Skip to content

Repository files navigation

HTTP Components

A collection of utility components that remix wasi:http types and interfaces.

Components

  • client: a higher-level HTTP client that delegates to wasi:http/client
  • status-codes: constants for HTTP status codes

Gates

Access control for wasi:http is split between gates and latches. A gate wraps wasi:http/client or wasi:http/handler and consults a latch before each request, a latch decides whether the request may proceed. Latches are small and single purpose, combine them to build a policy.

  • gate: gates both wasi:http/client and wasi:http/handler
  • gate-client: gates wasi:http/client, requests sent
  • gate-handler: gates wasi:http/handler, requests handled

A denied request fails with the latch's reason, and is logged as a warning. A latch error fails the request with internal-error, and is logged as an error.

Caution

Interfering with HTTP requests can have dramatic, unintended consequences. A denied request surfaces to the caller as a failed request, which can trigger retries, timeouts and fallbacks far from the request that was denied. Install new latches, and new configurations of existing latches, cautiously and monitor the result: roll out with latch-dry-run, watch decisions with latch-trace, and review the denials the gate logs.

Latches

Decide which requests are allowed. A latch defers or denies, a request proceeds unless a latch denies it. Deciding and acting on a decision are separate steps, a latch is told the final decision for each request with observe-decision.

Blanket decisions

Request properties

Fault injection

Deny requests on purpose, to prove a component is resilient to failures.

  • latch-deny-random: randomly denies a configurable fraction of requests, reproducible with a seed

Combining latches

Build a policy from several latches, apply a latch to only part of the requests, or try a policy before enforcing it.

Tracing

Log wasi:http calls, for debugging or auditing, without affecting them.

Choosing a component variant

Due to resource types being unique to the instance that defines them in the Component Model, fine grain composition of the wasi:http interfaces can be persnickety. Pick the most specific component that covers the interfaces the target component imports. While the base component is more universal, a larger surface area asks the host for capabilities the target component doesn't use.

For example, with the trace-* components:

The target component imports Use
wasi:http/types trace-types
wasi:http/types and wasi:http/client trace-client
wasi:http/types and wasi:http/handler trace-handler
wasi:http/types, wasi:http/client and wasi:http/handler trace
componentized:http/client trace-componentized-client

trace-client, trace-handler and trace also trace wasi:http/types, don't combine them with trace-types.

The wasi:http/handler exported by trace-handler and trace takes requests created with their exported wasi:http/types. Use them in front of a component that forwards requests with wasi:http/handler, a host serving incoming requests can't call them directly.

Build

Prereqs:

  • a rust toolchain
  • cargo-binstall, optional, to download prebuilt tools instead of building them
make components

The build creates each component in components into target/components, e.g. the client at target/components/client/client.wasm, along with target/components/interface.wasm, the componentized:http WIT package. Each component is also built with debug info, e.g. target/components/client/client.debug.wasm.

The cli tools the build uses, static-config, wasm-tools, wac, wasmtime and wkg, are pinned in tools/Cargo.toml and installed into target/tools/<platform>, e.g. target/tools/aarch64-apple-darwin, as needed, or ahead of time with make tools. Dependabot bumps the pinned versions.

Community

Code of Conduct

The Componentized project follow the Contributor Covenant Code of Conduct. In short, be kind and treat others with respect.

Communication

General discussion and questions about the project can occur in the project's GitHub discussions.

Contributing

The Componentized project team welcomes contributions from the community. A contributor license agreement (CLA) is not required. You own full rights to your contribution and agree to license the work to the community under the Apache License v2.0, via a Developer Certificate of Origin (DCO). For more detailed information, refer to CONTRIBUTING.md.

Acknowledgements

This project was conceived in discussion between Mark Fisher and Scott Andrews.

License

Apache License v2.0: see LICENSE for details.

About

collection of utility components that remix wasi:http types and interfaces

Resources

Code of conduct

Contributing

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages