Orion is a Rust workspace for a distributed node runtime with a facade crate, node binary, client SDK, transport adapters, and operator CLI.
The repository is split into focused crates so runtime, transport, client, and operational surfaces can evolve independently.
crates/orion: consumer-facing facade and public API re-exportscrates/node: node binary and runtime orchestrationcrates/client: Rust SDK for local and daemon clientscrates/orionctl: operator CLIcrates/runtime,crates/cluster,crates/control-plane,crates/data-plane: core runtime and protocol cratescrates/transport-*: HTTP, TCP, QUIC, and IPC transport adapterscrates/link:no_stdframing for the MCU link protocol (CRC frames, COBS streams, CAN / CAN FD segmentation)crates/auth,crates/service,crates/macros,crates/core: shared support crates
Additional repository notes live under docs/README.md.
Build the workspace:
cargo build --workspaceRun the node:
cargo run -p orion-nodeRun the CLI:
cargo run -p orionctl -- --helpRun the default validation surface:
cargo fmt --check
./scripts/check-file-sizes.sh
cargo clippy --workspace --all-targets --all-features -- -D warnings
cargo test --workspace --all-featuresCommon workspace commands:
./scripts/repo-clean.sh
cargo fmt --check
./scripts/check-file-sizes.sh
cargo clippy --workspace --all-targets --all-features -- -D warnings
cargo test --workspace --all-features
cargo doc --workspace --no-depsHeavier Docker, perf, and soak suites are intentionally separate and are documented in docs/testing.md.
- docs/README.md: repository documentation index
- docs/architecture-crate-map.md: how the workspace crates fit together
- docs/development.md: repo layout, validation commands, and CI expectations
- docs/testing.md: test surfaces, Docker suites, perf, and soak notes
- CHANGELOG.md: release history and notable workspace changes
- testing/README.md: local and CI validation entry points
- scripts/repo-clean.sh: pre-commit cleanup and verification entry point
- docs/node-env.md: runtime environment contract
- packaging/README.md: run
orion-nodeas a systemd service on Linux images (unit, env file, Gaia layer) - docs/release-validation.md: release validation checklist
- docs/observability.md: health, readiness, and observability notes
- docs/logging.md: runtime logging behavior
- docs/public-api.md: public constructors and compatibility shims
The node is configured primarily through environment variables. The typed entrypoints live in orion-node and use try_* constructors instead of panic-based startup helpers.
Important env vars include:
ORION_NODE_IDORION_NODE_HTTP_ADDRORION_NODE_IPC_SOCKETORION_NODE_PEERS(http://,https://, ororion+tcp://peers)ORION_NODE_PEER_ADDR(orion+tcppeer listener)ORION_NODE_PEER_AUTHORION_NODE_PEER_SYNC_MODEORION_NODE_STATE_DIRORION_NODE_HTTP_MTLSORION_NODE_LOCAL_AUTHORION_NODE_HTTP_PROBE_ADDRORION_NODE_AUDIT_LOG
For the full runtime contract, defaults, and failure behavior, see docs/node-env.md.
For release validation and ignored-suite guidance, see docs/release-validation.md.
For audit-log behavior and operator guidance, see docs/audit-logging.md.
For health/readiness/observability coverage, see docs/observability.md.
For runtime logging behavior and operator guidance, see docs/logging.md.
For preferred public constructors versus compatibility shims, see docs/public-api.md.
For the current locking, blocking, and peer-sync concurrency audit, see docs/performance-concurrency.md.
For the crate layout and layering, see docs/architecture-crate-map.md.
For peer sync transports, merge rules, tombstones, and the protocol v3 upgrade, see docs/peer-sync.md.
The facade crate orion is feature-gated by subsystem.
- Default features cover
core,auth,control-plane,data-plane, andruntime. clientenables the Rust SDK and impliesruntime.service,macros, andclusterare explicit opt-ins.- Transport layers stay opt-in through
transport-http,transport-ipc,transport-tcp, andtransport-quic. orion-clientdefaults to local IPC support through itsipcfeature.orion-nodeenablestransport-http,peer-tcp,transport-tcp, andtransport-quicby default. The local IPC control plane is always built.cargo build -p orion-node --no-default-featuresproduces an IPC-only node without the HTTP stack (no axum, hyper, reqwest, or rustls). In that build the HTTP control and probe listeners and HTTP TLS are unavailable, and configuring them fails at startup with an error. You can add back any of the transport features independently.orion-node'speer-tcpfeature syncs desired state withorion+tcp://peers over plain TCP with ed25519-signed requests and responses (ORION_NODE_PEER_ADDRlistener). It needs only tokio, so--no-default-features --features peer-tcpgives a small IPC-only node that can still cluster. Concurrent writes from different nodes are merged per object, last writer wins by hybrid logical clock. Seedocs/peer-sync.md.orion-node's opt-indiscovery-mdnsfeature finds the peers of a cluster with mDNS/DNS-SD (ORION_NODE_DISCOVERY=mdns,ORION_NODE_CLUSTER). Discovered peers are never trusted on their own: an operator enrolls them after comparing key fingerprints (orionctl get discovered-peers,orionctl peers enroll <node-id>), or nodes sharingORION_NODE_ENROLLMENT_KEYenroll each other with a challenge-response handshake. Works in the appliance build (--no-default-features --features peer-tcp,discovery-mdns). Seedocs/discovery.md.orion-client'sremotefeature is an embeddable remote operator client for desktop and fleet tools: an ed25519 operator identity, enrollment (administrator approval withorionctl operators enroll, or the shared enrollment key), and signedorion+tcprequests to list node records with host facts, read status (forwarded to the owning node), run actions (forwarded to the owning node) and read observability, without runningorion-nodeand without an HTTP stack. Nodes treat operators as their own principal kind with per-operator authorization; operators never become cluster members. Seedocs/remote-operator.md.orion-node's opt-inlink-gatewayfeature (Linux) serves microcontroller links (serial ports and SocketCAN, configured withORION_NODE_LINKS) and bridges eachorion-linkdevice into the node as an ordinary provider. It also works in the IPC-only build (--no-default-features --features link-gateway). Seedocs/link-protocol.md.orion-transport-httpexposes its protocol types (payloads, routes, codec, errors, and handler traits) without the network stack.clientaddsHttpClient(reqwest over rustls, no axum/hyper server),serveraddsHttpServer(axum, hyper, tokio-rustls), and the defaulttransportfeature enables both.orionctlfeatureshttp(--httpremote targets, HTTP client only),yamlandtoml(output formats and workload spec files) are all on by default.cargo build -p orionctl --no-default-featuresgives an IPC-only CLI with JSON output (1.80 MiB stripped, against 4.38 MiB for the default build); requesting a disabled transport or format fails with an error that names the feature. Seecrates/orionctl/README.md.
For production consumers that want a narrow dependency surface, prefer direct crate dependencies or disable default features on the facade and opt in explicitly.
orion-node exposes:
- health and readiness endpoints
- observability snapshots
- local IPC control and stream sockets
- peer sync over HTTP(S) or
orion+tcp, with per-object conflict resolution (docs/peer-sync.md) - optional HTTP/TCP/QUIC transport security
- optional audit logging
Current high-value runtime endpoints and surfaces:
- HTTP control surface on
ORION_NODE_HTTP_ADDR - optional HTTP probe surface on
ORION_NODE_HTTP_PROBE_ADDR - local IPC unary socket on
ORION_NODE_IPC_SOCKET - local IPC stream socket on
ORION_NODE_IPC_STREAM_SOCKET
Observability and runtime debugging rely on:
- health snapshots
- readiness snapshots
- observability snapshots with recent events and transport counters
- structured tracing from the node runtime
- optional audit log records for trust and transport-security lifecycle events
Most of the runtime and transport surface is written in an allocation-conscious style, but not every API is a zero-cost abstraction. In particular, orion-service intentionally uses Arc<dyn Trait> middleware for ergonomics at the control-plane boundary.
Licensed under either:
- MIT
- Apache-2.0