Repository navigation
Releases: pardnchiu/HakoRun
Release list
v0.7.0
v0.6.0 -> v0.7.0
Summary
Rebrands the project as HakoRun and makes an embedded store the default, moving the previous store behind a build flag. Extends sandboxed execution to macOS and fixes resource caps that never took effect. Documentation is regenerated around the self-hosted FaaS positioning.
翻譯
專案更名為 HakoRun,預設改用內嵌儲存,原儲存後端改由建置旗標啟用。沙箱執行擴展至 macOS,並修正資源上限從未生效的問題。文件依自架 FaaS 定位重新產生。
⚠️ Breaking Changes
Module path renamed to github.com/pardnchiu/HakoRun
Before:
module github.com/pardnchiu/go-faas
After:
module github.com/pardnchiu/HakoRun
Migration:
git remote set-url origin https://github.com/pardnchiu/HakoRun.git
git pull翻譯
Go module 路徑改為 github.com/pardnchiu/HakoRun;既有 clone 需更新 remote。專案僅含 main 與 internal package,無外部 import 需修改。
Default script store switched from Redis to ToriiDB
Before: every build connected to Redis via REDIS_* and stored scripts there.
After: the default build stores scripts in ToriiDB at ~/.config/pardnchiu/hakorun; Redis is used only when built with -tags redis. Scripts already in Redis are not visible to the default build.
Migration:
# keep using existing Redis data
make build redis # go build -tags redis -o bin/hako ./cmd/api
# or move to ToriiDB: re-upload each script with POST /upload on the default build
make build翻譯
預設儲存由 Redis 改為 ToriiDB(~/.config/pardnchiu/hakorun),Redis 僅在 -tags redis 建置時使用;既有 Redis 中的腳本在預設建置下看不到。要沿用 Redis 資料請以 make build redis 建置,否則需在預設建置下重新上傳腳本。
package.json removed; TypeScript dependencies installed manually
Before: npm install in the repo installed esbuild.
After: the repo has no package.json.
Migration:
npm install -g tsx typescript esbuild
npm install esbuild # in the project root, resolved by the TypeScript wrapper翻譯
移除 package.json,TypeScript 執行需求改為手動安裝:全域 tsx、typescript、esbuild,以及專案根目錄的本地 esbuild。
Changes
BREAKING
- Rename the Go module to
github.com/pardnchiu/HakoRunand the build output tobin/hako(@pardnio) [81c18d6, 73d5f02] - Switch the default script store to ToriiDB behind a shared backend interface; Redis via
-tags redis(@pardnio) [81c18d6, 73d5f02] - Remove
package.json; TypeScript runtime dependencies are installed manually (@pardnio) [3b5ef44]
翻譯
- Go module 改名為
github.com/pardnchiu/HakoRun,建置產物改為bin/hako - 預設儲存改為 ToriiDB 並抽出共用 backend 介面;Redis 改由
-tags redis啟用 - 移除
package.json,TypeScript 執行依賴改為手動安裝
FEAT
- Add macOS support: sandbox scripts with a
sandbox-execseatbelt profile, with no-op dependency check and slice setup on darwin (@pardnio) [78cfbf7]
翻譯
- 新增 macOS 支援:以
sandbox-execseatbelt profile 隔離腳本,darwin 上相依檢查與 slice 建立為 no-op
FIX
- Name the systemd slice unit
hakorun.slicesoMAX_CPUS/MAX_MEMORYcaps are actually loaded; the oldgo-faas-slicefile lacked the.slicesuffix and was ignored by systemd (@pardnio) [81c18d6, 78cfbf7]
翻譯
- systemd slice 單元改名為
hakorun.slice,讓MAX_CPUS/MAX_MEMORY上限確實生效;舊檔go-faas-slice缺.slice副檔名,systemd 不會載入
ADD
翻譯
- 新增
Makefile,提供build/run/test目標與redis切換
CHORE
- Require Go 1.25; add
github.com/pardnchiu/ToriiDB, dropgithub.com/joho/godotenv(@pardnio) [73d5f02] - Update
.gitignoreand removecover.png(@pardnio) [73d5f02, 04d0a6b, 3b5ef44]
翻譯
- 要求 Go 1.25;新增
github.com/pardnchiu/ToriiDB,移除github.com/joho/godotenv - 更新
.gitignore並移除cover.png
Scope
go.mod,go.sum— BREAKING, CHOREcmd/api/— BREAKINGinternal/database/— BREAKING (database.go,toriidb.go,redis.go,backend_toriidb.go,backend_redis.go)internal/sandbox/— FEAT, FIX (multiple files)internal/checker/— FEAT (checker.go,checker_darwin.go)internal/handler/,internal/router.go— BREAKINGMakefile— ADDpackage.json,package-lock.json— BREAKINGREADME.md,doc/— DOC.gitignore,.env.example,cover.png— CHORE
Generated by SKILL
v0.6.0
v0.5.2 -> v0.6.0
Summary
Add automatic dependency checker that detects OS distribution and installs required packages (bubblewrap, nodejs, npm, python3) on startup.
翻譯
新增啟動時自動偵測作業系統並安裝所需相依套件 (bubblewrap, nodejs, npm, python3) 的檢查機制Changes
FEAT
- Add
internal/checkerpackage with OS detection via/etc/os-release - Support multiple Linux distributions: Ubuntu, Debian, Rocky Linux, Alma Linux, Fedora, RedHat, Arch Linux, Alpine Linux
- Auto-install missing dependencies using appropriate package manager (apt, dnf, pacman, apk)
- Check for Node.js, TypeScript, esbuild, and Python on startup
翻譯
- 新增
internal/checker套件,透過/etc/os-release偵測作業系統 - 支援多種 Linux 發行版:Ubuntu、Debian、Rocky Linux、Alma Linux、Fedora、RedHat、Arch Linux、Alpine Linux
- 使用對應套件管理器 (apt, dnf, pacman, apk) 自動安裝缺失的相依套件
- 啟動時檢查 Node.js、TypeScript、esbuild 和 Python 是否已安裝
Files Changed
| File | Status | Tag |
|---|---|---|
cmd/api/main.go |
Modified | FEAT |
internal/checker/checker.go |
Added | FEAT |
Generated by SKILL
v0.5.2
v0.5.1 -> v0.5.2
Summary
Replaced per-execution resource limits with centralized systemd slice management and removed Podman container dependencies, transitioning to a pure bubblewrap sandbox architecture.
翻譯
以集中式 systemd slice 取代逐次執行的資源限制設定,並移除 Podman 容器依賴,轉換為純 bubblewrap 沙箱架構。Changes
REFACTOR
- Replace per-process systemd-run resource properties with shared
go-faas-sliceunit for centralized CPU/memory limits - Remove commented-out container pool initialization code in main.go
- Remove utils import from command.go (no longer needed for inline resource config)
翻譯
- 以共用的
go-faas-slice單元取代逐次執行的 systemd-run 資源屬性,集中管理 CPU/記憶體限制 - 移除 main.go 中已註解的容器池初始化程式碼
- 移除 command.go 中的 utils import(不再需要內聯資源配置)
ADD
- Add
internal/sandbox/slice.goto create and manage systemd user slice with configurable CPU/memory limits
翻譯
- 新增
internal/sandbox/slice.go建立並管理具有可配置 CPU/記憶體限制的 systemd user slice
REMOVE
- Delete
Dockerfile.runtime(standard runtime container) - Delete
Dockerfile.runtime.gpu(CUDA-enabled runtime container)
翻譯
- 刪除
Dockerfile.runtime(標準執行環境容器) - 刪除
Dockerfile.runtime.gpu(CUDA 執行環境容器)
UPDATE
- Simplify
.env.exampleby removing container-specific variables (MAX_CONTAINERS, GPU_ENABLED, etc.)
翻譯
- 簡化
.env.example,移除容器相關變數(MAX_CONTAINERS、GPU_ENABLED 等)
Files Changed
| File | Status | Tag |
|---|---|---|
.env.example |
Modified | UPDATE |
Dockerfile.runtime |
Deleted | REMOVE |
Dockerfile.runtime.gpu |
Deleted | REMOVE |
README.md |
Modified | DOC |
README.zh.md |
Modified | DOC |
cmd/api/main.go |
Modified | REFACTOR |
internal/sandbox/command.go |
Modified | REFACTOR |
internal/sandbox/slice.go |
Added | ADD |
Generated by SKILL
v0.5.1
v0.5.0 -> v0.5.1
Summary
Remove Podman container dependency and refactor to use bubblewrap sandbox with enhanced security hardening including network isolation and capability restrictions.
翻譯
移除 Podman 容器相依性,重構為使用 bubblewrap 沙箱執行,並強化安全設定包括網路隔離與權限限制。Changes
REFACTOR
- Remove entire
internal/container/package (build, container, health, operator) - Consolidate
RunBodyandRunNowBodystructs into singleRunBody - Extract
getRunBody(),getCodeMaxSize(),run(),setStream()helper functions - Remove commented-out Podman execution code from handlers
翻譯
- 移除整個
internal/container/套件(build、container、health、operator) - 合併
RunBody與RunNowBody結構為單一RunBody - 抽離
getRunBody()、getCodeMaxSize()、run()、setStream()輔助函式 - 移除 handlers 中已註解的 Podman 執行程式碼
SECURITY
- Enable network isolation with
--unshare-net(previously--share-net) - Add
--new-sessionto prevent TTY hijacking - Add
--cap-drop ALLto remove all capabilities - Remove
/binand/sbinbind mounts to reduce attack surface - Add sandbox home directory
/home/sandboxwith tmpfs - Clear sensitive environment variables (
LD_PRELOAD,LD_LIBRARY_PATH) - Set explicit locale and temp directory environment
翻譯
- 啟用網路隔離
--unshare-net(原為--share-net) - 新增
--new-session防止 TTY 劫持 - 新增
--cap-drop ALL移除所有 capabilities - 移除
/bin與/sbin綁定掛載以縮小攻擊面 - 新增沙箱家目錄
/home/sandbox使用 tmpfs - 清除敏感環境變數(
LD_PRELOAD、LD_LIBRARY_PATH) - 設定明確的語系與暫存目錄環境變數
Files Changed
| File | Status | Tag |
|---|---|---|
internal/container/build.go |
Deleted | REFACTOR |
internal/container/container.go |
Deleted | REFACTOR |
internal/container/health.go |
Deleted | REFACTOR |
internal/container/operator.go |
Deleted | REFACTOR |
internal/handler/run.go |
Modified | REFACTOR |
internal/handler/sse.go |
Modified | REFACTOR |
internal/sandbox/command.go |
Modified | SECURITY |
.gitignore |
Modified | CHORE |
package-lock.json |
Added | CHORE |
Generated by SKILL
v0.5.0
v0.4.3 -> v0.5.0
Summary
Replace Podman container isolation with bubblewrap (bwrap) sandbox for script execution, implementing systemd-run resource limits and graceful shutdown mechanism.
翻譯
以 bubblewrap (bwrap) 沙箱取代 Podman 容器隔離執行腳本,實作 systemd-run 資源限制與 graceful shutdown 機制。Changes
FEAT
- Add bubblewrap sandbox execution with namespace isolation (unshare-all, share-net)
- Implement systemd-run resource limits (CPUQuota, MemoryMax, MemorySwapMax)
- Support Python, JavaScript, TypeScript runtime via wrapper scripts
翻譯
- 新增 bubblewrap 沙箱執行,支援命名空間隔離 (unshare-all, share-net)
- 實作 systemd-run 資源限制 (CPUQuota, MemoryMax, MemorySwapMax)
- 支援 Python、JavaScript、TypeScript 執行環境透過 wrapper 腳本
REFACTOR
- Remove Podman container pool dependency, comment out container package code
- Restructure main.go with proper graceful shutdown using context timeout
- Simplify router to return
*http.Serverfor external lifecycle control
翻譯
- 移除 Podman 容器池依賴,註解 container 套件程式碼
- 重構 main.go 實作 graceful shutdown,使用 context timeout
- 簡化 router 回傳
*http.Server以支援外部生命週期控制
UPDATE
- Rename environment variables:
MAX_CPUS_PER_CONTAINER→MAX_CPUS,MAX_MEMORY_PER_CONTAINER→MAX_MEMORY - Change memory format from bytes to human-readable (e.g.,
128M)
翻譯
- 重新命名環境變數:
MAX_CPUS_PER_CONTAINER→MAX_CPUS,MAX_MEMORY_PER_CONTAINER→MAX_MEMORY - 記憶體格式從 bytes 改為人類可讀格式(如
128M)
Files Changed
| File | Status | Tag |
|---|---|---|
internal/sandbox/command.go |
Added | FEAT |
cmd/api/main.go |
Modified | REFACTOR |
internal/router.go |
Modified | REFACTOR |
internal/handler/run.go |
Modified | REFACTOR |
internal/handler/sse.go |
Modified | REFACTOR |
internal/container/build.go |
Modified | REFACTOR |
internal/container/container.go |
Modified | REFACTOR |
internal/container/health.go |
Modified | REFACTOR |
internal/container/operator.go |
Modified | REFACTOR |
.env.example |
Modified | UPDATE |
README.md |
Modified | DOC |
README.zh.md |
Modified | DOC |
cover.png |
Modified | CHORE |
package.json |
Added | CHORE |
.gitignore |
Modified | CHORE |
Generated by SKILL
v0.4.3
Summary
Refactored container management module with unified function and variable naming conventions, extracted container startup parameters into standalone function, and increased default CPU limit from 0.25 to 1.0.
REFACTOR
- Extracted
argsForRunfunction to unify container startup parameter handling
UPDATE
- Increased
MAX_CPUS_PER_CONTAINERdefault value from 0.25 to 1.0
Summary
重構容器管理模組,統一函式與變數命名規範,提取容器啟動參數為獨立函式,並調整預設 CPU 限制從 0.25 提升至 1.0。
REFACTOR
- 提取
argsForRun函式統一處理容器啟動參數 - 移除容器建立時的條件判斷邏輯,簡化參數處理
UPDATE
- 調整
MAX_CPUS_PER_CONTAINER預設值從 0.25 提升至 1.0
v0.4.2
Summary
Add CPU and memory limit configuration for containers, providing finer resource control, and optimize default runtime count calculation logic.
FEAT
- Add CPU limit configuration for containers, supporting
MAX_CPUS_PER_CONTAINERenvironment variable to set CPU quota per runtime (default0.25) - Add memory limit configuration for containers, supporting
MAX_MEMORY_PER_CONTAINERenvironment variable to set memory limit per runtime (default128MB)
UPDATE
- Optimize default runtime count calculation from
runtime.NumCPU()toruntime.NumCPU() * 2
Summary
新增 CPU 和記憶體限制配置,提供更精細的資源控制,並優化預設 runtime 數量計算邏輯。
FEAT
- 新增 CPU 限制配置功能,支援環境變數
MAX_CPUS_PER_CONTAINER設定 runtime 的 CPU 配額(預設0.25) - 新增記憶體限制配置功能,支援環境變數
MAX_MEMORY_PER_CONTAINER設定 runtime 的記憶體上限(預設128MB)
UPDATE
- 優化預設 runtime 數量計算邏輯,從
runtime.NumCPU()調整為runtime.NumCPU() * 2
v0.4.1
Summary
Refactored code execution mechanism from mounting temp folder for code file transmission to directly passing code and input via stdin, simplifying architecture and removing file system dependency.
REFACTOR
- Removed
tempfolder mount and health check configuration during container startup - Updated
runScriptandrunScriptWithSSEfunctions to pass code and input via stdin using JSON payload - Updated all wrapper scripts (JS/TS/Python) to read JSON payload from stdin instead of reading code from file
Summary
重構代碼傳遞機制,將原本透過掛載 temp 資料夾傳遞代碼檔案的方式,改為透過 stdin 直接傳遞代碼與輸入參數,簡化架構並移除檔案系統依賴。
REFACTOR
- 移除容器啟動時的
temp資料夾掛載與健康檢查設定 - 更新
runScript和runScriptWithSSE函式,改用 JSON payload 透過 stdin 傳遞代碼與輸入 - 更新所有 wrapper 腳本 (JS/TS/Python),從 stdin 讀取 JSON payload 而非從檔案讀取代碼
v0.4.0
Features
- Added SSE streaming support, returns multiple events with
stream=true wrapper.tsnow supports esbuild compilation- Supports
CODE_MAX_SIZEandTIMEOUT_SCRIPTenvironment variables
Changed
- Unified API input format, always use
inputas parameter - TypeScript/JavaScript/Python wrappers now use return for result
Docs
- Added streaming examples to
README.mdandREADME.zh.md - Expanded
test.httpwith more scenario cases
新增
- 新增 SSE 串流支持,透過
stream=true,回傳多段事件 wrapper.ts腳板支援esbuild編譯- 支援
CODE_MAX_SIZE、TIMEOUT_SCRIPT環境變數
調整
- API 輸入格式統一,一律使用
input作為參數輸入 - TypeScript/JavaScript/Python wrapper 統一使用 return 回傳結果
文檔
README.md、README.zh.md增加串流範例- 測試腳本
test.http補充多種情境案例