Running other people's templates safely with Twig's sandbox
CVolve imports CV templates from designers, JSON Resume themes and AI. Each one is compiled to Twig and rendered in a strict sandbox. Here is how.
A web studio for designers to create CV templates for CVolve: code editor, live A4 preview, imports, and an AI design assistant that uses your own key.
A CV template has to do more than look good. It has to handle a short CV and a long one. It has to break across pages cleanly, and work in English, German and right-to-left Arabic. It also has to stay usable when someone has twelve jobs instead of three.
CVolve Template Maker is a web studio built for exactly this job. Designers create templates for CVolve, test them against realistic CVs, and export a validated .cvolve package that installs in CVolve with one click.
The studio puts everything on one screen:
style.css, schema.json (which sections and fields the template supports) and manifest.json (name, fonts, page size and limits). Work is saved automatically.You can write templates in two ways. Mustache HTML uses simple placeholders such as {{header.name}}, so any HTML and CSS designer can start right away. Twig gives you full control. You can choose per project.
You do not have to start from a blank page. The maker can import:
.cvolve packages, including copies of CVolve's built-in presetsindex.html, stylesheets and fontsDescribe the design you want in a short brief, for example "a two-column layout with a navy sidebar, serif headings and a compact skills section". Your AI writes a complete template. The maker then checks it and, if something is wrong, gives the AI one automatic chance to fix it.
After that, the design assistant in the studio takes requests in plain language: "make the headings smaller", "move languages to the sidebar", "add more space between jobs". Every answer is a diff you review, then Apply or Discard. A revision is saved before each change, so nothing is ever lost.
Each designer connects their own AI accounts: Anthropic Claude, OpenAI, Google Gemini, Mistral, DeepSeek, xAI, a local Ollama model (no key needed), or any OpenAI-compatible service such as OpenRouter, Groq or LM Studio.
Keys are encrypted at rest with libsodium and are never shown again after you save them. Designers only ever see their own projects and connections.
The maker does not imitate CVolve's renderer. It uses the same code. The sandbox, validator, importers and renderer come from CVolve's shared template kit. If a template passes validation in the maker, it will install and render the same way in CVolve.
The finished workflow is simple:
.cvolve package and import it in CVolve.Revisions, font uploads (declared in the manifest automatically) and gallery thumbnails are built in.
The maker runs next to a copy of the CVolve repository, because it shares CVolve's template kit:
git clone https://github.com/future-site-ai/cvolve.git git clone https://github.com/future-site-ai/cvolve_template_maker.git cd cvolve_template_maker docker compose up -d --build
Then open http://localhost:8090. It is built with Symfony 7.4 LTS on PHP 8.3, PostgreSQL 16, CodeMirror 6 and Stimulus, with Neuron AI for the AI providers and Gotenberg for PDF previews and thumbnails.
CVolve Template Maker is free and open source under the MIT License.
Designers and developers are both welcome to contribute: bug reports, design feedback, documentation and code all help. Read the contributing guide and look for issues labelled good first issue.
If the project is useful to you, please star it on GitHub.
CVolve imports CV templates from designers, JSON Resume themes and AI. Each one is compiled to Twig and rendered in a strict sandbox. Here is how.