neverstored: hand over a secret without leaving traces
Andrea Fontana
nospam at example.org
Tue Sep 22 14:25:31 UTC 2026
On Monday, 14 September 2026 at 15:07:37 UTC, Andrea Fontana
wrote:
> Hi everyone,
>
> I just wanted to share a small project I wrote called
> neverstored.
Small follow-up.
neverstored now builds into a container that holds exactly one
file (~1.4MB). The binary is linked statically against musl, so
it runs inside a scratch container: no shell, no package manager,
no libc to keep patched.
Nothing else is inside the container, because the pages, scripts
and stylesheets are already inside the executable through
stringImportPaths.
It also works as a practical example of serverino needing no
dependencies whatsoever: there is nothing to install next to the
binary, which is what makes a scratch container possible at all.
What matters more for this project is that worker processes are
isolated from the daemon and from one another. Each worker is a
separate process with its own address space, holding nothing
beyond the request it is serving at that moment. All the state
(rooms, tokens, the payload in flight) lives in a broker thread
inside the daemon, which no worker can reach, so a leak of any
kind in a worker cannot expose what the daemon is keeping.
This is the buildType I used:
```
buildType "container" {
buildOptions "releaseMode" "optimize"
dflags "-Oz" "-static" "-linker=lld" "-L=--gc-sections"
"-L=--icf=all" platform="ldc"
}
```
The Dockerfile in full:
```
FROM alpine:3.22 AS build
RUN apk add --no-cache gcc musl-dev ldc dub lld
llvm-libunwind-static binutils
WORKDIR /src
COPY . .
RUN cp -n static/operator.ini.example static/operator.ini || true
RUN dub build --build=container --compiler=ldc2
RUN mkdir -p /empty
FROM scratch
COPY --from=build /src/neverstored /neverstored
COPY --from=build --chown=65534:65534 /empty /run
ENV NEVERSTORED_BIND=0.0.0.0 \
NEVERSTORED_PORT=8080 \
NEVERSTORED_SOCKET=/run/neverstored.sock
USER 65534:65534
EXPOSE 8080
ENTRYPOINT ["/neverstored"]
```
There is a compose file in the repo too, with Caddy in front (the
page needs a secure context, so outside localhost it needs TLS to
work at all):
```
git clone https://github.com/trikko/neverstored && cd neverstored
docker compose up -d --build
```
https://github.com/trikko/neverstored
https://neverstored.com
Andrea
More information about the Digitalmars-d-announce
mailing list