Sign inSign up

wolfware/moonlit

By wolfware

•Updated 3 days ago

Build and release automation powered by Rust and sandboxed WebAssembly plugins.

Image
Integration & delivery
Developer tools
0

680

wolfware/moonlit repository overview

⁠Moonlit

Build and release automation powered by Rust and sandboxed WebAssembly plugins.

Pipelines are declared in YAML and executed by a wasmtime host that runs every plugin as an isolated WebAssembly component — with no ambient access to your network, filesystem, environment, or subprocesses unless the pipeline grants it.

⁠Quick start

docker run --rm -v "$PWD:/work" wolfware/moonlit:latest run

The image runs as a non-root user and treats /work as the pipeline's working directory, so mount your repository there. moonlit is the entrypoint, so pass subcommands directly:

docker run --rm -v "$PWD:/work" wolfware/moonlit:latest validate
docker run --rm wolfware/moonlit:latest --help

⁠Running as your own user

On Linux the container runs as uid 1000, and a bind mount keeps the host's ownership, so a pipeline that writes into your repository needs the container to run as you. If your host uid differs from 1000 — most CI runners — pass your own uid with the root group:

docker run --rm \
  --user "$(id -u):0" \
  -v "$PWD:/work" \
  wolfware/moonlit:latest run

⁠Caching resolved plugins

Mount the plugin cache to avoid re-fetching plugins on every run:

docker run --rm \
  -v "$PWD:/work" \
  -v moonlit-cache:/home/moonlit/.cache/moonlit \
  wolfware/moonlit:latest run

⁠Example pipeline

name: demo

plugins:
  - name: github
    url: oci://registry.moonlitbuild.dev/wolfware/github:2.0.0
    permissions:
      network: ["api.github.com"]   # hosts reachable via wasi:http
      exec: []                      # programs the plugin may spawn
      env: ["GITHUB_*"]             # env vars it may read
      filesystem: read-only         # none | read-only | read-write

stages:
  release:
    - name: publish
      run: github.create-release
      config:
        name: v1.2.3
        tag: v1.2.3

⁠Tags and platforms

Tags follow the CLI: 1.2.3, 1.2, 1, and latest. Prereleases never move latest.

Images are published for linux/amd64 and linux/arm64.

⁠What is in the image

A Debian trixie-slim base with ca-certificates and git. The moonlit binary is the exact artifact published to the GitHub Release, the same one distributed via Homebrew, npm, and Chocolatey — nothing is compiled inside the image.

git is present because a plugin can only execute programs that exist in the image, and release pipelines almost always need it.

Tag summary

Content type

Image

Digest

sha256:db7507c2a…

Size

78.2 MB

Last updated

3 days ago

docker pull wolfware/moonlit