Skip to content Search docs /
Documentation menu Start here 2 Architecture 2 Adaptive Runtime 5 Operations 1 Console 6 Security 3 Benchmarks 26 Decision records 47 0001 Rust + Tokio + hyper for the data plane 0002 rustls with the aws-lc-rs crypto provider 0003 Declarative YAML configuration, validate-then-swap 0004 Two-level runtime contract (Handler / RuntimeAdapter) 0005 Metrics, logs and bounded cardinality 0006 Static file confinement 0007 Linux-first product, cross-platform development 0008 Managed application processes 0009 PHP via FastCGI using the `fastcgi-client` crate 0010 cgroup v2 placement, tenant resource limits and request quotas 0011 Data-driven application profiles and detection 0012 Bounded in-memory response cache 0013 Deterministic security engine (first stage) 0014 Deterministic optimizer (policy engine) 0015 Deterministic diagnostics 0016 Local AI advisor 0017 Admin API and operations 0018 ACME certificate automation 0019 HTTP/3 (QUIC): experimental, behind a feature 0020 Container runtime adapter 0021 Multi-node control plane (design only) 0022 Trusted proxies (X-Forwarded-For, PROXY protocol) 0023 Remote administration over mutual TLS 0024 Disk tier of the response cache 0025 Optional eBPF enrichment: per-application network accounting 0026 Per-tenant Unix users for application processes 0027 Zero-copy static file bodies with sendfile(2) 0028 Open file cache for static files 0029 Per-core event loops 0030 Kernel TLS for HTTPS/1.1 file bodies (opt-in) 0031 `.htaccess` compatibility (opt-in per application) 0032 FastCGI connection drivers for managed PHP-FPM pools 0033 Adaptive Runtime: control plane, data plane and listener sharing 0034 PressureScore v1 and bottleneck classification 0035 Instance lifecycle, draining, configuration generations and recovery 0036 State with several scalwsd instances on one host 0037 Listener generations: listener changes without restarting the controller 0038 Connection distribution: measure pressure, not connection counts 0039 HTTP/3 with several instances: a separate QUIC transport plane 0040 QUIC connection IDs: routing and privacy 0041 HTTP/3 graceful lifecycle (single and multiple instances) 0042 Per-domain request counters 0043 Upstream connection telemetry 0044 Fountain accept policy (opt-in) 0045 Experimental own HTTP/1 upstream client (opt-in) 0046 Own HTTP/1 server side (opt-in) 0047 Profile-guided release builds Decision records
ADR-0005: Metrics, logs and bounded cardinality
Status: Accepted (2026-10-05)
Decision
prometheus-client (official Rust client of the Prometheus project) for metrics,
served as text exposition on a dedicated listener (loopback by default).
tracing + tracing-subscriber with JSON output for structured logs; one access-log
event per request (target scalws::access).
Label policy: only tenant, app (from config, bounded), listener (config), method
(normalised to a fixed set + OTHER), status class (1xx..5xx), handler kind.
Never URLs, query strings, user agents or Host values. Unrouted requests use
tenant="_unmatched".
OpenTelemetry trace export (OTLP) is deferred until after M2 so that the dependency
footprint is justified by a working runtime platform; spans are already emitted via
tracing, so adding an OTLP layer is additive.