Builds & Features
Fluxheim wird mit Feature-Sets kompiliert. Wähl den kleinsten Build, der enthält, wos dei Deployment braucht.
Häufige Builds
| Build | Nutz es für |
|---|---|
| full | General production server with web, proxy, cache, TLS, ACME, PHP-FPM, metrics, and tracing. |
| wasm | Eigener Wasm-Build auf Basis vom vollständigen Produktionsprofil, mit begrenztn Richtlinien-Hooks, ACME, Metriken und OpenTelemetry. |
| proxy | Reverse proxy without local static hosting or cache. |
| cache | Cache edge in front of another origin. |
| load-balancer | Fokussiertes Upstream-Balancing und Health Checks. |
| php | Statisches Web plus PHP-FPM-Anwendungen wia WordPress. |
Profilbeispiele
cargo build --release --no-default-features --features profile-full,acme-client,metrics,metrics-otlp,otel-tracing,otel-otlp
cargo build --release --no-default-features --features profile-wasm,acme-client,metrics,metrics-otlp,otel-tracing,otel-otlp
cargo build --release --no-default-features --features profile-cache-edge,acme-client
cargo build --release --no-default-features --features profile-proxy-edge,acme-client
cargo build --release --no-default-features --features profile-web-server,php-fpm,acme-client
cargo build --release --no-default-features --features profile-load-balancer-edge,acme-client
Pingora-freie normale Builds
Seit 1.6.34 nutzen normale Fluxheim-Release-Profile de Fluxheim-owned native Runtime und kompiliern koa Pingora-crates mehr.
Eigener Wasm-Build auf Basis vom vollständigen Produktionsprofil, mit begrenztn Richtlinien-Hooks, ACME, Metriken und OpenTelemetry.
Nicht unterstützte native Runtime-Shapes schlagen weiter fail-closed mit expliziten Blockern fehl, statt auf Legacy-Adapter zruckzufallen.
Feature-Familien
| Familie | Wos es dazubringt |
|---|---|
web | Statisches Datei-Serving und lokale Web-Routen. |
proxy | Reverse proxy routes and upstream handling. |
cache | Shared cache policy, memory and disk tiers, purge, and cache tooling. |
php-fpm | FastCGI-Bridge und optionale verwaltete PHP-FPM-Überwachung. |
metrics | Prometheus metrics and optional OTLP metrics export. |
wasm | Optionale WebAssembly-Policy-Laufzeit mit begrenzte Zugriffs-, Header-, Routen- und Cache-Hooks; standardmäßig ausgschaltet. |
Wos ned zammpasst
- Wähl genau a TLS-Backend.
- Privacy-Builds enthoitn koa Cache, Metriken, Tracing, OTLP-Export oder Wasm-Funktionen.
- Fokussierte Edge-Images lassn Module außerhalb vo ihrer Aufgabe bewusst weg.
- Run the feature validator before packaging custom feature strings.
Nachweis fia FIPS-Backends
Fluxheim stellt getrennt angeheftete CI-Nachweisumgebungen fia de Profile OpenSSL-FIPS und rustls/AWS-LC-FIPS bereit. De bauen und starten genau des Profil-Binärprogramm, testen nachgelagerts und zertifikatsgeprüfts vorgelagerts TLS, lehnen unverträgliche Richtlinien ab und zeichnen Compiler-, Anbieter-, Abhängigkeits-, Binär- und Image-Identitäten auf.
Des san reproduzierbare Backend-Nachweis, koa FIPS-Validierung vom ganzen Produkt. Halt de Nachweis-Container von normale Release-Images getrennt und prüf d Nachweis genau fia den Build, den ausrollst.
Den Leitfaden fia FIPS-Nachweis lesn