Relational database engine in Rust: MVCC transactions, B+tree storage, WAL recovery, SQL.
10K+
NusaDB is a relational database engine built from scratch in Rust a clustered B-link/B+tree storage engine with MVCC, WAL-based crash recovery, a full SQL surface (parser, analyzer, planner, vectorized executor).
Pre-release notice: this is a
0.1.*.:latestbuild. The API, SQL surface, and on-disk format may still change before a stable Not yet recommended for production workloads.
latest — the current release; what the examples below use.linux/amd645678/tcp (wire protocol), 9100/tcp (Prometheus metrics, opt-in)/var/lib/nusadbNusaDB implements the classic 7-layer database stack — client, wire protocol, SQL engine (parser → analyzer → planner → executor), transaction layer (MVCC + lock manager), storage engine (clustered B-link/B+tree), WAL, and physical storage — as a single Rust binary. It speaks its own Nusa Wire Protocol with SCRAM-SHA-256 authentication and optional TLS/mTLS, and ships an interactive SQL shell (nusa-cli) alongside the server.
docker run -d \
--name nusadb \
-p 5678:5678 \
-v nusadb-data:/var/lib/nusadb \
nusadb/nusadb:latest
By default the server listens on 0.0.0.0:5678, stores data in /var/lib/nusadb, and runs trust-on-startup (no password) — fine for local development, not for anything reachable outside your machine.
docker exec -it nusadb nusa-cli --user nusa-root --database nusadb
Or from the host, using a local install of nusa-cli:
nusa-cli --host 127.0.0.1:5678 --user nusa-root --command "SELECT version();"
Point any NusaDB client at the wire-protocol port. The connection URL is:
jdbc:nusadb://<host>:<port>/<database>
localhost when published locally).5678 inside the container, so -p 5678:5678 → use 5678. If you mapped a different host port, use that one (e.g. -p 5433:5678 → use 5433).nusadb.nusa-root (whatever you set via NUSADB_USER / NUSADB_PASSWORD; omit both for a trust-on-startup server).DataGrip / DBeaver / any JDBC tool — install the JDBC driver (com.nusadb:nusadb-jdbc), then use a URL such as:
jdbc:nusadb://localhost:5678/nusadb # default port (-p 5678:5678)
jdbc:nusadb://localhost:5433/nusadb # if you published -p 5433:5678
In DataGrip: New → Data Source → (add the nusadb-jdbc driver) → URL = one of the above, then set the user/password.
Native drivers (Rust / Python / Node / Go / PHP / Ruby — see “Supported drivers” above) use the nusadb:// URL scheme:
nusadb://nusa-root:PASSWORD@localhost:5678/nusadb
Set NUSADB_USER / NUSADB_PASSWORD (canonical superuser is nusa-root) to require SCRAM-SHA-256 auth instead of trust-on-startup:
docker run -d \
--name nusadb \
-p 5678:5678 \
-e NUSADB_USER=nusa-root \
-e NUSADB_PASSWORD=change-me \
-v nusadb-data:/var/lib/nusadb \
nusadb/nusadb:latest
Mirroring the Postgres image convention: on a fresh (empty) data directory, any *.sql files mounted at /docker-entrypoint-initdb.d are executed in lexical order once the server is ready. This does not re-run against an existing data directory.
docker run -d \
--name nusadb \
-p 5678:5678 \
-v nusadb-data:/var/lib/nusadb \
-v ./init:/docker-entrypoint-initdb.d \
nusadb/nusadb:latest
-- ./init/01-schema.sql
CREATE DATABASE app;
CREATE SCHEMA tenant;
CREATE TABLE tenant.users (id UUID PRIMARY KEY, email TEXT NOT NULL);
docker run -d \
--name nusadb \
-p 5678:5678 \
-v nusadb-data:/var/lib/nusadb \
-v ./certs:/certs \
nusadb/nusadb:latest \
--tls-cert /certs/server.pem --tls-key /certs/server-key.pem
Add --tls-client-ca /certs/ca.pem to require mutual TLS.
docker run -d \
--name nusadb \
-p 5678:5678 -p 9100:9100 \
-v nusadb-data:/var/lib/nusadb \
nusadb/nusadb:latest \
--metrics-listen 0.0.0.0:9100
services:
nusadb:
image: nusadb/nusadb:latest
ports:
- "5678:5678"
environment:
NUSADB_USER: nusa-root
NUSADB_PASSWORD: change-me
volumes:
- nusadb-data:/var/lib/nusadb
- ./init:/docker-entrypoint-initdb.d
volumes:
nusadb-data:
| Variable | Description |
|---|---|
NUSADB_USER | Superuser name the init client authenticates as; also read by nusadb-server as the required auth identity. Omit both NUSADB_USER/NUSADB_PASSWORD for a trust-on-startup server. |
NUSADB_PASSWORD | Password paired with NUSADB_USER. Never passed on the command line — read from the environment to avoid leaking into the process list. |
NUSADB_INITDB_DIR | Override the init-script directory (default /docker-entrypoint-initdb.d). |
RUST_LOG | Log verbosity (tracing env-filter syntax). Defaults to info. |
nusadb-server flagsPass these after the image name (they extend/override the image's default CMD):
| Flag | Purpose |
|---|---|
--listen <ADDR> | Wire-protocol listen address (default 0.0.0.0:5678) |
--data-dir <PATH> | Data directory holding the durable WAL (default /var/lib/nusadb in this image) |
--auth-user <USER:PASSWORD> | Require SCRAM-SHA-256 auth for a user (repeatable); alternative to the env vars above |
--tls-cert / --tls-key / --tls-client-ca | Enable TLS / mutual TLS |
--max-connections <N> | Concurrent connection cap (default 25) |
--mem-budget / --work-mem / --spill-dir | RAM-aware auto-tuning and per-query memory bounds; auto-detects container cgroup limits when unset |
--metrics-listen <ADDR> | Serve Prometheus metrics (disabled unless set) |
--statement-timeout <SECS> | Cancel long-running statements |
--copy-max-bytes <N> | Cap buffered bytes for COPY ... FROM STDIN (default 1 GiB) |
Run docker run --rm nusadb/nusadb:latest --help for the full list.
All durable state (WAL + data files) lives under /var/lib/nusadb. Mount a named volume or bind mount there to persist data across container restarts/upgrades.
See the project repository for license terms.
Content type
Image
Digest
sha256:cc7705fe1…
Size
38.5 MB
Last updated
10 days ago
docker pull nusadb/nusadb