runtime

module
v0.16.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: Apache-2.0

README

Miren Runtime

Test Release Changelog License

A container orchestration system built on containerd for running secure, isolated applications with etcd-backed state management.

Overview

The Miren runtime provides a platform for deploying and managing containerized applications with strong isolation guarantees. It features an entity-based architecture with etcd as the distributed state store for managing applications, versions, sandboxes, and infrastructure components.

Key Features

  • Secure Isolation: Strong container isolation using containerd
  • Distributed State: etcd backend for reliable, distributed state management
  • Multi-tenant: Support for projects and isolated environments
  • HTTP Ingress: Built-in routing for HTTP traffic to applications
  • Hot Reload: Applications can be updated without downtime
  • CLI Tool: Comprehensive command-line interface for all operations

Architecture

Core Components
  • Entity Store: Central state management using etcd
  • Sandbox Controller: Manages isolated execution environments
  • App Server: Handles application lifecycle and deployments
  • Ingress Controller: Routes HTTP traffic to applications
  • Build Server: Handles application builds and image management
Entity Types
  • Apps: Application definitions with configuration
  • App Versions: Specific versions of applications with container specs
  • Sandboxes: Isolated execution environments running app versions
  • Routes: HTTP routing rules for ingress
  • Projects: Multi-tenant isolation boundaries

Getting Started

Prerequisites
  • Go 1.26.5+ (required for building)
  • iso (optional, for containerized development environment)
Development Setup
# Clone the repository
git clone https://github.com/mirendev/runtime.git
cd runtime

# Start development environment with all dependencies
make dev

# Or with tmux for split terminals
make dev-tmux

The development environment automatically sets up:

  • containerd for container runtime
  • etcd for state storage
Building
# Build the miren binary
make bin/miren

# Build with debug symbols
make bin/miren-debug

# Build release version
make release
Running Tests
# Run all tests
make test

# Run tests in a specific package
hack/it <package>

# Run a specific test
hack/run <package> <test-name>

CLI Usage

Application Management
# Initialize a new application
miren init

# Deploy an application
miren deploy

# List all applications
miren apps

# Get application details
miren app <app-name>

# View application logs
miren logs <app-name>
Sandbox Management
# List all sandboxes
miren sandbox list

# Filter sandboxes by status
miren sandbox list --status running

# Execute command in sandbox
miren sandbox exec <sandbox-id> -- <command>
Configuration Management

Cluster configurations are stored in ~/.config/miren/clientconfig.yaml.

# Show current configuration
miren config info

# Switch active cluster
miren config set-active <cluster-name>

# Load additional configuration
miren config load <config-file>

Application Configuration

Applications are configured using YAML files:

name: myapp
container:
  - name: web
    image: myapp:latest
    command: ["/app/server"]
    env:
      PORT: "8080"
    resource:
      memory: "256Mi"
      cpu: "100m"
route:
  - hostname: "myapp.example.com"
    path: "/"
    port: 8080

Development

Building from Source
# Build the miren binary
make bin/miren
Code Style
# Run linters on changed files
make lint-changed

Directories

Path Synopsis
api
addon
Package addon provides entity definitions for the addon system.
Package addon provides entity definitions for the addon system.
app
run
Package run defines the Run entity: one execution of an app task.
Package run defines the Run entity: one execution of an app task.
storage
Package storage provides entity definitions for disk provisioning and management.
Package storage provides entity definitions for disk provisioning and management.
blackbox
cli
cmd
miren command
components
appmetrics
Package appmetrics runs the coordinator's managed application metrics scraper and keeps its sandbox targets and remote-write identity current.
Package appmetrics runs the coordinator's managed application metrics scraper and keeps its sandbox targets and remote-write identity current.
base
Package base provides a shared framework for managing containerd-based service components.
Package base provides a shared framework for managing containerd-based service components.
buildkit
Package buildkit provides a component for managing a persistent BuildKit daemon using containerd.
Package buildkit provides a component for managing a persistent BuildKit daemon using containerd.
etcd
Package etcd provides a component for managing an etcd server using containerd.
Package etcd provides a component for managing an etcd server using containerd.
sqlitedisk
Package sqlitedisk replicates SQLite-provider disks from a runner to the coordinator's backup API.
Package sqlitedisk replicates SQLite-provider disks from a runner to the coordinator's backup API.
victorialogs
Package victorialogs provides a component for managing a VictoriaLogs server using containerd.
Package victorialogs provides a component for managing a VictoriaLogs server using containerd.
victoriametrics
Package victoriametrics provides a component for managing a VictoriaMetrics server using containerd.
Package victoriametrics provides a component for managing a VictoriaMetrics server using containerd.
controllers
deploymentattempts
Package deploymentattempts backfills canonical deployment attempts and continuously repairs the activation crash window.
Package deploymentattempts backfills canonical deployment attempts and continuously repairs the activation crash window.
deploymentgc
Package deploymentgc implements retention garbage collection for deployment records.
Package deploymentgc implements retention garbage collection for deployment records.
indexgc
Package indexgc runs a bounded, best-effort background sweep that removes entity-store index (collection) entries the backing entity no longer justifies: the entity is gone, or it still exists but no longer carries the value the entry indexes.
Package indexgc runs a bounded, best-effort background sweep that removes entity-store index (collection) entries the backing entity no longer justifies: the entity is gone, or it still exists but no longer carries the value the entry indexes.
keyrotation
Package keyrotation drives cluster-key rotation for the in-cluster secret store.
Package keyrotation drives cluster-key rotation for the in-cluster secret store.
run
Package run reconciles Run entities: one sandbox, one command, one exit code, then teardown.
Package run reconciles Run entities: one sandbox, one command, one exit code, then teardown.
sagagc
Package sagagc periodically drives saga retention, deleting executions that have been in a terminal state longer than the retention window.
Package sagagc periodically drives saga retention, deleting executions that have been in a terminal state longer than the retention window.
schemareindex
Package schemareindex runs the automatic reindex that follows an index schema change, as a paced background job rather than a startup step.
Package schemareindex runs the automatic reindex that follows an index schema change, as a paced background job rather than a startup step.
version
Package version implements retention garbage collection for AppVersions.
Package version implements retention garbage collection for AppVersions.
hack
cmd/remote-write-dump command
remote-write-dump is a small inspection receiver for managed metrics smoke tests.
remote-write-dump is a small inspection receiver for managed metrics smoke tests.
cmd/testfmt command
e2e_disk command
Command e2e_disk drives the real CloudUpdatesClient against a running cloud, exercising both update kinds end to end: an lbd log segment and a universal-mode image snapshot, then a restore.
Command e2e_disk drives the real CloudUpdatesClient against a running cloud, exercising both update kinds end to end: an lbd log segment and a universal-mode image snapshot, then a restore.
internal
remotewrite
Package remotewrite decodes the subset of Prometheus Remote Write used by runtime integration tests and developer inspection tools.
Package remotewrite decodes the subset of Prometheus Remote Write used by runtime integration tests and developer inspection tools.
pkg
addon/sqlite
Package sqlite provides an embedded SQLite database as an addon.
Package sqlite provides an embedded SQLite database as an addon.
anywhere
Package anywhere implements the runtime side of Miren Anywhere, the connectivity feature that links a cluster to Miren Cloud's POP network for NAT traversal and inbound request forwarding.
Package anywhere implements the runtime side of Miren Anywhere, the connectivity feature that links a cluster to Miren Cloud's POP network for NAT traversal and inbound request forwarding.
apphealth
Package apphealth defines the health classification strings that flow from app-status (ApplicationStatus / AppInfo) to consumers like `m app list` and the deploy poller.
Package apphealth defines the health classification strings that flow from app-status (ApplicationStatus / AppInfo) to consumers like `m app list` and the deploy poller.
apphealthsync
Package apphealthsync samples runtime-owned health for cloud's ephemeral cache.
Package apphealthsync samples runtime-owned health for cloud's ephemeral cache.
appspec
Package appspec builds the sandbox spec that runs an app's code.
Package appspec builds the sandbox spec that runs an app's code.
appversion
Package appversion holds shared helpers for managing AppVersion entities and the resources that hang off them.
Package appversion holds shared helpers for managing AppVersion entities and the resources that hang off them.
boot
Package boot starts components in dataflow order and passes their outputs to downstream components once startup succeeds.
Package boot starts components in dataflow order and passes their outputs to downstream components once startup succeeds.
cel
cloudapi
Package cloudapi talks to Miren Cloud's HTTP API on behalf of a logged-in user.
Package cloudapi talks to Miren Cloud's HTTP API on behalf of a logged-in user.
cloudapi/cloudapitest
Package cloudapitest provides a stand-in for Miren Cloud's HTTP API, so tests that need cloud to answer something can have it answer without a cloud.
Package cloudapitest provides a stand-in for Miren Cloud's HTTP API, so tests that need cloud to answer something can have it answer without a cloud.
cloudrpc
Package cloudrpc lets a caller reach this cluster's RPC server through Miren Cloud, over the same uplink the cluster already holds open.
Package cloudrpc lets a caller reach this cluster's RPC server through Miren Cloud, over the same uplink the cluster already holds open.
clusternetwork
Package clusternetwork tells cloud how this cluster can be reached, over the negotiated uplink session.
Package clusternetwork tells cloud how this cluster can be reached, over the negotiated uplink session.
clusterresources
Package clusterresources samples whole-host CPU, memory, and storage for cloud's ephemeral cache, over the negotiated uplink session.
Package clusterresources samples whole-host CPU, memory, and storage for cloud's ephemeral cache, over the negotiated uplink session.
color
Package color is an ANSI color package to output colorized or SGR defined output to the standard output.
Package color is an ANSI color package to output colorized or SGR defined output to the standard output.
connectors
Package connectors wraps github.com/dexidp/dex/connector with a small Miren-flavored interface.
Package connectors wraps github.com/dexidp/dex/connector with a small Miren-flavored interface.
containerboot
Package containerboot decides which miren binary a container install runs.
Package containerboot decides which miren binary a container install runs.
containerenv
Package containerenv detects whether the current process is running inside a container (Docker, Podman, or a Kubernetes pod).
Package containerenv detects whether the current process is running inside a container (Docker, Podman, or a Kubernetes pod).
deployevents
Package deployevents defines the `miren deploy --format jsonl` event stream: the shape of each event and the vocabulary of the status values inside them.
Package deployevents defines the `miren deploy --format jsonl` event stream: the shape of each event and the vocabulary of the status values inside them.
deploylifecycle
Package deploylifecycle owns the deployment record state machine: the set of valid statuses and phases, and the transitions between them.
Package deploylifecycle owns the deployment record state machine: the set of valid statuses and phases, and the transitions between them.
dns
entity/export
Package export defines the generated contract for entities that may leave the runtime.
Package export defines the generated contract for entities that may leave the runtime.
entity/indexwatch
Package indexwatch provides a robust, self-healing abstraction around the entity server's WatchIndex API.
Package indexwatch provides a robust, self-healing abstraction around the entity server's WatchIndex API.
entitysync
Package entitysync replicates schema-authorized runtime entities to Miren Cloud over the negotiated uplink.
Package entitysync replicates schema-authorized runtime entities to Miren Cloud over the negotiated uplink.
exitrecord
Package exitrecord persists why systemd last stopped a miren daemon, so the next run can tell the user about it.
Package exitrecord persists why systemd last stopped a miren daemon, so the next run can tell the user about it.
git
hey command
Command hey is an HTTP load generator.
Command hey is an HTTP load generator.
hey/requester
Hey supports two output formats: summary and CSV
Hey supports two output formats: summary and CSV
imagerefs
Package imagerefs centralizes all Docker image references used throughout the project.
Package imagerefs centralizes all Docker image references used throughout the project.
lifecyclesync
Package lifecyclesync makes the on-disk lifecycle ledger visible beyond the host.
Package lifecyclesync makes the on-disk lifecycle ledger visible beyond the host.
logfilter
Package logfilter provides a simple query syntax for filtering logs.
Package logfilter provides a simple query syntax for filtering logs.
oncalendar
Package oncalendar parses the subset of systemd's OnCalendar syntax that Miren accepts for scheduled tasks, and evaluates the firing times it describes.
Package oncalendar parses the subset of systemd's OnCalendar syntax that Miren accepts for scheduled tasks, and evaluates the firing times it describes.
rpc
rpc/cmd/rpcgen command
runnerlifecycle
Package runnerlifecycle adapts pkg/serverlifecycle to the runner daemon: how an executor on the runner's host observes the runner process.
Package runnerlifecycle adapts pkg/serverlifecycle to the runner daemon: how an executor on the runner's host observes the runner process.
saga
Package saga implements the Saga pattern for distributed operations with crash recovery.
Package saga implements the Saga pattern for distributed operations with crash recovery.
secret
Package secret models secrets that are referenced rather than copied.
Package secret models secrets that are referenced rather than copied.
secret/cluster
Package cluster implements the in-cluster secret backend.
Package cluster implements the in-cluster secret backend.
secret/keyring
Package keyring holds the cluster's key hierarchy for secrets at rest and performs the envelope encryption around it.
Package keyring holds the cluster's key hierarchy for secrets at rest and performs the envelope encryption around it.
secret/remote
Package remote resolves secret references over RPC, for nodes that hold no key material.
Package remote resolves secret references over RPC, for nodes that hold no key material.
serverinfo
Package serverinfo describes the running server process: build, instance identity, and readiness.
Package serverinfo describes the running server process: build, instance identity, and readiness.
serverlifecycle
Package serverlifecycle restarts and upgrades the server as durable, idempotent operations: JSON records on disk that outlive the process they act on, so a caller can hand off an operation id and ask about it later.
Package serverlifecycle restarts and upgrades the server as durable, idempotent operations: JSON records on disk that outlive the process they act on, so a caller can hand off an operation id and ask about it later.
servicelimits
Package servicelimits generates the systemd drop-in that bounds the memory a miren daemon may use, so a runaway control process degrades miren instead of taking the whole machine down with it.
Package servicelimits generates the systemd drop-in that bounds the memory a miren daemon may use, so a runaway control process degrades miren instead of taking the whole machine down with it.
set
slogout
Package slogout provides adapters to route container output through slog.Logger instead of directly to stdout/stderr.
Package slogout provides adapters to route container output through slog.Logger instead of directly to stdout/stderr.
subsystem
Package subsystem provides infrastructure for building composable server subsystems.
Package subsystem provides infrastructure for building composable server subsystems.
subsystem/metrics
Package metrics provides a subsystem for building metrics collection components.
Package metrics provides a subsystem for building metrics collection components.
subsystem/observability
Package observability provides a subsystem for building observability components.
Package observability provides a subsystem for building observability components.
tasks/run command
theme
Package theme centralizes the miren CLI's color palette and adapts it to the terminal it's running in.
Package theme centralizes the miren CLI's color palette and adapts it to the terminal it's running in.
ui
Package ui provides common UI components for the miren CLI
Package ui provides common UI components for the miren CLI
uplink
Package uplink implements the cluster's control-plane link to Miren Cloud: exactly one persistent, authenticated WebSocket per cluster, carrying typed coordination messages multiplexed by type.
Package uplink implements the cluster's control-plane link to Miren Cloud: exactly one persistent, authenticated WebSocket per cluster, carrying typed coordination messages multiplexed by type.
waf
workloadidentity
Package workloadidentity implements OIDC workload identity tokens for sandbox containers, following the GitHub Actions OIDC pattern.
Package workloadidentity implements OIDC workload identity tokens for sandbox containers, following the GitHub Actions OIDC pattern.
workloadroles
Package workloadroles is the single source of truth for the canned roles a sandbox's workload identity token can be minted with.
Package workloadroles is the single source of truth for the canned roles a sandbox's workload identity token can be minted with.
servers
app
routes
Package routes serves operator controls over existing HTTP routes.
Package routes serves operator controls over existing HTTP routes.
runnertelemetry
Package runnertelemetry accepts the metrics and logs a distributed runner ships, and forwards them to the cluster's VictoriaMetrics and VictoriaLogs.
Package runnertelemetry accepts the metrics and logs a distributed runner ships, and forwards them to the cluster's VictoriaMetrics and VictoriaLogs.
sandbox
Package sandbox serves the operator-facing sandbox inventory.
Package sandbox serves the operator-facing sandbox inventory.
secret
Package secret serves the cluster's secret store over RPC.
Package secret serves the cluster's secret store over RPC.
serverinfo
Package serverinfo serves the ServerInfo RPC from a serverinfo.Source.
Package serverinfo serves the ServerInfo RPC from a serverinfo.Source.
serverlifecycle
Package serverlifecycle serves the ServerLifecycle RPC in front of the on-disk operation ledger in pkg/serverlifecycle.
Package serverlifecycle serves the ServerLifecycle RPC in front of the on-disk operation ledger in pkg/serverlifecycle.
sqlitebackup
Package sqlitebackup stores the LTX transaction files that runners replicate from SQLite-provider disks.
Package sqlitebackup stores the LTX transaction files that runners replicate from SQLite-provider disks.
usage
Package usage answers cluster-wide resource questions: which sandboxes are consuming what, and which hosts are under pressure.
Package usage answers cluster-wide resource questions: which sandboxes are consuming what, and which hosts are under pressure.
x module

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL