Skip to content
CAI
Software that uses CAICheck a score

rivet-dev/actors

29.7

Weak · 29 September 2026

331.7k

lines of production code

Rust

with TypeScript

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is a distributed engine for hosting and managing serverless and dedicated game server actors, providing the core infrastructure for a multiplayer gaming platform. It features a custom distributed consensus engine (Epoxy) and a workflow scheduler (Gasoline) to handle actor lifecycle, state persistence, and cross-datacenter replication. The platform exposes comprehensive public and peer APIs for actor management, authentication, and real-time communication, supported by a container runner for hosting external game server processes.

How it got here

2023 — Legacy codebase and infrastructure cleanup

101 changes.

This period involved the massive removal of legacy Rust services, internal utility libraries, and direct SQL database access patterns across the repository. It also included the deletion of SaltStack and Linode-based infrastructure modules, alongside the removal of the Chirp client library and Protobuf definitions. The work consolidated the codebase by eliminating outdated components while introducing scaffolding for a new modular engine architecture.

2025 — Engine architecture and SDK expansion

113 changes.

This period focused on building the core engine infrastructure, introducing the Epoxy distributed consensus engine, the Gasoline workflow system, and the Guard routing service. It also involved expanding the SDK ecosystem with new TypeScript, Rust, and Go clients, while establishing a comprehensive shared UI component library and developer tooling for the frontend.

2026 — SDK expansion and storage engine overhaul

114 changes.

This period focused on expanding the SDK ecosystem with new Swift, Rust, and TypeScript libraries, including a durable workflow engine and structured error handling. Simultaneously, the engine underwent a major storage overhaul, introducing a new SQLite VFS, staged commit protocols, and point-in-time recovery capabilities within the depot system.

Features

Add Cloudflare Workers quickstart examples for Hono and raw routing

New example projects demonstrate how to integrate Rivet Actors with Cloudflare Workers. The Hono example shows mounting a Hono application alongside the Rivet handler, while the raw example illustrates a hand-rolled router setup. Both examples provide a starting point for developers to use Rivet's actor model within the Cloudflare Workers environment.

examples/hello-world-cloudflare-workers-hono, examples/hello-world-cloudflare-workers-raw · high confidence

Add Hono example using RivetKit actors and serverless API

The Hono example now demonstrates a serverless architecture using RivetKit. It introduces a counter actor with an increment action and sets up a Hono server that exposes this actor via a generic \/api/rivet/\*\ handler and a specific \/increment/:name\ endpoint, allowing users to interact with the actor through HTTP requests.

examples/hono · high confidence

Add Python bindings for async and sync Rivetkit clients

This change introduces the Python client library for Rivetkit, exposing both asynchronous and synchronous APIs. Users can now instantiate \AsyncClient\ and \AsyncSimpleClient\ for non-blocking operations or \Client\ and \SimpleClient\ for synchronous usage. The bindings support connecting via WebSocket or SSE transports and JSON or CBOR encodings. Key capabilities include actor management (get, create, get\_with\_id), invoking actor actions, and handling events through subscription and reception mechanisms.

rivetkit-python/client · high confidence

Add RivetKit DevTools browser extension

A new \devtools\ package has been added to the RivetKit monorepo, providing a browser-based developer tool. It injects a draggable, floating UI button into the page that opens the RivetKit Inspector in a new tab, automatically passing the client's endpoint, token, namespace, and pool name as URL parameters. The package includes the React components, hooks for positioning and dragging, and build configuration to bundle the UI as an IIFE script.

rivetkit-typescript/packages/rivetkit · high confidence

Add Rust examples for chat-room and hello-world actors

New Rust example projects have been added to demonstrate the Rivetkit actor framework. The chat-room example implements a persistent chat actor with SQL-backed message history, sending, and statistics, while the hello-world example provides a simple counter actor that supports incrementing, retrieving the count, and accessing connection labels.

examples/chat-room-rust, examples/hello-world-rust · high confidence

Add chat-room-render example application

Introduces a new example application demonstrating real-time messaging with persistent history using RivetKit and the Render DDS UI components. The frontend (App.tsx) provides a chat interface with room and username configuration, live connection status, and message history, while the backend (actors.ts) implements a chat room actor that manages message state and broadcasts updates. The example includes server setup via Hono for static serving and API routing, along with environment configuration for local development and Render cloud deployment.

examples/chat-room-render, examples/chat-room-render/frontend · high confidence

Add epoxy key definitions for reservation lookups

The epoxy module now includes a formal key structure for resolving reservations by name and key. This change introduces the \ReservationByKeyKey\ type, which defines how reservation identifiers are serialized, deserialized, and packed into the storage tuple format, enabling precise data access for this specific lookup pattern.

engine/packages/pegboard/src/keys/epoxy · high confidence

Add hello-world container image for Rivet Compute

A new hello-world container image is now available for Rivet Compute, allowing users to verify their setup with a simple Node.js application. The image serves a branded HTML page via HTTP on port 8080, providing a quick way to confirm that container deployment and networking are functioning correctly before building custom applications.

docker/compute-hello-world · high confidence

Add runtime-controllable Pyroscope profiling for Linux/macOS

The profiling package now integrates the Pyroscope agent on Linux and macOS (x86\_64/aarch64), enabling CPU profiling via pprof. The agent starts only when \config.pyroscope\ is set and can be toggled at runtime through the \rivet.debug.profile.config\ pubsub subject, allowing users to enable or disable profiling and override the sampling frequency without restarting the service. On unsupported platforms, the service remains a no-op and logs a warning if profiling is configured.

engine/packages/profiling · high confidence

Add serverless metadata type definitions and serialization tests

This change introduces the \serverless\_metadata\ module to the \rivetkit-shared-types\ package, defining Rust structs for serverless metadata payloads, including \ServerlessMetadataPayload\, \ServerlessMetadataEnvoy\, \ServerlessMetadataRunner\, and \ServerlessActorPreload\. These types support serialization to/from JSON with camelCase field naming, enabling consistent data exchange for serverless actor metadata. A test is added to verify that the Rust types correctly encode and decode the expected JSON structure, ensuring compatibility with the TypeScript client shape.

rivetkit-rust/packages/shared-types · high confidence

Add test snapshot generation tool for integration testing

Introduces a new CLI tool (\test-snapshot-gen\) that builds multi-replica test clusters, populates them with specific state scenarios (such as Epoxy keys or pre-migration actors), and checkpoints the RocksDB data into snapshot directories. This enables integration and migration tests to load pre-existing database states, ensuring that changes like the v2 migration or envoy introduction behave correctly against known data.

engine/packages/test-snapshot-gen/src · high confidence

Added 'db nuke' subcommand to clear local file-based databases

Users can now use the new \db nuke\ subcommand to permanently delete local file-based database storage. This command requires the \--yes\ flag to confirm the action and currently supports only file-system databases; attempting to nuke a PostgreSQL database will result in an error.

engine/packages/engine/src/commands/db · high confidence

Added Unity demo package for FishNet Bayou WebSocket transport

The \container-runner/examples/unity-demo\ location now includes the \com.firstgeargames.fishnet.bayou\ Unity package, providing a \Bayou\ transport component for FishNet. This component enables WebSocket-based networking with configurable MTU, port, and client limits, and supports WSS (secure WebSocket) via an \SslConfiguration\. It integrates the \SimpleWebTransport\ library (version 2.3.0) to handle client and server socket connections, allowing users to run networked Unity demos with WebSocket transport.

(repo-wide) · high confidence

Added datacenter health monitoring and latency ranking

The datacenter package now includes a background workflow that periodically pings peer datacenters via their /health endpoints to measure round-trip time (RTT) and record the last successful ping timestamp. An operation is provided to list datacenters sorted by this RTT, enabling components to identify the lowest-latency peers for routing or failover decisions.

engine/packages/datacenter · high confidence

Added default test callbacks for HTTP and WebSocket handling

The test-envoy SDK now includes a \DefaultTestCallbacks\ implementation in the \behaviors\ module. This provides out-of-the-box support for testing by handling HTTP requests (responding with a JSON status on \/ping\ and 404 otherwise) and echoing WebSocket messages, simplifying the setup for test environments.

engine/sdks/rust/test-envoy/src/behaviors · high confidence

Added local cache purge service

A new cache-purge component has been introduced to handle cache invalidation requests. It subscribes to cache purge topics, receives purge messages, and executes local cache purges directly without re-publishing events to NATS, ensuring efficient and isolated cache cleanup.

engine/packages/cache-purge · high confidence

Added workflow and signal debugging utilities

New utility modules have been added to the engine to improve debugging capabilities for workflows and signals. The \wf\ module now includes functions to print detailed workflow history and data, including state, tags, input, output, and error information, with support for both pretty-printed and table formats. Additionally, a new \signal\ module provides similar debugging output for signals, displaying signal details such as ID, creation time, acknowledgment status, state, and body. These utilities enhance the ability to inspect and troubleshoot workflow execution and signal handling within the engine.

engine/packages/engine/src/util/wf · high confidence

Auto-generated engine configuration and API documentation schemas

The engine now automatically generates and publishes its configuration schema and public API documentation during the build process. A new build script creates \config-schema.json\ in the engine artifacts directory, reflecting the requirement that authentication must be configured for a running engine. Additionally, an OpenAPI specification (\openapi.json\) for the public API router is generated and written to the same artifacts directory, ensuring documentation stays synchronized with the code.

engine/packages/config-schema-gen · high confidence

The example registry package now includes an auto-generated TypeScript file (\_gen.ts) that defines a structured list of example templates (such as Hello World, AI Agent, and Chat Room). This registry exposes metadata like technology stacks and tags, and provides direct Vercel deployment URLs for each example, enabling users to easily discover and deploy starter projects.

frontend/packages/example-registry · high confidence

Automated Rust and TypeScript SDK generation for Envoy Protocol

The build process now automatically generates Rust and TypeScript SDKs from local schema files during compilation. This ensures the Rust crate includes the correct protocol version constant and that the TypeScript SDK is built with the correct imports (replacing internal @bare-ts/lib references with @rivetkit/bare-ts) and a custom assertion function, making the generated code ready for distribution and use without manual intervention.

engine/sdks/rust/envoy-protocol · high confidence

Automated environment setup and service initialization for agents

The \.agents\ directory now includes executable scripts to standardize the development environment. The \setup\ script automatically installs Node.js v22.17.1, the Rust toolchain v1.91.1, and pnpm v10.13.1, then installs workspace dependencies and builds frontend components. The \resume\ script ensures that orb services are running, streamlining the process for agents to operate within the configured environment.

.agents · high confidence

Automatic workflow and signal pruning with dead-workflow backfill

The gasoline runtime now includes a new automatic pruning workflow that periodically removes completed workflows and signals based on a configurable eligibility duration, processing data in chunks to avoid performance spikes. It also registers a backfill workflow to handle any previously missed cleanup tasks, ensuring system hygiene without manual intervention.

engine/packages/gasoline-runtime · high confidence

Client protocol v4 with trace context and queue support

The client-protocol package now defines and generates code for protocol version 4, which is set as the default. This version introduces an ActorSpecifier field to Error and HttpResponseError types for better error context, adds an HttpQueueSendRequest/Response pair for queue operations, and includes telemetry header constants (traceparent, tracestate, ray ID) to support distributed tracing. The package also includes a build script to generate TypeScript codecs from BARE schemas and implements versioned serialization/deserialization logic to handle migrations between v1 through v4.

rivetkit-rust/packages/client-protocol · high confidence

Engine now supports runtime dynamic configuration and safe protocol version upgrades

The engine introduces a new \dynamic-config\ package that allows runtime reconfiguration of the entire cluster without restarts. Operators can now broadcast updates to log filters and OpenTelemetry sampling ratios via pubsub, with changes applied immediately to all processes. Additionally, a new \version-management\ package ensures safe rolling deployments by tracking engine and runtime protocol versions (Envoy, UPS, UniversalDB, Epoxy) in the database. It enforces a 'hold-back' strategy where newer engine instances adopt the oldest active protocol version until old instances expire, preventing data corruption from version mismatches during upgrades.

engine/packages/build-meta, engine/packages/dynamic-config, engine/packages/version-management · high confidence

Engine process management and error handling

The engine-process package now includes a new error module defining specific failure modes for engine binary resolution, download, and health checks, alongside a process manager that handles spawning, reusing, and monitoring the rivet-engine subprocess.

rivetkit-rust/packages/engine-process · high confidence

Epoxy consensus engine core implementation

The Epoxy distributed consensus engine is now available in the open-source engine, introducing the core infrastructure for multi-datacenter replication. This includes HTTP-based inter-replica communication with automatic protocol version negotiation, configurable quorum logic (fast, slow, all, any) for proposal and fanout operations, and changelog synchronization for learner catch-up. The engine exposes operational metrics for proposals, request durations, and cluster state, and registers workflows for backfill, coordination, and replica management.

engine/packages/epoxy/src · high confidence

Epoxy protocol schema versions v2, v3, and v4 added

New schema definitions for Epoxy protocol versions v2, v3, and v4 have been added to the SDK. These files define the data structures for the protocol, including common types (ReplicaId, Ballot), cluster configuration, recovery and proposal phases (Prepare, PreAccept, Accept, Commit), cache control, and key-value operations. The schemas establish the wire format and type contracts for these protocol versions.

engine/sdks/schemas/epoxy-protocol · high confidence

Epoxy replica protocol implementation

The Epoxy replica now implements the core distributed consensus protocol, handling Prepare, Accept, and Commit phases to ensure data consistency across replicas. This includes ballot management for conflict resolution, a changelog for tracking state changes, and support for reading both committed and in-flight state. The replica also handles configuration updates and exposes a health check endpoint, providing the foundational logic for the Epoxy v4 rollout.

engine/packages/epoxy/src/replica · high confidence

Epoxy v2 proposal and backfill operations introduced

The Epoxy engine now exposes v2 proposal logic and a background backfill workflow. The new \ops/propose\ module handles single-command proposals (Set and Check-and-Set) with explicit consensus failure reasons (prepare/accept phase failures, stale ballots, value mismatches) and optional replica scoping. A new \ops/read\_cluster\_config\ operation retrieves the current cluster configuration from the underlying database. Additionally, the \workflows/backfill\ module implements \epoxy\_backfill\_v2\, which migrates legacy committed values and changelog data to the v2 format in chunks, ensuring new learners can access the updated changelog while old data remains readable via dual-read fallback until migration completes.

engine/packages/epoxy/src/ops · high confidence

Initial implementation of the Guard service with routing, metrics, and TLS support

The Guard service has been introduced as a new component within the engine to handle request routing, security, and observability. It provides structured error handling for routing failures (such as missing headers, invalid parameters, or timeouts) and exposes detailed Prometheus metrics for monitoring route dispatch durations, gateway selections, and authorization checks. The service initializes shared state for multiple pegboard gateway versions and integrates with JWT authentication caches, while also including a placeholder for TLS certificate resolution to support future HTTPS configurations.

engine/packages/guard/src · high confidence

Initial release of the @rivetkit/rivetkit-wasm package

This change introduces the new \@rivetkit/rivetkit-wasm\ package, providing a WebAssembly-based runtime for Rivet. The package includes the core Rust implementation (\src/lib.rs\) compiled for the browser, along with TypeScript entry points (\index.js\, \index.d.ts\) that re-export the generated bindings. It also provides build infrastructure (\scripts/build.mjs\) using \wasm-pack\ and validation scripts (\scripts/check-package.mjs\) to ensure the published package contains all necessary artifacts.

rivetkit-typescript/packages/engine-runner-protocol, rivetkit-typescript/packages/rivetkit-wasm · high confidence

Initial release of the Envoy Protocol TypeScript SDK

This change introduces the \envoy-protocol\ TypeScript SDK, providing generated serialization and deserialization functions for the Envoy protocol's binary format. The SDK exposes types for identifiers (Id, GatewayId, RequestId), key-value store operations (KvKey, KvValue, KvMetadata), and various query types (KvListAllQuery, KvListRangeQuery, KvListPrefixQuery). It also includes support for HTTP stream abort reasons and is configured to build for both CommonJS and ESM targets using tsup. A golden test is included to verify the correctness of the HTTP abort message encoding against expected binary bytes.

engine/sdks/typescript/envoy-protocol, engine/sdks/typescript/runner-protocol · high confidence

Inspector UI bundle now ships embedded in the rivetkit-core crate

The inspector UI and tab assets are now bundled directly into the published rivetkit-core crate, ensuring the inspector UI is served from embedded memory rather than degrading to a 404. A new build.rs stages the frontend dist into the crate during packaging, and a release verification script confirms the assets are included in the archive and served correctly at runtime.

rivetkit-rust/packages/rivetkit-core · high confidence

Inspector protocol schema and versioning updated to v6

The inspector-protocol package now defines and supports protocol version 6, introducing new capabilities for actor scheduling (SchedulesRequest, ScheduleHistoryRequest, ScheduleDeleteRequest) and tab configuration (TabConfigEntry). The package includes a build script that generates TypeScript codecs from BARE schemas and provides Rust serialization/deserialization logic with converters for all six protocol versions (v1–v6).

rivetkit-rust/packages/inspector-protocol · high confidence

Introduce Epoxy Replica v2 workflow for cluster initialization and catch-up

Added a new \epoxy\_replica\_v2\ workflow that manages the replica lifecycle, starting with a \BeginLearning\ signal to trigger setup. This workflow stores the cluster configuration, performs a catch-up loop to apply historical entries until no more are available, and finally notifies the coordinator that the replica is active. This replaces the previous replica setup logic with a structured workflow-based approach.

engine/packages/epoxy/src/workflows/replica · high confidence

Introduce Epoxy v2 key definitions and subspace management

The Epoxy engine now defines a new set of storage keys (KvValueKey, KvBallotKey, KvAcceptedKey, etc.) and subspace helpers (subspace, legacy\_subspace) for its v2 protocol implementation. These keys handle serialization and deserialization of committed values, ballots, and accepted proposal states, with specific handling for versioned data and legacy compatibility. This change establishes the foundational key structure for the new Epoxy v2 replica configuration and data storage layout.

engine/packages/epoxy/src/keys · high confidence

Introduce Inspector MCP app and Ladle storybook for frontend development

The frontend now includes a standalone Inspector MCP application (apps/inspector-ui) that runs as a sandboxed iframe, featuring a postMessage bridge for shell communication, in-memory storage fallbacks for sandboxed environments, and dedicated telemetry for Sentry and PostHog. Additionally, a Ladle storybook has been added for component development, complete with a dark-themed CSS configuration and Caddyfile for local serving.

frontend · high confidence

Introduce Pegboard Gateway v2 with hibernation support and enhanced observability

This change introduces a new gateway implementation (Pegboard Gateway v2) that adds support for request hibernation, allowing long-lived connections to persist across actor restarts via a keepalive mechanism. It includes dedicated tasks for managing WebSocket tunnels, pings, and metrics collection, along with a comprehensive set of Prometheus metrics for monitoring tunnel latency, in-flight requests, and data transfer volumes. The new gateway also implements rate limiting for WebSocket ingress and improved error handling for tunnel subscriptions and garbage collection.

engine/packages/pegboard-gateway2 · high confidence

Introduce React integration for RivetKit actors

This change adds the \@rivetkit/react\ package, providing React-specific hooks to integrate with RivetKit actors. It introduces \createRivetKit\ and \createRivetKitWithClient\ to initialize the client, and exposes a \useActor\ hook that manages actor connection state (including \isConnected\, \isConnecting\, and \connStatus\) and provides a \useEvent\ method for subscribing to actor events with full type safety. The package includes configuration files (\tsconfig.json\, \tsup.config.ts\, \turbo.json\) to support building and bundling the React bindings.

rivetkit-typescript/packages/react · high confidence

Introduce Rivet CLI with compute pool, token, and logging capabilities

The CLI now supports managing Rivet Compute infrastructure directly from the command line. Users can create and manage namespace-scoped tokens via the new \token\ command, view and filter logs for compute instances with the \logs\ command, and manage compute pools (including creation, deletion, and configuration) via the \pool\ command. Deployment commands now accept resource flags such as \--cpu\, \--memory\, \--min-scale\, \--max-scale\, and \--instance-request-concurrency\ to configure managed pool resources, along with runner configuration flags like \--max-concurrent-actors\. Authentication is handled via a new credential file at \\~/.rivet/credentials\ or the \RIVET\_CLOUD\_TOKEN\ environment variable, and the CLI includes a \setup-ci\ command to install a GitHub Actions workflow for automated deployments.

engine/packages/cli/src · high confidence

Introduce RivetError derive macro for structured error handling

Adds the \engine/packages/error-macros\ crate, which provides the \RivetError\ procedural macro. This allows developers to derive error types that automatically generate structured error schemas, supporting both named and unnamed struct fields with optional formatted descriptions. The macro integrates with the \rivet\_error\ and \anyhow\ crates to produce standardized error objects with metadata.

engine/packages/error-macros · high confidence

Introduce RivetKit Next.js driver for serverless and edge applications

The \rivetkit-typescript/packages/next-js\ package is added, providing a framework to build serverless and edge applications using Next.js with RivetKit's actor model. It exports a \toNextHandler\ function that configures the RivetKit registry for Next.js API routes, automatically setting the base path and enabling hot-reloading in development by polling a metadata endpoint to detect code changes and drain older envoys. The package also includes a client module re-exporting \@rivetkit/react\ and a logging utility, supported by standard TypeScript and build configuration files.

rivetkit-typescript/packages/next-js · high confidence

Introduce RocksDB driver for UniversalDB with conflict-aware retries and snapshot isolation

A new RocksDB-based database driver has been added to the UniversalDB engine, providing an alternative to the existing PostgreSQL driver. This implementation uses an OptimisticTransactionDB to support transaction retries with configurable limits and exponential backoff, ensuring that conflicts are handled gracefully without data loss. It enforces snapshot isolation by pinning a read version at the first read operation within a transaction, preventing partial visibility of concurrent commits. The driver also includes specific safeguards to avoid undefined behavior when handling empty values during iteration, ensuring stability in debug builds.

engine/packages/universaldb/src/driver/rocksdb · high confidence

Introduce Swift SDK for RivetKit

Adds a new Swift client library for interacting with Rivet actors, providing a SwiftUI-compatible API with declarative state management via the @Actor property wrapper. The SDK supports async actions and event handling using Swift parameter packs for variadic typed arguments, enforces CBOR encoding for the wire protocol, and includes utilities for configuration, error handling, and WebSocket communication.

rivetkit-swift · high confidence

Introduce TypeScript runner SDK with hibernating WebSocket support

The TypeScript runner SDK is now available in \engine/sdks/typescript/runner\, providing the core \Runner\ class and \RunnerActor\ implementation for managing actor lifecycles. This release introduces support for hibernating WebSockets, allowing connections to persist while actors sleep, along with a new protocol version (v7) and a \Tunnel\ layer for message buffering and restoration. The SDK includes utilities for logging, payload size enforcement, and wrapping arithmetic, alongside a new \importWebSocket\ function for environment-agnostic WebSocket handling.

engine/sdks/typescript/runner · high confidence

Introduce TypeScript test-runner SDK with internal HTTP server and runner lifecycle management

This change adds a new TypeScript test-runner component located at engine/sdks/typescript/test-runner. It provides an internal HTTP server (powered by Hono) that exposes endpoints for health checks (/health), readiness (/wait-ready), actor verification (/has-actor), and controlled shutdown (/shutdown). The runner supports manual initialization via an SSE stream at /api/rivet/start and can automatically configure serverless settings via /api/rivet/metadata. Configuration is driven by environment variables (e.g., RIVET\_ENDPOINT, RIVET\_TOKEN, INTERNAL\_SERVER\_PORT) and includes a custom Pino-based logging layer with configurable levels and target tracking. The package is set up with tsup for ESM bundling, vitest for testing, and turbo for build orchestration.

engine/sdks/typescript/test-runner · high confidence

Introduce WebSocket hibernation and keepalive mechanisms in the Pegboard Gateway

The Pegboard Gateway now supports WebSocket hibernation, allowing idle WebSocket connections to be suspended and resumed without dropping the underlying request state. This change introduces dedicated tasks to manage the lifecycle of hibernating connections: a keepalive task periodically updates the request's status in the database to prevent garbage collection, a ping task sends regular pings to maintain the tunnel connection, and a metrics task tracks ingress and egress byte counts for monitoring. The shared state logic has been updated to handle hibernation states, manage pending message queues, and enforce timeouts, ensuring that in-flight requests remain valid while the WebSocket is hibernated.

engine/packages/pegboard-gateway · high confidence

Introduce Workflow World integration and SDK example

This change adds a new \integrations/workflow-world\ package that implements the backend actors (coordinator, dispatcher, hook-token, streams, and workflow-run) and database schema for the Workflow World runtime, alongside a new \examples/workflow-sdk\ example that demonstrates how to start and query workflow runs using the Hono-based SDK server.

examples/workflow-sdk, integrations/workflow-world · high confidence

Introduce base framework package with actor management and TypeScript configuration

This change introduces the \framework-base\ package, establishing the foundational infrastructure for actor management in RivetKit. It adds the \ActorOptions\ interface, which now supports a \noCreate\ option to retrieve existing actors without creating new ones, and defines the \createRivetKit\ function to initialize the actor store and cache. The package also includes standard TypeScript build configuration (\tsconfig.json\, \tsconfig.build.json\) and bundler setup (\tsup.config.ts\) to support the framework's module resolution and compilation.

rivetkit-typescript/packages/framework-base · high confidence

Introduce centralized connection pooling and SSRF-protected HTTP clients

The \pools\ package now provides a unified \Pools\ struct that manages database connections for UPS, UDB, and ClickHouse, along with a dedicated \NodeId\ for service identification. It also introduces pre-configured HTTP clients: a standard client for internal engine traffic and guarded clients (\guarded\_client\, \guarded\_client\_no\_timeout\) that enforce an SSRF policy via \rivet\_outbound\_guard\ to restrict user-configured URLs from reaching internal network services. Additionally, Prometheus metrics for SQL query and connection acquisition are registered, and the Rust TLS provider is automatically installed during pool initialization.

engine/packages/pools/src · high confidence

Introduce container-runner for hosting dedicated game servers

Adds a new \container-runner\ component that allows users to wrap dedicated game servers (such as Unity or Node processes) in a container. The runner spawns a child process per actor, proxies Rivet HTTP/WebSocket traffic to it, and keeps the instance warm after the last actor stops to support efficient cold-starts. The entry includes the Rust source code, a release Dockerfile for building the standalone binary, and a build script that embeds the git commit SHA into the binary for version logging.

container-runner · high confidence

Introduce experimental Actor Runtime Socket protocol with SQLite support

This change adds the initial version (v1) of the Actor Runtime Socket wire protocol, defining the schema for a handshake mechanism and a set of SQLite API requests and responses (including exec, query, and transaction management). It includes the Rust SDK code to serialize and deserialize these versioned frames, a build script that generates corresponding TypeScript codecs for the Rivetkit tooling, and tests verifying the round-trip encoding of the protocol frames.

engine/sdks/rust/actor-runtime-socket-protocol · high confidence

Introduce guard-core library for request proxying and TLS management

The guard-core library has been added to the engine, providing the core logic for the Guard service. It includes a custom TLS certificate resolver for SNI-based HTTPS support, a comprehensive error type system for structured error reporting, and a proxy service that handles HTTP and WebSocket routing, caching, and admission controls (rate limiting and in-flight request limits). The library also exposes detailed metrics for gateway requests, TCP connections, and WebSocket operations, along with utilities for request context management and response body streaming.

engine/packages/guard-core/src · high confidence

Introduce initial Rust client for RivetKit actors

Adds the \rivetkit-client\ Rust package, providing a new way for Rust applications to connect to and interact with RivetKit actors. The client supports WebSocket transport for actor connections and offers multiple encoding formats (JSON, CBOR, and Bare). It exposes APIs for getting, creating, and getting-or-creating actors, as well as sending actions, queueing messages, and subscribing to actor events. The implementation includes a remote manager for gateway communication, backoff logic for reconnection, and comprehensive protocol handling for both HTTP and WebSocket interactions.

rivetkit-rust/packages/client · high confidence

Introduce new Pegboard runner WebSocket implementation

The \pegboard-runner\ package now provides a complete WebSocket-based runner connection layer, replacing the previous implementation. This new component handles runner lifecycle management (including connection initialization, ping/pong keep-alive, and eviction), routes bidirectional traffic between the runner and the gateway via pub/sub topics, and introduces an \ActorEventDemuxer\ to batch and efficiently forward actor events to their respective workflows. It supports both the legacy protocol and the new \mk2\ protocol version, ensuring backward compatibility while enabling improved performance and reliability for runner operations.

engine/packages/pegboard-runner · high confidence

Introduce new \`util-id\` package for ID generation and serialization

A new \util-id\ library has been added to the engine, providing a standardized \Id\ type (currently supporting V1) that combines a UUID with a 16-bit label. This component enables users to generate, parse, and serialize IDs using a compact 30-character base36 string format, facilitating consistent identifier handling across the system.

engine/packages/util-id · high confidence

Introduce platform-specific binary resolution for the Rivet engine CLI

The \@rivetkit/engine-cli\ package now provides a JavaScript entry point that automatically resolves the correct \rivet-engine\ binary for the current host (Linux x64/arm64, macOS Intel/Apple Silicon, and Windows x64 on release builds). It supports overriding the binary path via the \RIVET\_ENGINE\_BINARY\ environment variable and falls back to a local binary for development, ensuring the engine binary is available across supported platforms without manual configuration.

rivetkit-typescript/packages/engine-cli · high confidence

Introduce serverless metadata fetch operation with SSRF protection

Added a new \pegboard\_serverless\_metadata\_fetch\ operation that retrieves runtime, version, and actor name metadata from serverless runners. The implementation includes SSRF protection by validating URLs against an outbound policy before making requests, and standardizes error reporting into a stable \{message, details, metadata}\ envelope for consistent API client handling.

_engine/packages/pegboard/src/ops/serverless\metadata · high confidence

Introduce standardized terminal helper library

The \term\ package now provides a shared library of terminal utilities for all Rivet CLIs, including colored status logging (info, progress, success, warn, error), interactive prompts (boolean, string, secure input, and parsed values), formatted table output, and hidden progress bars that respect non-interactive environments.

engine/packages/term · high confidence

Introduce stateless depot conveyer with branch, commit, and compaction infrastructure

The depot engine now uses a new stateless conveyer architecture to manage database operations. This change introduces branch management capabilities, including the ability to fork databases and buckets, resolve branch ancestry, and perform rollbacks. It also implements a new commit path that supports staged commits with segment-based storage for large payloads, ensuring they fit within transaction limits. Additionally, the conveyer integrates with the compaction workflow, handling hot and cold tier storage, delta blob chunking, and LTX V3 encoding, while enforcing strict bounds on fork depth, restore points, and commit sizes to maintain system stability.

engine/packages/depot/src/conveyer · high confidence

Introduce structured error handling and registry web handler in @rivetkit/effect

The \@rivetkit/effect\ package now provides a comprehensive, schema-driven error classification system via \RivetError\, replacing generic failures with granular reason classes (e.g., \ActorNotFound\, \GuardServiceUnavailable\, \ActionErrorDecodeFailed\) that expose normalized accessors like \isRetryable\ and \retryAfter\. This structured approach ensures that action error metadata is correctly decoded and surfaced to users. Additionally, the package introduces a \Registry\ module with a \toWebHandler\ adapter, allowing registered actors to be served as standard Fetch-compatible HTTP handlers with configurable serverless routing options like \basePath\ and \maxStartPayloadBytes\.

rivetkit-typescript/packages/effect · high confidence

Introduce structured history tracking with cursor and location support

The history module in the gasoline engine now includes a new \Cursor\ for traversing workflow history events, a \Location\ and \Coordinate\ system for precise event positioning, and structured event types (such as \ActivityEvent\, \SignalSendEvent\, and \Removed\) to support replay and versioning. This change provides the foundational infrastructure for managing workflow state history, enabling features like graceful signal handling and batch listening in workflows.

engine/packages/gasoline/src/history · high confidence

Introduce traces package with BARE schema and OpenTelemetry export

The new traces package provides a complete tracing implementation for Rivetkit. It defines a BARE schema (v1.bare) for an append-only Span stream, which is compiled to TypeScript and handled via versioned serialization (versioned.ts) for efficient storage. The core logic (traces.ts) manages span lifecycle, chunking, and persistence through a pluggable TracesDriver, while read-range.ts converts internal records into OTLP v1 JSON for export. A browser-specific entry (index.browser.ts) ensures the server-only API is stubbed out in client bundles, and a noop implementation (noop.ts) is available for environments where tracing is disabled.

rivetkit-typescript/packages/traces · high confidence

Introduce universal pubsub engine with NATS driver, chunking, and metrics

The \universalpubsub\ package is introduced, providing a unified pub/sub abstraction with a new NATS driver (\async-nats\) that supports queue subscriptions, request-reply patterns, and a 1 MB message size limit. It adds automatic message chunking for payloads exceeding the driver limit, featuring a fast-path for single-chunk messages and garbage collection for in-flight chunk buffers. The engine also includes comprehensive Prometheus metrics for subscriber counts, message throughput, publish latency, and NATS client internals, along with structured error handling for timeouts and publish failures.

engine/packages/universalpubsub/src · high confidence

Introduce versioned SQLite storage protocol for DB head serialization

The depot-protocol crate now includes a new versioned serialization layer for the SQLite storage protocol. It defines a \DBHead\ type that wraps the latest schema version (v1) and handles encoding/decoding with an embedded 2-byte version prefix using \serde\_bare\. This enables forward-compatible storage of database head metadata, with a constant \SQLITE\_STORAGE\_PROTOCOL\_VERSION\ set to 1 to track the current schema version.

engine/sdks/rust/depot-protocol · high confidence

Introduce versioned data types for SQLite branch, compaction, and restore point management

The depot engine now defines a comprehensive set of versioned data structures to support point-in-time recovery (PITR), database forking, and cold storage compaction. This change adds type definitions for branch states (Live/Frozen), bucket and database branch records, and pointers, enabling the engine to track fork history and restore points. It also introduces types for compaction management, including cold shard references, reclaim progress, and staged hot shards, as well as policies for PITR intervals and shard cache retention. These types provide the serialization and versioning infrastructure required for the new SQLite storage features.

engine/packages/depot/src/conveyer/types · high confidence

Introduces SQLite VFS v2 on-disk metadata schema

A new on-disk metadata schema (v1.bare) is added to define the structure for the SQLite VFS v2 storage layer. This schema introduces a DBHead record that tracks transaction IDs, storage metrics, and a new SqliteOrigin enum to distinguish between actors created natively on v2 storage and those undergoing or having completed migration from v1.

engine/sdks/schemas/depot · high confidence

Introduces database utility primitives for key management and transaction handling

Adds a new set of utility modules to the universal database engine to support internal data operations. This includes a \CherryPick\ trait for atomically retrieving specific keys from a transaction, a \Subspace\ wrapper that instruments key packing and unpacking with metrics, and a comprehensive \keys\ module defining numeric constants and string mappings for internal data structures (such as actors, workflows, and runners). The update also provides helper traits for deserializing keys from byte slices and implements an exponential backoff algorithm for transaction retries.

engine/packages/universaldb/src/utils · high confidence

Introduces embedded SQLite transport for in-process deployments

Adds a new \EmbeddedDepotSqliteTransport\ implementation that allows the SQLite VFS to run in the same process as the Depot backend. This change enables deployments where the database and engine share memory, keeping engine storage dependencies out of the base \depot-client\ crate used by NAPI, and provides a new \open\_database\_from\_embedded\_depot\ entry point for initializing the database via this embedded transport.

engine/packages/depot-client-embedded · high confidence

Introduces end-to-end HTTP body streaming and hibernation support in the gateway

The gateway now supports streaming HTTP request and response bodies end-to-end, replacing the previous buffering approach. This change adds a new \http\_stream\ module that handles chunked request uploads, response delivery with back-pressure and window management, and request aborts. It also introduces hibernation support for long-lived requests, allowing the gateway to persist request state and keep it alive while the actor is stopped, ensuring that streaming connections can resume correctly. Additionally, the gateway now forwards the request ray ID to actors for better traceability.

engine/packages/pegboard-gateway3 · high confidence

Introduces native and WASM WebSocket transport implementations for the Envoy client

The \envoy-client\ SDK now supports connecting to the Envoy control plane via WebSocket on both native Rust and WebAssembly targets. This change adds \connection/mod.rs\, \connection/native.rs\, and \connection/wasm.rs\ to handle connection lifecycle, including session management, reconnection with exponential backoff, and streaming HTTP bodies over the WebSocket tunnel. The implementation enforces mutual exclusivity between \native-transport\ and \wasm-transport\ features and includes byte-budgeting for HTTP messages to prevent unbounded memory usage.

engine/sdks/rust/envoy-client/src/connection · high confidence

Introduces new database compaction and maintenance workflows

The depot engine now includes a suite of new workflows to handle database compaction and maintenance. This adds a backfill workflow to initialize compaction managers for existing databases, a hot compactor to stage and process hot data slices, a manager to coordinate compaction activities and schedule wakes, and a reclaimer to sweep and clear abandoned commit and delta history. These changes shift compaction from a purely lazy, write-triggered model to a more proactive and managed system with dedicated lifecycle workflows.

engine/packages/depot/src/workflows · high confidence

Introduces workflow builder components for loops, messages, signals, and sub-workflows

The workflow builder module now includes new implementations for core workflow primitives: \lupe.rs\ provides the loop builder with configurable commit intervals and history replay support; \message.rs\ handles message dispatch with optional topic targeting and wait modes; \signal.rs\ enables sending signals to specific workflows with tag-based routing and graceful not-found handling; and \sub\_workflow.rs\ allows dispatching sub-workflows with unique constraint support and tag-based filtering. These builders integrate with the workflow context to manage history cursors, commit events to the database, and emit metrics for loop commits, message sends, signal dispatches, and sub-workflow invocations.

engine/packages/gasoline/src/builder/workflow · high confidence

Introducing the durable TypeScript workflow engine

The \@rivetkit/workflow-engine\ package is now available, providing a durable execution system for TypeScript that enables long-running, fault-tolerant workflows. Workflows are written as standard async functions and automatically persist their history to an \EngineDriver\, allowing them to survive process crashes, restarts, and deployments by replaying from the last known state. The engine supports complex control flow including durable loops with state checkpoints, parallel execution via \join\ and \race\, and external event handling through queue waits. It also includes built-in fault tolerance with automatic step retries, rollback handlers for undoing completed steps on failure, and helpers like \tryStep\ and \try\ to manage terminal errors gracefully.

rivetkit-typescript/packages/workflow-engine · high confidence

Introduction of a unified PubSub driver interface

The engine now exposes a standardized \PubSubDriver\ trait and associated types (such as \PublishBehavior\ and \SubscriberDriver\) within the \universalpubsub\ package. This interface abstracts the underlying messaging transport, allowing the system to support both in-memory optimizations for single-subscriber scenarios and broadcast capabilities, while providing a consistent API for subscribing, publishing, and flushing messages across different backends.

engine/packages/universalpubsub/src/driver · high confidence

Introduction of the Gasoline workflow engine core

This change introduces the foundational components of the Gasoline workflow engine within the \engine/packages/gasoline/src\ directory. It defines the core abstractions for workflow execution, including the \Workflow\, \Activity\, \Operation\, and \Executable\ traits, which structure how tasks are defined and run. The diff adds a comprehensive error handling system via \WorkflowError\, a registry for managing workflow definitions, and a worker implementation that polls for and executes workflows. Additionally, it establishes the infrastructure for observability by adding Prometheus metrics for workflow lifecycle, activity performance, and worker health, as well as utilities for message handling, signal joining, and context management.

engine/packages/gasoline/src · high confidence

Introduction of the service-manager package for runtime service orchestration

The new \engine/packages/service-manager\ package provides the core runtime logic for managing and executing background services. It defines a \Service\ struct and \ServiceKind\ enum to categorize workloads (such as \ApiPublic\, \Standalone\, \Oneshot\, \Cron\, and \Core\) and dictates their lifecycle behavior, including automatic restarts for long-running services and scheduled execution for cron jobs. The \start\ function orchestrates these services, integrating a metrics server, handling SIGTERM signals for graceful shutdown, and managing task concurrency via Tokio.

engine/packages/service-manager · high confidence

Introduction of the workflow-worker service entry point

A new \workflow-worker\ package has been added to the engine, providing the main entry point (\start\) for initializing and running the workflow worker. This component sets up the necessary database and registry connections, specifically merging the \rivet\_auth\_jwt\ registry to enable namespace-scoped JWT authentication within the worker context.

engine/packages/workflow-worker · high confidence

Introduction of workflow and activity macro attributes

The gasoline-macros package now provides \\#\[workflow\]\ and \\#\[activity\]\ procedural macro attributes that automatically generate the necessary trait implementations for defining workflows and activities. The \\#\[workflow\]\ macro supports configuration for pruning variants (All, History, None) and enforces naming conventions, while the \\#\[activity\]\ macro allows setting retry counts and timeouts, defaulting to 5 retries and a 30-second timeout if not specified.

engine/packages/gasoline-macros · high confidence

Kitchen-sink example expanded with comprehensive actor lifecycle and integration demos

The kitchen-sink example has been significantly expanded to demonstrate a wide range of RivetKit actor capabilities. New examples cover action inputs and timeouts, synchronous and asynchronous action patterns, and detailed error handling with UserError. It now includes actors for managing WebSocket connections with per-connection state, rejecting connections, and accessing raw HTTP request properties. The example also features raw HTTP routing using Hono, a WebSocket chat room, and serverless WebSocket smoke tests. Inter-actor communication is demonstrated through an inventory and checkout workflow. Lifecycle management is thoroughly covered with examples for hibernation, sleep/wake cycles, scheduled tasks, run handlers with queue consumption, and actor destruction observers.

examples/kitchen-sink · high confidence

Memory pub/sub driver adds queue subscription support and garbage collection

The in-memory pub/sub driver now supports queue-based subscriptions alongside standard topic subscriptions, allowing multiple subscribers to share a queue where each message is delivered to only one consumer. It also introduces a background garbage collection task that periodically cleans up closed subscriber channels to prevent memory leaks and updates metrics to track the total subscriber count.

engine/packages/universalpubsub/src/driver/memory · high confidence

Namespace creation workflow implementation

The engine now includes a workflow for creating namespaces, located in \engine/packages/namespace/src/workflows\. This workflow validates input (checking name and display name constraints), ensures the leader node performs the operation, and persists the namespace details to the database within a transaction. It handles success by emitting a \CreateComplete\ message and errors by emitting a \Failed\ message, both scoped to the specific namespace ID. The workflow also sets up a listener for future \Update\ signals.

engine/packages/namespace/src/workflows · high confidence

Namespace-scoped JWT authentication and authorization

The engine now supports authenticating requests via Rivet JWTs in addition to administrator tokens. The \auth\ package verifies JWT signatures using a key ring cache and extracts an \EffectiveAuthority\ containing namespace-scoped grants. The \auth-policy\ package provides the underlying policy engine that evaluates these grants against access requests, enforcing strict scope matching (preventing delegation from widening namespace, resource, target, or operation authority) and returning specific error codes for invalid, expired, or insufficiently permitted tokens.

engine/packages/auth, engine/packages/auth-policy · high confidence

Namespace-scoped JWT authentication with strict claims and key-ring caching

The auth-jwt package now implements a new JWT authentication protocol where access tokens are scoped to specific namespaces via a \rivet\_ns\ claim and contain versioned, base64-encoded grants. The system enforces strict claims validation (rejecting unknown fields) and supports EdDSA signing with a managed key ring that handles active, pending, and retiring keys. A new \KeyRingCache\ component caches verification keys and manages background refreshes, including a specific \EpoxyV4Pending\ state that allows the Guard service to start up even if the Epoxy v4 key-ring service is not yet available.

engine/packages/auth-jwt · high confidence

New 'create-launch-post' skill for automated launch workflows

A new Claude skill has been added to automate the creation and publication of Rivet launch and changelog posts. This tool guides users through a structured workflow including release research, hero image rendering (supporting both painting and logo-tile variations), MDX blog post drafting, R2 asset uploading, and Buffer thread scheduling. It includes specific scripts for rendering technical images and social graphics, ensuring consistent visual assets and verified publication steps.

.claude/skills/create-launch-post · high confidence

New @rivetkit/cloudflare-workers package for hosting Rivet Actors on Cloudflare Workers

The new @rivetkit/cloudflare-workers package enables hosting Rivet Actors on Cloudflare Workers. It provides a \setup\ function to initialize the registry with the WebAssembly runtime and a \createHandler\ function to serve the Rivet manager API (defaulting to \/api/rivet\) while allowing custom routes via a \fetch\ option. The package automatically installs a fetch-based WebSocket shim to support the wasm runtime's outbound tunnel to the Rivet engine, and it reads connection configuration (\RIVET\_ENDPOINT\, \RIVET\_NAMESPACE\, \RIVET\_TOKEN\, \RIVET\_POOL\) from Worker environment variables if not explicitly provided.

rivetkit-typescript/packages/cloudflare-workers · high confidence

New AI agent example using the Effect SDK

The \examples/ai-agent-effect\ directory now contains a complete example of an AI chat agent built with the Effect SDK. It defines an \Agent\ actor with \SendMessage\ and \GetHistory\ actions, persisting conversation turns in state. The implementation uses dependency injection to swap the underlying LLM provider, defaulting to OpenAI via \OpenAiModelLayer\, and includes client and server wiring examples with telemetry support.

examples/ai-agent-effect · high confidence

New API builder library for Axum-based services

The \engine/packages/api-builder\ package introduces a new Rust library that simplifies building HTTP APIs with Axum. It provides a standardized request context (\ApiCtx\) for dependency injection, a structured error handling system that maps internal errors to specific HTTP status codes and JSON responses, and custom extractors for JSON, query, path, and extension data. The library includes a router factory that automatically configures CORS, request logging, metrics (pending requests, total count, duration, errors), and OpenTelemetry tracing, along with helper macros for defining route handlers for all standard HTTP methods.

engine/packages/api-builder · high confidence

New API type definitions for actors, auth, and infrastructure management

The \engine/packages/api-types\ package now provides the formal request and response schemas for the engine's public API. This includes type definitions for actor lifecycle operations (create, delete, get-or-create, list, reschedule, sleep, and key-value access), namespace-scoped JWT authentication tokens, and listing capabilities for namespaces, runners, runner configs, envoys, and datacenters. These types establish the contract for how clients interact with the engine's core resources.

engine/packages/api-types · high confidence

New Docker base images for engine and rivetkit builds

Added a suite of Docker base images in docker/builder-base to standardize and accelerate cross-platform builds. The engine-builder image provides a Linux environment with Rust 1.91.1, Node.js 22, and FoundationDB 7.3.68 for engine container builds. Runtime images (full and slim) supply the FoundationDB client library for Linux deployments. Platform-specific images (linux-gnu, linux-musl, osxcross, windows-mingw) pre-configure the necessary toolchains (Clang 14, MinGW, osxcross), Rust targets, Node.js 22, and sccache to support native addon compilation for Linux, macOS, and Windows.

docker/builder-base · high confidence

New Epoxy v2 coordinator workflow for cluster state management

The Epoxy engine now includes a new v2 coordinator workflow (located in \engine/packages/epoxy/src/workflows/coordinator\) that manages cluster configuration and replica lifecycle. This workflow initializes cluster state, detects configuration changes, and handles the addition of new replicas by performing health checks, transitioning them to a joining state, and sending 'BeginLearning' signals. It also manages replica status changes, automatically incrementing the cluster epoch when replicas become active, and ensures all replicas receive updated configuration via the \NotifyAllReplicas\ activity. This replaces the previous coordination logic with a structured workflow that supports dynamic cluster reconfiguration and state override capabilities.

engine/packages/epoxy/src/workflows/coordinator · high confidence

New Flue integration for Rivet Actors

Added the \@rivet-dev/flue\ integration package, which allows Flue agents and workflows to be compiled and deployed as durable Rivet Actors. This integration provides a runtime adapter that maps Flue execution models to Rivet's actor lifecycle, utilizing each actor's native SQLite database for durable session storage, submission recovery, and event streaming. It includes a build target for the Flue CLI to generate the necessary RivetKit entry points and exposes the necessary runtime APIs for inter-actor dispatch and durable state management.

integrations · high confidence

New Go SDK for API interaction

The Go SDK in \engine/sdks/go\ has been replaced with a new, auto-generated client library (generated by Fern). This update provides a structured API client with dedicated sub-clients for managing actors, namespaces, runners, envoys, datacenters, and health status, along with core utilities for HTTP calls, error handling, and request configuration.

engine/sdks/go · high confidence

New KV-based workflow database driver for Gasoline

The Gasoline engine now includes a new key-value database driver implementation located in \engine/packages/gasoline/src/db/kv\. This driver, built on UniversalDB and UniversalPubSub, provides the core persistence layer for workflows, including detailed debug inspection capabilities (\debug.rs\), automatic detection and repair of corrupted workflow history states (\repair.rs\), and system-level metrics collection such as CPU usage tracking (\system.rs\).

engine/packages/gasoline/src/db/kv · high confidence

New React integration example for Rivet Actors

Added a new example application in the \examples/react-render\ directory that demonstrates how to integrate Rivet Actors with a React frontend. The example includes a backend (\src/actors.ts\, \src/index.ts\) defining a counter actor and a Hono-based server for static assets and API routing, alongside a React frontend (\frontend/app/App.tsx\) that uses \createRivetKit\ and \useActor\ to manage real-time state and UI updates.

examples/react-render, examples/react-render/frontend · high confidence

New Rivet CLI commands for deployment, local development, and pool management

The CLI now includes a suite of new commands to manage the full lifecycle of Rivet applications. The \deploy\ command allows users to build and push Docker images to managed compute pools, with new flags to configure compute resources (CPU, memory, scaling limits) and a \--reuse-image\ option to update resources without rebuilding. Local development is streamlined with the \dev\ command, which supports providers like Supabase and Cloudflare, automatically injecting the engine endpoint and handling handler registration. Users can now inspect logs with the \logs\ command (supporting live tailing and history filtering) and manage compute pools directly via \pool list\ and \pool delete\. Additionally, the \token\ command enables the creation of namespace-scoped tokens (secret, public, or connection), and \setup\_ci\ generates a GitHub Actions workflow for automated deployments.

engine/packages/cli/src/commands · high confidence

New Rivet Docs MCP Server package

The \@rivetkit/mcp-hub\ package introduces a standalone Model Context Protocol (MCP) server that serves Rivet documentation. It exposes tools for searching, retrieving, and listing documentation sections, sourcing metadata from \https://rivet.dev/metadata/docs.json\ (overridable via \DOCS\_METADATA\_URL\ or \DOCS\_METADATA\_PATH\). The package provides a CLI entry point for local development and a library API (\createDocsMcpServer\, \createSseResponse\) for embedding the server in HTTP handlers, and includes a Dockerfile for containerized deployment.

rivetkit-typescript/packages/mcp-hub · high confidence

New Rust test-envoy SDK for local Envoy simulation

A new Rust SDK (\test-envoy\) is introduced to provide a local, configurable Envoy proxy for testing purposes. It exposes a library interface (\lib.rs\) re-exporting core client types and a binary entrypoint (\main.rs\) that runs an HTTP server (\server.rs\). This server manages the Envoy lifecycle via environment variables (e.g., \RIVET\_NAMESPACE\, \RIVET\_ENVOY\_VERSION\) and exposes endpoints for health checks, shutdown, and triggering serverless actors, allowing developers to simulate the Envoy protocol locally without external dependencies.

engine/sdks/rust/test-envoy/src · high confidence

New SQLite compaction diagnostics and burst-mode behavior

Engine operators now have a Python script to estimate compaction backlog directly from FoundationDB, providing drain rates and projected finish times for troubleshooting. The engine also introduces a burst-mode mechanism that detects when cold compaction lags significantly behind the head and temporarily increases the hot compaction quota cap to accelerate catch-up. Additionally, a shell script is provided to verify that fault-injection symbols do not leak into production release builds.

engine/packages/depot/src · high confidence

New State Management example with persistent chat

Added a new example demonstrating persistent actor state management using RivetKit. This example features a chat application where messages survive server restarts through automatic serialization. The frontend (React) connects to a backend (Hono) that exposes the actor registry, allowing users to send, view, and clear messages in real-time while seeing connection status.

examples/state-render, examples/state-render/frontend · high confidence

New Stream Processor example with real-time top-K leaderboard

Added a new example application in the \examples/stream-render\ directory that demonstrates a real-time stream processing capability using RivetKit. The backend actor (\src/actors.ts\) maintains a live leaderboard of the top 3 values, broadcasting updates to connected clients whenever a new value is added or the state is reset. The frontend (\examples/stream-render/frontend/app/App.tsx\) provides a UI to input values and view the live-updating leaderboard, total count, and highest value, connecting to the backend via a Rivet client configured in \rivet-client.ts\. The example includes server setup using Hono to serve the static frontend and handle Rivet API routes, with environment-based configuration for local development versus Render cloud deployment.

examples/stream-render, examples/stream-render/frontend · high confidence

New TypeScript API SDK for Node and Browser environments

This change introduces the \api-full\ TypeScript SDK, providing a client library to interact with the Rivet engine API. The SDK includes a \RivetClient\ with resource-specific sub-clients for managing actors, auth tokens, datacenters, envoys, health, metadata, namespaces, and runners. It supports both Node.js (via CommonJS and ESM) and browser environments, generated from the API definition using Fern, and includes a build script to bundle the code for these different targets.

engine/sdks/typescript/api-full · high confidence

New TypeScript engine runner implementation

The \engine-runner\ package now provides a complete TypeScript implementation of the actor runner, replacing the previous version. This introduces a new \Runner\ class and \RunnerActor\ model that manage actor lifecycles, including start/stop events and hibernatable WebSocket connections. The runner handles protocol version 7, manages pending HTTP requests and WebSocket tunnels, and supports restoring hibernated WebSocket states across actor restarts. It also includes utilities for logging (via pino), backoff calculations, and safe u16 index wrapping for message sequencing.

rivetkit-typescript/packages/engine-runner · high confidence

New UDB interactive CLI with key navigation and data operations

The engine now includes a new interactive command-line interface for UniversalDB (UDB) located in \engine/packages/engine/src/commands/udb\. This tool provides an interactive shell (with history support) and a non-interactive query mode (\-q\) for managing UDB data. Users can navigate key paths using \cd\, \get\, and \ls\ commands, which support relative paths, type hints, and various display styles. The CLI also supports data manipulation via \set\, \clear\, and \move\ commands, as well as size estimation with \size\. Additionally, it includes one-off maintenance commands for reapplying lost serverless data and repairing epoxy v2 changelog entries.

engine/packages/engine/src/commands/udb · high confidence

New VirtualWebSocket library for abstracting WebSocket connections

A new shared TypeScript library has been added at shared/typescript/virtual-websocket, introducing a VirtualWebSocket class that implements a UniversalWebSocket interface. This allows developers to create linked WebSocket pairs and delegate send/close operations to callbacks, providing a standardized way to handle WebSocket-like connections without relying on the native browser API directly. The library includes specific event interfaces (RivetEvent, RivetMessageEvent, RivetCloseEvent) with experimental support for gateway and request IDs, and is configured for both ESM and CJS output formats.

shared/typescript/virtual-websocket · high confidence

New actor lifecycle workflows in Pegboard

The Pegboard engine now manages actor lifecycles through dedicated workflows in the \actor\ module. The main \pegboard\_actor\ workflow orchestrates creation, including validation, Epoxy key reservation, and index population. A new \destroy\ workflow handles cleanup, ensuring serverless autoscaler slots are released and KV storage is cleared. A \metrics\ workflow tracks actor awake duration and KV storage usage, while \runtime\ manages the active execution state, runner allocation, and crash policies.

engine/packages/pegboard/src/workflows/actor · high confidence

New actor2 workflow with configurable envoy load balancing and SQLite v2 support

The actor2 workflow introduces a new allocation strategy for serverful actors, allowing operators to choose from four envoy load-balancing strategies (hash, random\_ping\_timestamp, newest\_ping\_timestamp, and random\_full\_range) to control how actors are assigned to envoys. It also adds a migration path from SQLite v1 to v2 for existing actors and includes a dedicated metrics workflow to track actor awake duration and KV storage usage.

engine/packages/pegboard/src/workflows/actor2 · high confidence

New agentOS example applications

Added a suite of example applications for the agentOS runtime, demonstrating core capabilities such as agent sessions, cron scheduling, filesystem operations, Git workflows, process management, networking, sandboxing, and custom toolkits. Each example includes a server configuration (server.ts) that sets up the agentOS VM with specific software modules and mounts, and a client script (client.ts) that interacts with the agent to perform tasks like writing files, executing commands, scheduling jobs, and calling external tools.

examples/agent-os · high confidence

New api-peer service exposes actor, runner, and depot inspection APIs

A new api-peer service has been introduced to handle specific API endpoints, replacing or supplementing previous routing. It provides a comprehensive set of actor management operations including creation, deletion, get-or-create (with duplicate key handling), listing, and key-value retrieval, as well as lifecycle controls like sleep and reschedule. The service also exposes endpoints for listing and managing namespaces, runners, runner configs, and envoys. Additionally, it offers a detailed depot inspection API for debugging and inspecting database buckets, branches, and raw keys, along with internal endpoints for cache purging, epoxy coordinator state management, and profiling configuration.

engine/packages/api-peer · high confidence

New bootstrap package initializes core infrastructure and runs backfills

The \engine/packages/bootstrap\ package has been introduced to centralize the initialization of the engine's core infrastructure. On startup, it now automatically sets up the Epoxy replica and coordinator, creates a default namespace, and configures essential background services including the Pegboard metrics aggregator, the Gas pruner, and the datacenter ping workflow. Additionally, it executes a series of database backfills to ensure data consistency for actor runner name selectors, serverless configurations, runner pools, actor migrations, and depot compaction.

engine/packages/bootstrap · high confidence

New builder API for dispatching messages, signals, and workflows

Engine users now have a new fluent builder interface in the common builder module for interacting with the engine's core primitives. The \MessageBuilder\ allows dispatching messages to specific topics with optional wait-for-completion behavior and tracks send duration metrics. The \SignalBuilder\ enables sending signals to workflows by name (with tag-based lookup) or by ID, supporting custom tags and a \graceful\_not\_found\ mode that returns \Ok(None)\ instead of an error when the target workflow is missing. The \WorkflowBuilder\ provides a fluent way to dispatch workflows with optional unique-constraint enforcement (preventing duplicate dispatches with the same name and tags), custom tags, and methods to either wait for the workflow output or retrieve its current data state. All builders include error handling for invalid states and emit tracing/metrics for observability.

engine/packages/gasoline/src/builder/common · high confidence

New chat-room-effect example demonstrating typed actor interactions

Added a new example under \examples/chat-room-effect\ that showcases the \@rivetkit/effect\ SDK. It implements a \ChatRoom\ actor with schema-validated actions (Initialize, Join, Leave, SendMessage, GetHistory, Archive) and a \Moderator\ actor for content filtering. The example includes both a raw HTTP client (\client-raw.ts\) and an Effect-native client (\client.ts\) to demonstrate how domain errors like \MemberNotNotInRoomError\ and \BannedWordsError\ are handled, along with server-side wiring (\main.ts\) and telemetry layers.

examples/chat-room-effect · high confidence

New container runner implementation for hosting game server actors

The container runner has been rewritten using the RivetKit actor runtime to host child game-server processes. It now manages one child process per actor, handling port reservation, log piping, and readiness checks. Traffic from the platform is proxied to the child via HTTP and WebSocket tunnels. The runner supports an idle timeout with jitter to keep instances warm or sleep them when inactive, and implements a graceful drain period before stopping children on engine pause or shutdown. It also includes a resource monitor that samples memory and CPU usage, adapting to cgroup v1 (gVisor) or v2 environments.

container-runner/src · high confidence

New data schemas for authentication, runner configuration, and messaging protocol

This change introduces a set of new schema definitions in the \engine/sdks/schemas/data\ directory, establishing the data structures for several core engine capabilities. It adds \auth.grants.v1.bare\ to define namespace-scoped access control grants, and \auth.jwt\_key\ring.v1.bare\ through \v3.bare\ to manage JWT signing keys and issuer states, supporting the new namespace-scoped JWT authentication. It also defines runner lifecycle and configuration schemas (\pegboard.namespace.runner\\*\), including a multi-version evolution of runner configuration (\v1\–\v6\) that introduces support for both Serverless and Normal runner modes, actor eviction policies, and version upgrade draining. Finally, it adds \ups-protocol/v1.bare\ through \v3.bare\ to define the message structure for the internal messaging protocol, including chunked message support and request deadlines.

engine/sdks/schemas/data · high confidence

New database debug and repair capabilities for workflow history

The database layer now exposes a \DatabaseDebug\ trait and a \RepairVariant\ enum, enabling operators to inspect, silence, wake, and repair workflows with specific history defects. This includes tools to find workflows by tags, manage signal states, and automatically or manually prune completed workflow history and acknowledged signals. Crucially, it introduces targeted repair mechanisms for known issues such as loop iteration mismatches, orphaned sleep states, and history divergence, allowing the system to recover from certain corruption scenarios without manual intervention.

engine/packages/gasoline/src/db · high confidence

New deployment platform configuration and filtering logic

The shared-data package now exports a comprehensive list of supported deployment targets (including Docker Compose, Kubernetes, AWS ECS, Railway, Vercel, Cloudflare Workers, Google Cloud Run, AWS Lambda, and Supabase Functions) along with metadata such as icons, descriptions, and support levels for worker versus control-plane roles. Consumers can use the new \deployOptionsForRole\ helper to filter this list, ensuring that unsupported platforms (like serverless options for the control plane) are automatically excluded from UI selections or documentation generation.

frontend/packages/shared-data · high confidence

New developer tooling and API helper scripts

This change introduces a suite of new scripts to aid development and debugging. In scripts/api, it adds interactive CLI helpers for managing actors and runner configurations (create, list, upsert, delete) and for pinging actors via the gateway. In scripts/cargo, it adds a script to update the Rust workspace Cargo.toml, a check to ensure rivetkit-core builds cleanly for WebAssembly without native dependencies, and utilities to fix linting issues and kill orphaned test processes. In scripts/ci, it adds a guard to prevent native packages from leaking into the Supabase edge adapter bundle. Finally, in scripts/debug, it adds several decoders for internal binary formats (Epoxy, runner config, FDB tuples), a Mermaid gantt debugger, a log-to-gantt converter, an endian converter, and a local web server for viewing git diffs.

scripts · high confidence

New engine CLI commands for authentication, configuration, depot management, and debugging

The engine now exposes a comprehensive set of new CLI subcommands in the \commands\ module, allowing operators to manage runtime behavior and storage without external tools. The \auth\ command enables JWT key ring management, including viewing status, staging normal rotations, and performing emergency key revocations. The \config\ command allows runtime updates to dynamic settings such as worker pull intervals, concurrency limits, and FoundationDB compaction budgets. The \depot\ command suite provides storage maintenance capabilities, including a \Doctor\ for diagnosing SQLite databases, \Export\/\Import\ for transferring database state, \Repair\ for fixing corruption, and \ScanCorruption\ for detecting specific storage issues. Additionally, the \epoxy\ command adds debugging tools for the UDB replica and coordinator, while \profile\ and \tracing\ commands allow enabling CPU profiling and adjusting log filters and sampling ratios across the datacenter.

engine/packages/engine/src/commands · high confidence

New engine packages for logging, telemetry, and namespace management

This change introduces several new internal engine packages. The \logs\ package provides cross-platform (Unix and Windows) log rotation and pruning, redirecting stdout and stderr to daily log files. The \telemetry\ package initializes Sentry error tracking based on a configuration flag, tagging events with database, pubsub, cache, and topology details. The \namespace\ package registers workflows and defines error types for namespace and runner configuration operations. Additionally, \cache-result\ adds a rate-limiting result structure, and \gasoline\ introduces a workflow builder with error handling and representation traits.

(repo-wide) · high confidence

New example applications demonstrating actor patterns and WebSocket handling

Added four new example projects to the repository: \actor-actions\ (showcasing employee and company actor interactions), \cross-actor-actions\ (demonstrating inventory and checkout actor communication), \raw-websocket-handler\ (implementing a real-time chat room with WebSocket support), and \sqlite-drizzle\ (containing commented-out code for database integration). These examples illustrate how to define actors, manage state, handle inter-actor communication, and integrate with WebSockets using the \rivetkit\ framework.

(repo-wide) · high confidence

New examples for actor actions and agentOS

Added the \actor-actions\ example, which demonstrates type-safe RPC-style communication between actors and clients using RivetKit actions and state management, and the \agent-os\ example, which shows how to run coding agents inside isolated VMs with filesystem, process, and network control. Also added an \agent-os-e2e\ smoke test that exercises these agentOS capabilities end-to-end.

examples · high confidence

New hello-world-effect example demonstrates Rivet Effect SDK usage

This change introduces a new \hello-world-effect\ example that showcases the \@rivetkit/effect\ SDK for building Rivet Actors. It provides a complete, runnable reference implementation including a typed \Counter\ actor definition with schema-validated actions (\Increment\, \GetCount\) and custom error handling (\NegativeAmountError\). The example demonstrates server-side actor implementation using Effect layers, client-side interaction via the typed client API, and integration with observability tools like Pino logging and OpenTelemetry tracing.

examples/hello-world-effect · high confidence

New in-memory cache implementation with in-flight deduplication

The engine now includes a new in-memory caching layer (engine/packages/cache) built on the Moka library, replacing previous caching mechanisms. This implementation introduces in-flight request deduplication, ensuring that concurrent requests for the same cache key share a single underlying data fetch operation rather than executing multiple redundant getters. The cache supports configurable TTLs (defaulting to 2 hours), custom expiration logic, and key-based purging via UniversalPubSub. It also provides comprehensive Prometheus metrics for cache requests, misses, and purges, along with robust error handling for serialization and configuration issues.

engine/packages/cache · high confidence

New key definitions for workflow history, metrics, signals, and wake conditions

The engine's key-value store now includes structured key definitions for tracking workflow history (including active and forgotten states), global gauge metrics (such as active, sleeping, dead, and complete workflow counts), signal bodies and timestamps, and workflow wake conditions (immediate, deadline, sub-workflow, and signal-based). These changes introduce new database subspace structures and serialization logic for these specific data domains, supporting features like metric collection, signal handling, and workflow lifecycle management.

engine/packages/gasoline/src/db/kv/keys · high confidence

New multiplayer game pattern examples added

The multiplayer-game-patterns example now includes reference implementations for several game genres, including Arena, Battle Royale, Idle, IO-style, Open World, Party, Physics 2D/3D, Ranked, and Turn-Based modes. Each pattern provides a complete backend structure with dedicated matchmaker actors for player matching and lobby management, along with match actors that handle game state, tick loops, and event broadcasting. The examples demonstrate various matchmaking strategies such as queue-based filling, two-phase reservation with pending player expiration, and private party creation with join tickets, alongside game logic patterns like zone shrinking, resource production, and chunk-based world partitioning.

examples/multiplayer-game-patterns · high confidence

New namespace resolution and listing operations

The namespace package now exposes new operations to retrieve and list namespaces, supporting both local (leader-only) and global (cross-datacenter) access patterns. Users can now fetch namespaces by ID via \namespace\_get\_global\ (which delegates to the leader for non-leader nodes) and \namespace\_get\_local\, resolve namespaces by name via \namespace\_resolve\_for\_name\_global\ and \namespace\_resolve\_for\_name\_local\, and list all namespaces with pagination via \namespace\_list\. These operations integrate with the existing caching layer and the universal database to provide consistent namespace data across the engine.

engine/packages/namespace/src/ops · high confidence

New path-based actor routing with query resolution and Gateway v3 support

The guard service now supports routing to actors via path-based URLs, including a new query-based routing mode that resolves actor IDs using 'get' and 'getOrCreate' operations. This change introduces CORS handling for preflight and actual requests, and integrates a new Gateway v3 selector that routes traffic based on protocol version and request type (WebSocket, SSE, etc.) with configurable sampling.

_engine/packages/guard/src/routing/pegboard\gateway · high confidence

New public API endpoints for actor lifecycle, key-value storage, and authentication

The \api-public\ package now exposes a comprehensive set of REST endpoints for managing actors and authentication. Users can create, delete, list, and get-or-create actors, as well as perform cross-datacenter routing for these operations. New endpoints allow reading actor key-value pairs (\/actors/{actor\_id}/kv/keys/{key}\), putting actors to sleep (\/actors/{actor\_id}/sleep\), and rescheduling them (\/actors/{actor\_id}/reschedule\). Additionally, the API now supports creating and inspecting JWT tokens (\/auth/tokens\) and provides a build metadata endpoint (\/metadata\) that includes protocol versions. The package also includes a build script that embeds the frontend UI or serves a fallback page if the frontend is not built.

engine/packages/api-public · high confidence

New publish workflow tooling for CI and local releases

The \scripts/publish\ directory now contains a complete, structured publish system. The CI entrypoint (\bin.ts\) orchestrates releases via subcommands, resolving context once and passing it to downstream steps. It supports selective preview publishes via a \targets\ input (rivetkit, container-runner, engine, cli) and allows custom preview names. The system handles version bumping for both npm (\package.json\) and Rust (\Cargo.toml\) workspaces, including injecting optional dependencies for meta-packages at publish time. It manages npm publishing with parallelism, retries, and idempotency, and handles Docker multi-arch manifest creation and retagging. It also manages Git tagging, GitHub release creation, and uploading assets to R2. A local \cut-release\ script is provided for manual release cuts, which updates source files, runs checks, and triggers the CI workflow.

scripts/publish · high confidence

New runner lifecycle and discovery operations in Pegboard

The Pegboard engine now exposes a comprehensive set of operations for managing runner state and discovery. A new \drain\ operation allows older runner versions to be automatically stopped when a new version connects, controlled by the \drain\_on\_version\_upgrade\ configuration. Discovery is enhanced with \get\, \get\_by\_key\, \list\_names\, and \list\_for\_ns\ operations to retrieve and filter runners by namespace, name, and status (active vs. stopped). Additionally, \list\_runner\_config\_enabled\_dcs\ and \list\_runner\_config\_epoxy\_replica\_ids\ identify which datacenters and Epoxy replicas hold configuration for a specific runner, while \update\_alloc\_idx\ manages the allocation index, tracking runner eligibility, ping times, and protocol versions to support efficient task scheduling.

engine/packages/pegboard/src/ops/runner · high confidence

New runtime package with lifecycle, metrics, and signal handling

The \engine/packages/runtime\ crate now provides the core application lifecycle management. It introduces a \run\ entry point that initializes the Tokio runtime, configures worker threads (including optional subtraction via \TOKIO\_WORKER\_THREADS\_SUBTRACT\), and sets up a unified tracing pipeline that integrates OpenTelemetry, Sentry, and optional GCP logfmt/JSON formatting. The runtime exposes detailed Tokio metrics (thread counts, queue depths, task durations) and implements a cross-platform termination signal handler (\TermSignal\) that manages graceful shutdowns on Unix (SIGTERM/SIGINT) and Windows (Ctrl+C).

engine/packages/runtime · high confidence

New self-hosted Docker Compose template generator for development environments

A new TypeScript-based code generator has been added to the \self-host/compose/template\ directory to automatically produce Docker Compose configurations for local development. This tool supports single-node, multi-node, and multi-datacenter topologies (via \dev\, \dev-multinode\, \dev-multidc\, and \dev-multidc-multinode\ templates) and generates the complete infrastructure stack, including Rivet Engine, PostgreSQL, ClickHouse, Prometheus, Grafana, Vector, and OpenTelemetry Collector. It handles service discovery, network isolation, and configuration generation for core and edge services, ensuring that multi-engine datacenters are correctly wired with NATS for coordination while single-engine setups use in-process defaults.

self-host/compose/template · high confidence

New self-hosted development environment with full observability stack

A new \dev-host\ Docker Compose template is now available for self-hosted development, providing a complete local environment that includes the Rivet Engine, Runner, PostgreSQL, ClickHouse, Vector, and OpenTelemetry Collector. This setup automatically provisions ClickHouse with tables for OpenTelemetry logs, traces, and metrics, and pre-configures Grafana with dashboards for API performance, caching, epoxy proposals, workflows, and system internals, allowing developers to run and observe the full stack locally with a single \docker-compose up\ command.

self-host · high confidence

New serverless outbound request handling with observability

The engine now includes a dedicated outbound service (pegboard-outbound) that processes serverless actor requests via a queue subscription. This service manages the lifecycle of outbound connections, including graceful shutdown with progress logging and timeout handling. It exposes comprehensive Prometheus metrics for monitoring request volume, duration, errors, and active connections, allowing users to track performance and reliability of serverless outbound traffic.

engine/packages/pegboard-outbound · high confidence

New shared UI component library and auto-form system

The \frontend/packages/components\ package now provides a centralized set of reusable UI components and a theme configuration. It introduces a dark-mode-aware CSS theme using zinc color tokens and IBM Plex fonts, along with a new \ActionCard\ and \CtaCard\ for consistent content presentation. A significant addition is the \AutoForm\ system, which automatically generates forms from Zod schemas, supporting various field types (text, number, date, select, radio, switch, file, arrays, and unions) and complex field dependencies (hide, disable, require, set options). The package also includes utility components for code display (\CodeGroup\, \CodeFrame\), clipboard operations (\CopyArea\, \ClickToCopy\), and a CodeMirror wrapper for JSON editing.

frontend/packages/components · high confidence

New stack-merge skill for bulk-merging Graphite PR stacks

Added a new Claude skill that replaces the Graphite merge queue by performing a bulk fast-forward push of an entire PR stack into main in a single operation. The skill includes a main workflow definition, supporting scripts to enumerate the merge path, validate safety (including admin-bypass checks and FF safety), and execute the push, along with reference documentation detailing operational gotchas and phase-specific procedures.

.claude/skills/stack-merge · high confidence

New standalone metrics server with OpenTelemetry support

The metrics-server package has been restructured into a standalone service that exposes Prometheus metrics via HTTP and integrates OpenTelemetry tracing. It now supports dynamic trace sampling ratios that can be updated at runtime, initializes OpenTelemetry providers based on environment variables, and provides a dedicated HTTP endpoint for scraping metrics.

engine/packages/metrics-server · high confidence

New test infrastructure for managing Dockerized Postgres, NATS, and Toxiproxy

The \test-deps-docker\ package now provides a Rust library to automatically provision and manage test dependencies via Docker. It supports configuring Postgres (using image \postgres:18\) and NATS (using \nats:2.10.22-scratch\) as either in-memory or containerized backends, controlled by environment variables \RIVET\_TEST\_DATABASE\ and \RIVET\_TEST\_PUBSUB\. Additionally, it includes a Toxiproxy wrapper to inject network faults like latency and timeouts during tests, enabling more robust reliability testing for database and pub/sub components.

engine/packages/test-deps-docker · high confidence

New test infrastructure for setting up and managing datacenter dependencies

The \engine/packages/test-deps\ package now provides a \TestDeps\ struct and \setup\_single\_datacenter\ function to automate the lifecycle of test dependencies. This includes starting and stopping Docker containers for databases and pub/sub services, configuring topology with specific datacenter labels, and managing API/guard ports. Tests can now easily spin up isolated datacenter environments with configurable timeouts and connection settings, ensuring proper cleanup of resources upon test completion.

engine/packages/test-deps · high confidence

New tracing utilities for custom future instrumentation and metrics

The \tracing-utils\ package now includes a new \lib.rs\ module providing a \select\_all\_or\_wait\ helper for non-panicking future selection and a \CustomInstrumentExt\ trait. This trait allows futures to be instrumented with custom spans that automatically record duration metrics (exposed as Prometheus histograms) upon completion, enhancing observability for asynchronous operations.

engine/packages/tracing-utils · high confidence

New utility primitives for throttling, serialization, and async operations

The \engine/packages/util\ crate now includes a suite of new capabilities: a \RateLimiter\ supporting both Fixed Window and Leaky Bucket algorithms with blocking and non-blocking acquisition, an \AsyncCounter\ for tracking concurrent operations with zero-state notifications, and a \SimpleValue\ type for serializing/deserializing flat JSON structures. It also introduces observability macros (\observe!\, \json\_to\_vec!\, etc.) that automatically record duration and size metrics for code blocks and serialization calls, alongside helper modules for duration formatting, input validation, and safe string slicing.

engine/packages/util · high confidence

New workflow and signal debugging commands

The CLI now includes a new \wf\ command group with subcommands for inspecting and managing workflows and signals. Users can list, get, silence, wake, and revive workflows, as well as view their history. A new \dead\ subcommand lists dead workflows and shows available repairs, while \repair\ allows operators to diagnose and apply automatic or manual repairs to fix history defects. Additionally, signal management commands (\get\, \list\, \silence\, \prune\) are now available under \wf signal\, enabling users to manage signal states and prune old acked signals.

engine/packages/engine/src/commands/wf · high confidence

New workflow context types for the Gasoline engine

The Gasoline engine now exposes a structured set of context types in \engine/packages/gasoline/src/ctx\ to manage workflow execution. \WorkflowCtx\ serves as the core context for running workflows, handling state, history, and signal listening. \ActivityCtx\ and \OperationCtx\ provide isolated environments for executing activities and operations, with \OperationCtx\ supporting the creation of sub-workflows and signals. \StandaloneCtx\ allows for independent execution outside of a workflow, while \VersionedWorkflowCtx\ enables versioned branching within workflows. \ListenCtx\ manages signal listening with specific constraints, and \MessageCtx\ handles pub/sub messaging. A \TestCtx\ is also provided to facilitate testing by spinning up a local worker and database.

engine/packages/gasoline/src/ctx · high confidence

Pegboard engine workflows and backfill utilities

The pegboard engine now includes a comprehensive set of workflows for managing runner lifecycles, actor allocation, and serverless runner pools, alongside data migration and metrics backfills. New workflows include \pegboard\_runner\ and \pegboard\_runner2\ for handling runner connections and actor events, \pegboard\_runner\_pool\ and \pegboard\_runner\_pool2\ for managing serverless runner scaling, and \pegboard\_runner\_pool\_error\_tracker\ for debouncing and tracking pool errors. Additionally, backfill workflows have been added to migrate actor data (\actor\_migration\_fix\_backfill\), populate missing runner name selectors (\actor\_runner\_name\_selector\_backfill\), and initialize runner pool keys in epoxy (\runner\_pool\_backfill\, \runner\_pool2\_backfill\). A \metrics\_aggregator\ workflow is also introduced to periodically scan and aggregate pending actor metrics.

engine/packages/pegboard/src/workflows · high confidence

Postgres driver overhaul for multi-node reliability and chunked NATS commits

The Postgres driver in the UniversalDB engine has been rewritten to support robust multi-node deployments. It now introduces a separate connection pool for the leader to prevent follower load from starving leadership operations, and implements a chunked commit protocol over NATS to handle requests that exceed the server's max payload size. The driver also adds failover deduplication to ensure exactly-once commit application during leader transitions, concurrent read execution within transactions for better performance, and configurable SSL/TLS support for Postgres connections.

engine/packages/universaldb/src/driver/postgres · high confidence

Rivet Icons package released with pre-generated Font Awesome assets

The \@rivet-gg/icons\ package is now available, providing pre-generated SVG icons from Font Awesome Pro and a custom kit for use in Rivet products. The package includes a React \Icon\ component and individual icon exports (e.g., \faCheckCircle\), allowing developers to import icons without requiring a Font Awesome token at runtime. The package is licensed exclusively for Rivet internal use, and the repository includes documentation for maintainers on how to vendor new icons from the Font Awesome kit.

frontend/packages/icons · high confidence

Rivet engine CLI and service initialization structure

The engine package now exposes a structured CLI entry point (\main.rs\) and a library interface (\lib.rs\) that define the available subcommands (Start, Database, Workflow, Config, Auth, Tracing, Profile, Epoxy, Depot, Udb) and their execution flow. The \run\_config.rs\ module registers the core services (api\_peer, guard, workflow\_worker, pegboard\_outbound, bootstrap, dynamic\_config, version\_management, epoxy\_protocol\_version, cache\_purge, profiling) with their respective service kinds and startup logic, establishing the runtime's service topology.

engine/packages/engine/src · high confidence

Rivetkit runtime adapter moves to a native N-API implementation

The \rivetkit-napi\ package now provides a Rust-based native binding (N-API) that replaces the previous TypeScript-only runtime adapter. This change introduces a new build pipeline (using \build.rs\ and \napi-build\) and ships precompiled binaries for multiple platforms (Linux x64/arm64, macOS, Windows, Android). For users, this means the core actor lifecycle, state management, key-value storage, database access, HTTP streaming, and queue operations are now executed in native code, exposing a consistent JavaScript/TypeScript interface via \index.d.ts\ and \index.js\ while improving performance and stability for the Rivetkit actor runtime.

rivetkit-typescript/packages/rivetkit-napi · high confidence

Rust SDK introduces versioned data schemas and migration logic

The Rust SDK now includes a new \data\ crate that provides versioned wrappers for Pegboard and Auth schemas, enabling safe serialization and deserialization across multiple schema versions. This change adds build-time schema processing to generate version constants and implements explicit migration converters for \NamespaceRunnerConfig\ (V1–V6), \AuthJwtKeyRing\ (V1–V3), and \RunnerAllocIdxKey\ (V1–V2), ensuring that existing data can be upgraded to the latest schema version automatically.

engine/sdks/rust/data · high confidence

Rust actor framework implementation

The \rivetkit\ package is now implemented in Rust, providing a typed wrapper over \rivetkit-core\ that mirrors the TypeScript API. This introduces a new \Actor\ trait for defining actors, a \Ctx\ context for managing state and client interactions, and typed handling for actions, events, and queues. The framework supports both Envoy and serverless runtime modes, configurable via the \RIVETKIT\_RUNTIME\_MODE\ environment variable, and includes a test harness for in-process end-to-end actor testing.

rivetkit-rust/packages/rivetkit · high confidence

Rust envoy-client SDK introduced with full actor lifecycle and streaming support

The Rust envoy-client SDK is now available in the \engine/sdks/rust/envoy-client\ crate, providing a native implementation for managing actor lifecycles, HTTP streaming, WebSocket tunnels, and key-value/SQLite interactions. This SDK exposes a comprehensive \EnvoyCallbacks\ interface for handling actor start/stop events, fetch requests, and WebSocket connections, while internally managing command deduplication, event persistence, and connection health via ping checks. It supports both standard Rust and WebAssembly targets, includes debug tools like artificial latency injection, and exposes detailed Prometheus metrics for observability.

engine/sdks/rust/envoy-client/src · high confidence

Rust port of the counter-latency load-test script

The \examples/kitchen-sink/scripts/counter-latency\ directory now contains a Rust implementation of the previous TypeScript load-test client. This tool provides three subcommands—\concurrent\, \agent-concurrent\, and \agent-concurrent-2\—to ramp raw WebSocket tunnel-stress actors and SQLite-backed agent actors in steady or rolling modes. It supports configurable concurrency, message intervals, and agent-specific parameters like token insertion rates and query multipliers, while mirroring the original TypeScript behavior for endpoint parsing, live colored logging, and graceful scale-down on signals.

examples/kitchen-sink/scripts/counter-latency · high confidence

Rust runner protocol implementation with versioned serialization and SDK generation

The runner-protocol package now includes a Rust implementation that handles versioned serialization for the runner protocol (MK1 and MK2), including compatibility logic for tunnel acknowledgments and UUID-based ID encoding. A build script automatically generates both Rust and TypeScript SDKs from schema definitions, ensuring the TypeScript client library stays in sync with the latest protocol version. This change introduces support for multiple protocol versions (v3 through v7) with conversion logic between them, enabling backward compatibility while allowing the system to evolve the protocol over time.

engine/packages/runner-protocol · high confidence

SQLite engine gains point-in-time recovery and database forking

The depot engine now supports creating named restore points and forking databases or buckets to specific historical states. Users can pin a database to a specific timestamp or version, and later restore it to that point or fork a new branch from it. This introduces branch lifecycle operations like rollback and deletion, along with the underlying catalog and resolution logic required to navigate fork chains and maintain data consistency across branches.

_engine/packages/depot/src/conveyer/branch, engine/packages/depot/src/conveyer/restore\point · high confidence

Shared SQLite execution types and commit segmentation logic

The depot-client-types package now provides shared constants and utilities for SQLite execution, including head-fence mismatch detection, shard sizing (64 pages per shard), and commit segment cutting logic. It defines core data structures for query and execution results, such as ExecuteResult, QueryResult, and ExecResult, along with column value types. This ensures consistent handling of commit boundaries and result formats between the client and engine.

engine/packages/depot-client-types · high confidence

Standalone Rivet Inspector application with local connection UI

The Rivet Inspector is now a standalone frontend application, separated from the main dashboard. It provides a dedicated interface for local development, featuring a connection screen that prompts users to enter their local RivetKit endpoint and requests local network access if needed. Once connected, the app displays actor details and build information, utilizing a resizable sidebar layout and integrating Sentry for error tracking and PostHog for analytics.

frontend/apps/inspector · high confidence

Unified cross-platform build Dockerfiles for all target architectures

The build system now uses a set of standardized, unified Dockerfiles to produce release artifacts for every supported platform and architecture. New files have been added for darwin-arm64, darwin-x64, linux-arm64-gnu, linux-arm64-musl, linux-x64-gnu, linux-x64-musl, and windows-x64. Each Dockerfile is configured to build the \rivet-engine\, \rivet-cli\, \rivet-container-runner\, or \rivetkit-napi\ targets using the Rust 1.91.1 toolchain, with platform-specific optimizations such as static linking for musl builds, MinGW cross-compilation for Windows, and osxcross for macOS. All builds leverage sccache via Depot.dev for faster compilation and support embedding the \@rivetkit/engine-frontend\ (inspector UI) when the \BUILD\_FRONTEND\ flag is enabled.

docker/build · high confidence

UniversalDB introduces atomic mutations, range-scanning chunking, and cluster-wide byte-rate throttling

The UniversalDB engine now supports FoundationDB-style atomic value mutations (Add, BitAnd, BitOr, BitXor, AppendIfFits, Max, Min, ByteMin, ByteMax, CompareAndClear) via the new \atomic\ module, allowing in-place updates without full value replacement. Range scans are optimized with client-side batching in the \chunk\ module, which splits large reads into manageable fetches to reduce memory pressure and improve responsiveness for early-exit iterations. Additionally, a cluster-wide byte-rate throttle has been added to the \Database\ API, enabling background workloads to automatically charge against a shared budget and back off when limits are approached, with metrics exposed for monitoring throttle decisions and charged bytes.

engine/packages/universaldb/src · high confidence

Removals

Matchmaker worker service removed

The \svc/pkg/mm/worker\ service, which previously handled core matchmaker operations such as lobby creation, finding, cleanup, and player registration/removal, has been deleted. This removes the standalone worker process and its associated logic for managing lobby state and player connections.

svc/pkg/mm/worker · high confidence

Party API service removed

The party API service located at \svc/api/party\ has been completely removed from the codebase. This deletion eliminates the entire module, including the authentication middleware (\auth.rs\), data conversion logic (\convert/\), data fetching routines (\fetch/\), and all HTTP route handlers (\route/\) for party management and matchmaker activity. Consequently, the endpoints previously served by this service are no longer available.

svc/api/party, svc/pkg/nomad-log/standalone/follower, svc/pkg/team/worker · high confidence

Removal of Bolt-based secrets retrieval module

The Terraform module located at infra/tf/modules/secrets, which previously retrieved secrets by invoking the 'bolt' CLI tool via the HashiCorp external provider, has been deleted. This change removes the infrastructure capability to fetch secret values using the bolt headless reading mechanism, including the associated inputs for secret keys and optional flags, as well as the outputs exposing those values.

infra/tf/modules/secrets · high confidence

Removal of CDN and User-Dev worker services

The \cdn/worker\ and \user-dev/worker\ services have been removed from the system. This deletion eliminates the \cdn-ns-config-populate\ worker, which previously synchronized CDN namespace configurations to Redis, and the \user-dev-game-update\ worker, which dispatched game update notifications to developer team members. Consequently, automatic CDN config population and developer game-update notifications are no longer processed by these specific worker components.

svc/pkg/cdn/worker, svc/pkg/user-dev/worker, svc/pkg/team-dev/ops/halt, svc/pkg/team-dev/standalone/halt-collect · high confidence

Removal of CDN namespace auth user update and get operations

The \cdn-namespace-auth-user-update\ and \cdn-namespace-get\ operations have been removed from the CDN service. This eliminates the ability to update authentication users for a namespace (including password validation and count limits) and retrieve namespace configuration details such as domains, auth types, and associated auth users via the API.

svc/pkg/cdn/ops/namespace-auth-user-update · high confidence

Removal of Cloudflare Tunnel Terraform module

The \infra/tf/modules/cloudflare\_tunnel\ module has been deleted, removing the infrastructure definition for Cloudflare Tunnels, including the tunnel resource, associated DNS CNAME records, and Cloudflare Access policies (both user-based group access and service-token-based access). This change eliminates the automated provisioning of secure tunnel endpoints and their corresponding access controls previously managed by this module.

_infra/tf/modules/cloudflare\tunnel · high confidence

Removal of IP info lookup operation

The \ip-info\ operation implementation has been removed from the service. This deletes the logic that previously queried the \ips\ table in the database and fetched data from the external \ipinfo.io\ API to resolve IP addresses to geographic coordinates, effectively eliminating this specific IP information retrieval capability.

svc/pkg/ip/ops/info · high confidence

Removal of KV worker implementation files

The source files for the key-value worker service have been deleted, including the main entry point, the workers module, and the specific write worker logic. This removes the ability to process KV write operations, such as upserting or deleting values in the database, from this component.

svc/pkg/kv/worker · high confidence

Removal of NATS test container and captcha utility function

The \lib/test-images\ crate, which provided a \Nats\ test container implementation for integration testing, has been deleted. Additionally, the \serialize\_topic\_str\ utility function from \svc/pkg/captcha/util\, used for converting topic maps to deterministic strings for database keys, has been removed.

lib/test-images, svc/pkg/captcha/util · high confidence

Removal of Nomad log worker implementation

The \svc/pkg/nomad-log/worker\ component has been completely removed from the codebase. This deletion eliminates the Rust-based workers responsible for writing Nomad logs to ClickHouse (\nomad-log-write\) and exporting them to object storage (\nomad-log-export\). Users relying on this specific worker for log persistence and retrieval will no longer have this functionality available through this service path.

(repo-wide) · high confidence

Removal of SaltStack infrastructure management

The SaltStack configuration and provisioning infrastructure has been removed from the system. This includes the deletion of all Salt state files (\.sls\) and pillar data used to manage services such as ClickHouse, MinIO, Consul, Nomad, NATS, and CockroachDB, as well as the associated Nix package definitions and service unit files that were previously deployed via Salt.

infra · high confidence

Removal of SaltStack master and minion provisioning modules

The Terraform modules for installing and configuring SaltStack (both master and minion) have been removed from the infrastructure codebase. This deletion eliminates the local-exec and remote-exec provisioners that previously bootstrapped Salt via shell scripts, uploaded master configuration files, and managed minion key acceptance and grain uploads. As a result, the platform no longer provisions or manages SaltStack agents on servers through these specific Terraform resources.

_infra/tf/modules/install\_salt\_master, infra/tf/modules/install\_salt\minion · high confidence

Removal of build creation and listing operations

The \build-create\ and \build-list-for-game\ operations have been removed from the system. This deletion eliminates the ability to initiate new builds (including image upload preparation and database insertion) and to retrieve the list of builds associated with a specific game.

svc/pkg/build/ops/create · high confidence

Removal of chat message validation operations

The \chat-message-body-validate\ and \chat-message-validate\ operations have been removed from the system. This eliminates the server-side validation logic that previously enforced constraints on chat message bodies (such as length limits and required sender IDs) and validated topic-body compatibility (such as restricting party join requests to specific topic types). Users will no longer receive specific validation errors from these endpoints, as the validation functionality itself has been deleted.

svc/pkg/chat-message/ops/body-validate, svc/pkg/chat-message/ops/validate, svc/pkg/game/ops/namespace-validate, svc/pkg/team/ops/validate, svc/pkg/game/ops/validate, svc/pkg/mm-config/ops/namespace-config-validate · high confidence

Removal of chat utility key generation functions

The \svc/pkg/chat/util\ package has been removed, eliminating the \key\ module that previously provided functions for generating Redis key names for user thread history, thread tail messages, and typing statuses. This change removes the shared utility logic for constructing these specific cache keys from the chat service's utility layer.

svc/pkg/chat/util · high confidence

Removal of chat-thread get-for-topic and list-for-participant operations

The \chat-thread-get-for-topic\ and \chat-thread-list-for-participant\ operations have been removed from the service. These operations previously handled retrieving chat threads by topic (team, party, or direct) and listing threads for a specific participant, including logic for querying the database and mapping results to backend thread objects. Their deletion indicates these specific retrieval endpoints are no longer supported or have been replaced by other mechanisms.

(repo-wide) · high confidence

Removal of chat-thread participant-list and get-or-create-for-topic operations

The \chat-thread-participant-list\ operation, which previously retrieved participants for team, party, and direct chat threads, and the \chat-thread-get-or-create-for-topic\ operation, which managed thread creation based on topics, have been removed from the codebase.

svc/pkg/chat-thread/ops/participant-list · high confidence

The \svc/pkg/cloud/worker\ module has been removed, deleting the main entry point and the \device\_link\_complete\ worker logic. This eliminates the background process that previously handled device linking by creating cloud game tokens and publishing completion messages, effectively removing this specific cloud infrastructure capability from the worker service.

svc/pkg/cloud/worker · high confidence

Removal of development namespace token creation service

The \cloud-namespace-token-development-create\ operation has been removed from the system. This service previously validated development hostnames and ports, created a long-lived token with specific game namespace development entitlements, and persisted the association in the database. Its removal indicates that the capability to generate these specific development tokens is no longer supported or has been replaced by a different mechanism.

svc/pkg/build/standalone/default-create, svc/pkg/cloud/ops/namespace-token-development-create, svc/pkg/cloud/ops/namespace-token-public-create · high confidence

Removal of email sending implementation

The email sending operation logic has been removed from this service. The code that previously handled constructing SendGrid API requests, managing recipients, attachments, and template data is no longer present.

svc/pkg/email/ops/send · high confidence

Removal of email verification completion operation

The implementation for the \email-verification-complete\ operation has been removed from the service. This deletes the logic that previously handled verifying email codes, checking expiration, enforcing attempt limits, and recording completion status in the database.

svc/pkg/email-verification/ops/complete, svc/pkg/team/ops/avatar-upload-complete, svc/pkg/user/ops/avatar-upload-complete · high confidence

Removal of faker game-namespace and game-version operations

The faker operations for creating game namespaces and game versions have been removed from the service. This eliminates the ability to automatically provision test environments for these specific components via the faker tool, likely as part of a cleanup to consolidate or replace these legacy test setup mechanisms.

svc/pkg/faker/ops/game-version · high confidence

Removal of faker matchmaker player and team operations

The faker service no longer provides operations to generate fake matchmaker players or fake teams. The \faker-mm-player\ operation, which previously created fake player tokens and joined them to lobbies, and the \faker-team\ operation, which previously created fake teams with members and developer status, have been deleted from the system.

svc/pkg/faker/ops/mm-player · high confidence

Removal of game creation operation implementation

The implementation for the \game-create\ operation has been removed from the codebase. This operation previously handled the validation of game details, verified the developer team's status, and inserted game records along with their tags into the database before emitting an analytics event.

svc/pkg/game/ops/create · high confidence

Removal of game namespace URL resolution operation

The \game-namespace-resolve-url\ operation has been removed from the service. This operation previously handled the resolution of game and namespace identifiers from URLs by parsing domains (either rivet.game subdomains or custom CDN domains) and querying backend services. Its removal means that URL-based namespace resolution via this specific endpoint is no longer available.

svc/pkg/game/ops/namespace-resolve-url · high confidence

Removal of game version and token validation logic

The \game-version-validate\ and \game-token-development-validate\ operations have been removed from the codebase. This eliminates the server-side validation logic that previously enforced constraints on game version display names, CDN route configurations, and lobby port assignments (including uniqueness, range overlaps, and protocol compatibility).

svc/pkg/game/ops/version-validate · high confidence

The \game-user-link-create\ operation has been removed from the \svc/pkg/game-user/ops/link-create\ service. This operation previously generated a short-lived token and recorded a link between a game user and a namespace in the database, triggering an analytics event upon creation. Its deletion indicates that this specific linking mechanism is no longer supported or has been replaced by a different implementation elsewhere in the system.

(repo-wide) · high confidence

Removal of game-user recommendation operation

The \game-user-recommend\ operation has been removed from the service. The implementation file is deleted, meaning the operation no longer exists to fetch or recommend game users.

svc/pkg/game-user/ops/recommend · high confidence

Removal of hCaptcha configuration retrieval operation

The \captcha-hcaptcha-config-get\ operation has been removed from the service. This operation previously allowed clients to retrieve the hCaptcha site key based on a difficulty level by reading specific environment variables (e.g., \HCAPTCHA\_SITE\_KEY\_EASY\). Its removal means this configuration data is no longer accessible via this API endpoint.

svc/pkg/captcha/ops/hcaptcha-config-get · high confidence

Removal of hCaptcha verification operation

The hCaptcha verification operation (captcha-hcaptcha-verify) has been removed from the system. This change eliminates the ability to verify hCaptcha tokens via this specific service component, as the implementation file containing the verification logic and HTTP client interaction has been deleted.

svc/pkg/captcha/ops/hcaptcha-verify · high confidence

Removal of hardcoded tier listing logic

The \svc/pkg/tier/ops/list\ operation source file has been deleted, removing the server-side logic that previously generated and returned a static list of tier definitions (such as \basic-4d1\, \basic-2d1\, etc.) based on hardcoded resource reservations. This change eliminates the local computation of tier attributes like CPU, memory, and bandwidth from this specific service component.

svc/pkg/tier/ops/list · high confidence

Removal of internal S3 utility library

The \lib/s3-util\ library has been removed from the codebase. This module previously provided an S3 client wrapper that handled endpoint configuration for internal (Consul-based) and external access, including specific logic to resolve Minio's Consul DNS address for job servers. Its removal indicates a shift in how S3 connectivity is managed, likely moving away from the Consul DNS resolution pattern for internal cluster communication.

lib/s3-util · high confidence

Removal of internal utility libraries and service operations

This change removes several internal Rust source files, including the \redis-util\ library (containing Redis result wrappers and search query escaping), various service operations (\cf-turnstile-verify\, \faker-user\, \mm-lobby-list-for-namespace\, \mm-lobby-player-count\, \mm-player-count-for-namespace\, \perf-log-get\), and utility modules (\game-user\, \kv\, \nsfw\). These deletions eliminate the associated code for Cloudflare Turnstile verification, user data generation, multiplayer lobby and player count retrieval, performance log fetching, and key-value store utilities.

(repo-wide) · high confidence

Removal of job utility constants and helpers

The job utility module has been stripped of its previous configuration and helper definitions. Specifically, the hardcoded TCP and UDP port ranges for ingress load balancers (previously 20000–20512 and 26000–26512) have been removed, along with the Redis key generation logic for proxied ports. Additionally, utility functions for identifying Nomad job runs and constants for task cleanup resource limits (CPU and memory) and task names have been deleted from the library.

svc/pkg/job/util · high confidence

Removal of legacy 'build' cache implementation

The \lib/cache/build\ module has been completely removed. This deletion eliminates the previous caching layer, including its error handling, key serialization, request configuration, getter context, and rate-limiting logic, along with its associated integration tests.

lib/cache · high confidence

Removal of legacy API services

The \api-admin\, \api-auth\, \api-cf-verification\, \api-chat\, \api-cloud\, \api-group\, \api-identity\, \api-job\, \api-kv\, \api-matchmaker\, and \api-party\ services have been removed from the system. This change eliminates the service definitions, router configurations, and associated integration tests for these previously distinct API endpoints.

svc · high confidence

Removal of legacy Bolt CLI commands and configuration modules

The Bolt CLI has removed a large set of legacy commands and their supporting configuration modules. Specifically, the \admin\, \check\, \config\, \db\, \generate\, \infra\, \init\, \logs\, \output\, \salt\, \secret\, \ssh\, \terraform\, \test\, and \up\ subcommands have been deleted from the CLI entry point. Additionally, the \default\_regions.toml\ file containing Linode region definitions and the \cache\, \local\, \ns\, \project\, and \service\ configuration modules have been removed from the config crate. The \core\ module's \context\ and \dep/cargo\ implementations have also been stripped, indicating a significant reduction in the local development and infrastructure management capabilities provided by this library.

lib/bolt · high confidence

Removal of legacy Bolt-based build retrieval operation

The \build-get\ operation implementation in \svc/pkg/build/ops/get\ has been removed. This deletion eliminates the legacy code path that directly queried the \builds\ table via SQLx to retrieve build details (such as game ID, upload ID, and image tag), indicating a migration away from the previous data access pattern or storage backend.

svc/pkg/build/ops/get · high confidence

Removal of legacy Cloud API service and Cloudflare verification service

The \svc/api/cloud\ and \svc/api/cf-verification\ services have been completely removed from the codebase. This deletion eliminates the legacy HTTP endpoints for managing game resources (such as builds, CDNs, matchmaker lobbies, and namespaces) and the Cloudflare custom hostname verification route. Users relying on these specific API endpoints for game cloud management or domain verification will no longer have access to this functionality through these services.

svc/api/cloud · high confidence

Removal of legacy OpenAPI-generated Rust client

The legacy OpenAPI-generated Rust API client located in \gen/openapi/internal/rust\ has been removed. This change deletes the generated source code, documentation, and build configuration files (including \Cargo.toml\, \.gitignore\, and \.openapi-generator-ignore\), indicating a migration away from this specific code generation pipeline for the Rust SDK.

gen · high confidence

Removal of legacy admin API authentication and routes

The legacy admin API service located in \svc/api/admin\ has been removed. This change deletes the previous authentication mechanism, which relied on a static token read from environment variables, and removes the associated route definitions, including the endpoint for converting a group to a developer. Users relying on this specific admin interface will no longer have access to these legacy endpoints.

svc/api/admin · high confidence

Removal of legacy api-helper build components

The \lib/api-helper/build\ module and its associated proc-macro crate have been removed. This deletion eliminates the legacy server startup logic, the generic \Ctx\ context structure, the \ApiAuth\ trait, the \anchor\ watch-index mechanism, and the internal CORS and error-handling utilities that were previously generated via macros. API services relying on this specific build-time scaffolding must migrate to the updated API helper implementation.

lib/api-helper · high confidence

Removal of legacy auth and job API services

The \svc/api/auth\ and \svc/api/job\ services have been deleted, removing the endpoints for identity management (including email verification and token refresh) and job run cleanup. This eliminates the legacy authentication middleware, route handlers, and associated utility functions that previously managed user sessions and job lifecycle operations.

svc/api/auth · high confidence

Removal of legacy backend and common Protobuf definitions

The entire \proto/\ directory has been removed, deleting all shared Protobuf definitions including \common.proto\, \claims.proto\, and all backend service schemas (billing, blog, captcha, cdn, chat, cloud, game, identity, job, kv, matchmaker, net, nomad\_log, notification, party, region, team, upload, user, and chirp). This cleanup eliminates the legacy API contract layer that previously defined data structures for services such as the matchmaker, chat, and user identity systems.

proto · high confidence

Removal of legacy chat message and thread listing operations

The \chat-message-list-for-user\ and \chat-thread-recent-for-user\ operations have been removed from the codebase. This deletes the implementation logic that previously fetched chat messages and recent thread lists directly from the database and Redis cache, indicating a migration away from these specific service endpoints.

svc/pkg/chat-message/ops/list-for-user, svc/pkg/chat-thread/ops/recent-for-user · high confidence

Removal of legacy chat, game, group, identity, and party conversion modules

The \lib/convert\ library has removed the \chat\, \game\, \group\, \identity\, and \party\ modules, along with their corresponding \fetch\ modules. This deletion eliminates the code responsible for converting backend protocol buffer data into Smithy API models for these specific domains, effectively removing the legacy conversion logic for chat messages, game summaries, group/team details, user identities, and party states from this library.

lib/convert · high confidence

Removal of legacy connection pool library

The \lib/pools\ crate has been completely removed from the codebase. This deletion eliminates the legacy implementation for managing NATS, Redis, and CockroachDB connection pools, along with its associated error types, metrics recording, and transaction retry utilities.

lib/pools · high confidence

Removal of legacy developer team billing collection service

The standalone \billing-collect\ service, which previously handled billing metric aggregation for developer teams, has been removed. This eliminates the legacy logic that queried \dev\_teams\ from the database, aggregated billing metrics via \team\_billing\_aggregate\, and prepared data for Stripe integration.

svc/pkg/team/standalone/billing-collect · high confidence

Removal of legacy game namespace and name-id resolution operations

The \game-namespace-get\ and \game-resolve-name-id\ operations have been removed from the service. This eliminates the direct SQL queries against the \game\_namespaces\ and \games\ tables that previously handled namespace retrieval and name-to-ID resolution, indicating a shift in how these lookups are performed within the system.

svc/pkg/game/ops/resolve-name-id · high confidence

Removal of legacy matchmaking utility module

The \svc/pkg/mm/util\ module has been completely removed from the codebase. This deletion eliminates hardcoded constants for lobby and player timeouts, default player capacity limits, and Redis key generation logic for lobby and player configurations. It also removes the \JoinKind\ and \FindQueryStatus\ enums, Nomad port formatting utilities, and version migration definitions that were previously shared across the matchmaking service. Users relying on these internal utilities for custom integrations or extensions will no longer have access to these shared definitions.

svc/pkg/mm/util · high confidence

Removal of legacy operation core library and macros

The \lib/operation/core\ library, including the \Operation\ trait, \OperationContext\, and the \lib/operation/macros\ crate containing the \\#\[operation\]\ procedural macro, has been removed. This eliminates the previous mechanism for defining and invoking operations via the \op!\ macro and associated context handling, indicating a migration to a different operation execution model or framework within the system.

lib/operation · high confidence

Removal of legacy service operation implementations

The implementation files for the \cdn-version-publish\, \faker-mm-lobby-row\, \game-user-create\, and \token-exchange\ operations have been deleted from the repository. This removes the specific Rust logic that previously handled CDN version publishing, matchmaking lobby row generation, game user creation with token issuance, and token exchange via direct SQL queries against CockroachDB. These changes are part of a broader migration to a single database architecture, indicating that the functionality previously managed by these individual service operations is being consolidated or replaced.

(repo-wide) · high confidence

Removal of legacy utility libraries

The \lib/util\ crate and its submodules (\core\, \env\, \macros\, \search\) have been removed from the codebase. This deletion eliminates a wide range of internal helper functions, including input validation (identifiers, display names, domains), string formatting, duration and file-size conversions, UUID parsing, route generation, and environment variable accessors. Any code previously depending on these utilities will need to adopt alternative implementations or dependencies.

lib/util · high confidence

Removal of lib/runtime module

The \lib/runtime\ module, which previously handled Tokio runtime configuration and JSON-based logging setup, has been removed from the codebase. This change eliminates the centralized runtime initialization logic and associated Prometheus metrics for thread counting that were previously exposed through this library.

lib/runtime · high confidence

Removal of lib/types build infrastructure and generated schema

The build logic for the \lib/types\ crate has been removed, including the \lib/types/build\ source, the \lib/types/core/build.rs\ build script, and the \lib/types/core/src/lib.rs\ file that previously included the generated \schema.rs\. This deletion eliminates the custom Protobuf compilation pipeline (which utilized \schemac\ and specific plugins like \CommonPlugin\ and \BackendMessagePlugin\) and the static \uuid\_expanded.rs\ template used to handle UUID serialization. Consequently, the \lib/types\ crate no longer generates or exposes the schema types that were previously produced by this build process.

lib/types · high confidence

Removal of lobby find try-complete operation

The \mm-lobby-find-try-complete\ operation has been removed from the codebase. This operation previously handled the completion of matchmaking queries by validating their state in Redis, checking lobby readiness, removing query data from Redis, updating the query status in the database, and publishing completion messages. Its removal indicates that this specific mechanism for finalizing lobby find queries is no longer part of the service's functionality.

(repo-wide) · high confidence

Removal of matchmaker API service source code

The source code for the matchmaker API service located in \svc/api/matchmaker\ has been completely removed. This deletion eliminates the implementation of core matchmaking endpoints, including lobby management (ready, join, find, closed, list), player connection tracking (connected, disconnected, statistics), and region listing. Consequently, the service's authentication logic, route definitions, and utility functions are no longer present in this location.

svc/api/matchmaker · high confidence

Removal of party, member, and invite operations and utilities

The party service has removed the implementation for retrieving party details, listing and getting party members, and managing party invites (including alias lookup). Additionally, the Redis population standalone tool and the shared utility modules defining party key structures and state enums have been deleted, effectively disabling all party-related data retrieval and management capabilities in this service.

(repo-wide) · high confidence

Removal of pending-delete-toggle operation implementation

The implementation for the \pending-delete-toggle\ operation has been removed from the codebase. This operation previously handled the logic for toggling a user's pending deletion status by verifying their identity, updating the \delete\_request\_ts\ field in the database, and publishing a message to update the user record. Its removal indicates that this specific functionality is no longer supported or has been replaced by a different mechanism.

(repo-wide) · high confidence

Removal of region configuration utility

The region configuration loading logic has been removed from the region utility package. Specifically, the \config.rs\ module, which previously read and parsed \region-config.json\ from the Nomad task directory into a map of \Region\ structs, has been deleted. Consequently, the \config\ module is no longer exported from the package's \lib.rs\, meaning consumers of this utility can no longer access region configuration data through this specific interface.

svc/pkg/region/util · high confidence

Removal of region recommendation logic

The \region-recommend\ operation implementation has been removed from the codebase. This deletes the logic that previously recommended regions based on user coordinates or IP address by calculating distances to available servers, effectively disabling this specific recommendation capability.

svc/pkg/region/ops/recommend · high confidence

Removal of several internal operation handlers

The \cdn-version-prepare\, \cloud-device-link-create\, \faker-cdn-site\, \identity-config-version-prepare\, \kv-config-version-prepare\, and \mm-dev-player-token-create\ operation handlers have been removed from the codebase. This deletion eliminates the backend logic for preparing CDN and configuration versions, creating cloud device links, generating fake CDN site data, and creating development player tokens for the matchmaker.

(repo-wide) · high confidence

Removal of standalone CDN and Identity Config version-get operations

The dedicated \cdn-version-get\ and \identity-config-version-get\ operations have been removed from the codebase. This change eliminates the specific Rust implementations that previously queried the \game\_versions\, \game\_version\_custom\_headers\, \custom\_display\_names\, and \custom\_avatars\ tables to retrieve CDN routing rules and identity customizations. Users relying on these specific operation endpoints will no longer have access to this data retrieval path, indicating a migration to a different mechanism for fetching version configurations.

svc/pkg/cdn/ops/version-get, svc/pkg/identity-config/ops/version-get · high confidence

Removal of standalone allocation and evaluation monitors

The standalone services for monitoring Nomad allocation updates (alloc-update-monitor) and evaluation updates (eval-update-monitor) have been removed. This eliminates the dedicated background processes that previously listened for these specific Nomad events and forwarded them via internal messages, indicating a consolidation or architectural shift in how Nomad state changes are processed.

svc/pkg/job-run/standalone/alloc-update-monitor, svc/pkg/job-run/standalone/eval-update-monitor · high confidence

Removal of standalone health-check service library

The standalone health-check library (\lib/health-checks\) has been removed from the codebase. This library previously provided a standalone HTTP server (using Hyper) to expose health endpoints for CRDB, Redis, NATS, and liveness checks. Its removal indicates that this specific standalone service component is no longer part of the product architecture.

lib/health-checks · high confidence

Removal of standalone metrics server and histogram buckets

The metrics library no longer exposes a standalone HTTP server for exporting Prometheus metrics, nor does it provide the predefined histogram bucket configuration. Specifically, the \run\_standalone\ function, the \BUCKETS\ constant, and the internal modules (\server.rs\, \buckets.rs\) have been removed from the public API, meaning users can no longer start a separate metrics endpoint or rely on these specific histogram boundaries from this crate.

lib/metrics · high confidence

Removal of standalone pending user deletion service

The standalone service responsible for deleting pending users (svc/pkg/user/standalone/delete-pending) has been removed. This eliminates the background process that queried the database for users with pending deletion requests older than 30 days and published delete messages, indicating that this specific cleanup logic is no longer executed via this standalone component.

svc/pkg/user/standalone/delete-pending · high confidence

Removal of team member relationship retrieval operation

The \team-member-relationship-get\ operation has been removed from the codebase. This operation previously allowed clients to query shared team memberships between user pairs by executing a SQL query against the \team\_members\ table. Its removal means this specific capability to retrieve mutual team IDs for user pairs is no longer available via this service endpoint.

svc/pkg/team/ops/member-relationship-get · high confidence

Removal of team member retrieval operation implementation

The implementation for the \team-member-get\ operation has been removed from the codebase. This change eliminates the logic responsible for querying and returning team member details (team ID, user ID, and join timestamp) from the database, effectively disabling this specific data retrieval capability within the team service.

svc/pkg/team/ops/member-get · high confidence

Removal of team-invite worker service

The \svc/pkg/team-invite/worker\ service has been completely removed from the codebase. This deletion eliminates the standalone Rust worker that previously handled the creation of invitation codes and the consumption of those invites to add users to teams. Consequently, the logic for generating unique invite codes, validating their expiration and usage limits, and triggering the subsequent team membership creation messages is no longer present in this specific service location.

(repo-wide) · high confidence

Removal of the Chirp client library and worker framework

The \lib/chirp\ directory has been completely removed, deleting the entire Chirp client library, worker framework, and associated tooling. This includes the \chirp\_client\ crate (handling NATS and Redis communication, message serialization, and RPC logic), the \chirp\_worker\ crate (managing worker lifecycles, configuration, and request handling), the \chirp\_worker\_attributes\ proc-macro crate (providing the \\#\[worker\]\ attribute), and supporting modules for metrics, performance context, and type definitions. Users of this library will no longer have access to these components for inter-service communication or worker management.

lib/chirp · high confidence

Removal of the api-status service and its matchmaker health-check endpoint

The api-status service has been completely removed from the codebase. This eliminates the /matchmaker endpoint that previously performed health checks against individual game nodes by creating temporary bypass tokens and querying the matchmaker service. Users relying on this specific status check for matchmaker availability will no longer have access to this data through this service.

svc/api/status · high confidence

Removal of the global-error library

The \lib/global-error\ crate has been completely removed from the codebase. This deletion eliminates the \GlobalError\ and \GlobalResult\ types, along with associated helper modules (\ext\, \macros\) and utility structs like \Location\. Consequently, any code previously relying on this library's error handling macros (such as \err\_code\, \internal\_panic\, \retry\_panic\) or error conversion traits must be updated to use the new error handling mechanisms.

(repo-wide) · high confidence

Removal of the legacy api-chat service

The \svc/api/chat\ service has been completely removed from the codebase. This deletion eliminates the legacy implementation for chat functionality, including the removal of its authentication middleware, route handlers (such as sending messages and retrieving thread history), and data conversion logic for chat messages, identities, and parties. Users relying on this specific service endpoint will no longer have access to these legacy chat operations.

svc/api/chat, svc/api/group, svc/api/kv · high confidence

Removal of the lib/connection crate

The \lib/connection\ crate has been deleted, removing the centralized \Connection\ struct that previously aggregated the Chirp client, database pools, and cache into a single handle. This eliminates the convenience methods for accessing specific Redis clusters (such as \redis-cache\, \redis-cdn\, \redis-job\, \redis-mm\, \redis-party\, \redis-user-presence\, and \redis-search\) and the \crdb\ pool accessor, as well as the \wrap\ method used to propagate tracing context across operations. Consumers of this library must now manage these dependencies directly.

lib/connection, lib/schemac · high confidence

Removal of the standalone MM garbage collection service

The standalone garbage collection service (\svc/pkg/mm/standalone/gc\) has been removed. This service previously handled the periodic cleanup of unready lobbies and unregistered players by querying Redis and sending stop/remove messages. Its removal indicates that this cleanup logic is no longer managed by this specific standalone process, likely having been migrated to other services or handled differently within the system.

(repo-wide) · high confidence

Removal of the upload-delete worker

The upload-delete worker, which previously handled the deletion of upload files from S3 buckets and updated the database status, has been removed from the service. This change eliminates the code responsible for querying upload records, batching S3 object deletions, and marking uploads as deleted.

svc/pkg/upload/worker · high confidence

Removal of token creation and revocation service implementations

The implementation files for the token creation (\token-create\) and token revocation (\token-revoke\) operations have been deleted from the repository. This removes the code responsible for generating JWTs, managing session states, handling refresh token logic, and marking tokens as revoked in the database. Users relying on these specific service endpoints for token lifecycle management will no longer have access to these functionalities within this package.

svc/pkg/token/ops/create · high confidence

Removal of user identity deletion operation

The \user-identity-delete\ operation has been removed from the codebase. This eliminates the functionality that previously deleted email records associated with specific user IDs from the \emails\ table in the \db-user-identity\ database.

svc/pkg/user-identity/ops/delete · high confidence

Removal of user profile validation logic

The \user-profile-validate\ operation implementation has been removed from the codebase. This change eliminates the server-side validation for user display names, account numbers, and biographies, as well as the logic that checked for handle uniqueness against the database.

svc/pkg/user/ops/profile-validate · high confidence

Removal of user-follow request ignore worker

The worker responsible for processing user-follow request ignore operations has been removed from the service. This eliminates the background job that previously updated the \user\_follows\ table to mark specific follow requests as ignored and emitted a completion message, effectively disabling the ability to ignore follow requests via this specific worker component.

svc/pkg/user-follow/worker · high confidence

Removal of user-presence service operations

The \user-presence-get\ and \user-presence-touch\ operations have been removed from the system. This eliminates the ability to query user presence status and game activity via Redis, as well as the mechanism for updating presence timestamps and triggering arrival messages.

svc/pkg/user-presence/ops/get · high confidence

Removal of user-presence utility module

The \svc/pkg/user-presence/util\ package has been removed, deleting the \key.rs\ and \lib.rs\ source files. This eliminates the helper functions for generating Redis keys (such as \user\_presence\ and \game\_activity\) and the \State\ structs for serializing user presence and game activity data, along with the defined TTL constant.

svc/pkg/user-presence/util · high confidence

Removed Linode server provisioning module

The Terraform module for provisioning Linode instances has been completely removed from the infrastructure codebase. This deletion eliminates the ability to create Linode virtual servers, associated SSH keys, root passwords, boot disks, swap partitions, and network firewalls via this module. Users relying on this module for Linode-based server deployments will no longer be able to provision or manage these resources through this specific infrastructure path.

_infra/tf/modules/generic\server · high confidence

Removed game and team recommendation operations

The \game-recommend\, \team-member-count\, and \team-recommend\ operations have been removed from the codebase. This eliminates the server-side logic that previously fetched all games, counted members for specific teams, and recommended teams based on creation timestamp, effectively disabling these recommendation features for users.

svc/pkg/game/ops/recommend, svc/pkg/team/ops/member-count, svc/pkg/team/ops/recommend · high confidence

Removed game banner and logo upload completion operations

The \game-banner-upload-complete\ and \game-logo-upload-complete\ operations have been removed from the system. These services previously handled the finalization of banner and logo uploads by confirming the upload, updating the corresponding \banner\_upload\_id\ or \logo\_upload\_id\ in the \games\ table, and triggering an update message. Their removal indicates a shift in how game asset uploads are finalized, likely consolidating this logic into a different service or workflow.

svc/pkg/game/ops/banner-upload-complete, svc/pkg/game/ops/logo-upload-complete · high confidence

Removed generated Rust SDK code for the api-auth service

The generated Rust client library for the \api-auth\ service has been removed from the \lib/smithy-output\ directory. This deletion eliminates the auto-generated source files (including models, client, config, error handling, and serialization logic) that previously provided an SDK for interacting with authentication endpoints such as email verification and identity token refresh. Users relying on this specific generated Rust client will no longer have access to these bindings.

lib/smithy-output · high confidence

Removed push notification worker implementation

The push notification worker service, including its main entry point and the logic for sending Firebase Cloud Messaging (FCM) notifications, has been removed from the codebase. This deletion eliminates the component responsible for processing push notification creation messages and delivering them to users via Firebase.

svc/pkg/push-notification/worker · high confidence

Removed user-notification-auth register and unregister operations

The \user-notification-auth-register\ and \user-notification-auth-unregister\ service operations have been removed from the codebase. This eliminates the direct database interactions for upserting and deleting Firebase access keys in the \users\ table, indicating that this functionality is no longer handled by these specific service endpoints.

svc/pkg/user-notification-auth/ops/register, svc/pkg/user-notification-auth/ops/unregister · high confidence

API

Runner protocol schema evolves through v7 with breaking changes and new KV operations

The runner-protocol schema definitions have been updated from v1 through v7, introducing several breaking changes and new capabilities. Key structural shifts include the removal of \actorId\ from individual events and commands in v5/v6 (relying on context instead), the renaming of \createTs\ to \updateTs\ in \KvMetadata\ (v4), and the addition of \ActorCheckpoint\ tracking in event/command wrappers (v4+). The schema also expands key-value store capabilities with the introduction of \KvDeleteRangeRequest\ in v7, allowing range-based deletions alongside existing get, list, put, and drop operations.

engine/sdks/schemas/runner-protocol · high confidence

Architecture

Introduce shared engine type definitions for actors, runners, and configurations

This change establishes a new \engine/packages/types\ crate to centralize core data structures, resolving circular dependencies between engine components. It introduces explicit type definitions for \Actor\ (including lifecycle timestamps like \reschedule\_ts\ and error states), \Runner\, \Envoy\, \Namespace\, and \Datacenter\. It also defines \RunnerConfig\ with distinct \Normal\ and \Serverless\ modes, supporting features like version-upgrade draining and actor eviction policies, and provides serialization mappings to the underlying \pegboard\ storage schema.

engine/packages/types · high confidence

New module structure for pegboard operations

The pegboard engine now exposes a new \ops\ module that organizes core operational components into distinct sub-modules: \actor\, \envoy\, \runner\, \runner\_config\, and \serverless\_metadata\. This structural change provides a clearer separation of concerns for the underlying execution and metadata handling logic within the pegboard package.

engine/packages/pegboard/src/ops · high confidence

Runner config operations migrated to Epoxy consensus

The runner configuration management in Pegboard has been refactored to use the Epoxy distributed consensus engine. This change moves the storage and lifecycle of runner configs (create, update, delete, list, and metadata refresh) from local database writes to Epoxy proposals, ensuring strong consistency across data centers. The implementation includes new operations for upserting, deleting, and listing configs, as well as validating serverless URLs and headers against an SSRF policy before storage. Additionally, a new operation ensures that missing normal runner configs are automatically created on demand, and cache invalidation is coordinated through Epoxy to maintain data integrity.

_engine/packages/pegboard/src/ops/runner\config · high confidence

Behavioural changes

Actor KV storage quota increased to 10 GiB

The maximum storage capacity for actor key-value data has been increased from the previous limit to 10 GiB. This change is implemented in the \actor\_kv\ module of the engine, where the \MAX\_STORAGE\_SIZE\ constant is now set to 10 GB and enforced by validation logic in \utils.rs\ to prevent writes that would exceed the new quota.

_engine/packages/pegboard/src/actor\kv · high confidence

Actor creation now supports rate limiting and dual-version workflow dispatch

The actor creation operation now enforces a per-namespace rate limit on actor creation using a leaky-bucket algorithm, rejecting requests that exceed the configured threshold. Additionally, the creation logic has been updated to detect and dispatch to either the legacy actor workflow or the newer actor2 workflow based on the runner's protocol version, ensuring compatibility with both V1 and V2 actor implementations.

engine/packages/pegboard/src/ops/actor · high confidence

Actor persistence schema upgraded to v4 with queue support and legacy data fixes

The actor-persist package now uses schema version 4, introducing a new QueueMessage type to support queue-based workflow runs and adding hibernatable WebSocket support in earlier versions. To ensure data integrity during this transition, the system now correctly handles legacy v4 actor schedules where arguments were stored as raw bytes instead of the expected CBOR format, preventing deserialization failures for actors persisted by a previous buggy writer. This change also includes a build script to compile BARE schemas and comprehensive tests to verify round-trip serialization and legacy fallback decoding.

rivetkit-rust/packages/actor-persist · high confidence

Add hibernating request tracking operations

The engine now tracks hibernating WebSocket requests to improve connection management. New operations in the pegboard module allow the system to record (upsert), list, and delete hibernating request entries, enabling the engine to maintain state for idle connections and prevent unnecessary open messages from being sent to hibernating websockets.

_engine/packages/pegboard/src/ops/actor/hibernating\request · high confidence

Engine configuration schema restructured with new security and runtime controls

The engine's configuration system has been reorganized into a modular schema, introducing several new capabilities and behavioral changes. Authentication now supports namespace-scoped JWTs by default, with an explicit \insecure\_allow\_unauthenticated\ flag to restore legacy unauthenticated access if needed. A new outbound request policy gates serverless runner HTTP calls behind an SSRF policy, allowing loopback by default but denying private networks and insecure schemes unless explicitly enabled. Runtime behavior includes a new \allow\_version\_rollback\ flag to control engine upgrades, configurable worker load-shedding curves, and a \force\_shutdown\_duration\ to prevent hanging processes. Additionally, SQLite depot configuration now exposes knobs to disable compaction and manage storage quotas, while the Guard service gains granular timeouts and rate-limiting controls for WebSocket and HTTP traffic.

engine/packages/config · high confidence

Envoy protocol SDK restructured with v8 types and streaming window configuration

The Rust Envoy protocol SDK has been reorganized to expose the latest protocol definitions (v8) as the default public API, replacing previous versioned exports. A new constant, HTTP\_STREAM\_INITIAL\_WINDOW\_BYTES, is now exposed to configure the initial unacknowledged body bytes allowed in HTTP stream directions, supporting end-to-end streaming behavior. Additionally, utility functions for generating random gateway and request IDs, along with ID-to-string conversion, have been added to the public interface.

engine/sdks/rust/envoy-protocol/src · high confidence

Envoy protocol schema advances to v8 with staged SQLite commits

The \engine/sdks/rust/envoy-protocol/schemas\ directory has been updated to include protocol definitions from v1 through v8. The most significant change is the introduction of staged commits in v8, which allows large SQLite updates to be written as a sequence of shard-aligned segments and finalized atomically, preventing partial visibility. This evolution also includes refinements to the SQLite error response structure (adding \group\ and \code\ fields) and adjustments to generation/transaction ID handling across versions.

engine/sdks/rust/envoy-protocol/schemas · high confidence

Envoy protocol schema evolves through v8 with staged SQLite commits

The Envoy protocol schema in engine/sdks/schemas/envoy-protocol has progressed from v1 to v8, introducing and refining capabilities for key-value storage, actor lifecycle management, and native SQLite integration. Early versions established core primitives, KV operations, and actor intents/states. Subsequent iterations added SQLite page fetching and commit mechanics, then expanded into remote SQL execution with typed value bindings. The latest changes in v7 and v8 introduce a staged commit mechanism for SQLite, allowing large transactions to be written as shard-aligned segments and finalized atomically, improving reliability and performance for heavy write workloads while maintaining backward compatibility with single-shot commits for smaller operations.

engine/sdks/schemas/envoy-protocol · high confidence

Envoy protocol versioning scaffolding and compatibility checks

The \envoy-protocol\ crate now includes a \versioned\ module that manages protocol evolution from v1 through v8. This location provides the bidirectional conversion logic (e.g., \v1\_to\_v2.rs\, \v2\_to\_v3.rs\) and the central \ToEnvoy\ enum that handles serialization and deserialization across versions. It also introduces \ProtocolCompatibilityFeature\ and \ProtocolCompatibilityError\ to enforce version requirements for specific capabilities, such as SQLite startup data, page I/O, and remote execution.

engine/sdks/rust/envoy-protocol/src/versioned · high confidence

Epoxy KV read operations now support multiple consistency modes

The Epoxy key-value store now exposes a unified \epoxy\_kv\_get\ operation that allows callers to choose between four read consistency modes: \LocalCommitted\ for fast, single-replica reads; \LatestReachable\ to fetch the newest value across all reachable replicas (best-effort availability); \Linearizable\ to ensure strict consistency via a quorum-based promise protocol; and \OptimisticImmutable\ for values that never change, which uses a local cache and fan-out to find the value quickly. This change introduces the underlying implementation files (\get.rs\, \get\_latest.rs\, \get\_local.rs\, \get\_optimistic.rs\, \linearizable.rs\) and a \purge\_local\ operation to manage the optimistic cache, replacing the previous single-path read logic with a flexible, mode-aware system.

engine/packages/epoxy/src/ops/kv · high confidence

Epoxy protocol upgrades to v4 with backward-compatible versioned serialization

The Rust epoxy-protocol SDK now defaults to protocol v4, introducing a new build system that auto-generates types from schema files and exposes a \PROTOCOL\_VERSION\ constant. To ensure smooth migration, the library implements versioned serialization for core types (CommittedValue, CachedValue, AcceptedValue), allowing clients to encode and decode data in v2, v3, or v4 formats. Explicit converters handle field mapping between versions, and read-state operations now strictly require v4, while older v3 binaries can still read storage serialized in v3.

engine/sdks/rust/epoxy-protocol · high confidence

Examples now use explicit registry.start() to initialize the server

All example applications in the repository have been updated to explicitly call \registry.start()\ after defining their actors and registering them via \setup()\. This change ensures that the Rivet server is properly initialized and started within each example's entry point, providing a consistent and explicit startup pattern across the codebase.

(repo-wide) · high confidence

Examples updated to use RivetKit with explicit registry initialization

The Elysia and tRPC examples have been rewritten to adopt the RivetKit framework, introducing a standardized pattern where actors are defined and registered via a \setup\ call that returns a registry, which is then explicitly started with \registry.start()\. The Elysia example now exposes this registry through a generic handler at \/api/rivet/\\ alongside a direct HTTP route, while the tRPC example integrates the registry with a Hono-based tRPC server, exposing actor actions through tRPC mutations at \/trpc/\\ and the RivetKit handler at \/api/rivet/\*\.

examples/elysia, examples/trpc · high confidence

Freestyle example now supports serverless deployment via a local API

The \ai-and-user-generated-actors-freestyle\ example has been updated to a serverless format, introducing a local HTTP API (listening on port 6421) that accepts deployment requests. This API supports two deployment modes—Rivet Cloud and self-hosted—by creating namespaces, configuring serverless runners, and deploying the application to Freestyle Sandboxes. The change replaces previous deployment mechanisms with this new \deploy-with-rivet-cloud.ts\ and \deploy-with-rivet-self-hosted.ts\ logic, exposing a standardized interface for triggering serverless deployments from the example.

examples/ai-and-user-generated-actors-freestyle · high confidence

Guard routing module restructured with new path-based and query-based actor routing

The guard service's routing logic has been reorganized into a new modular structure under \engine/packages/guard/src/routing\. This change introduces \actor\_path.rs\, which enables routing to actors via URL query parameters (prefixed with \rvt-\) in addition to the existing direct path-based routing, allowing clients to specify actor details like namespace, method, and key via query strings. New modules for \api\_public\, \envoy\, \runner\, and \ws\_health\ provide dedicated routing handlers, with \envoy\ and \runner\ now supporting both header-based and path-based routing (e.g., \/envoys/connect\ and \/runners/connect\). The \ws\_health\ module adds a WebSocket-based health check endpoint at \/health/ws\ that responds to ping/pong messages. The main \mod.rs\ file orchestrates these routes with improved timeout handling and authentication checks.

engine/packages/guard/src/routing · high confidence

Introduce depot-client as the new SQLite VFS and transport layer

The \depot-client\ package has been introduced to replace the previous \rivetkit-sqlite\ implementation, providing a unified native SQLite VFS and transport layer for Rivet actors. This change adds a dedicated single-threaded worker to handle SQLite commands, implements generation-based fencing to prevent data corruption on fence mismatches, and introduces a comprehensive set of SQLite optimization flags (controllable via environment variables) for features like adaptive read-ahead, page caching, and startup preloading. The new architecture also includes a staging cache for commits and refined metrics for monitoring open phases and worker performance.

engine/packages/depot-client/src · high confidence

Introduce unified database and pub/sub connection pool setup

The engine now centralizes connection initialization for its core data stores and messaging layer through new setup modules. A new ClickHouse client is configured with HTTP/HTTPS support and TLS root fallbacks. UniversalDB (UDB) setup now supports both Postgres (with optional NATS for multi-node mode and explicit SSL configuration) and a local RocksDB file-system driver, including dynamic throttle configuration. The Universal Pub/Sub (UPS) layer is initialized via either a NATS driver (with comprehensive event handling, reconnection logic, and background statistics metrics) or an in-memory driver, allowing operators to choose the transport based on their deployment needs.

engine/packages/pools/src/db · high confidence

Introduces RAII-based gauge guards and standardized metric buckets

The metrics package now provides RAII-style gauge guards (IntGaugeGuard, FloatGaugeGuard) via the GaugeGuardExt trait, allowing users to automatically decrement gauges when a scope ends or a panic occurs, ensuring accurate tracking of in-progress work. Additionally, the package exposes standardized histogram bucket configurations (BUCKETS, MICRO\_BUCKETS, LIFETIME\_BUCKETS, PAGE\_COUNT\_BUCKETS, TASK\_POLL\_BUCKETS) and a centralized Prometheus registry, replacing previous ad-hoc metric definitions with a consistent, reusable library.

engine/packages/metrics · high confidence

Introduces structured cache key generation for the guard engine

The guard engine now uses a dedicated cache module to generate request cache keys based on routing context. For path-based actor routing, keys include the actor ID, stripped path, and HTTP method. For target-based routing (via headers or WebSocket protocols), keys incorporate the target, actor ID, path, and method. Query-based actor paths generate keys from routing-relevant fields (namespace, name, key, etc.) while intentionally excluding tokens to ensure consistent caching across different authentication tokens. A fallback mechanism hashes the hostname, path, and method for other requests.

engine/packages/guard/src/cache · high confidence

Move lobby runtime aggregate logic into a dedicated query

The implementation of the lobby runtime aggregate operation has been refactored to move the core aggregation logic into a dedicated query. This change consolidates the data processing steps, ensuring that the aggregation of lobby durations and metadata is handled more efficiently within the query layer rather than in the application code.

svc/pkg/mm/ops/lobby-runtime-aggregate · medium confidence

Multi-node commit protocol adds chunking support for large payloads

The universaldb commit wire format has been updated to version 2 to support splitting large commit requests across multiple NATS messages. This change introduces a \CommitRequestChunk\ type that allows followers to fragment requests exceeding the NATS server's \max\_payload\ limit, ensuring reliable transmission to the leader in multi-node Postgres deployments. The schema also retains the original v1 structure for compatibility during rolling upgrades, while adding an \attempt\ counter to prevent mixing pieces from failed resend attempts.

engine/sdks/schemas/universaldb-commit · high confidence

New database key definitions for Pegboard actors, runners, and namespaces

The Pegboard engine now includes a comprehensive set of database key definitions in \engine/packages/pegboard/src/keys\ to manage internal state. This change introduces key structures for actors (including creation timestamps, workflow IDs, runner assignments, and connectivity flags), actor key-value stores (with support for exact and range queries), and runners (tracking creation, slots, and protocol versions). It also adds keys for namespace-level runner allocation indexes, runner configurations, and hibernating request tracking, establishing the data layout for these core engine components.

engine/packages/pegboard/src/keys · high confidence

New internal storage key definitions for namespace metrics and metadata

The namespace package now includes formalized key structures for storing and retrieving internal metrics (such as actor awake time, KV storage usage, and SQLite bytes) and namespace metadata (including name, display name, and creation timestamp). These changes introduce new Rust types that define how these data points are serialized, deserialized, and packed into the underlying storage subspace, establishing the schema for future metric collection and namespace attribute management.

engine/packages/namespace/src/keys · high confidence

New pegboard operations for envoy lifecycle and connection fencing

The pegboard engine now includes a new set of operations in the \envoy\ module to manage envoy registrations with stricter connection ownership and cleaner state transitions. These changes introduce connection fencing via \expected\_envoy\_conn\_id\ in \evict\_actors\, \expire\, and \update\_ping\ to prevent stale connections from modifying state. It adds \drain\ to gracefully close older envoy versions during upgrades, \get\ and \list\ to retrieve envoy details, and \update\_ping\ to handle heartbeats and load-balancer index updates. These operations collectively improve the reliability and consistency of envoy connection management within the engine.

engine/packages/pegboard/src/ops/envoy · high confidence

New universal database driver interface with transaction tagging and graceful shutdown

The \universaldb\ driver module now exposes a unified \DatabaseDriver\ trait that standardizes access to underlying storage engines (Postgres and RocksDB). This interface introduces transaction tagging via the new \tag\ method, allowing operations to be labeled for observability, and adds a \shutdown\ hook that enables graceful resource release, such as handing off Postgres leader leases to standby nodes. Additionally, the \TransactionDriver\ trait now supports per-transaction retry limits via \retry\_limit\, giving callers precise control over retry behavior rather than relying solely on global settings.

engine/packages/universaldb/src/driver · high confidence

Pegboard engine restructured with SQLite v1-to-v2 migration and envoy expiration scheduler

The Pegboard engine source has been reorganized into a new modular structure, introducing a dedicated SQLite v1-to-v2 migration workflow that safely imports legacy actor databases into the new v2 storage format with crash-resilient checkpointing. Additionally, a new in-process Envoy expiration scheduler has been added to manage stale envoy cleanup with concurrency limits and deduplication, replacing the previous per-process spawning pattern. The update also includes comprehensive error definitions for actor and runner operations, new Prometheus metrics for tracking migration progress and envoy lifecycle, and pubsub subjects for runner and envoy routing.

engine/packages/pegboard/src · high confidence

Pegboard-envoy actor lifecycle and event handling rewritten

The pegboard-envoy service now manages actor connections and data using a new modular task architecture. Actor events are routed through a dedicated demuxer that batches and dispatches signals to actor workflows, while separate background tasks handle key-value operations, remote SQLite execution, and page-level SQLite requests. Connection lifecycle is now explicitly managed with dedicated stop and shutdown routines that safely evict local SQLite caches and close remote executors without deadlocking the command path. The system also introduces a ping task to monitor envoy liveness and an eviction mechanism that uses pubsub to coordinate connection ownership, ensuring that only the current registration handles actor commands.

engine/packages/pegboard-envoy/src · high confidence

Postgres resolver driver overhaul with leader lease management and batched apply

The Postgres resolver driver in \universaldb\ has been restructured to support both single-node and multi-node modes with explicit leader election via a PostgreSQL-backed lease mechanism. A new \lease.rs\ module handles leader acquisition, renewal, and graceful release using epoch-based CAS operations, enabling automatic failover when a leader steps down or crashes. The \apply.rs\ module introduces a new \fold\_winners\ function that batches multiple winning commits into a single materialized write-set, applying operations sequentially within an in-memory overlay to preserve serializability and reduce database round-trips. The driver now supports group commit with a configurable batch size (default 256), improving throughput by amortizing Postgres round-trips and fsync costs across multiple commits. Tests verify the correctness of the batched apply logic against a reference implementation.

engine/packages/universaldb/src/driver/postgres/resolver · high confidence

Refactored commit pipeline with staged writes and improved truncate cleanup

The commit logic in the depot engine has been restructured into modular components (apply, branch\_init, dirty, helpers, publish, stage, truncate) to support both single-shot and large staged commits. This change introduces a staged commit path that writes large transactions as shard-aligned segments to avoid transaction size limits, while ensuring atomic visibility via a finalization step. It also refactors truncate cleanup to selectively retain shard versions required by history pins and Point-in-Time Recovery (PITR) intervals, preventing data loss during database shrinking. Additionally, the codebase now includes fault injection hooks for testing commit resilience and helper utilities for transaction-scoped database operations.

engine/packages/depot/src/conveyer/commit · high confidence

Removal of legacy database operation implementations

This change removes the source code for multiple service operations (including CDN, Cloud, Game, Identity-Config, KV-Config, MM-Config, and User services) that previously handled database interactions via direct SQL queries. These files, which managed tasks such as namespace creation, version publishing, and token generation, have been deleted, indicating a migration away from the previous database access pattern in these specific service locations.

(repo-wide) · high confidence

Removal of legacy database query implementations

The direct SQL query implementations in the \game-user\, \mm\, \team-invite\, \token\, and \upload\ services have been removed. This cleanup eliminates the manual \sqlx\ query logic and row-mapping code that previously handled data retrieval for operations such as fetching game-user links, listing users, retrieving recent sessions, getting player details, fetching team invitations, validating tokens, and listing user uploads, indicating a shift away from these specific hand-written database access patterns.

(repo-wide) · high confidence

Removal of legacy database query operations

Deleted the implementation files for multiple service operations (including CDN namespace resolution, site retrieval, Cloud game configuration, Game listing and versioning, Matchmaker configuration, Team and User identity resolution, and Cloudflare custom hostname management). These operations previously executed direct SQL queries against their respective dedicated databases (such as db-cdn, db-game, db-cloud, db-mm-config, db-team, and db-user-identity) and are now removed, indicating a migration away from these standalone database access patterns.

(repo-wide) · high confidence

Removal of legacy key-value and search operation implementations

The codebase has removed the source files for several core operations, including \kv-get\, \kv-list\, \mm-lobby-history\, and \team-search\. These deletions indicate that the underlying logic for retrieving key-value pairs, listing KV entries, fetching lobby history, and searching teams has been replaced or migrated elsewhere, likely as part of the broader effort to migrate services to a single database and standardize query handling via macros.

(repo-wide) · medium confidence

Removal of namespaces and secrets documentation placeholders

The placeholder documentation files (.gitkeep and README.md) for the namespaces and secrets configuration directories have been removed. This eliminates the previous instructions for placing namespace and secrets configuration files as .toml files in these directories, indicating that this manual file-based configuration approach is no longer supported or documented in these locations.

namespaces, secrets · high confidence

Removal of team profile validation operation

The \team-profile-validate\ operation implementation has been removed from the codebase. This change eliminates the server-side logic that previously validated team display names (checking for length, format, and uniqueness) and biography fields (checking for length and format). Users relying on this specific validation step during profile updates will no longer have these checks performed by this operation.

svc/pkg/team/ops/profile-validate · high confidence

Removal of user-follow count and list operation implementations

The source files for the \user-follow-count\ and \user-follow-list\ operations have been deleted from the service. This removes the direct SQL query logic and response handling previously contained in these modules, indicating that the implementation for retrieving follow counts and listing follows has been moved or replaced elsewhere.

svc/pkg/user-follow/ops/count, svc/pkg/user-follow/ops/list · high confidence

Removal of user-follow relationship-get operation implementation

The implementation file for the user-follow-relationship-get operation has been deleted. This removes the logic that previously queried the database to determine follower/following status between user pairs and returned the mutual, follower, and following flags. This change is part of the broader migration to a single database and macro-based query structure.

svc/pkg/user-follow/ops/relationship-get · high confidence

RivetKit SDK breaking changes and self-hosted authentication requirements

The Rust SDK now supports actor action sets containing up to 128 action types (increased from 16). For self-hosted deployments, the engine now requires an admin token (\auth.admin\_token\) and Bearer token authentication; legacy unauthenticated access can be restored by setting \auth.insecure\_allow\_unauthenticated: true\. In the TypeScript SDK (\rivetkit\), \ctx.sql\ is removed in favor of \ctx.db\ from \rivetkit/db\, and concrete error classes like \QueueFull\ are replaced by the standardized \RivetError\ with \isRivetErrorCode\ checks. Several internal entrypoints (\rivetkit/driver-helpers\, \rivetkit/topologies\, \rivetkit/dynamic\, \rivetkit/sandbox\) are permanently removed, while \Registry.handler\ and \Registry.serve\ are restored for the native serverless runner.

(repo-wide) · high confidence

Rust SDK regenerated with namespace-scoped auth tokens and updated API surface

The Rust API client in engine/sdks/rust/api-full has been regenerated (OpenAPI Generator 7.14.0) to reflect the latest API schema. This update introduces namespace-scoped JWT authentication, adding new models (AuthTokenCreateRequest, AuthTokenGrant, AuthTokenTargetScope, etc.) and endpoints (AuthTokensApi) for creating and inspecting auth tokens. It also includes updated documentation and code for existing resources like Actors, Namespaces, Runners, and Datacenters, ensuring the SDK stays in sync with the backend API version 2.3.19.

engine/sdks/rust/api-full · high confidence

Serverless runner lifecycle management moved to dedicated workflows

The serverless runner connection, receiver, and backfill logic has been extracted into dedicated workflow modules (conn, receiver, backfill) within the pegboard serverless package. This change ensures that existing serverless configurations are properly backfilled with runner pool workflows and that the connection lifecycle (including drain signals and retry backoffs) is handled by isolated workflows, improving reliability and separation of concerns for serverless runner management.

engine/packages/pegboard/src/workflows/serverless · high confidence

Structured error handling for cross-datacenter requests

The \api-util\ package now introduces a dedicated \Datacenter\ error type to provide specific, structured error responses (such as \NotFound\) when interacting with remote datacenters, replacing generic failures. This change improves the user experience by ensuring that cross-datacenter API calls return meaningful error context rather than generic 500 errors, and includes enhanced logging for debugging remote request issues.

engine/packages/api-util · high confidence

UniversalDB commit protocol upgraded to version 2 with backward compatibility

The Rust SDK for universaldb-commit now uses protocol version 2 as the latest standard for commit requests, replies, and watermarks. This change introduces a new versioned data model that automatically handles serialization and deserialization for both v1 and v2 formats, ensuring backward compatibility with existing clients. The build process now dynamically determines the highest schema version and embeds it as a constant, while conversion logic between v1 and v2 is implemented to support seamless migration for users.

engine/sdks/rust/universaldb-commit · high confidence

Ups-protocol SDK adds versioned message support with v1–v3 migration

The Rust ups-protocol SDK now includes a versioned message abstraction (UpsMessage) that supports protocol versions 1, 2, and 3. It automatically detects the highest schema version and exposes it via PROTOCOL\_VERSION, while providing bidirectional conversion functions (v1↔v2, v2↔v3) to migrate messages between versions. This enables consumers to serialize/deserialize messages across protocol versions and ensures compatibility when upgrading or downgrading the protocol.

engine/sdks/rust/ups-protocol · high confidence

Fixes

Introduce structured error handling with internal error exposure control

The engine now uses a new \RivetError\ system in \engine/packages/error/src\ that structures errors with groups, codes, and optional metadata, while introducing a mechanism to control the visibility of internal diagnostic details. Specifically, the \RivetError::build\_internal\ method now checks the \RIVET\_EXPOSE\_ERRORS\ environment variable; if set to \1\, internal error messages are exposed to the user, otherwise they are suppressed to prevent leaking sensitive implementation details. This change ensures that internal bridge errors are handled consistently and securely by default.

engine/packages/error/src · high confidence

Test coverage

Added benchmark suite for universalpubsub; Added comprehensive test coverage for UniversalDB drivers; Added comprehensive test coverage for depot compaction and actor throttle behaviors; Added end-to-end tests for the Python client; Added fault-injection and VFS test harness for depot-client; Added inline tests for depot compaction, conveyer, and metadata logic; Added integration and unit tests for guard-core proxy, WebSocket, and TLS features; Added integration and unit tests for the Gasoline workflow engine; Added integration tests for Epoxy engine core operations; Added integration tests for engine actor migration, serverless runner configuration, JWT authentication, and WebSocket payload handling; Added protocol compatibility and roundtrip tests for SQLite operations; Added snapshot test fixtures for Epoxy and protobuf actor storage; Added test coverage for UniversalPubSub chunking, integration, reconnect, and subject metrics; Added test coverage for pegboard actor lifecycle, SQLite migration, and envoy load-balancing; Added test harness for Epoxy engine replicas; Added test infrastructure for guard-core proxy service; Added test infrastructure for the engine API; Added test support for HTTP streaming actor lifecycle; Added test utilities for pegboard hash allocation; Added tests for Envoy protocol v6/v7 serialization and downgrade constraints; Added tests for actor lifecycle management and envoy connection metrics; Added tests for actor path parsing in the gateway; Added tests for boot ID stability and actor input/state serialization; Added tests for envoy-client command deduplication, SQLite VFS disconnect handling, actor draining, and WebSocket lock contention; Added tests for error handling and serialization; Added tests for response body lifecycle and authorization deadlines; Added tests for tunnel delivery, payload accounting, and SQLite actor caching; Added unit tests for range streaming, chunked commits, and Postgres query plans; Expanded engine runner test coverage for actor lifecycle and KV operations; Expanded integration tests for the Envoy actor engine; New local end-to-end test harness for container-runner; New shared test infrastructure for engine integration tests.

Dependencies

Introduce container-runner and engine package scaffolding

This change adds the \container-runner\ crate, a Rust serverless runner that hosts actors by spawning child game-server processes and proxying traffic, along with its associated e2e test examples. It also scaffolds a large number of new \engine/packages\ crates (including \api-builder\, \api-public\, \auth\, \bootstrap\, \cache\, \cli\, \config\, \depot-client\, \epoxy\, and \guard-core\), establishing the workspace structure and dependency definitions for the engine's modular architecture.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 30 → 30 (+0.1)
  • Rubric changed (rubric-2026.09.10 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 67 → 67 (-0.3)
  • Architecture 46 → 48 (+1.2)
  • Maturity 83 → 83 (+0.0)
  • Readiness 42 → 36 (-5.6)
  • Security 38 → 47 (+9.1)
  • Event-Driven 10 → 10 (+0.0)
  • Event Sourcing 100 → 100 (+0.0)
  • Accessibility 68 → 67 (-0.7)
  • Performance 69 (new)

Resolved (475)

  • ActorHandleRaw.#sendActionNow (cognitive 31) (rivetkit-typescript/packages/rivetkit/src/client/actor-handle.ts)
  • ActorHandleRaw.#sendActionNow (cyclomatic 19) (rivetkit-typescript/packages/rivetkit/src/client/actor-handle.ts)
  • Change coupling: napi-runtime.ts ↔ wasm-runtime.ts (rivetkit-typescript/packages/rivetkit/src/registry/napi-runtime.ts)
  • Critical CVE: [CVE redacted] (pnpm-lock.yaml)
  • Critical CVE: [CVE redacted] (pnpm-lock.yaml)
  • Critical CVE: [CVE redacted] (pnpm-lock.yaml)
  • Critical CVE: [CVE redacted] (pnpm-lock.yaml)
  • Critical CVE: [CVE redacted] (pnpm-lock.yaml)
  • Critical CVE: [CVE redacted] (pnpm-lock.yaml)
  • Critical CVE: [CVE redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • DatabaseKv::revive_workflows_inner (cognitive 16) (engine/packages/gasoline/src/db/kv/debug.rs)
  • Duplicated block (10 lines × 2) (engine/packages/gasoline/src/db/kv/debug.rs)
  • Duplicated block (10 lines × 2) (engine/packages/universaldb/src/driver/rocksdb/transaction_task.rs)
  • Duplicated block (10 lines × 2) (engine/sdks/rust/envoy-protocol/src/versioned/v7_to_v6.rs)
  • Duplicated block (10 lines × 2) (engine/sdks/rust/envoy-protocol/src/versioned/v7_to_v8.rs)
  • Duplicated block (12 lines × 2) (engine/sdks/rust/envoy-protocol/src/versioned/v7_to_v6.rs)
  • Duplicated block (13 lines × 2) (engine/packages/universaldb/src/driver/postgres/database.rs)
  • Duplicated block (13 lines × 4) (engine/packages/pegboard-gateway2/src/shared_state.rs)
  • …and 455 more

New (320)

  • ActorConnRaw.#handleOnClose (cyclomatic 18) (rivetkit-typescript/packages/rivetkit/src/client/actor-conn.ts)
  • ActorHandleRaw.#sendActionAttempts (cognitive 31) (rivetkit-typescript/packages/rivetkit/src/client/actor-handle.ts)
  • ActorHandleRaw.#sendActionAttempts (cyclomatic 19) (rivetkit-typescript/packages/rivetkit/src/client/actor-handle.ts)
  • Change coupling: actor_context.rs ↔ telemetry.ts (rivetkit-typescript/packages/rivetkit-napi/src/actor_context.rs)
  • Change coupling: lib.rs ↔ napi-runtime.ts (rivetkit-rust/packages/rivetkit-core/src/lib.rs)
  • Change coupling: telemetry.rs ↔ telemetry.ts (rivetkit-rust/packages/rivetkit-core/src/telemetry.rs)
  • Change-coupling hub: wasm-runtime.ts → context.rs, lib.rs, napi-runtime.ts (rivetkit-typescript/packages/rivetkit/src/registry/wasm-runtime.ts)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
  • DatabaseKv::inspect_missing_init_state (cognitive 25) (engine/packages/gasoline/src/db/kv/repair.rs)
  • DatabaseKv::inspect_missing_init_state (cyclomatic 22) (engine/packages/gasoline/src/db/kv/repair.rs)
  • Duplicated block (10 lines × 2) (engine/sdks/rust/envoy-protocol/src/versioned/v6_to_v5.rs)
  • Duplicated block (10 lines × 2) (rivetkit-swift/Sources/RivetKitClient/ActorConnection.swift)
  • Duplicated block (10 lines × 2) (rivetkit-swift/Sources/RivetKitClient/ActorConnection.swift)
  • Duplicated block (11 lines × 7) (rivetkit-swift/Sources/RivetKitSwiftUI/ActorObservable.swift)
  • Duplicated block (11–12 lines × 3) (engine/packages/api-public/src/actors/create.rs)
  • Duplicated block (12 lines × 2) (engine/packages/universaldb/src/driver/rocksdb/transaction_task.rs)
  • Duplicated block (12 lines × 4) (engine/sdks/rust/envoy-protocol/src/versioned/v6_to_v5.rs)
  • Duplicated block (13 lines × 2) (engine/packages/depot/src/compaction/companion.rs)
  • …and 300 more

Changes since last survey

  • 88 commits — 60 feature/other, 28 fixes

By area

  • frontend/src — 18 commits
  • rivetkit-typescript/packages — 14 commits
  • engine/packages — 12 commits
  • rivetkit-rust/packages — 10 commits
  • (repo) — 5 commits
  • examples/docs — 5 commits
  • docs/actors — 4 commits
  • docs/general — 4 commits
  • (root) — 3 commits
  • docs-internal/engine — 3 commits
  • engine/sdks — 3 commits
  • docs/api — 2 commits
  • .github/workflows — 1 commit
  • container-runner/src — 1 commit
  • docs/content — 1 commit
  • examples/jwt-better-auth — 1 commit
  • frontend/vite.config.ts — 1 commit

Notable commits

  • fix: fix(auth-jwt): allow Guard startup during Epoxy v4 rollout
  • fix: fix(container-runner): propagate fallible serve config parsing
  • fix: fix(depot): import BucketId in the inline compaction workflow tests
  • fix: fix(envoy): replay terminal actor events after reconnect
  • fix: fix(examples): stop showing unverified JWT decoding as verification
  • fix: fix(frontend): allow the sandbox portal hostname in the dev server
  • fix: fix(frontend): decode region restarted time from operator boot id
  • fix: fix(frontend): enforce dns-safe cluster names in byoc create form
  • fix: fix(frontend): poll byoc cluster regions on a 5s interval
  • fix: fix(frontend): show product picker note under the step title instead of below the grid (#5742)
  • fix: fix(frontend): stop double-counting compute in paid-plan bill totals
  • fix: fix(frontend): use cloud namespace for onboarding deploy command
  • fix: fix(frontend): use services pool name in managed services upsert
  • fix: fix(pegboard-envoy): use async scc methods so actor stop cannot deadlock the envoy command stream
  • fix: fix(pegboard-gateway): forward request ray id to actors
  • fix: fix(rivetkit): add trace ids to logs written inside a workflow
  • fix: fix(rivetkit): disable services in driver test runtimes
  • fix: fix(rivetkit): finish a step span after its result is written
  • fix: fix(rivetkit): log resolved envoy version at startup (#5785)
  • fix: fix(rivetkit): sync Rust env parsing with TypeScript
  • …and 68 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

rivet-dev/actors was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit cd05273396430a48ff0841a8e12ed596b1d08aa1 — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-c4983f2d4e5c.