. The system balances discoverability with isolation, enabling both focused work within projects and cross-project composition.</p>
<h3 id="hierarchy-structure">Hierarchy Structure</h3>
<p><strong>Workspaces</strong> serve as the top-level organizational unit, typically mapping to Git repositories or major project boundaries. Each workspace contains its own configuration, executable discovery rules, and isolated namespace hierarchy.</p>
<p><strong>Namespaces</strong> provide logical grouping within workspaces, similar to packages in programming languages. They enable organizational flexibility. A single workspace might have namespaces for <code>frontend</code>, <code>backend</code>, <code>deploy</code>, or <code>tools</code>. Namespaces are optional but recommended for workspaces with many executables.</p>
<p><strong>Executables</strong> are the atomic units of automation, uniquely identified within their namespace by their name and verb combination. This allows multiple executables with the same name but different purposes (<code>build api</code> vs <code>deploy api</code>).</p>
<h3 id="reference-system">Reference System</h3>
<p>Flow uses a URI-like reference system for executable identification:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-fallback" data-lang="fallback"><span class="line"><span class="cl">workspace/namespace:name
</span></span><span class="line"><span class="cl">    │         │       │
</span></span><span class="line"><span class="cl">    │         │       └─ Executable name (Optional but unique within verb group + namespace)
</span></span><span class="line"><span class="cl">    │         └───────── Optional namespace grouping
</span></span><span class="line"><span class="cl">    └─────────────────── Workspace boundary
</span></span></code></pre></div><p><strong>Reference Resolution Rules:</strong></p>
<ul>
<li><code>my-task</code> → Current workspace, current namespace, name=&ldquo;my-task&rdquo;</li>
<li><code>backend:api</code> → Current workspace, namespace=&ldquo;backend&rdquo;, name=&ldquo;api&rdquo;</li>
<li><code>project/deploy:prod</code> → workspace=&ldquo;project&rdquo;, namespace=&ldquo;deploy&rdquo;, name=&ldquo;prod&rdquo;</li>
<li><code>project/</code> → workspace=&ldquo;project&rdquo;, no namespace, nameless executable</li>
</ul>
<p><strong>Reference Format Trade-offs:</strong></p>
<ul>
<li><strong>Chosen:</strong> Slightly more verbose for simple cases</li>
<li><strong>Avoided:</strong> Naming collisions, poor tooling support, brittle file/directory coupling</li>
</ul>
<h3 id="verb-system">Verb System</h3>
<p>Verbs describe the action an executable performs while enabling natural language interaction. Verbs can be organized into semantic groups with aliases:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="c"># Executable definition</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="nt">verb</span><span class="p">:</span><span class="w"> </span><span class="l">build</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="nt">verbAliases</span><span class="p">:</span><span class="w"> </span><span class="p">[</span><span class="l">compile, package, bundle]</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="nt">name</span><span class="p">:</span><span class="w"> </span><span class="l">my-app</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="c"># With the above, all of these commands are equivalent:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="l">flow build my-app</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="l">flow compile my-app</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="l">flow package my-app</span><span class="w">
</span></span></span></code></pre></div><p>This system allows developers to use whichever verb feels most natural while maintaining executable uniqueness through the <code>[verb group + name]</code> constraint.</p>
<p>I&rsquo;ve significantly reduced the number of default verb groups to focus on the most common actions with the most semantic clarity. See the <a href="https://flowexec.io/types/flowfile#executableverb">flow documentation</a> for the latest default list.</p>
<p><img src="https://jahvon.dev/images/flow-ws-tree.png" srcset="https://jahvon.dev/images/flow-ws-tree_hu_52af242d3fa7b2b1.png 691w, https://jahvon.dev/images/flow-ws-tree.png 1383w" sizes="(min-width: 768px) 720px, 100vw" width="1383" height="425"
     alt="Flow Workspace Tree Example"
     loading="lazy" decoding="async">
</p>
<h3 id="context-awareness">Context Awareness</h3>
<p>Flow maintains context awareness to reduce typing and improve ergonomics:</p>
<p><strong>Current Workspace Resolution:</strong></p>
<ul>
<li><strong>Dynamic Mode</strong>: Automatically detects workspace based on current directory</li>
<li><strong>Fixed Mode</strong>: Uses explicitly set workspace regardless of location</li>
</ul>
<p><strong>Namespace Scoping:</strong></p>
<ul>
<li>Commands inherit current namespace setting</li>
<li>Explicit namespace references override current context</li>
</ul>
<p><em>Note to self: Explicit command overrides of workspace / namespace may become an emerging need with the Desktop UI and MCP server usage.</em></p>
<h3 id="cross-project-composition">Cross-Project Composition</h3>
<p>The reference system enables powerful cross-project workflows:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">executables</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span>- <span class="nt">verb</span><span class="p">:</span><span class="w"> </span><span class="l">deploy</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">name</span><span class="p">:</span><span class="w"> </span><span class="l">full-stack</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">serial</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">execs</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span>- <span class="nt">ref</span><span class="p">:</span><span class="w"> </span><span class="s2">&#34;build frontend/&#34;</span><span class="w">     </span><span class="c"># Different workspace</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span>- <span class="nt">ref</span><span class="p">:</span><span class="w"> </span><span class="s2">&#34;build backend:api&#34;</span><span class="w">   </span><span class="c"># Different namespace</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span>- <span class="nt">ref</span><span class="p">:</span><span class="w"> </span><span class="s2">&#34;deploy&#34;</span><span class="w">              </span><span class="c"># Current context</span><span class="w">
</span></span></span></code></pre></div><h3 id="finding-the-workspace">Finding the Workspace</h3>
<p>Registration is an optimization, not a prerequisite. In dynamic mode flow finds its workspace by
walking up from the current directory to the nearest <code>flow.yaml</code>, the same way <code>make</code> and
<code>bazel</code> find their root. Clone a repo and its executables work immediately.</p>
<p>An unregistered workspace is named after its directory, runs normally, and is never written
anywhere. Not to the config, not to the shared executable cache. What you give up is the ability
to <code>flow workspace switch</code> to it, and other workspaces cannot reference its executables by name.</p>
<p>Resolution runs in this order:</p>
<ol>
<li><code>--workspace</code> or <code>$FLOW_WORKSPACE</code>, which accepts a registered name or a path</li>
<li>The nearest <code>flow.yaml</code> at or above the working directory (dynamic mode only)</li>
<li>A registered workspace whose directory contains the working directory</li>
<li>Whatever <code>flow workspace switch</code> last set</li>
</ol>
<p>A directory containing its own <code>flow.yaml</code> is a boundary. The closest one wins, and a parent
workspace does not scan into it. Discovery also walks past <code>vendor/</code>, <code>node_modules/</code>,
<code>third_party/</code>, <code>external/</code>, <code>.git/</code> and <code>.claude/</code>, because a <code>flow.yaml</code> in there belongs to
that copy rather than to your project. The honest caveat is that there is no stopping point above
your home directory, so a <code>flow.yaml</code> in <code>~</code> makes your entire home directory a workspace.</p>
<h3 id="git-workspaces">Git Workspaces</h3>
<p>A workspace can be a git remote rather than a local path. Clones are cached under
<code>~/.cache/flow/git-workspaces/</code>, following Go module conventions, and can be pinned to a branch
or tag. <code>flow sync --git</code> refreshes them. This is what lets a workspace of shared team
executables be consumed the same way a dependency is.</p>
]]></content:encoded>
    </item>
    <item>
      <title>The Execution Engine</title>
      <link>https://jahvon.dev/architecture/flow/execution/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://jahvon.dev/architecture/flow/execution/</guid>
      <description>The five executable types, how parameters and arguments reach a process, running a step inside a container, and where state lives between steps.</description>
      <content:encoded><![CDATA[<h2 id="execution-engine">Execution Engine</h2>
<p>The execution engine is the core of Flow, responsible for running executables defined in YAML files.</p>
<h3 id="runner-interface">Runner Interface</h3>
<p>The execution system uses a runner interface pattern where each executable type implements:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="kd">type</span><span class="w"> </span><span class="nx">Runner</span><span class="w"> </span><span class="kd">interface</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nf">Name</span><span class="p">()</span><span class="w"> </span><span class="kt">string</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nf">Exec</span><span class="p">(</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">		</span><span class="nx">ctx</span><span class="w"> </span><span class="nx">context</span><span class="p">.</span><span class="nx">Context</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">		</span><span class="nx">exec</span><span class="w"> </span><span class="o">*</span><span class="nx">executable</span><span class="p">.</span><span class="nx">Executable</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">		</span><span class="nx">eng</span><span class="w"> </span><span class="nx">engine</span><span class="p">.</span><span class="nx">Engine</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">		</span><span class="nx">inputEnv</span><span class="w"> </span><span class="kd">map</span><span class="p">[</span><span class="kt">string</span><span class="p">]</span><span class="kt">string</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">		</span><span class="nx">inputArgs</span><span class="w"> </span><span class="p">[]</span><span class="kt">string</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="p">)</span><span class="w"> </span><span class="kt">error</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nf">IsCompatible</span><span class="p">(</span><span class="nx">executable</span><span class="w"> </span><span class="o">*</span><span class="nx">executable</span><span class="p">.</span><span class="nx">Executable</span><span class="p">)</span><span class="w"> </span><span class="kt">bool</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><p>Current runner implementations include:</p>
<ul>
<li><strong>Exec Runner</strong>: Shell command execution</li>
<li><strong>Request Runner</strong>: HTTP request handling</li>
<li><strong>Launch Runner</strong>: Application/URI launching</li>
<li><strong>Render Runner</strong>: Markdown rendering</li>
<li><strong>Serial Runner</strong>: Sequential execution of multiple executables</li>
<li><strong>Parallel Runner</strong>: Concurrent execution with resource limits</li>
</ul>
<h3 id="workflows-serial-and-parallel">Workflows (Serial and Parallel)</h3>
<p>The serial and parallel runners allow for composing complex workflows from simpler executables. Steps are defined with a <code>RefConfig</code> that supports inline commands or references to other executables:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="kd">type</span><span class="w"> </span><span class="nx">SerialRefConfig</span><span class="w"> </span><span class="kd">struct</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nx">Cmd</span><span class="w"> </span><span class="kt">string</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nx">Ref</span><span class="w"> </span><span class="nx">Ref</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nx">Args</span><span class="w"> </span><span class="p">[]</span><span class="kt">string</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nx">If</span><span class="w"> </span><span class="kt">string</span><span class="w">          </span><span class="c1">// Expression to conditionally skip the step</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nx">Retries</span><span class="w"> </span><span class="kt">int</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nx">ReviewRequired</span><span class="w"> </span><span class="kt">bool</span><span class="w"> </span><span class="c1">// Prompts the user before continuing</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><p>Execution and result handling is managed by the internal <code>engine.Engine</code> interface. The <a href="https://github.com/flowexec/flow/tree/main/internal/runner/engine">current implementation</a> includes retry logic, error handling, and result aggregation.</p>
<h3 id="execution-environment-and-state">Execution Environment and State</h3>
<p><strong>Environment Inheritance Hierarchy:</strong></p>
<p>Environment variables are provided to the running executable in the following order:</p>
<ol>
<li>System environment variables (lowest priority)</li>
<li>Dotenv files (<code>.env</code>, workspace-specific)</li>
<li>Flow context variables (<code>FLOW_WORKSPACE_PATH</code>, <code>FLOW_NAMESPACE</code>, etc.)</li>
<li>Executable <code>params</code> (secrets, prompts, static values)</li>
<li>Executable <code>args</code> (command-line arguments)</li>
<li>CLI <code>--param</code> overrides (highest priority)</li>
</ol>
<p><strong>State Management</strong></p>
<p>There are two ways state can be managed when composing workflows:</p>
<ul>
<li>Cache Store: Key-value persistence across executions with scoped lifetime. Values set outside executables persist globally; values set within executables are cleaned up on completion. Uses <a href="https://go.etcd.io/bbolt">bbolt</a> for cross-process storage.</li>
<li>Temporary Directories: Isolated scratch space (<code>f:tmp</code>) with automatic cleanup and shared access across serial/parallel workflow steps.</li>
</ul>
<p><strong>File System Access</strong></p>
<p>By default, the working directory is the directory containing the flow file that defines the executable. This can be configured using special prefixes: <code>//</code> (workspace root), <code>~/</code> (user home), <code>f:tmp</code> (temporary).</p>
<p>There is no automatic sandboxing. Executables inherit full user permissions. <em>Flow assumes users understand their workflows&rsquo; scope and potential for system modification, prioritizing automation flexibility over execution isolation.</em> Containerized execution is a planned future improvement.</p>
<p>See the <a href="https://flowexec.io/guides/executables">executable guide</a> and <a href="https://flowexec.io/guides/advanced#managing-state">state management</a> for usage details.</p>
<h2 id="performance-and-caching">Performance and Caching</h2>
<p>Flow uses eager discovery with multi-level caching to keep response times fast. Workspace scanning runs up front and is cached to disk, with in-memory caching layered on top for quick lookups. The cache is invalidated and refreshed via <code>flow sync</code> or the <code>--sync</code> flag.</p>
<p><em>Note to self: Some performance testing needed to validate sub-100ms discovery targets across large workspace trees.</em></p>
<p>For implementation details, see the <a href="https://deepwiki.com/flowexec/flow">DeepWiki reference</a>.</p>
<h2 id="getting-values-into-a-process">Getting Values Into a Process</h2>
<p>Everything reaches an executable as an environment variable. There are four sources:</p>
<table>
  <thead>
      <tr>
          <th>Source</th>
          <th>What it does</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>secretRef</code></td>
          <td>Reads from the vault, including <code>vault/name</code> to cross vaults</td>
      </tr>
      <tr>
          <td><code>prompt</code></td>
          <td>Asks interactively at run time</td>
      </tr>
      <tr>
          <td><code>text</code></td>
          <td>A static value written into the definition</td>
      </tr>
      <tr>
          <td><code>envFile</code></td>
          <td>A <code>key=value</code> file</td>
      </tr>
  </tbody>
</table>
<p>Each can write to <code>envKey</code> or, when something needs a real file on disk, to <code>outputFile</code>, which
is cleaned up after the run.</p>
<p>Arguments are separate from parameters and come from the command line, either positionally
(<code>pos: 1</code>) or as flags (<code>flag: name</code>), with a type and an optional default:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">flow build container -- v1.2.3 --publish<span class="o">=</span><span class="nb">true</span>
</span></span></code></pre></div><p>Resolution runs highest to lowest: a <code>--param</code> override, then the executable&rsquo;s <code>params</code>, then its
<code>args</code>, then the surrounding shell environment. Parent values propagate into children in serial
and parallel workflows.</p>
<p>Paths get their own small vocabulary, which keeps definitions portable: <code>//</code> is the workspace
root, <code>~/</code> is home, <code>./</code> is relative to the flowfile, <code>$VAR</code> expands from the environment, and
<code>f:tmp</code> is a temp directory created once per run and cleaned up after.</p>
<h2 id="containers">Containers</h2>
<p>A step can declare an image and run there instead of on the host:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">exec</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">cmd</span><span class="p">:</span><span class="w"> </span><span class="l">pytest -q</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">container</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">image</span><span class="p">:</span><span class="w"> </span><span class="l">python:3.13-alpine</span><span class="w">
</span></span></span></code></pre></div><p>The runtime is Docker or Podman, auto-detected unless pinned. The workspace mounts at
<code>/workspace</code> by default, additional volumes use the same path prefixes as everything else, and
the <code>FLOW_*</code> variables come along automatically. Secrets go in through a temporary
<code>--env-file</code> rather than the command line, so they never appear in the container&rsquo;s argv.</p>
<h2 id="conditions-and-state">Conditions and State</h2>
<p>Steps can be skipped with an <code>if</code> expression evaluated against <code>os</code>, <code>arch</code>, <code>env</code>, <code>store</code>, and
a <code>ctx</code> object carrying the current workspace, namespace and flowfile paths. Conditions are the
one place where a <code>$(&quot;command&quot;)</code> shell escape is available.</p>
<p>The <code>store</code> is a small key-value cache with two lifetimes, and the distinction matters more than
it looks:</p>
<ul>
<li><strong>Global</strong>, set outside a run with <code>flow cache set</code>, persists until cleared.</li>
<li><strong>Execution</strong>, set from inside an executable, is cleared automatically when the parent
finishes. A serial workflow can pass state between its own steps without leaking it.</li>
</ul>
<p>Two more things exist at the step level because workflows meet reality: <code>retries: N</code>, and
<code>reviewRequired: true</code>, which pauses for a human before continuing.</p>
]]></content:encoded>
    </item>
    <item>
      <title>Secrets and the Vault</title>
      <link>https://jahvon.dev/architecture/flow/secrets/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://jahvon.dev/architecture/flow/secrets/</guid>
      <description>Five vault backends, how secrets reach a process without touching the command line, and why external vaults store links rather than copies.</description>
      <content:encoded><![CDATA[<h2 id="vault-system">Vault System</h2>
<p>The vault system provides secure storage, management, and retrieval of secrets across workspaces and executables. It extends the executable environment with multiple encryption backends.</p>
<p><strong>Implementation</strong>: <a href="https://github.com/flowexec/vault">github.com/flowexec/vault</a></p>
<h3 id="provider-architecture">Provider Architecture</h3>
<p>The vault system supports multiple storage backends through a common <code>Provider</code> interface:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="kd">type</span><span class="w"> </span><span class="nx">Provider</span><span class="w"> </span><span class="kd">interface</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nf">ID</span><span class="p">()</span><span class="w"> </span><span class="kt">string</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nf">GetSecret</span><span class="p">(</span><span class="nx">key</span><span class="w"> </span><span class="kt">string</span><span class="p">)</span><span class="w"> </span><span class="p">(</span><span class="nx">Secret</span><span class="p">,</span><span class="w"> </span><span class="kt">error</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nf">SetSecret</span><span class="p">(</span><span class="nx">key</span><span class="w"> </span><span class="kt">string</span><span class="p">,</span><span class="w"> </span><span class="nx">value</span><span class="w"> </span><span class="nx">Secret</span><span class="p">)</span><span class="w"> </span><span class="kt">error</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nf">DeleteSecret</span><span class="p">(</span><span class="nx">key</span><span class="w"> </span><span class="kt">string</span><span class="p">)</span><span class="w"> </span><span class="kt">error</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nf">ListSecrets</span><span class="p">()</span><span class="w"> </span><span class="p">([]</span><span class="kt">string</span><span class="p">,</span><span class="w"> </span><span class="kt">error</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nf">HasSecret</span><span class="p">(</span><span class="nx">key</span><span class="w"> </span><span class="kt">string</span><span class="p">)</span><span class="w"> </span><span class="p">(</span><span class="kt">bool</span><span class="p">,</span><span class="w"> </span><span class="kt">error</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nf">Metadata</span><span class="p">()</span><span class="w"> </span><span class="nx">Metadata</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nf">Close</span><span class="p">()</span><span class="w"> </span><span class="kt">error</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><h4 id="current-providers">Current Providers</h4>
<ul>
<li><strong>Unencrypted Provider</strong>: Simple key-value store for development and testing</li>
<li><strong>AES Provider</strong>: Symmetric file encryption using AES-256-GCM (single key management)</li>
<li><strong>Age Provider</strong>: Asymmetric file encryption using the <a href="https://github.com/FiloSottile/age">Age</a> specification (supports multiple recipients)</li>
<li><strong>Keyring Provider</strong>: Uses system keyring (macOS Keychain, Linux Secret Service)</li>
<li><strong>External Provider</strong>: Integration with external CLI tools (1Password, Bitwarden) via command execution</li>
</ul>
<h3 id="vault-switching">Vault Switching</h3>
<p>Vaults can be switched using a context-based system:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">flow vault switch development
</span></span><span class="line"><span class="cl">flow secret <span class="nb">set</span> api-key <span class="s2">&#34;dev-value&#34;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">flow vault switch production
</span></span><span class="line"><span class="cl">flow secret <span class="nb">set</span> api-key <span class="s2">&#34;prod-value&#34;</span>
</span></span></code></pre></div><p>Secret references support both current vault context (<code>secretRef: &quot;api-key&quot;</code>) and explicit vault specification (<code>secretRef: &quot;production/api-key&quot;</code>).</p>
<h2 id="backends">Backends</h2>
<table>
  <thead>
      <tr>
          <th>Type</th>
          <th>Encryption</th>
          <th>Where the key lives</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>aes256</code> (default)</td>
          <td>Symmetric, generated 32-byte key</td>
          <td><code>FLOW_VAULT_KEY</code></td>
      </tr>
      <tr>
          <td><code>age</code></td>
          <td>Asymmetric, recipient keys</td>
          <td><code>FLOW_VAULT_IDENTITY</code></td>
      </tr>
      <tr>
          <td><code>keyring</code></td>
          <td>Delegated to the OS keyring</td>
          <td>OS-managed</td>
      </tr>
      <tr>
          <td><code>external</code></td>
          <td>None of flow&rsquo;s business</td>
          <td>The provider authenticates</td>
      </tr>
      <tr>
          <td><code>unencrypted</code></td>
          <td>Plaintext JSON</td>
          <td>n/a</td>
      </tr>
  </tbody>
</table>
<p>Key storage is configurable per vault, and an existing valid key in the target variable is
reused rather than regenerated, which is how one key ends up shared across several vaults.</p>
<h2 id="external-vaults">External Vaults</h2>
<p>This is the design I am happiest with. An external vault holds <strong>links, not secrets</strong>. Each link
pairs a name you choose with a reference the provider understands. Reading the name resolves the
reference and reads through. Nothing is copied into flow and nothing is ever written back, so
pointing a vault at a store you already use cannot damage it.</p>
<p>The configuration carries a <code>get</code> command, an optional <code>metadata</code> command, and two patterns that
turn out to matter a lot:</p>
<ul>
<li><code>reference_pattern</code> describes what a reference for this provider looks like, so a typo is
caught when you link it rather than weeks later when you read it.</li>
<li><code>not_found_pattern</code> separates &ldquo;this link is broken&rdquo; from &ldquo;the provider is unreachable&rdquo;.
Without it, an expired session is indistinguishable from a deleted secret.</li>
</ul>
<p>Because it is read-through, <code>flow secret set</code> fails against an external vault and
<code>flow secret remove</code> removes the link rather than the secret.</p>
<h2 id="injection">Injection</h2>
<p>Secrets never appear in a command line. They are resolved at run time and handed to the process
as environment variables:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">params</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span>- <span class="nt">secretRef</span><span class="p">:</span><span class="w"> </span><span class="l">api-key</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">envKey</span><span class="p">:</span><span class="w"> </span><span class="l">API_KEY</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span>- <span class="nt">secretRef</span><span class="p">:</span><span class="w"> </span><span class="l">production/db-password  </span><span class="w"> </span><span class="c"># a different vault</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">envKey</span><span class="p">:</span><span class="w"> </span><span class="l">DB_PASSWORD</span><span class="w">
</span></span></span></code></pre></div><p>When something genuinely needs a file, <code>outputFile</code> writes one and deletes it afterwards. In
container runs the same values go through a temporary <code>--env-file</code>, for the same reason.</p>
]]></content:encoded>
    </item>
    <item>
      <title>flow as an Agent Runtime</title>
      <link>https://jahvon.dev/architecture/flow/ai/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://jahvon.dev/architecture/flow/ai/</guid>
      <description>The MCP server, why running work through flow beats a raw shell tool, and the Python interpreter that is currently in flight.</description>
      <content:encoded><![CDATA[<p>Most of what an assistant does on your behalf is run commands. The usual way it does that is a
generic shell tool: it composes a string, something executes it, the output comes back, and the
whole thing evaporates when the conversation scrolls. That works, and it is also the reason you
cannot answer &ldquo;what did it actually do&rdquo; an hour later.</p>
<p>flow already had the pieces to do better. It knows your workspace, it holds your secrets, it
captures logs, and it records every run. Exposing that over MCP turns it from a task runner into
somewhere an agent can work.</p>
<h2 id="the-scope-boundary">The Scope Boundary</h2>
<p>Worth stating up front, because it shapes everything else:</p>
<blockquote>
<p>flow is an AI <strong>tool provider</strong>, not an AI <strong>consumer</strong>.</p>
</blockquote>
<p>The core exposes deterministic capabilities: an MCP server, published JSON schemas, an
<code>llms.txt</code>. It does not make model calls. No LLM parsing of natural-language commands, no
generation inside the CLI. That would put vendor keys, per-call cost, and non-determinism in the
critical path of a task runner. Anything applying a model to flow does so from outside, through
the MCP surface. <a href="https://jahvon.dev/architecture/mochi/">Mochi</a> is exactly that: a consumer built on top.</p>
<h2 id="the-ladder">The Ladder</h2>
<p>The run tools are deliberately ordered, closest fit first:</p>
<table>
  <thead>
      <tr>
          <th>Tool</th>
          <th>For</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>execute</code></td>
          <td>A task you have already named. Runs the project&rsquo;s real <code>test</code> or <code>deploy</code>.</td>
      </tr>
      <tr>
          <td><code>run_command</code></td>
          <td>A one-off shell command.</td>
      </tr>
      <tr>
          <td><code>run_python</code></td>
          <td>The one-off, when it is Python rather than shell.</td>
      </tr>
      <tr>
          <td><code>run_executable</code></td>
          <td>Something richer than a single command.</td>
      </tr>
  </tbody>
</table>
<p>The reason <code>run_python</code> is its own tool rather than a flag on <code>run_command</code> is small and
practical: agents select tools by name, and a tool called &ldquo;run_command&rdquo; is not what gets reached
for when the task is Python.</p>
<p>Around those sit discovery and inspection tools (<code>list_executables</code>, <code>get_executable</code>,
<code>list_workspaces</code>, <code>get_workspace</code>, <code>switch_workspace</code>, <code>get_info</code>), history (<code>get_execution_logs</code>),
and authoring (<code>write_flowfile</code>, which validates against the schema server-side before writing).
There are MCP resources for workspaces, executables, flowfiles and logs, and prompts for
generating and debugging executables.</p>
<p>The server is built on <a href="https://mcp-go.dev/">mcp-go</a>, and exposes Tools, Prompts and
<a href="https://modelcontextprotocol.io/specification/2026-07-28/server/resources">Resources</a>. I discovered that client support for Resources is still thin but I have them for clients that do support them.</p>
<p>The boundary is stated honestly in the server instructions: fall back to a raw shell for things
that genuinely should not be recorded, or that flow is not suited to, like anything needing a TTY.</p>
<h2 id="what-running-through-flow-buys-you">What Running Through flow Buys You</h2>
<p>Compared to a generic execute tool:</p>
<ul>
<li><strong>Named work first.</strong> Discovery means the agent runs your actual <code>test</code> executable rather than
its own approximation of one.</li>
<li><strong>Workspace resolution from a directory.</strong> Pass a path and flow walks up to the nearest
<code>flow.yaml</code>. Works in a fresh clone or a git worktree with nothing registered.</li>
<li><strong>Secrets from the vault</strong>, injected as environment, never in the argv.</li>
<li><strong>Provenance on every run.</strong> <code>source</code>, <code>clientName</code>, <code>sessionId</code>, <code>workingDir</code>.</li>
<li><strong>Lifecycle-aware history.</strong> Written as <code>running</code> at start and upserted on completion, so a log
can be read while the run is still going.</li>
<li><strong>Approval gates in the workflow</strong>, via <code>reviewRequired</code> on a step, rather than depending on the
client to ask.</li>
<li><strong>Byte-capped structured output</strong>, so a runaway log cannot eat the context window.</li>
</ul>
<h3 id="provenance-has-opinions">Provenance Has Opinions</h3>
<p>Three environment variables carry it: <code>FLOW_RUN_SOURCE</code>, <code>FLOW_RUN_CLIENT</code>, <code>FLOW_RUN_SESSION</code>.
Two decisions behind that are worth repeating.</p>
<p>There is <strong>no client registry</strong>. flow does not sniff for <code>CLAUDE_CODE_SESSION_ID</code> or any other
vendor&rsquo;s variables. Those are undocumented internals that get renamed, and detection built on
them fails silently, so history quietly stops grouping and nobody notices. Each tool maps its own
variables onto the contract instead.</p>
<p>And identity is <strong>exported, not passed</strong>. Environment beats a flag the assistant has to remember
on every call: a model can silently omit an argument, but it cannot omit a variable it never
sees. Parameters are for intent, which is the only thing the model actually knows.</p>
<h2 id="the-python-interpreter">The Python Interpreter</h2>
<p>You can run <code>python</code> alongside the built-in POSIX shell:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">executables</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span>- <span class="nt">verb</span><span class="p">:</span><span class="w"> </span><span class="l">run</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">name</span><span class="p">:</span><span class="w"> </span><span class="l">report</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">exec</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">interpreter</span><span class="p">:</span><span class="w"> </span><span class="l">python</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">cmd</span><span class="p">:</span><span class="w"> </span><span class="p">|</span><span class="sd">
</span></span></span><span class="line"><span class="cl"><span class="sd">        import json, sys
</span></span></span><span class="line"><span class="cl"><span class="sd">        print(json.dumps({&#34;python&#34;: sys.version_info[:2]}))</span><span class="w">
</span></span></span></code></pre></div><p>A <code>.py</code> file needs no <code>interpreter</code> field at all, since the extension implies it. The same field
works on serial and parallel steps, and inside containers, where the entrypoint follows the
interpreter rather than being hardcoded to a shell.</p>
<p>Nothing is embedded. There is no bundled CPython, no Starlark, no WebAssembly. flow resolves a
real interpreter on the host, preferring a project&rsquo;s virtualenv over bare system Python, so an
agent running Python inside a repo gets that repo&rsquo;s dependencies. The search order is
<code>FLOW_PYTHON_BIN</code>, then <code>$VIRTUAL_ENV</code>, then the workspace&rsquo;s <code>.venv</code>, then <code>python3</code> on the path.
An override that does not resolve fails rather than quietly falling back.</p>
<p>Two details I liked:</p>
<p><strong>Inline code runs from a temporary file, never <code>python -c</code>.</strong> That keeps user code, which may
have interpolated secrets, out of the process table; it produces tracebacks with real line
numbers; and it sidesteps shell quoting for multi-line scripts.</p>
<p><strong><code>PYTHONUNBUFFERED</code> is set by default</strong>, because flow pipes stdout to a log writer rather than a
terminal, and CPython block-buffers to a pipe. Without it a long run emits nothing until it
exits, which looks hung to anyone watching, human or otherwise.</p>
<p>The MCP side is the reason the rest exists. <code>run_python</code> gives an assistant a Python runtime with
the same workspace environment and secrets, the same captured logs, and the same attributable
history entry it already gets for shell. It is the difference between an agent writing a scratch
file and an agent doing work you can audit afterwards.</p>
]]></content:encoded>
    </item>
    <item>
      <title>Generation and Integrations</title>
      <link>https://jahvon.dev/architecture/flow/generation/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://jahvon.dev/architecture/flow/generation/</guid>
      <description>Templates for scaffolding new projects, importing executables from files you already have, and where flow plugs into CI and other tools.</description>
      <content:encoded><![CDATA[<h2 id="template-system">Template System</h2>
<p>Flow includes a templating system for generating executables and workspaces from reusable templates, built on Go&rsquo;s <code>text/template</code> and the <a href="https://expr-lang.org/">Expr</a> expression language. See the <a href="https://flowexec.io">documentation</a> for usage details and examples.</p>
<h2 id="where-flow-plugs-in">Where flow Plugs In</h2>
<p>Two integration surfaces have their own pages, because both turned out to be more than a
paragraph:</p>
<ul>
<li><a href="https://jahvon.dev/architecture/flow/github-action/">The GitHub Action</a> runs the same executables in CI that you run locally.</li>
<li><a href="https://jahvon.dev/architecture/flow/ai/">flow as an agent runtime</a> covers the MCP server and the tools it exposes.</li>
</ul>
<p>There is also a Docker image at <code>ghcr.io/flowexec/flow</code> for other CI systems, though it has not
been exercised nearly as hard as the Action has.</p>
<h2 id="schemas">Schemas</h2>
<p>The flowfile, workspace, template and config formats are published as JSON Schema (see the
<a href="https://flowexec.io/types/">configuration reference</a>), which is what gives editors completion and
validation, and what lets an assistant author a valid flowfile without guessing. There is an
<code>llms.txt</code> alongside them. The Go types are generated from those same schemas, so the contract
has one source.</p>
]]></content:encoded>
    </item>
    <item>
      <title>The GitHub Action</title>
      <link>https://jahvon.dev/architecture/flow/github-action/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://jahvon.dev/architecture/flow/github-action/</guid>
      <description>Running the same executables in CI that you run locally. A composite action, an ephemeral vault, and the parts of &amp;ldquo;just run it on a runner&amp;rdquo; that turned out not to be simple.</description>
      <content:encoded><![CDATA[<p>Running the same thing locally and in CI has been a goal from early on. If a project&rsquo;s build
is a flow executable, then CI should run <em>that</em>, not a hand-copied approximation of it that
drifts the first time someone changes a flag.</p>
<p><a href="https://github.com/flowexec/action"><code>flowexec/action</code></a> is how. It publishes to the Marketplace
as <strong>flow-execute</strong>, and the smallest useful thing you can write with it is:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl">- <span class="nt">uses</span><span class="p">:</span><span class="w"> </span><span class="l">flowexec/action@v1</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">with</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">executable</span><span class="p">:</span><span class="w"> </span><span class="s1">&#39;build app&#39;</span><span class="w">
</span></span></span></code></pre></div><p>That is the whole point of it. The executable named there is the same one you run with
<code>flow build app</code> at your desk. Every repository in the flowexec organization uses this on itself.</p>
<h2 id="what-it-actually-is">What It Actually Is</h2>
<p>A composite action, not a container or a JavaScript action. It is a handful of bash steps in a
trench coat, which is the right shape for something whose job is to install a binary and run it:</p>
<ol>
<li>Resolve where flow should be installed, then restore it from the runner cache.</li>
<li>Install the CLI if the cache missed.</li>
<li>Register workspaces, cloning any that are git remotes.</li>
<li>Create a vault and load secrets into it, but only if secrets were passed.</li>
<li>Run the executable.</li>
<li>Upload logs as an artifact, but only on failure, and only if asked.</li>
</ol>
<p>Keeping it composite means each step shows up separately in the workflow log, so a failure
points at the thing that failed rather than at one opaque action.</p>
<h2 id="workspaces-including-ones-that-are-not-there-yet">Workspaces, Including Ones That Are Not There Yet</h2>
<p>The interesting input is <code>workspaces</code>. A workspace can be a local path, but it can also be a git
URL, which the action clones and registers before running anything:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl">- <span class="nt">uses</span><span class="p">:</span><span class="w"> </span><span class="l">flowexec/action@v1</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">with</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">executable</span><span class="p">:</span><span class="w"> </span><span class="s1">&#39;deploy staging&#39;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">workspaces</span><span class="p">:</span><span class="w"> </span><span class="p">|</span><span class="sd">
</span></span></span><span class="line"><span class="cl"><span class="sd">      backend: ./backend
</span></span></span><span class="line"><span class="cl"><span class="sd">      frontend: https://github.com/user/frontend-repo.git
</span></span></span><span class="line"><span class="cl"><span class="sd">      shared:
</span></span></span><span class="line"><span class="cl"><span class="sd">        repo: https://github.com/myorg/shared-flows.git
</span></span></span><span class="line"><span class="cl"><span class="sd">        ref: v1.0.0</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">clone-token</span><span class="p">:</span><span class="w"> </span><span class="l">${{ secrets.GITHUB_TOKEN }}</span><span class="w">
</span></span></span></code></pre></div><p>This is the CI expression of flow&rsquo;s cross-project composition. A workflow can pull in a shared
workspace of common executables, pin it to a tag, and reference its executables the same way it
would locally. Clone depth defaults to 1, because CI almost never needs the history.</p>
<h2 id="secrets-and-the-ephemeral-vault">Secrets and the Ephemeral Vault</h2>
<p>Secrets were the part that needed real thought. flow reads secrets from a vault, and a CI runner
has no vault, so the action makes one and throws it away.</p>
<p>When secrets are passed, it creates a vault named <code>github-actions</code> keyed to an environment
variable, loads each secret in, and switches to it. The generated key is immediately masked in
the log with <code>::add-mask::</code> and exposed as an output.</p>
<p>That output exists for one reason, and it is the nicest bit of the design: <strong>a vault can outlive
a job</strong>. Emit the key from one job, pass it to the next, and the second job decrypts the same
vault rather than re-loading every secret from GitHub:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">jobs</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">setup</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">outputs</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">vault-key</span><span class="p">:</span><span class="w"> </span><span class="l">${{ steps.init.outputs.vault-key }}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">steps</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span>- <span class="nt">uses</span><span class="p">:</span><span class="w"> </span><span class="l">flowexec/action@v1</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="nt">id</span><span class="p">:</span><span class="w"> </span><span class="l">init</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="nt">with</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">          </span><span class="nt">executable</span><span class="p">:</span><span class="w"> </span><span class="s1">&#39;validate&#39;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">          </span><span class="nt">secrets</span><span class="p">:</span><span class="w"> </span><span class="p">|</span><span class="sd">
</span></span></span><span class="line"><span class="cl"><span class="sd">            SHARED_SECRET=${{ secrets.SHARED_SECRET }}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">deploy</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">needs</span><span class="p">:</span><span class="w"> </span><span class="l">setup</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">steps</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span>- <span class="nt">uses</span><span class="p">:</span><span class="w"> </span><span class="l">flowexec/action@v1</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="nt">with</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">          </span><span class="nt">executable</span><span class="p">:</span><span class="w"> </span><span class="s1">&#39;deploy production&#39;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">          </span><span class="nt">vault-key</span><span class="p">:</span><span class="w"> </span><span class="l">${{ needs.setup.outputs.vault-key }}</span><span class="w">
</span></span></span></code></pre></div><p>The vault step is skipped entirely when there are no secrets and no key, so a plain build job
does not pay for machinery it is not using.</p>
<h2 id="failing-usefully">Failing Usefully</h2>
<p>A CI action that only tells you &ldquo;exit code 1&rdquo; is not much better than running the command
yourself. This one parses flow&rsquo;s structured JSON error output and surfaces the code:</p>
<table>
  <thead>
      <tr>
          <th>Output</th>
          <th>What it carries</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>exit-code</code></td>
          <td>The executable&rsquo;s exit code</td>
      </tr>
      <tr>
          <td><code>error-code</code></td>
          <td>A machine-readable code such as <code>EXECUTION_FAILED</code>, <code>TIMEOUT</code>, <code>NOT_FOUND</code></td>
      </tr>
      <tr>
          <td><code>output</code></td>
          <td>Captured stdout, when <code>upload</code> is on</td>
      </tr>
      <tr>
          <td><code>vault-key</code></td>
          <td>The generated key, when secrets were configured without one</td>
      </tr>
  </tbody>
</table>
<p>Which means a workflow can branch on <em>why</em> something failed rather than just that it did:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl">- <span class="nt">name</span><span class="p">:</span><span class="w"> </span><span class="l">Handle failure</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">if</span><span class="p">:</span><span class="w"> </span><span class="l">steps.migrate.outputs.exit-code != &#39;0&#39;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">run</span><span class="p">:</span><span class="w"> </span><span class="p">|</span><span class="sd">
</span></span></span><span class="line"><span class="cl"><span class="sd">    if [ &#34;${{ steps.migrate.outputs.error-code }}&#34; = &#34;TIMEOUT&#34; ]; then
</span></span></span><span class="line"><span class="cl"><span class="sd">      echo &#34;Consider increasing the timeout&#34;
</span></span></span><span class="line"><span class="cl"><span class="sd">    fi</span><span class="w">
</span></span></span></code></pre></div><p>Captured output is truncated at 65,000 bytes, because that is GitHub&rsquo;s limit on a step output,
and the full log is available as an artifact instead.</p>
<h2 id="the-unglamorous-parts">The Unglamorous Parts</h2>
<p>Most of the commit history is Windows and shell edge cases, which is what this kind of tool is
actually made of:</p>
<ul>
<li>Windows runners need <code>$HOME/bin</code> pushed onto <code>GITHUB_PATH</code>, and workspace paths in native form
rather than the POSIX form the rest of the script assumes.</li>
<li><code>TERM=dumb</code> on Windows, because flow&rsquo;s TUI would otherwise try to render into something that
is not a terminal and hang the job.</li>
<li>The vault key is extracted from structured JSON output, with a fallback to scraping the plain
text message for older CLI versions.</li>
<li>The binary is cached between runs, keyed on the resolved version, so a workflow that runs the
action several times installs flow once.</li>
</ul>
<p>None of that is interesting to write about, and all of it is the difference between an action
that works on your machine and one that works on someone else&rsquo;s.</p>
<h2 id="resources">Resources</h2>
<ul>
<li><a href="https://github.com/flowexec/action">flowexec/action</a></li>
<li><a href="https://github.com/marketplace/actions/flow-execute">flow-execute on the Marketplace</a></li>
<li><a href="https://github.com/flowexec/flow/blob/main/.github/workflows/ci.yaml">flow&rsquo;s own CI workflow</a>, which uses it</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>AI as a Development Partner</title>
      <link>https://jahvon.dev/notes/ai-development-partner/</link>
      <pubDate>Wed, 06 May 2026 00:00:00 +0000</pubDate>
      <guid>https://jahvon.dev/notes/ai-development-partner/</guid>
      <description>Reflections on how I&amp;rsquo;ve been using AI as a development partner - what I delegate, what I don&amp;rsquo;t, and what it&amp;rsquo;s produced.</description>
      <content:encoded><![CDATA[<p>Last fall I wrote about <a href="https://jahvon.dev/notes/ai-creative-partner/">using AI as a creative partner</a> after helping with a HGSE module on vibe coding. The conclusion I landed on was careful: AI works best as a scaffold, not a substitute. Use it consciously, review everything, keep your judgment in the loop. I still believe that. But I&rsquo;ve spent the last few months testing what that actually looks like when the output has to live somewhere.</p>
<p>Creative work you experience once. Development work you live in. That difference changes what you need from a partner.</p>
<h2 id="the-bench">The Bench</h2>
<p>When I was at <a href="https://jahvon.dev/tags/recurse/">Recurse Center</a> last summer, I started integrating AI more intentionally into how I build. Not for speed, for learning. I wanted to experiment with architectures I wouldn&rsquo;t normally try, undo decisions cheaply, and see what held up. <a href="https://jahvon.dev/tags/flow/">Flow</a> was the natural workbench. It&rsquo;s my own tool and I know every corner of it.</p>
<p>Over the last few months I&rsquo;ve been building Flow Desktop and refactoring pieces of the core CLI with AI doing a lot of the implementation work. The experience has been different from vibe coding in ways that matter. In the HGSE projects, I was optimizing for something working. Here, I&rsquo;m optimizing for something I can read six weeks later, find when I need it, and build on without second-guessing what&rsquo;s underneath.</p>
<p>That changes what I actually delegate.</p>
<h2 id="the-delegation-model">The Delegation Model</h2>
<p>The architectural decisions stay with me. What the data model looks like, how executables get resolved, where state lives. What I hand off is the implementation of decisions I&rsquo;ve already made. I describe the shape of what I want, review what comes back against that shape, and merge when it aligns. When it doesn&rsquo;t, I say so explicitly.</p>
<p>A concrete example: I&rsquo;ve been building an AI proxy backed by <a href="https://www.cloudflare.com/developer-platform/products/ai-gateway/">Cloudflare AI Gateway</a> that sits across all of my tools. I decided on the architecture, what the proxy needs to do, how it integrates with the <a href="https://jahvon.dev/notes/cloudflare-experience/">Cloudflare platform</a>, what observability I want. AI implemented it. The Cloudflare MCP server made the feedback loop tight enough that I could test and iterate without switching contexts.</p>
<p>What makes this work is having a single place to see everything. Everything I&rsquo;ve configured, discoverable from one surface.</p>
<video class="demo-video"
       autoplay loop muted playsinline preload="metadata"
       aria-label="The flow v2 terminal UI">
  <source src="https://jahvon.dev/images/flow-v2-tui.mp4" type="video/mp4">
</video>

<p>One of the real risks of AI-assisted development is ending up with code you can&rsquo;t navigate. Outputs that don&rsquo;t connect to anything, a project that sprawls in ways you can&rsquo;t audit. The workspace model keeps that from happening. I know where things live because I designed where they live.</p>
<p>I&rsquo;ve also started using AI to enrich Flow itself, generating executable metadata, adding descriptions and tags, making the library more useful as it grows. Flow has an MCP server, so AI tools can interact with it directly. Watching an AI tool work with Flow rather than just producing files has been one of the more interesting parts of this.</p>
<p>Licklider&rsquo;s framing from the last post still holds here. Set the goals, determine the criteria, perform the evaluations. That&rsquo;s still your job. What&rsquo;s changed is my confidence in what I can hand off once those things are set.</p>
<h2 id="what-it-produced">What It Produced</h2>
<p>The review and iterate phase is where the real work happens. AI gets you to a first draft faster. Whether that draft is right is still a judgment call only you can make.</p>
<p>A few months of this produced Flow v2 and something I&rsquo;ve been sitting on: <a href="https://mochiexec.io">Mochi</a>. Development workflows have a way of becoming invisible. They exist, they&rsquo;re just not anywhere you can see them. It&rsquo;s a local-first dev ops dashboard built on Flow. Point it at a directory and it finds your development scripts and automations, turns them into a unified, AI-enriched dashboard. No cloud, no accounts, works with whatever you&rsquo;re already running.</p>
<p><img src="https://jahvon.dev/images/mochi-executables_hu_3937508efceff644.png" srcset="https://jahvon.dev/images/mochi-executables_hu_e108e5df939cf6e.png 700w, https://jahvon.dev/images/mochi-executables_hu_3937508efceff644.png 1400w" sizes="(min-width: 768px) 720px, 100vw" data-zoom-src="https://jahvon.dev/images/mochi-executables.aec2ad9fd23d482d0003d84a995b6ff0c0972ba228d8c392f64f92a3378ad175.png" width="1400" height="1279"
     alt="Mochi Executables View"
     loading="lazy" decoding="async">

<em>Executables view. Everything Mochi found across my workspaces, tagged and filterable.</em></p>
<p>Still early. If it sounds useful, the waitlist is at <a href="https://mochiexec.io">mochiexec.io</a>.</p>
<p>I&rsquo;m more convinced than I was last fall that the gap worth closing isn&rsquo;t between what AI can produce and what you can prompt. It&rsquo;s between what AI produces and what you actually understand. Building in a system you designed is one way to stay honest about that.</p>
]]></content:encoded>
    </item>
    <item>
      <title>6 Weeks of flow at Recurse Center</title>
      <link>https://jahvon.dev/notes/rc-6-week-flow/</link>
      <pubDate>Mon, 30 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://jahvon.dev/notes/rc-6-week-flow/</guid>
      <description>An update on my journey tackling developer tool chaos with a personal automation platform. 6 weeks of building desktop apps, cryptographic vaults, and feature planning at Recurse Center.</description>
      <content:encoded><![CDATA[<p>I&rsquo;ve been thinking a lot about developer tooling and the idea of a &ldquo;personal developer platform&rdquo; - something that I could adapt to aid how <em>I</em> want to develop. Modern development can feel like tool chaos at times - we&rsquo;re juggling package managers, test runners, linters, deployment scripts, language-specific tooling, and dozens of open source CLI tools. Each project accumulates its own collection of scripts and commands that live in different places with different interfaces.</p>
<p>I introduced <a href="https://flowexec.io/">flow</a> in <a href="https://jahvon.dev/notes/forging-flow/">another post</a> a few months ago, but I&rsquo;ve had the amazing opportunity to start a sabbatical at the <a href="https://www.recurse.com/scout/click?t=420ecb9ef5810758f6fe8dec816d80a8">Recurse Center</a>, where I&rsquo;ve been able to think more deeply about the problems I was solving and the technologies I wanted to learn about! As I mentioned in that post, flow has been my &ldquo;learning platform&rdquo; over the last 2 years and I knew I wanted to take it a step further at Recurse.</p>
<p>I&rsquo;m at the halfway point of my time at RC and am excited to share how my first 6 weeks have been on my main coding project.</p>
<h2 id="flow-desktop">flow desktop</h2>
<p>I&rsquo;ve been itching to work on a frontend project for a while now. While building the flow TUI library, I had lots of fun thinking about how I could create a good experience through visuals and layout. <a href="https://github.com/charmbracelet/bubbletea">Bubble Tea</a> has been fun to use here, but I&rsquo;ve wanted to do some UI development with more possibilities. Doing this in the &ldquo;browser&rdquo; and using new-to-me technologies sounded like a great plan.</p>
<p>Coming into RC, this was something I knew I wanted to work on, but my excitement grew as I started to learn about the fascinating world of frontend development through RC pair programming, events, and chats.</p>
<p><strong>Architecture Decision: CLI as Single Source of Truth</strong></p>
<p>Instead of duplicating business logic in my desktop app, I&rsquo;ve been building it as a pure visualization layer over the existing CLI.</p>
<p><img src="https://jahvon.dev/images/flow-desktop-arch.png" srcset="https://jahvon.dev/images/flow-desktop-arch_hu_fde535ab93ee9ac8.png 600w, https://jahvon.dev/images/flow-desktop-arch.png 1201w" sizes="(min-width: 768px) 720px, 100vw" width="1201" height="446"
     alt="Desktop Architecture"
     loading="lazy" decoding="async">
</p>
<p>This felt risky at first - wouldn&rsquo;t spawning processes be too slow? Turns out CLI commands execute pretty fast thanks to some caching I do on the CLI side. The whole round trip feels instant with my current usage.</p>
<p><strong>Tech Stack</strong></p>
<p>All of the resources, pairing, feedback, and individual research I&rsquo;ve done has landed me on the following:</p>
<ul>
<li><strong>Tauri</strong>: Gives me Rust backend + web frontend without Electron&rsquo;s bloat. Bonus that it&rsquo;s an opportunity to learn some Rust.</li>
<li><strong>TypeScript</strong>: I was able to get TS and Rust types generated from the same JSON schema that I use to generate Go code. This has been making development much smoother across the 3 languages that flow now uses.</li>
<li><strong>React &amp; Mantine UI</strong>: VSCode-like components without building everything from scratch. Their <a href="https://mantine.dev/x/spotlight/">Spotlight</a> extension is what sold me - it could be a really cool search and command center for the UI!</li>
</ul>
<p><strong>Demo!</strong></p>
<p>Here is a quick demo of me using my current implementation of the desktop. This shows the workspace and executable viewer/runner in action - you can see me running an executable directly from the UI and playing with the theme picker I prototyped for customization.</p>
<video class="demo-video"
       controls preload="none" poster="https://jahvon.dev/images/desktop-demo-poster.png"
       aria-label="The flow desktop app, early build">
  <source src="https://jahvon.dev/images/flow-desktop-demo.mp4" type="video/mp4">
</video>

<p>I still have more work to do here, but it&rsquo;s been satisfying seeing my ideas come to life as I pick up these new technologies.</p>
<h2 id="vaults-v2">vaults v2</h2>
<p>I had a couple of pain points with the vault that I initially built for flow. The UX was pretty simple but limiting. I&rsquo;ve also been really wanting a way to integrate my Bitwarden secrets into flow seamlessly. This led me to brainstorm a new design for that feature. I spent my first 2 weeks at RC doing some light research on cryptography with Go, studying how other tools handle secrets, and building a simple POC.</p>
<p>I decided to introduce a &ldquo;provider&rdquo; concept that also improves the experience around having multiple vaults. I currently have an implementation for an updated version of my AES symmetrically encrypted vault, added an Age asymmetric encryption backend, and plan to add a backend for custom CLI-tool vault managers. You can see what I came up with in <a href="https://github.com/jahvon/vault">this repo</a>. From the flow perspective, the experience would be like this:</p>
<p><strong>Creating a vault</strong></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="c1"># Auto-generates everything for the AES vault</span>
</span></span><span class="line"><span class="cl">flow vault create development
</span></span><span class="line"><span class="cl"><span class="c1"># Create an Age vault with identity generated from age-keygen</span>
</span></span><span class="line"><span class="cl">flow vault create team --type age --recipients key1,key2,key3 --identityFile id.txt
</span></span><span class="line"><span class="cl"><span class="c1"># External needs CLI integration</span>
</span></span><span class="line"><span class="cl">flow vault create bitwarden --type external --interactive
</span></span></code></pre></div><p><strong>Vault Switching as Primary UX</strong></p>
<p>Borrowed the mental model from git/kubectl:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">flow vault switch development    <span class="c1"># Like git checkout</span>
</span></span><span class="line"><span class="cl">flow secret <span class="nb">set</span> api-key <span class="s2">&#34;dev-123&#34;</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">flow vault switch production
</span></span><span class="line"><span class="cl">flow secret <span class="nb">set</span> api-key <span class="s2">&#34;prod-456&#34;</span>
</span></span></code></pre></div><p>This allows for clean secret references in executables: <code>secretRef: &quot;api-key&quot;</code> uses current vault, <code>secretRef: &quot;production/api-key&quot;</code> is explicit.</p>
<h2 id="technical-decisions">Technical decisions</h2>
<h3 id="executable-composition">Executable composition</h3>
<p>Executables aren&rsquo;t just scripts - they&rsquo;re composable units with conditional logic:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">serial</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">failFast</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">execs</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span>- <span class="nt">if</span><span class="p">:</span><span class="w"> </span><span class="l">os == &#34;darwin&#34;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">cmd</span><span class="p">:</span><span class="w"> </span><span class="s2">&#34;command -v mytool || brew install mytool&#34;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span>- <span class="nt">if</span><span class="p">:</span><span class="w"> </span><span class="l">env[&#34;PUSH&#34;] == &#34;true&#34;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">cmd</span><span class="p">:</span><span class="w"> </span><span class="l">make image</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span>- <span class="nt">ref</span><span class="p">:</span><span class="w"> </span><span class="l">deploy development</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">reviewRequired</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span><span class="w">  </span><span class="c"># Pauses for human confirmation</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span>- <span class="nt">ref</span><span class="p">:</span><span class="w"> </span><span class="l">launch app</span><span class="w">
</span></span></span></code></pre></div><p>The expression language (using <a href="https://github.com/expr-lang/expr">Expr</a>) has access to OS info, environment variables, and flow&rsquo;s cache. It&rsquo;s like having bash conditionals but declarative.</p>
<h3 id="process-architecture">Process architecture</h3>
<p>The desktop app&rsquo;s process model is pretty simple. Each user action spawns a CLI process:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-rust" data-lang="rust"><span class="line"><span class="cl"><span class="cp">#[tauri::command]</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="k">async</span><span class="w"> </span><span class="k">fn</span> <span class="nf">get_workspaces</span><span class="p">()</span><span class="w"> </span>-&gt; <span class="nb">Result</span><span class="o">&lt;</span><span class="nb">Vec</span><span class="o">&lt;</span><span class="n">Workspace</span><span class="o">&gt;</span><span class="p">,</span><span class="w"> </span><span class="nb">String</span><span class="o">&gt;</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="kd">let</span><span class="w"> </span><span class="n">output</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="n">Command</span>::<span class="n">new</span><span class="p">(</span><span class="s">&#34;flow&#34;</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="p">.</span><span class="n">args</span><span class="p">([</span><span class="s">&#34;workspace&#34;</span><span class="p">,</span><span class="w"> </span><span class="s">&#34;list&#34;</span><span class="p">,</span><span class="w"> </span><span class="s">&#34;--output&#34;</span><span class="p">,</span><span class="w"> </span><span class="s">&#34;json&#34;</span><span class="p">])</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="p">.</span><span class="n">output</span><span class="p">().</span><span class="k">await</span><span class="o">?</span><span class="p">;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="n">serde_json</span>::<span class="n">from_slice</span><span class="p">(</span><span class="o">&amp;</span><span class="n">output</span><span class="p">.</span><span class="n">stdout</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><p>This seems inefficient but has huge benefits:</p>
<ul>
<li>Desktop crashes don&rsquo;t corrupt CLI state</li>
<li>CLI updates immediately benefit desktop</li>
<li>No state synchronization between processes</li>
<li>Easy to debug - each operation is a discrete CLI command</li>
</ul>
<h2 id="rc-moments-that-shaped-the-code">RC moments that shaped the code</h2>
<p><strong>Pair Programming</strong>: I paired on setting up Tauri and trying to integrate it with the CLI. We came up with the great idea of using some of my existing CLI output formatting options to get data through the app. This turned out to be a great decision to make on the fly. Conversations with others helped me confirm that CLI-as-source-of-truth wasn&rsquo;t a compromise - it was the right abstraction.</p>
<p><strong>The Feedback Loop</strong>: RC&rsquo;s culture of sharing work-in-progress meant getting feedback on half-baked ideas. I&rsquo;ve enjoyed presenting and demoing my progress throughout my time. I&rsquo;d thought extensions would be a neat feature but I never actually needed them myself. Hearing about the different ways that others think flow could be extended convinced me to reopen an <a href="https://github.com/flowexec/flow/issues/185">issue</a> I closed.</p>
<p><strong>Community Inspiration</strong>: Seeing the variety of projects and approaches at RC has reinforced my belief that developer tools should be adaptable rather than prescriptive. Everyone has their own workflow, and the best tools are the ones that bend to fit how you think, not the other way around.</p>
<h2 id="next-up">Next up</h2>
<h3 id="flow-mcp-server">flow MCP server</h3>
<p>I&rsquo;ve started using Claude Code and this has inspired me to learn how to create a Model Context Protocol server that will allow AI to understand flow workspaces and executables natively. I&rsquo;d love to eventually have something that enables:</p>
<ul>
<li>Browsing flow files and suggesting syntax improvements</li>
<li>Generating new workflows from natural language</li>
<li>Debugging failures with full workspace context 🚀</li>
</ul>
<h3 id="wasm-plugin-system">WASM plugin system</h3>
<p>Extending flow with WASM-integrated extensions. I want to try to allow automations to be programmable in two ways:</p>
<ul>
<li><strong>Executable template generator</strong>: Plugins that run template generation for flow-discoverable executables (from APIs, templates, external sources). I&rsquo;m thinking of something like Taskfile/just → flow executable integrations to start</li>
<li><strong>WASM Runtime executable type</strong>: Plugin executables that run sandboxed through flow</li>
</ul>
<p>This will be my first time getting hands-on with WebAssembly and I already have many ideas for cool plugins that will allow me to tinker with a variety of languages in the future.</p>
<h3 id="test--release-improvements">Test &amp; release improvements</h3>
<p>The best way to try out some of these new and upcoming features would be to clone the flow repo and run the <code>build binary</code> executable to get a local go build. Note that the main branch is not guaranteed to be stable, though.</p>
<p>With a new component in the flow ecosystem, I need to level up the test and release process as I prepare for v1 over the next couple of months. This means learning frontend testing practices, updating my GitHub workflows to handle multi-language builds, and rethinking the installation process to bundle the desktop app alongside the CLI.</p>
]]></content:encoded>
    </item>
    <item>
      <title>Forging flow: My Journey of Creation and Learning</title>
      <link>https://jahvon.dev/notes/forging-flow/</link>
      <pubDate>Sat, 08 Feb 2025 00:00:00 +0000</pubDate>
      <guid>https://jahvon.dev/notes/forging-flow/</guid>
      <description>&lt;p&gt;Over the last couple of years, I have been having fun experimenting with ways to streamline my developer experience. This may largely stem from my Developer Experience (DevX) focus as a software / platform engineer in the CarGurus DevX organization. (&lt;em&gt;side note: Check out &lt;a href=&#34;https://www.cargurus.dev/How-CarGurus-is-supercharging-our-microservice-developer-experience/&#34;&gt;this blog post&lt;/a&gt; I wrote on how we supercharged the experience for our Product Engineers&lt;/em&gt;)&lt;/p&gt;
&lt;p&gt;However, the challenges that &lt;em&gt;I&lt;/em&gt; face at work and on my side projects aren&amp;rsquo;t quite the same as the ones faced by CarGurus product engineers. I started to find myself drowning in a sea of scattered commands, scripts, and tools. This, combined with my desire to find opportunities to learn more about Go patterns and libraries in a low-risk way, motivated me to invest some free time developing an &amp;ldquo;integrated development platform&amp;rdquo; - or at least the foundations for one!&lt;/p&gt;</description>
      <content:encoded><![CDATA[<p>Over the last couple of years, I have been having fun experimenting with ways to streamline my developer experience. This may largely stem from my Developer Experience (DevX) focus as a software / platform engineer in the CarGurus DevX organization. (<em>side note: Check out <a href="https://www.cargurus.dev/How-CarGurus-is-supercharging-our-microservice-developer-experience/">this blog post</a> I wrote on how we supercharged the experience for our Product Engineers</em>)</p>
<p>However, the challenges that <em>I</em> face at work and on my side projects aren&rsquo;t quite the same as the ones faced by CarGurus product engineers. I started to find myself drowning in a sea of scattered commands, scripts, and tools. This, combined with my desire to find opportunities to learn more about Go patterns and libraries in a low-risk way, motivated me to invest some free time developing an &ldquo;integrated development platform&rdquo; - or at least the foundations for one!</p>
<p>Enter flow: my open-source task runner and workflow automation tool. What started as a simple itch to scratch has evolved into the foundations of a comprehensive platform for wrangling dev workflows across projects. Looking back, I realize it would have been easier to just migrate everything into a tool like <a href="https://taskfile.dev/">Taskfile</a> or <a href="https://just.systems/">Just</a>, but my vision for my own personal platform doesn&rsquo;t stop at the CLI. Taking that route also would have left my learning desires unmet. While much of my influence for flow comes from cloud-native projects and ideals, I&rsquo;ve approached it from a local-first perspective - one where repeatable &ldquo;micro-workflows&rdquo; can be pieced together however <em>you</em> desire; making them easily discoverable, automated, and observable.</p>
<p>It&rsquo;s ambitious, but that&rsquo;s what excites me! There&rsquo;s so much experimenting and learning ahead. This is my first blog post, but if this interests you, please return! I&rsquo;ll be using it to document my learnings and progress on this project and some of my other side projects.</p>
<h2 id="building-the-foundation">Building the Foundation</h2>
<p>My first build of flow centered around two simple concepts driven by YAML files:</p>
<ul>
<li>Workspaces for organizing tasks across projects/repos</li>
<li>Executables for defining those tasks</li>
</ul>
<p>I included a simple <a href="https://github.com/rivo/tview/">tview</a> terminal UI implementation to simplify the discovery of workspaces and executables across my system. While I&rsquo;ve since moved away from that library, it helped me conceptualize much of the current TUI.</p>
<p>Through usage, I found myself iterating <em>a lot</em>. As I onboarded more workspaces and as those workspaces grew in complexity, flow&rsquo;s feature set had to grow. My favorite components to implement have been the <a href="https://github.com/charmbracelet/bubbletea">bubbletea</a> TUI framework, an internal documentation generator for the <a href="https://flowexec.io/">flowexec.io</a> site, the <a href="https://flowexec.io/#/guide/templating">templating</a> workflow, and the <a href="https://flowexec.io/#/guide/state">state</a> and <a href="https://flowexec.io/#/guide/conditional">conditional</a> management of  serial and parallel executable types. &rsquo;ll dive deeper into those in follow-up posts, but I invite you to explore the guides at flowexec.io for a complete overview of where flow stands today.</p>
<p>At it&rsquo;s core, the flow CLI is a YAML-driven task runner. Here is an example of a flow file that I have for my Authentik server deployed in my home cluster; it uses the <code>exec</code> executable type to define the command that&rsquo;s run:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">namespace</span><span class="p">:</span><span class="w"> </span><span class="l">authentik</span><span class="w"> </span><span class="c"># optional, additional grouping in a workspace</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="nt">tags</span><span class="p">:</span><span class="w"> </span><span class="p">[</span><span class="l">k8s, auth]</span><span class="w"> </span><span class="c"># useful for filtering the `flow library` command</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="c"># this description is rendered as markdown (alongside other executable info)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="c"># when viewing in the `flow library`.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="nt">description</span><span class="p">:</span><span class="w"> </span><span class="p">|</span><span class="sd">
</span></span></span><span class="line"><span class="cl"><span class="sd">  **References:**
</span></span></span><span class="line"><span class="cl"><span class="sd">  - https://goauthentik.io/
</span></span></span><span class="line"><span class="cl"><span class="sd">  - https://github.com/goauthentik/helm</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="nt">executables</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="c"># flow install authentik:app</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span>- <span class="nt">verb</span><span class="p">:</span><span class="w"> </span><span class="l">install</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">name</span><span class="p">:</span><span class="w"> </span><span class="l">app</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">aliases</span><span class="p">:</span><span class="w"> </span><span class="p">[</span><span class="l">chart]</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">description</span><span class="p">:</span><span class="w"> </span><span class="l">Upgrade/install Authentik Helm chart</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">exec</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">params</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span><span class="c"># secrets are managed with the integrated vault via the `flow secret` command</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span>- <span class="nt">secretRef</span><span class="p">:</span><span class="w"> </span><span class="l">authentik-secret-key</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">          </span><span class="nt">envKey</span><span class="p">:</span><span class="w"> </span><span class="l">AUTHENTIK_SECRET_KEY</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span>- <span class="nt">secretRef</span><span class="p">:</span><span class="w"> </span><span class="l">authentik-db-password</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">          </span><span class="nt">envKey</span><span class="p">:</span><span class="w"> </span><span class="l">AUTHENTIK_DB_PASSWORD</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">cmd</span><span class="p">:</span><span class="w"> </span><span class="p">|</span><span class="sd">
</span></span></span><span class="line"><span class="cl"><span class="sd">        helm upgrade --install authentik authentik/authentik \
</span></span></span><span class="line"><span class="cl"><span class="sd">          --version 2024.10.4 \
</span></span></span><span class="line"><span class="cl"><span class="sd">          --namespace auth --create-namespace \
</span></span></span><span class="line"><span class="cl"><span class="sd">          --set authentik.secret_key=$AUTHENTIK_SECRET_KEY \
</span></span></span><span class="line"><span class="cl"><span class="sd">          --set authentik.postgresql.password=$AUTHENTIK_DB_PASSWORD \
</span></span></span><span class="line"><span class="cl"><span class="sd">          --set postgresql.auth.password=$AUTHENTIK_DB_PASSWORD \
</span></span></span><span class="line"><span class="cl"><span class="sd">          --set postgresql.postgresqlPassword=$AUTHENTIK_DB_PASSWORD \
</span></span></span><span class="line"><span class="cl"><span class="sd">          -f values.yaml</span><span class="w">
</span></span></span></code></pre></div><p>The flow CLI provides a consistent experience for all executable runs and searches. This includes automatically generating a summary markdown document viewable with the <code>flow library</code> command, log formatting and archiving, and a configurable TUI experience.</p>
<p>This will show up in the <code>flow library</code> as rendered markdown:</p>
<p><img src="https://jahvon.dev/images/library-authentik-exec_hu_ce3ceb83172b1543.png" srcset="https://jahvon.dev/images/library-authentik-exec_hu_69fabeb981d37580.png 700w, https://jahvon.dev/images/library-authentik-exec_hu_ce3ceb83172b1543.png 1400w" sizes="(min-width: 768px) 720px, 100vw" data-zoom-src="https://jahvon.dev/images/library-authentik-exec.72a7791a5d00574821c54e4666a9a5366f5c4632ead429e14bff952cc2d5cc21.png" width="1400" height="1375"
     alt="Authentik Executable"
     loading="lazy" decoding="async">
</p>
<p>As my needs evolved, I added more executable configurations and types. Here&rsquo;s an example of a common <code>request</code> executable I use to pause my home&rsquo;s pi.hole blocking:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">executables</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="c"># flow pause pihole</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span>- <span class="nt">verb</span><span class="p">:</span><span class="w"> </span><span class="l">pause</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">name</span><span class="p">:</span><span class="w"> </span><span class="l">pihole</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">request</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">method</span><span class="p">:</span><span class="w"> </span><span class="s2">&#34;POST&#34;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">args</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span>- <span class="nt">pos</span><span class="p">:</span><span class="w"> </span><span class="m">1</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">          </span><span class="nt">envKey</span><span class="p">:</span><span class="w"> </span><span class="l">DURATION</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">          </span><span class="nt">default</span><span class="p">:</span><span class="w"> </span><span class="m">300</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">          </span><span class="nt">type</span><span class="p">:</span><span class="w"> </span><span class="l">int</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">params</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">        </span>- <span class="nt">secretRef</span><span class="p">:</span><span class="w"> </span><span class="l">pihole-pwhash</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">          </span><span class="nt">envKey</span><span class="p">:</span><span class="w"> </span><span class="l">PWHASH</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">url</span><span class="p">:</span><span class="w"> </span><span class="l">http://pi.hole/admin/api.php?disable=$DURATION&amp;auth=$PWHASH</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">validStatusCodes</span><span class="p">:</span><span class="w"> </span><span class="p">[</span><span class="m">200</span><span class="p">]</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">logResponse</span><span class="p">:</span><span class="w"> </span><span class="kc">true</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">transformResponse</span><span class="p">:</span><span class="w"> </span><span class="l">if .status == &#34;disabled&#34; then .status = &#34;paused&#34; else . end</span><span class="w">
</span></span></span></code></pre></div><p><img src="https://jahvon.dev/images/library-pihole-exec_hu_560c97ea9463da37.png" srcset="https://jahvon.dev/images/library-pihole-exec_hu_ed7791a134bf4c1.png 700w, https://jahvon.dev/images/library-pihole-exec_hu_560c97ea9463da37.png 1400w" sizes="(min-width: 768px) 720px, 100vw" data-zoom-src="https://jahvon.dev/images/library-pihole-exec.4ce8f7efff753ae1192643673548abb8e8b632e935e64f543592eaf06ca5076b.png" width="1400" height="1165"
     alt="PiHole Executable"
     loading="lazy" decoding="async">
</p>
<p>Here&rsquo;s an example of the log output:</p>
<p><img src="https://jahvon.dev/images/log-pihole-exec_hu_8f60b8d8976ed9f2.png" srcset="https://jahvon.dev/images/log-pihole-exec_hu_a24131036a77d8be.png 700w, https://jahvon.dev/images/log-pihole-exec_hu_8f60b8d8976ed9f2.png 1400w" sizes="(min-width: 768px) 720px, 100vw" data-zoom-src="https://jahvon.dev/images/log-pihole-exec.43caacb1e63c7fa66f70a912185fbc43945225d4ceef18e2695c7c3558309b42.png" width="1400" height="111"
     alt="PiHole Executable Logs"
     loading="lazy" decoding="async">
</p>
<h2 id="lessons-learned">Lessons Learned</h2>
<p>Building flow has been an incredible opportunity to deepen my understanding of Go and its ecosystem. Here are a few key lessons that have significantly shaped how I write Go now:</p>
<h3 id="small-packages-and-interfaces-made-testing-a-breeze">Small Packages and Interfaces Made Testing a Breeze</h3>
<p>This approach makes testing easier, improves code organization, and makes refactoring as ideas evolve a joy.</p>
<p>Each executable type has its own Runner, making it simple to extend the system with new types. Here&rsquo;s a snippet that demonstrates the ease of using this type when assigning an executable to a <code>Runner</code>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="cp">//go:generate mockgen -destination=mocks/mock_runner.go -package=mocks github.com/jahvon/flow/internal/runner Runner</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="kd">type</span><span class="w"> </span><span class="nx">Runner</span><span class="w"> </span><span class="kd">interface</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nf">Name</span><span class="p">()</span><span class="w"> </span><span class="kt">string</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nf">Exec</span><span class="p">(</span><span class="nx">ctx</span><span class="w"> </span><span class="o">*</span><span class="nx">context</span><span class="p">.</span><span class="nx">Context</span><span class="p">,</span><span class="w"> </span><span class="nx">e</span><span class="w"> </span><span class="o">*</span><span class="nx">executable</span><span class="p">.</span><span class="nx">Executable</span><span class="p">,</span><span class="w"> </span><span class="nx">eng</span><span class="w"> </span><span class="nx">engine</span><span class="p">.</span><span class="nx">Engine</span><span class="p">,</span><span class="w"> </span><span class="nx">inputEnv</span><span class="w"> </span><span class="kd">map</span><span class="p">[</span><span class="kt">string</span><span class="p">]</span><span class="kt">string</span><span class="p">)</span><span class="w"> </span><span class="kt">error</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nf">IsCompatible</span><span class="p">(</span><span class="nx">executable</span><span class="w"> </span><span class="o">*</span><span class="nx">executable</span><span class="p">.</span><span class="nx">Executable</span><span class="p">)</span><span class="w"> </span><span class="kt">bool</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><p>This interface allows me to easily add new executable types by just implementing these three methods. The core execution logic remains clean and extensible:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="kd">func</span><span class="w"> </span><span class="nf">Exec</span><span class="p">(</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nx">ctx</span><span class="w"> </span><span class="o">*</span><span class="nx">context</span><span class="p">.</span><span class="nx">Context</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nx">executable</span><span class="w"> </span><span class="o">*</span><span class="nx">executable</span><span class="p">.</span><span class="nx">Executable</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nx">eng</span><span class="w"> </span><span class="nx">engine</span><span class="p">.</span><span class="nx">Engine</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nx">inputEnv</span><span class="w"> </span><span class="kd">map</span><span class="p">[</span><span class="kt">string</span><span class="p">]</span><span class="kt">string</span><span class="p">,</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">)</span><span class="w"> </span><span class="kt">error</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="kd">var</span><span class="w"> </span><span class="nx">assignedRunner</span><span class="w"> </span><span class="nx">Runner</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="k">for</span><span class="w"> </span><span class="nx">_</span><span class="p">,</span><span class="w"> </span><span class="nx">runner</span><span class="w"> </span><span class="o">:=</span><span class="w"> </span><span class="k">range</span><span class="w"> </span><span class="nx">registeredRunners</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">       </span><span class="k">if</span><span class="w"> </span><span class="nx">runner</span><span class="p">.</span><span class="nf">IsCompatible</span><span class="p">(</span><span class="nx">executable</span><span class="p">)</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">          </span><span class="nx">assignedRunner</span><span class="w"> </span><span class="p">=</span><span class="w"> </span><span class="nx">runner</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">          </span><span class="k">break</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">       </span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">}</span><span class="w">    </span><span class="k">if</span><span class="w"> </span><span class="nx">assignedRunner</span><span class="w"> </span><span class="o">==</span><span class="w"> </span><span class="kc">nil</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">       </span><span class="k">return</span><span class="w"> </span><span class="nx">fmt</span><span class="p">.</span><span class="nf">Errorf</span><span class="p">(</span><span class="s">&#34;compatible runner not found for executable %s&#34;</span><span class="p">,</span><span class="w"> </span><span class="nx">executable</span><span class="p">.</span><span class="nf">ID</span><span class="p">())</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="k">if</span><span class="w"> </span><span class="nx">executable</span><span class="p">.</span><span class="nx">Timeout</span><span class="w"> </span><span class="o">==</span><span class="w"> </span><span class="mi">0</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">       </span><span class="k">return</span><span class="w"> </span><span class="nx">assignedRunner</span><span class="p">.</span><span class="nf">Exec</span><span class="p">(</span><span class="nx">ctx</span><span class="p">,</span><span class="w"> </span><span class="nx">executable</span><span class="p">,</span><span class="w"> </span><span class="nx">eng</span><span class="p">,</span><span class="w"> </span><span class="nx">inputEnv</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nx">done</span><span class="w"> </span><span class="o">:=</span><span class="w"> </span><span class="nb">make</span><span class="p">(</span><span class="kd">chan</span><span class="w"> </span><span class="kt">error</span><span class="p">,</span><span class="w"> </span><span class="mi">1</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="k">go</span><span class="w"> </span><span class="kd">func</span><span class="p">()</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">       </span><span class="nx">done</span><span class="w"> </span><span class="o">&lt;-</span><span class="w"> </span><span class="nx">assignedRunner</span><span class="p">.</span><span class="nf">Exec</span><span class="p">(</span><span class="nx">ctx</span><span class="p">,</span><span class="w"> </span><span class="nx">executable</span><span class="p">,</span><span class="w"> </span><span class="nx">eng</span><span class="p">,</span><span class="w"> </span><span class="nx">inputEnv</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">}()</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="k">select</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="k">case</span><span class="w"> </span><span class="nx">err</span><span class="w"> </span><span class="o">:=</span><span class="w"> </span><span class="o">&lt;-</span><span class="nx">done</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">       </span><span class="k">return</span><span class="w"> </span><span class="nx">err</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="k">case</span><span class="w"> </span><span class="o">&lt;-</span><span class="nx">time</span><span class="p">.</span><span class="nf">After</span><span class="p">(</span><span class="nx">executable</span><span class="p">.</span><span class="nx">Timeout</span><span class="p">):</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">       </span><span class="k">return</span><span class="w"> </span><span class="nx">fmt</span><span class="p">.</span><span class="nf">Errorf</span><span class="p">(</span><span class="s">&#34;timeout after %v&#34;</span><span class="p">,</span><span class="w"> </span><span class="nx">executable</span><span class="p">.</span><span class="nx">Timeout</span><span class="p">)</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="p">}</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><p>For testing, I use <a href="https://onsi.github.io/ginkgo/">ginkgo</a> for its expressive BDD-style syntax and <a href="https://github.com/uber-go/mock">GoMock</a> to generate a mock runner. This mock simulates serial and parallel execution without the complexity of managing real subprocesses or network calls. This approach has been invaluable for verifying complex concurrent behaviors, especially when testing features like timeout handling, parallel execution limits, and failure modes in a reliable, repeatable way.</p>
<h3 id="build-better-abstractions-with-service-layers">Build Better Abstractions with Service Layers</h3>
<p>When working with third-party modules or I/O components, wrapping your interaction with a service layer is invaluable. It keeps business logic decoupled from implementation details and simplifies testing and refactoring. In flow, I use this pattern extensively for components like shell operations, file system operations, and process management.</p>
<p>For example, my run service abstracts away the complexities of running shell operations with the <a href="https://github.com/mvdan/sh">github.com/mvdan/sh</a> library.  This means if I need to change how shell commands are executed or add new shell features, I only need to update the service implementation, not the core application logic. You can explore some of my service implementations in the <a href="https://github.com/jahvon/flow/tree/main/internal/services">source code</a>.</p>
<h3 id="good-tools-are-worth-the-investment">Good Tools Are Worth the Investment</h3>
<p>Investing in custom tooling or incoproating open source, especially for patterns like code generation, can significantly streamline your development workflow and reduce boilerplate. In flow, I define all types in YAML and use <a href="https://github.com/atombender/go-jsonschema">go-jsonschema</a> for <code>codegen</code>.</p>
<p>Here&rsquo;s an example of how my <code>Launch</code> executable type is defined:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-yaml" data-lang="yaml"><span class="line"><span class="cl"><span class="nt">LaunchExecutableType</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">type</span><span class="p">:</span><span class="w"> </span><span class="l">object</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">required</span><span class="p">:</span><span class="w"> </span><span class="p">[</span><span class="l">uri]</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">description</span><span class="p">:</span><span class="w"> </span><span class="l">Launches an application or opens a URI.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">  </span><span class="nt">properties</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">params</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	  </span><span class="nt">$ref</span><span class="p">:</span><span class="w"> </span><span class="s1">&#39;#/definitions/ParameterList&#39;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">args</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">$ref</span><span class="p">:</span><span class="w"> </span><span class="s1">&#39;#/definitions/ArgumentList&#39;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">app</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">type</span><span class="p">:</span><span class="w"> </span><span class="l">string</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">description</span><span class="p">:</span><span class="w"> </span><span class="l">The application to launch the URI with.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">default</span><span class="p">:</span><span class="w"> </span><span class="s2">&#34;&#34;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">uri</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">type</span><span class="p">:</span><span class="w"> </span><span class="l">string</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">description</span><span class="p">:</span><span class="w"> </span><span class="l">The URI to launch. This can be a file path or a web URL.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">default</span><span class="p">:</span><span class="w"> </span><span class="s2">&#34;&#34;</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">    </span><span class="nt">wait</span><span class="p">:</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">type</span><span class="p">:</span><span class="w"> </span><span class="l">boolean</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">description</span><span class="p">:</span><span class="w"> </span><span class="l">If set to true, the executable will wait for the launched application to exit before continuing.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">      </span><span class="nt">default</span><span class="p">:</span><span class="w"> </span><span class="kc">false</span><span class="w">
</span></span></span></code></pre></div><p>This generates both the Go type and its documentation:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-go" data-lang="go"><span class="line"><span class="cl"><span class="c1">// Launches an application or opens a URI.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="kd">type</span><span class="w"> </span><span class="nx">LaunchExecutableType</span><span class="w"> </span><span class="kd">struct</span><span class="w"> </span><span class="p">{</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="c1">// The application to launch the URI with.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">App</span><span class="w"> </span><span class="kt">string</span><span class="w"> </span><span class="s">`json:&#34;app,omitempty&#34; yaml:&#34;app,omitempty&#34; mapstructure:&#34;app,omitempty&#34;`</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="c1">// Args corresponds to the JSON schema field &#34;args&#34;.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">Args</span><span class="w"> </span><span class="nx">ArgumentList</span><span class="w"> </span><span class="s">`json:&#34;args,omitempty&#34; yaml:&#34;args,omitempty&#34; mapstructure:&#34;args,omitempty&#34;`</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="c1">// Params corresponds to the JSON schema field &#34;params&#34;.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">Params</span><span class="w"> </span><span class="nx">ParameterList</span><span class="w"> </span><span class="s">`json:&#34;params,omitempty&#34; yaml:&#34;params,omitempty&#34; mapstructure:&#34;params,omitempty&#34;`</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="c1">// The URI to launch. This can be a file path or a web URL.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">URI</span><span class="w"> </span><span class="kt">string</span><span class="w"> </span><span class="s">`json:&#34;uri&#34; yaml:&#34;uri&#34; mapstructure:&#34;uri&#34;`</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="c1">// If set to true, the executable will wait for the launched application to exit</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="c1">// before continuing.</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="w">	</span><span class="nx">Wait</span><span class="w"> </span><span class="kt">bool</span><span class="w"> </span><span class="s">`json:&#34;wait,omitempty&#34; yaml:&#34;wait,omitempty&#34; mapstructure:&#34;wait,omitempty&#34;`</span><span class="w">
</span></span></span><span class="line"><span class="cl"><span class="p">}</span><span class="w">
</span></span></span></code></pre></div><p>I&rsquo;ve also built a <code>docsgen</code> tool that uses this same schema to generate structured documentation. This means my types, code, and documentation all stay in sync automatically. You can see the generated type documentation for Launch <a href="https://flowexec.io/#/types/flowfile?id=executablelaunchexecutabletype">here</a>.</p>
<p>This investment in tooling has paid off repeatedly, especially as flow&rsquo;s type system has grown more complex. It reduces errors, ensures consistency, and lets me focus on implementing features rather than maintaining boilerplate code.</p>
<h2 id="the-road-ahead">The Road Ahead</h2>
<p>Looking forward, I&rsquo;m excited to explore building extensions around the flow CLI, from allowing users to BYO-vault to providing a local browser-based UI for executing workflows and discovering what&rsquo;s on your machine.</p>
<p>flow is a reflection of my passion for crafting tools that make developers&rsquo; lives easier. What started as a personal project has grown into something I believe can help other developers take control of their development experience. I invite you to <a href="https://flowexec.io/#/development">contribute</a>, star the <a href="https://github.com/jahvon/flow">repo</a> to show your support, and to open issues to report bugs or suggest features!</p>
]]></content:encoded>
    </item>
  </channel>
</rss>
