// the find
ovh/utask
µTask is an automation engine that models and executes business processes declared in yaml. ✏️📋
µTask is a Go-based workflow engine that runs business processes described as YAML templates, backed by nothing but Postgres. It's aimed at ops/platform teams who need auditable, resumable multi-step automation — cert provisioning, employee onboarding, approval flows — without standing up a full orchestration stack.
Single dependency (Postgres) with no external scheduler or broker — multiple instances coordinate task ownership through row locking in the DB, which is a genuinely simple operational story. The step model supports pre-hooks, custom states, foreach loops, and conditional state transitions, so you can express real branching logic (404 vs 200 handling, human approval steps via resolver_inputs) declaratively. Built-in plugins cover the common ops surface out of the box: http, ssh, email, Slack/Opsgenie/webhook notifications, and subtask/batch spawning for composing workflows. Data-at-rest encryption with a documented key-rotation procedure is a level of care most side-project automation tools skip entirely.
The vanilla build has no authentication of its own — it trusts an x-remote-user header from a reverse proxy, and the one built-in alternative (basic-auth via configstore) is explicitly documented as not for production, so you're on your own for a real auth layer. Variable expressions use otto for JS evaluation, which is an ES5-only interpreter with a slow/no-maintenance history — anyone expecting real Node-like semantics in template expressions will hit gaps. Action plugins are loaded as compiled .so files, which ties custom extensions to matching Go compiler versions and Linux, and produces classic 'plugin failed to load' failures when core and plugin builds drift. The templating DSL (conditions, custom_states, dependency state-qualifiers like step:STATE) is powerful but has a steep authoring curve, and there's no static validation beyond JSON-schema checks on step output — mistakes surface at runtime.