CLI Commands
The tsdevstack CLI handles project management, code generation, and deployment workflows.
Installation
The CLI is installed as a project devDependency (@tsdevstack/cli). Run commands with npx tsdevstack (or npx tsds) from your project root.
Local Development Commands
sync
Regenerate all framework-managed configuration files. This is the most frequently used command.
What it generates:
kong.tsdevstack.yml- Gateway routes from OpenAPI specsdocker-compose.yml- Container orchestration with injected secrets.secrets.tsdevstack.json- Framework secrets.secrets.local.json- Merged secrets for local development
When to run:
- After adding or removing services
- After changing OpenAPI decorators
- After modifying
.tsdevstack/config.json - After pulling changes that modify service structure
add-service
Add a new application to the monorepo.
Types:
Example:
remove-service
Remove a service from the local project.
Removes the service directory and updates .tsdevstack/config.json. If no service name is provided, prompts for selection.
generate-kong
Generate Kong gateway configuration from OpenAPI specs.
Generates kong.tsdevstack.yml with exact routes derived from your service OpenAPI specifications, merges it with kong.user.yml into kong.yml, and writes the gateway image build context in infrastructure/kong/ (generated Dockerfile, .dockerignore, and a staged copy of the framework plugins and your kong-plugins/). Rebuild the gateway afterwards with docker compose up -d --build gateway, or use sync, which does both. See Kong Plugins.
Partner services get the API key check and the per-IP ceiling (framework.apiKeys.ipLimitPerMinute in .tsdevstack/config.json); the default key limits are copied from the global rate-limiting in kong.user.yml. It warns about consumers with keyauth_credentials in kong.user.yml, which no longer work. See API Keys.
generate-secrets
Generate secrets for local development.
Creates:
.secrets.tsdevstack.json- Framework-generated secrets (JWT keys, database passwords, etc.).secrets.user.json- Your custom secrets (preserved across regeneration).secrets.local.json- Merged result used by docker-compose
generate-docker-compose
Generate docker-compose.yml with injected secrets.
generate-client
Generate TypeScript API client from OpenAPI spec.
Creates a typed API client package in packages/ that frontends can import.
validate-service
Validate a service follows naming conventions and structure.
Worker Commands
register-detached-worker
Register a worker for separate container deployment.
unregister-detached-worker
Remove a detached worker registration.
Storage Commands
add-bucket-storage
Add an object storage bucket to the project.
What it does:
- Adds bucket to
storage.bucketsinconfig.json - Regenerates
docker-compose.ymlwith MinIO (first bucket adds MinIO container + minio-init job) - Regenerates secrets with
STORAGE_ENDPOINT,STORAGE_ACCESS_KEY,STORAGE_SECRET_KEY,STORAGE_BUCKET_{NAME}
Options:
Example:
After adding, run docker compose up -d to start MinIO. Console at http://localhost:9001 (minioadmin/minioadmin).
remove-bucket-storage
Remove a storage bucket from the project.
Removes the bucket from config.json and regenerates docker-compose and secrets. If no name is provided, prompts for selection. Does not delete local MinIO data or cloud resources.
Options:
Messaging Commands
add-messaging-topic
Add an async messaging topic to the project.
What it does:
- Adds topic to
messaging.topicsinconfig.json - Validates name (kebab-case, no duplicates)
- Validates publisher/subscriber service names exist and are NestJS type
- Runs
sync
Options:
Example:
remove-messaging-topic
Remove a messaging topic from the project.
Removes the topic from config.json and runs sync. Does not delete stream data in Redis.
Options:
update-messaging-topic
Update publishers and subscribers for an existing topic.
Options:
--publishers and --subscribers use replace semantics — always pass the complete desired list, not just additions.
Cloud Secrets Commands
cloud:init
Initialize cloud secrets provider integration.
cloud-secrets:push
Push local secrets to cloud environment.
cloud-secrets:diff
Compare local and cloud secrets.
cloud-secrets:set
Set or update a secret in cloud.
cloud-secrets:get
Get a secret value from cloud.
cloud-secrets:list
List all secrets in cloud environment.
cloud-secrets:remove
Remove a secret from cloud.
Infrastructure Commands
All infrastructure commands use the infra: prefix and require cloud credentials (except CI commands — see below).
Note: Environment names (e.g., dev, staging, prod) are user-defined based on your cloud credentials configuration. The framework does not enforce specific environment names.
infra:bootstrap
Bootstrap GCP project (enable APIs, add roles to service account).
infra:init
Initialize infrastructure (creates Terraform state bucket).
infra:generate
Generate Terraform files.
With the auth template, it warns when the environment's scheduledJobs lack the sync-api-key-usage job and prints the entry to add. See API Keys.
infra:plan
Show planned infrastructure changes.
infra:deploy
Deploy full infrastructure: base + services + Kong + load balancer.
infra:destroy
Destroy infrastructure.
infra:deploy-service
Build, push, and deploy a single service.
infra:deploy-services
Build, push, and deploy all services in parallel.
infra:remove-service
Remove a service from cloud (deletes Cloud Run, secrets, database, etc.).
infra:deploy-kong
Deploy Kong Gateway to Cloud Run.
infra:deploy-lb
Deploy External HTTP(S) Load Balancer for Kong Gateway.
infra:init-ci
Initialize CI/CD (generates GitHub Actions workflows). No cloud credentials required.
Options:
NPM_TOKEN
If your project root has an .npmrc, generated workflows automatically include a job-level env: NPM_TOKEN: ${{ secrets.NPM_TOKEN }} block (single global secret, not per-env) so private npm packages can be installed in CI. See CI/CD Setup — Private npm packages.
infra:generate-ci
Regenerate CI workflows from ci.json. No cloud credentials required.
NPM_TOKEN
Like init-ci, this re-emits the NPM_TOKEN env block into every workflow if .npmrc exists at the project root. Re-run after creating an .npmrc to wire private-registry auth through the workflows.
infra:status
Check infrastructure configuration status.
infra:list-deployed
List all deployed services in an environment.
infra:service-status
Check cloud resource status for a specific service.
Database Migration Commands
infra:plan-db-migrate
Show pending database migrations for a service.
The --service flag is required. It specifies which service's database to check.
infra:run-db-migrate
Apply pending database migrations.
The --service flag is required. It specifies which service's database to migrate.
Scheduled Jobs Commands
The scheduler commands work across all providers, but each provider uses a different underlying service:
infra:deploy-scheduler
Deploy a single scheduled job.
infra:deploy-schedulers
Deploy all scheduled jobs.
infra:list-schedulers
List scheduled jobs and their deployment status.
infra:remove-scheduler
Remove a scheduled job.
Advanced Infrastructure Commands
These commands are typically called internally by higher-level commands but can be used directly for debugging or custom workflows.
infra:generate-docker
Generate Dockerfiles for services.
If .npmrc exists at the project root, generated Dockerfiles include .npmrc in the deps-stage COPY and emit a BuildKit env-source secret mount on npm ci (--mount=type=secret,id=npm_token,env=NPM_TOKEN). See CI/CD Setup — Private npm packages.
infra:build-docker
Build Docker images with BuildKit.
NPM_TOKEN
If .npmrc exists at the project root, the docker build invocation appends --secret id=npm_token,env=NPM_TOKEN automatically. Make sure NPM_TOKEN is exported in your shell (export NPM_TOKEN=… or ~/.zshrc) before running.
infra:push-docker
Push Docker images to container registry.
infra:generate-kong
Generate Kong configuration for cloud deployment (infrastructure/kong/{env}/kong.yml, with secret placeholders; commit it).
infra:build-kong
Build and push the Kong Docker image for an environment: the same image definition as locally, with the framework plugins, your kong-plugins/ and the resolved config baked in. Deploy it with infra:deploy-kong.
infra:remove-detached-worker
Remove orphaned detached workers from cloud.
Development npm Scripts
These npm scripts are available in your project root:
To stop services, press Ctrl+C in the terminal running npm run dev, or use docker compose down to stop containers.