Everything in the last three lessons, a vanilla MVC app, a ColdBox app, or an FW/1 app, needs somewhere to actually run. CommandBox is the standard way to get a CFML server running locally without installing Adobe ColdFusion or Lucee by hand, and it doubles as a package manager and automation shell.
Learning Objectives
After completing this lesson, you'll be able to:
- Initialize a project and understand what box.json tracks.
- Start an embedded server running a specific CFML engine and version.
- Install and manage packages through ForgeBox.
- Scaffold ColdBox boilerplate and run quick CFML snippets from the CLI.
How CommandBox Fits Together
box Launches the Shell
the interactive CommandBox CLI
init Creates box.json
tracks metadata and dependencies
server start Runs the App
embedded server, any engine/version
install Pulls Packages
from ForgeBox
Installing and Initializing a Project
# install CommandBox, then launch the interactive shell box # inside a project folder, create box.json init
box.json tracks a project's metadata and dependencies, similar in spirit to package.json in a Node project.
Running an Embedded Server
CommandBox's built-in server means you don't need Adobe ColdFusion or Lucee installed manually, just specify which engine and version you want.
# defaults to the latest stable Lucee if no engine is specified server start # or specify an exact engine and version server start engine=adobe@2023 server start engine=lucee@6 server stop server status
Package Management with ForgeBox
ForgeBox is the CFML community's package repository, and CommandBox is its client. Frameworks, libraries, and ColdBox modules are all installed the same way.
install coldbox install cbvalidation@3.0.0 uninstall coldbox
Scaffolding ColdBox Code
coldbox create app myApp coldbox create handler name=Users
This is the same scaffolding mentioned in the ColdBox Overview lesson, CommandBox is what actually runs it.
Useful CLI Shortcuts
| Command | Does |
|---|---|
| repl | Opens a REPL for running quick CFML snippets directly, without a full request |
| !<command> | Runs a native OS shell command from inside the CommandBox shell, e.g. !git status |
A Real Detail: CommandBox Also Ships an Official Docker Image
CommandBox isn't only a local development tool, Ortus publishes an official Docker image too, configured through the same box.json already used for local dependencies. Worth knowing about before the next lesson's coverage of CAR files and EAR/WAR archives, a containerized deployment is a third real option alongside those.
Common Beginner Mistakes
Assuming server start always uses Adobe ColdFusion
It defaults to the latest stable Lucee unless an engine is specified explicitly with engine=adobe@<version> or engine=lucee@<version>.
Installing a package without checking box.json afterward
install adds the dependency to box.json, worth checking that it landed there (and at the version expected) rather than assuming it worked silently.
Not realizing ! runs a real OS command, not a CommandBox command
The exclamation-mark prefix hands the rest of the line straight to the underlying operating system shell, it's a convenience for staying inside the CommandBox session, not a CommandBox-specific feature itself.
Best Practices
- Commit box.json (and its lockfile) so teammates install the exact same dependency versions.
- Pin specific package versions (install cbvalidation@3.0.0) for anything going to production, rather than always installing latest.
- Use server start engine=... explicitly in a project that needs to match a specific production CFML engine and version, rather than relying on the default.
Interview Questions
What does CommandBox's embedded server actually remove the need for?
Installing Adobe ColdFusion or Lucee manually on a development machine. server start spins up a servlet container running whichever engine and version you specify, directly from the project folder.
What is ForgeBox, and what's its relationship to CommandBox?
ForgeBox is the CFML community's package repository. CommandBox is the client used to install, update, and remove packages from it, frameworks, libraries, and ColdBox modules all included.
What does box.json track, and why does it matter for a team?
A project's metadata and dependencies. Committing it means every teammate (and the CI pipeline) installs the exact same dependency set, rather than whatever happened to be installed locally.
Summary
In this lesson, you initialized a project with box.json, ran an embedded server for a specific CFML engine and version, installed packages through ForgeBox, scaffolded ColdBox boilerplate, and used the repl and ! shortcuts for quick CFML snippets and native OS commands.
What's Next?
The next lesson covers actually deploying a ColdFusion application beyond local development.