neverstored: hand over a secret without leaving traces

Andrea Fontana nospam at example.org
Tue Sep 22 14:25:31 UTC 2026


On Monday, 14 September 2026 at 15:07:37 UTC, Andrea Fontana 
wrote:
> Hi everyone,
>
> I just wanted to share a small project I wrote called 
> neverstored.

Small follow-up.

neverstored now builds into a container that holds exactly one 
file (~1.4MB). The binary is linked statically against musl, so 
it runs inside a scratch container: no shell, no package manager, 
no libc to keep patched.

Nothing else is inside the container, because the pages, scripts 
and stylesheets are already inside the executable through 
stringImportPaths.

It also works as a practical example of serverino needing no 
dependencies whatsoever: there is nothing to install next to the 
binary, which is what makes a scratch container possible at all.

What matters more for this project is that worker processes are 
isolated from the daemon and from one another. Each worker is a 
separate process with its own address space, holding nothing 
beyond the request it is serving at that moment. All the state 
(rooms, tokens, the payload in flight) lives in a broker thread 
inside the daemon, which no worker can reach, so a leak of any 
kind in a worker cannot expose what the daemon is keeping.

This is the buildType I used:

```
buildType "container" {
       buildOptions "releaseMode" "optimize"
       dflags "-Oz" "-static" "-linker=lld" "-L=--gc-sections" 
"-L=--icf=all" platform="ldc"
}
```


The Dockerfile in full:

```
FROM alpine:3.22 AS build

RUN apk add --no-cache gcc musl-dev ldc dub lld 
llvm-libunwind-static binutils

WORKDIR /src
COPY . .
RUN cp -n static/operator.ini.example static/operator.ini || true
RUN dub build --build=container --compiler=ldc2
RUN mkdir -p /empty

FROM scratch

COPY --from=build /src/neverstored /neverstored
COPY --from=build --chown=65534:65534 /empty /run

ENV NEVERSTORED_BIND=0.0.0.0 \
     NEVERSTORED_PORT=8080 \
     NEVERSTORED_SOCKET=/run/neverstored.sock

USER 65534:65534
EXPOSE 8080
ENTRYPOINT ["/neverstored"]
```

There is a compose file in the repo too, with Caddy in front (the 
page needs a secure context, so outside localhost it needs TLS to 
work at all):

```
git clone https://github.com/trikko/neverstored && cd neverstored
docker compose up -d --build
```

https://github.com/trikko/neverstored
https://neverstored.com

Andrea


More information about the Digitalmars-d-announce mailing list