Build and release automation powered by Rust and sandboxed WebAssembly plugins.
680
Build and release automation powered by Rust and sandboxed WebAssembly plugins.
Pipelines are declared in YAML and executed by a wasmtime host that runs every plugin as an
isolated WebAssembly component — with no ambient access to your network, filesystem, environment,
or subprocesses unless the pipeline grants it.
docker run --rm -v "$PWD:/work" wolfware/moonlit:latest run
The image runs as a non-root user and treats /work as the pipeline's working directory, so mount
your repository there. moonlit is the entrypoint, so pass subcommands directly:
docker run --rm -v "$PWD:/work" wolfware/moonlit:latest validate
docker run --rm wolfware/moonlit:latest --help
On Linux the container runs as uid 1000, and a bind mount keeps the host's ownership, so a pipeline that writes into your repository needs the container to run as you. If your host uid differs from 1000 — most CI runners — pass your own uid with the root group:
docker run --rm \
--user "$(id -u):0" \
-v "$PWD:/work" \
wolfware/moonlit:latest run
Mount the plugin cache to avoid re-fetching plugins on every run:
docker run --rm \
-v "$PWD:/work" \
-v moonlit-cache:/home/moonlit/.cache/moonlit \
wolfware/moonlit:latest run
name: demo
plugins:
- name: github
url: oci://registry.moonlitbuild.dev/wolfware/github:2.0.0
permissions:
network: ["api.github.com"] # hosts reachable via wasi:http
exec: [] # programs the plugin may spawn
env: ["GITHUB_*"] # env vars it may read
filesystem: read-only # none | read-only | read-write
stages:
release:
- name: publish
run: github.create-release
config:
name: v1.2.3
tag: v1.2.3
Tags follow the CLI: 1.2.3, 1.2, 1, and latest. Prereleases never move latest.
Images are published for linux/amd64 and linux/arm64.
A Debian trixie-slim base with ca-certificates and git. The moonlit binary is the exact
artifact published to the GitHub Release, the same one distributed via Homebrew, npm, and
Chocolatey — nothing is compiled inside the image.
git is present because a plugin can only execute programs that exist in the image, and release
pipelines almost always need it.
Content type
Image
Digest
sha256:db7507c2a…
Size
78.2 MB
Last updated
3 days ago
docker pull wolfware/moonlit