WDL workerd runtime for gateway, control, D1, Durable Objects, auth, and user runtime services.
8.1K
getwdl/wdl-workerd contains the workerd-based runtime services used by WDL deployments.
WDL is a self-hosted multi-tenant Workers platform built on stock Cloudflare workerd. This image packages the compiled workerd configs and JavaScript platform tiers that run tenant workers and platform control services:
gateway: public/admin ingress, host routing, custom pattern routing, and WebSocket holder path.user-runtime: tenant worker runtime pool with dynamic worker loading.system-runtime: control/auth/static system workers and privileged __system__ runtime pool.d1-runtime: D1 workerd runtime for SQLite execution behind owner routing.do-runtime: Durable Object workerd runtime for native facets, SQLite storage, alarms, and WebSockets.All five roles ship in one image; the container entrypoint and command pick which one runs. The compiled configs live in /app/dist/workerd-configs/.
| Role | Entrypoint | Command |
|---|---|---|
gateway | workerd | serve -b /app/dist/workerd-configs/gateway.bin |
user-runtime | workerd | serve -b /app/dist/workerd-configs/user-runtime.bin --experimental |
system-runtime | workerd | serve -b /app/dist/workerd-configs/system-runtime.bin --experimental |
d1-runtime | d1-supervisor | — |
do-runtime | do-supervisor | — |
The stateful runtimes run a Rust supervisor as PID 1, which spawns workerd as a child process so drain and lease renewal are orchestrated locally. Give them a stop timeout of at least 20 seconds so the drain completes.
The base is gcr.io/distroless/base-debian13: no shell and no package manager. workerd's official Linux build is glibc-linked, so the runtime stage stays on a glibc base rather than Alpine.
latest — the most recent release.wdl.YYYYMMDD.<8-char-sha> — immutable per-release tag. The date tracks the bundled workerd version; the suffix names the exact released commit. Pin this in production.Images are multi-arch (linux/amd64, linux/arm64) and published with provenance attestations and an SBOM. The same tags are mirrored to ghcr.io/wdl-dev/wdl-workerd.
Pair this image with getwdl/wdl-rust, which provides the redis-proxy, scheduler, and workflows binaries. Use WDL's Docker Compose, Kubernetes, or Terraform deployment paths rather than running this image as a standalone app.
git clone https://github.com/wdl-dev/wdl.git && cd wdl
npm ci && npm run compile:workerd:local
docker compose -f docker-compose.yml -f docker-compose.images.yml up -d --pull always --no-build --wait
Note that the Compose path bind-mounts a locally compiled ./dist over the image's built configs, which is why the compile step is required on a fresh clone.
License and third-party notices are included in the image under /usr/share/licenses/wdl/.
WDL is not affiliated with, endorsed by, or sponsored by Cloudflare, Inc. Cloudflare, Cloudflare Workers, Wrangler, and workerd are trademarks or registered trademarks of Cloudflare, Inc.
Content type
Image
Digest
sha256:794ea8edd…
Size
50 MB
Last updated
5 days ago
docker pull getwdl/wdl-workerd