Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .almide-checksums.sha256
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
4c5ba89fdeabea7a07679795a714a5f840e1b4024205b1012554c580bb4820fe almide-linux-aarch64.tar.gz
9a723b256e85b48e36c1a1d6faab9a2d4154e71ea8c0f41b8d9534e2aea6ae50 almide-linux-x86_64.tar.gz
0432fe433bc56e3ce14dab7b5a2c6e4d5de9bb5c58cdb191da77b17181199921 almide-macos-aarch64.tar.gz
5cb07a8115410705249b2b5f46f73561aaa28a4356817e2b8815edbf7c9cace9 almide-macos-x86_64.tar.gz
1 change: 1 addition & 0 deletions .almide-release
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
v0.66.0
1 change: 0 additions & 1 deletion .almide-revision

This file was deleted.

3 changes: 3 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -15,3 +15,6 @@ node_modules
**/.env*
**/.dev.vars*
**/*.private.json
**/.terraform
**/*.tfstate*
**/*.tfvars
2 changes: 1 addition & 1 deletion .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:
cache: npm
- name: Install pinned Rust
run: rustup toolchain install 1.99.0 --profile minimal
- name: Build pinned Almide
- name: Install pinned Almide release
run: ./scripts/install-almide.sh
- run: npm ci
- run: npm run build
Expand Down
8 changes: 8 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -11,3 +11,11 @@ node_modules/
local.settings.json
.azure/
*.private.json
.terraform/
*.tfstate
*.tfstate.*
*.tfvars
!*.tfvars.example
.terraform.tfstate.lock.info
.terraform.lock.hcl
crash.log
10 changes: 6 additions & 4 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,13 +1,15 @@
# Exact Rust version and Almide commit; base-image digests are not locked yet.
FROM rust:1.99.0-bookworm AS build
# Exact Rust version and Almide release (checksum-verified); base-image digests are
# not locked yet. The release binary needs glibc 2.39+, hence Debian trixie. Native
# `almide build` emits Rust and compiles it with cargo, so the build stage keeps Rust.
FROM rust:1.99.0-trixie AS build
WORKDIR /work
COPY .almide-revision rust-toolchain.toml ./
COPY .almide-release .almide-checksums.sha256 rust-toolchain.toml ./
COPY scripts/install-almide.sh scripts/install-almide.sh
RUN ./scripts/install-almide.sh
COPY src/ src/
RUN mkdir build && .tools/bin/almide build src/native.almd -o build/server

FROM debian:bookworm-slim AS runtime
FROM debian:trixie-slim AS runtime
WORKDIR /app
COPY --from=build /work/build/server ./server
COPY LICENSE /app/LICENSE
Expand Down
62 changes: 37 additions & 25 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,39 +12,47 @@ every provider.

## Verified scope

Checked on **2026-10-04** against Almide commit
[`852b028a5706801fd008a753bcbdf8b3ea93156f`](https://github.com/almide/almide/commit/852b028a5706801fd008a753bcbdf8b3ea93156f)
(compiler reports `0.66.0 (dev)`). The exact source revision is in
[.almide-revision](.almide-revision). A released `0.66.0` binary is not assumed to
be the same compiler.
The compiler is the official Almide
[`v0.66.0`](https://github.com/almide/almide/releases/tag/v0.66.0) release binary
(`almide 0.66.0 (release, 819bbc74f)`), pinned by [.almide-release](.almide-release)
and the archive checksums in [.almide-checksums.sha256](.almide-checksums.sha256).
Results checked on **2026-10-04**. Most rows below were first established with a
source build of the earlier pin, commit
[`852b028`](https://github.com/almide/almide/commit/852b028a5706801fd008a753bcbdf8b3ea93156f)
(`0.66.0 (dev)`); after the switch, every local suite, Docker/Compose on macOS arm64
and on the ConoHa VPS, and GitHub Actions were rerun with the release binary.
Cloudflare and Google deployments have not been repeated with it.
See [verification notes](docs/verification.md#compiler-pin-moved-to-the-v0660-release).

| Route | Build / bundle | Shared API contract | Live cloud |
| --- | --- | --- | --- |
| Linux x86_64 native HTTP | Passed locally | 18 cases passed over HTTP | Not deployed |
| macOS arm64 native HTTP | Passed locally with the `--release` installer | 18 cases passed over HTTP | Not applicable |
| Wasm + generated JS, Node 24.19.0 | Passed locally | Same 18 cases + 1,000 repeated string calls | Not applicable |
| Workers, Wrangler 4.147.0 / local workerd | Dry-run bundle passed; real `wrangler deploy` uploaded | Same 18 cases passed over HTTP locally and on the workers.dev edge | Deployed temporarily to workers.dev, verified, deleted |
| ConoHa Docker / Compose | Image built and Compose started on Docker 29.6.1, linux/arm64 only | Same 18 cases passed against the container | Not deployed |
| ConoHa Docker / Compose | Image built and Compose started on macOS arm64 (Docker 29.6.1) and on a ConoHa VPS, x86_64 (Docker 29.2.1, Compose v5.0.2) | Same 18 cases passed against the container on both | VPS created with [Terraform](providers/conoha/terraform/), verified, destroyed |
| Google Cloud Run container | linux/amd64 image built (QEMU on Apple silicon), pushed by digest; `replace --dry-run` and deploy passed | Same 18 cases passed from a VM inside the VPC with an ID token | Deployed temporarily with internal ingress + IAM, verified, deleted |
| Azure Container Apps / ECS Fargate | Provider templates and local safety/shape checks passed; image not built for them | Shared native contract passed; provider runtime not run | Not deployed |
| AWS Lambda, Node 24 | Source package generated; adapter/config tests passed | 18 common cases, base64/event/HEAD/warm-call checks; staged package executed locally | Not deployed |
| Google Cloud Run functions, Node 24 | Source package, local Functions Framework, and managed source build via `deploy.sh --execute` | 18 direct adapter cases; in the cloud, 18 octet-stream cases passed and JSON showed the same 3 framework rejections as locally | Deployed temporarily with internal ingress + IAM, verified, deleted |
| Azure Functions v4, Node 24 | Source package, adapter/config tests and actual SDK request objects tested | 18 common cases; Functions host/key enforcement not run | Not deployed |

GitHub Actions (`ubuntu-24.04`, full bootstrap and every reproduction step) has
passed on this branch. See [verification notes](docs/verification.md) for exact
commands and limits.
GitHub Actions (`ubuntu-24.04`, compiler install and every reproduction step) has
passed. See [verification notes](docs/verification.md) for exact commands and limits.

## Quick start

Requires Linux or macOS, Git, Rust **1.99.0**, a C build toolchain, Bash, and Node
**22+**. Local evidence used Linux x86_64 with Node **24.19.0**, and macOS arm64
with Node **24.21.0** and **22.23.1**. Rust installation is a prerequisite; the
repository does not install it for you. `rust-toolchain.toml` selects 1.99.0 only
when `cargo` is the rustup proxy; a standalone `cargo` earlier on `PATH` ignores it.
Requires Linux (glibc 2.39+, e.g. Ubuntu 24.04 or Debian 13) or macOS, curl, Rust
**1.99.0**, a C build toolchain, Bash, and Node **22+**. Rust is still needed
because native `almide build` emits Rust and compiles it with cargo; the compiler
itself is downloaded. Local evidence used Linux x86_64 with Node **24.19.0**, and
macOS arm64 with Node **24.21.0** and **22.23.1**. Rust installation is a
prerequisite; the repository does not install it for you. `rust-toolchain.toml`
selects 1.99.0 only when `cargo` is the rustup proxy; a standalone `cargo` earlier
on `PATH` ignores it.

```sh
./scripts/install-almide.sh # builds the exact compiler commit; first build is substantial
./scripts/install-almide.sh # downloads the pinned release and checks its sha256 (seconds)
npm ci
npm run build
npm test
Expand Down Expand Up @@ -84,9 +92,10 @@ npm run dev:workers
Container templates use existing infrastructure and private/internal ingress;
function examples retain IAM or function-key authentication. They do not create
accounts or silently grant caller access. Read [deployment safety and cleanup](docs/deployment-safety.md)
before applying any example. The Cloudflare Workers, Google Cloud Run container and
Cloud Run functions examples have been deployed temporarily for verification and
then deleted; the other providers have not been deployed.
before applying any example. The Cloudflare Workers, Google Cloud Run container,
Cloud Run functions and ConoHa VPS examples have been deployed temporarily for
verification and then deleted; the AWS and Azure examples have not been deployed.
The ConoHa VPS itself is created by the optional [Terraform](providers/conoha/terraform/).

### Prepare and test function packages locally

Expand Down Expand Up @@ -149,13 +158,16 @@ custom WASI shim or a provider-specific compiler backend.

## Build discipline

The installer refuses modified or untracked compiler source without deleting edits.
Almide is pinned by full commit, Rust by exact version, Wrangler by exact version
and npm lockfile, and GitHub Actions by commit. Docker base images use explicit
version tags but are not digest-locked; this is not yet a fully hermetic build.
The installer downloads the release archive for the current platform and refuses
to unpack or install it unless its sha256 matches the committed checksum.
Almide is pinned by release tag and archive checksum, Rust by exact version,
Wrangler by exact version and npm lockfile, and GitHub Actions by commit. Docker
base images use explicit version tags but are not digest-locked; this is not yet
a fully hermetic build. To move to another release, update `.almide-release` and
copy that release's `almide-checksums.sha256` lines into `.almide-checksums.sha256`.
`ALMIDE_BIN=/absolute/path/to/almide npm run build` is available for local compiler
development, but bypasses the default revision-file check; record the source
revision yourself when using it.
development, but bypasses the default release check; record the compiler version
yourself when using it.

Generated Wasm/JS, executables, dependencies and local credentials are ignored.
Nothing in the default build/test workflow provisions cloud resources or deploys.
Expand All @@ -168,4 +180,4 @@ Copyright (c) 2026 Aid-On Inc.
Almide and other third-party tools and dependencies retain their own licenses.
This repository's MIT license does not relicense the pinned Almide compiler,
its runtime, generated third-party code, or npm dependencies. See the
[upstream Almide license at the pinned revision](https://github.com/almide/almide/blob/852b028a5706801fd008a753bcbdf8b3ea93156f/LICENSE).
[upstream Almide license at the pinned release](https://github.com/almide/almide/blob/v0.66.0/LICENSE).
77 changes: 68 additions & 9 deletions docs/verification.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@

Date: 2026-10-04 (UTC)

The compiler pin is now the official `v0.66.0` release binary; see
[Compiler pin moved to the v0.66.0 release](#compiler-pin-moved-to-the-v0660-release).
The sections before it record runs made with a source build of the earlier pin.

## Toolchain and source

- Almide source: `852b028a5706801fd008a753bcbdf8b3ea93156f`
Expand Down Expand Up @@ -184,11 +188,66 @@ Cloud Run functions:
(invalid JSON, body limit, trailing text) failed, matching the local record
4. 403 without a token from the VPC; 404 with a valid token from the internet

## Compiler pin moved to the v0.66.0 release

Building the compiler from source dominated every build: about 7.5 minutes on an
Apple silicon Mac, and 5m46s of a 7m18s `docker compose build` on a 4-core VPS.
The official `v0.66.0` release (2026-10-03) ships linux x86_64/aarch64 and macOS
binaries with a checksum file, so the pin moved from source commit `852b028` to
that release. Its tag commit `819bbc7` and `852b028` have diverged (30 and 155
commits apart), so it is a different compiler and was re-verified:

1. `install-almide.sh` downloads the platform archive and installs it only if its
sha256 matches `.almide-checksums.sha256` (copied from the release's
`almide-checksums.sha256`). 2.4 seconds on macOS arm64
2. The installer tests stub only the download: a matching archive installs
`almide` and `almide-verify`; a wrong checksum installs nothing; a malformed
tag is refused before any download
3. macOS arm64, Node 24.21.0: `npm test` 117/117, `test:workers` 19/19,
`test:google-framework` 39/39, `test:staged-functions` 38/38. App build 7 s
4. The release binary needs glibc 2.39+, so it fails on Debian bookworm; the
Dockerfile moved to `rust:1.99.0-trixie` / `debian:trixie-slim`. Native
`almide build` still emits Rust and runs cargo (it fails without cargo), so
the build stage keeps Rust
5. macOS arm64 `docker build`: 10 s with cached base images; Compose and the 18
cases passed, read-only root filesystem and UID 65532 retained
6. ConoHa VPS x86_64 (below): 91 s including base-image pulls, 24 s with
`--no-cache`; 18 cases passed

The earlier Cloudflare and Google deployments used the source-built compiler and
were not repeated with the release binary. License texts are identical at both pins.

## ConoHa VPS

Date: 2026-10-04. Created with [providers/conoha/terraform](../providers/conoha/terraform/)
(Terraform 1.14.9, the Aid-On fork of the conohavps provider at `ff59ace`, built
locally and used through `dev_overrides`), region c3j1.

1. `terraform plan`: 5 to add (server, boot volume, key pair, security group, one
SSH rule from the operator's /32). Existing servers, keys and groups in the
account were not in the plan and were unchanged afterwards
2. `terraform apply`: 1m10s. `g2l-t-c4m4`, `vmi-docker-29.2-ubuntu-24.04-amd64`:
Ubuntu 24.04.4, x86_64, 4 vCPU, 3.8 GiB, Docker 29.2.1, Compose v5.0.2. The
account's second server was accepted
3. First boot ran unattended upgrades through cloud-init for about 15 minutes;
the build waited for `cloud-init status --wait`
4. ConoHa README commands from a clone of the repository:
- with the source-build installer (main at `42cecaa`): build 7m18s (compiler
5m46s); `/health`, `/greet` and the 18 cases passed
- with the release installer (`4f72f7b`): build 91 s including base-image
pulls, 24 s with `--no-cache`; the 18 cases passed
5. The 18 cases ran from the Mac through `ssh -L` to the VPS loopback. The app
listened only on `127.0.0.1:8080`; port 8080 on the public address was not
reachable. The container ran as 65532 with a read-only root filesystem and
`CapDrop=[ALL]`; `docker compose down` took 0.5 s
6. `terraform destroy` removed all 5 resources; the VPS existed about 23 minutes

## Not established

- x86_64 Compose startup or native x86_64 Docker build (the amd64 image was
built and run only under QEMU, and run on Cloud Run)
- A ConoHa VPS installation, ingress, TLS, restart behavior or production load
- Native x86_64 Docker build outside the ConoHa VPS
- ConoHa TLS/reverse proxy, restart behavior, production load, or plans smaller
than `g2l-t-c4m4`
- Cloudflare and Google deployments with the release compiler
- Azure Container Apps or ECS Fargate provider validation/deployment
- Lambda managed runtime or Azure Functions host execution/authentication
- Google Cloud costs, load, cold-start latency or long-running behavior
Expand All @@ -214,12 +273,12 @@ npm run test:google-framework
npm run test:staged-functions
```

For a future Docker gate, run the Compose commands in the ConoHa README on a
machine with Docker and verify `/health` and `/greet` before marking the route
container-tested. Deployments require a separate, explicit decision.
For a Docker gate, run the Compose commands in the ConoHa README on a machine with
Docker and verify `/health` and `/greet`. Deployments require a separate,
explicit decision.

## Upstream references

- [HTTP server semantics at the pin](https://github.com/almide/almide/blob/852b028a5706801fd008a753bcbdf8b3ea93156f/docs/stdlib/http.md)
- [Generated JS host at the pin](https://github.com/almide/almide/blob/852b028a5706801fd008a753bcbdf8b3ea93156f/src/cli/js_host.rs)
- [JS host contract at the pin](https://github.com/almide/almide/blob/852b028a5706801fd008a753bcbdf8b3ea93156f/docs/wasm/WASM-OUTPUT.md)
- [HTTP server semantics at the pin](https://github.com/almide/almide/blob/v0.66.0/docs/stdlib/http.md)
- [Generated JS host at the pin](https://github.com/almide/almide/blob/v0.66.0/src/cli/js_host.rs)
- [JS host contract at the pin](https://github.com/almide/almide/blob/v0.66.0/docs/wasm/WASM-OUTPUT.md)
3 changes: 2 additions & 1 deletion licenses/README.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,8 @@
# Third-party notices

The files `Almide-MIT.txt` and `Almide-APACHE.txt` reproduce the license texts from
[Almide at the compiler revision pinned by this repository](https://github.com/almide/almide/tree/852b028a5706801fd008a753bcbdf8b3ea93156f).
[Almide at the release pinned by this repository](https://github.com/almide/almide/tree/v0.66.0)
(identical to those at the earlier source pin `852b028`).
Almide is offered under MIT or Apache-2.0, at the recipient's option. These notices
accompany the generated Wasm packages; our root MIT license does not replace them.

Expand Down
4 changes: 2 additions & 2 deletions providers/azure-container-apps/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -95,8 +95,8 @@ Use the returned SHA-256 digest, removing only the `sha256:` prefix, for the
tag. Confirm that this digest identifies the tested amd64 image. ARM's length
constraints do not prove the digest exists or validate its architecture.

The shared image runs as UID/GID 65532 and uses `PORT=8080`. Its compiler build is
substantial; build on a suitably sized machine. Explicit `--platform` matters
The shared image runs as UID/GID 65532 and uses `PORT=8080`. Its build downloads
the pinned compiler and compiles only the app. Explicit `--platform` matters
on ARM laptops. Base images currently use version tags, so pinning the deployed
image digest does not make source rebuilds fully hermetic.

Expand Down
Loading
Loading