Start here
Getting started
https://scalws.com · daemon scalwsd · CLI scalwsctl · ScalWS Adaptive Runtime
controller scalws-controller
A Linux-first web and application server written in Rust: fast, observable, secure and multi-tenant, with PHP, Node.js, Python and arbitrary upstreams as first-class runtimes.
Status: M10. All milestones of the handoff (M0–M10) and all acceptance gates are done: serving core, managed PHP-FPM / Node.js / Python / container runtimes, cgroup v2 tenancy, framework profiles, response cache (memory + disk), deterministic security and optimizer, diagnostics, optional local AI advisor, admin API (Unix socket, optional mTLS) with
scalwsctl, ACME certificates, DEB/RPM packages for amd64 and arm64. Experimental and opt-in at build time: HTTP/3 (--features http3) and eBPF network accounting (--features ebpf). The multi-node control plane is designed (ADR-0021), not built.
What works today
- HTTP/1.1 and HTTP/2 (ALPN and h2c prior knowledge), TLS 1.2/1.3 via rustls with SNI certificate selection (exact and wildcard)
- Tenant → application → domain model; host routing (exact +
*.wildcard); path routes matched on normalised paths - Handlers: confined static files (conditional + range requests), HTTP reverse proxy over TCP, TLS or Unix sockets with WebSocket tunnelling, fixed responses
- Managed runtimes: PHP-FPM pools over FastCGI (front controller,
PATH_INFO), Node.js processes, Python ASGI/WSGI servers (uvicorn, hypercorn, gunicorn) — supervised with readiness, crash backoff, restart-loop detection, graceful drain and log capture - Tenancy: cgroup v2 limits per tenant (CPU, memory, pids, I/O weight) with race-free worker placement and live updates; per-tenant concurrency and rate quotas; per-tenant and per-application resource accounting
- Application profiles:
scalwsctl detect /srv/apprecognises WordPress, WooCommerce, Laravel, Next.js, Django, Flask, FastAPI and generic PHP/Node/Python apps, shows its evidence and proposes a configuration;profile: wordpressin config - Response cache (opt-in per app): explicit freshness only,
Vary, stale-while-revalidate, profile bypass rules, purge by URL/prefix/tag - Security: profile deny rules (e.g.
wp-config.php,.env), per-IP connection and request limits with bounded memory, write timeout for slow readers, strict SNI (421) - Optimizer: deterministic worker rules with cooldowns, bounds and automatic rollback;
recommend-only unless
autoscale: auto; audited (scalwsctl recommendations) - Diagnostics: correlated findings (crash loops, OOM kills, CPU/memory/I/O pressure,
upstream timeouts, saturation, …) and recent failed/slow requests (
scalwsctl diagnose) - ACME (HTTP-01) certificates with renewal without restart; trusted proxies
(
X-Forwarded-For, PROXY protocol); container applications (podman/docker) - Optional local AI advisor (off by default): explains diagnostics with an operator-chosen
local model; redacted input, validated output, never acts (
scalwsctl explain) - Operations: admin API on a Unix socket,
scalwsctl(reload, rollback, diff, restart, scale, purge, top, backup/restore), read-only dashboard, DEB/RPM packages — see docs/OPERATIONS.md - Limits: connections, header size/count, URI length, body size, TLS handshake / header / body / idle timeouts, HTTP/2 stream and reset limits
- Prometheus metrics (
/metrics) and JSON access logs, bounded label cardinality - Validate-then-swap configuration reload (
SIGHUP), restart-only topology changes rejected, graceful drain onSIGTERM scalwsctl checkruns the exact prepare path a reload would
Install
Ubuntu 24.04 or later, Debian 13 or later (amd64), from the signed ScalWS apt repository:
curl -fsSL https://scalws.com/apt/scalws-archive-keyring.gpg -o /usr/share/keyrings/scalws-archive-keyring.gpg
echo 'deb [signed-by=/usr/share/keyrings/scalws-archive-keyring.gpg] https://scalws.com/apt stable main' > /etc/apt/sources.list.d/scalws.list
apt update && apt install scalws
scalwsctl check && systemctl enable --now scalwsdConfiguration: /etc/scalws/scalws.yaml; console: https://<host>:8090 (see
docs/OPERATIONS.md).
Quick start from source
cargo build --release
./target/release/scalwsctl check examples/scalws.yaml # needs the referenced files
./target/release/scalwsd --config examples/scalws.yaml
kill -HUP $(pidof scalwsd) # reload
curl -s 127.0.0.1:9901/metrics | grep scalws_http_requests_totalLayout
crates/ scalws-core scalws-config scalws-runtime scalws-runtime-node scalws-runtime-python
scalws-runtime-php scalws-router scalws-tls scalws-static scalws-proxy scalws-observe scalws-http
scalws-server
cmd/ scalwsd (daemon), scalwsctl (CLI)
tests/ integration (end-to-end serving + security tests)
bench/ benchmark harness (Docker), bench upstream, nginx/caddy comparison configs
docs/ ARCHITECTURE.md, THREAT_MODEL.md, DECISIONS.md, adr/
examples/ configuration examples
profiles/ application profiles (YAML, embedded at build time)
packaging/systemd
docker/ test.Dockerfile (Linux test image with PHP-FPM, Node.js, Python servers)
scripts/ linux-test.sh, smoke.sh, profile.shDevelopment
cargo test --workspace # any OS
scripts/linux-test.sh --docker # authoritative Linux run (fmt, clippy, tests)
cargo deny check && cargo audit # supply chain (CI runs both)Benchmarks: see bench/README.md.