Skip to content

Begin typing to search this documentation.

Host capabilities

Hoplite separates synchronous request state from asynchronous host services.

A route using the :raw adapter receives a borrowed exchange. hoplite.raw reads a bounded set of Nginx-backed fields directly, including the scheme, protocol, host, server and connection identity, ports, request ID, request timing and byte counts.

(ns example.request
(:require [hoplite.raw :as raw]))
(defn show [exchange]
(raw/respond! exchange
200
{"content-type" "text/plain"}
(raw/request-id exchange)))

This path does not use Host/call, and it does not accept arbitrary Nginx variable names or directives. See Raw Nginx exchange.

Asynchronous event-loop operations remain explicit capabilities. A project using them declares:

:project/capabilities #{:host/nginx}

hoplite.raw/sleep is the typed request-scoped timer wrapper. It suspends the handler without blocking the Nginx worker and accepts 0 through 3,600,000 milliseconds:

(ns example.delay
(:require [hoplite.raw :as raw]))
(defn ^:async delayed [exchange]
(Coroutine/await (raw/sleep 25))
(raw/respond! exchange 200 "ready"))

The wrapper uses Hoplite’s bounded Nginx service internally; application code does not select a generic service name or operation.

hoplite.socket exposes OpenResty-compatible TCP and UDP cosocket names through typed Hara functions. The production implementation is integrated with the Nginx event loop; a suspended connect, send, or receive does not block the worker. Socket handles are request-scoped, owner-checked, cancellation-aware, and closed exactly once.

The first production slice supports numeric-address TCP connect, bounded send, fixed/line/all receive, close, and independent timeouts. DNS, keepalive pools, TLS, Unix sockets, delimiter iterators, concurrent directional operations, and UDP advance under issue #163. Application code does not name the native hoplite.socket service or its operation strings.

Development

The interactive console installs the hoplite.dev host. Its public HAL functions call the host with methods such as start, stop, restart, status, list-all, and logs.

hoplite.host supplies bounded randomness, SHA-256 hashing, canonical HTA value digests, base64url and hexadecimal conversion, strict P-256 public JWK conversion, Ed25519/P-256 signature verification, and Unix time. It contains no account, session, database, credential store, or authorization policy.

A trusted embedding may register an immutable service descriptor during worker startup. Applications can call an installed application-neutral service but cannot register it or select its driver, path, credentials, or limits. Hoplite ships no concrete storage or credential provider. See Data-plane boundaries.

The host service name and operation are explicit in the call. Hoplite does not treat arbitrary shell commands, opaque numeric handles, provider paths, or undeclared server definitions as capabilities.