Skip to content

Run on Bun: bun install, Bun image, Bun for web + orchestrator - #242

Merged
ralyodio merged 1 commit into
masterfrom
chore/bun-runtime
Oct 1, 2026
Merged

ralyodio merged 1 commit into
masterfrom
chore/bun-runtime

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Part of the fleet Node → Bun migration (recipe from the phonenumbers.bot pilot). meshhook.com now uses Bun as both package manager and runtime.

Changes

  • Lockfile: bun.lock was migrated from pnpm-lock.yaml, not regenerated, so every version stays exact (kit 2.70.2, svelte 5.56.8, vite 5.4.21, pg 8.23.0, undici 6.28.0). pnpm-workspace.yaml becomes workspaces in package.json, and the esbuild build approval becomes trustedDependencies.
  • Image: oven/bun:1.4.0-slim, running as the non-root bun user, with CMD ["bun", "server.mjs"] and a HEALTHCHECK on 127.0.0.1. The supervisor spawns the SvelteKit server and the orchestrator with process.execPath, so both children run on Bun as well. Port 3000, env and the / health path are unchanged, and dev2's compose file needs no change.
  • Scripts and the mh CLI: they call bun instead of node or pnpm. The build is bun --bun vite build.
  • Tests: vitest runs via bun --bun vitest run and the node:test suites run under bun test. Four http-call tests had been pasted inside another test's body. Node ran them as subtests; Bun skipped them without saying so. They are un-nested now, and both runners execute all 258.
  • CI: a new ci workflow does a frozen install, runs the tests, builds, and boots the web server under Bun.

Verified locally (image built from git archive HEAD, dev2-shaped compose, throwaway Postgres loaded with migrations-pg)

  • Processes: docker top shows bun server.mjs, bun apps/web/build/index.js and bun workers/orchestrator.mjs.
  • Pages and routes against live: / and /auth/login return 200 at the same sizes; the HTML differs only in the SvelteKit build id and asset hashes. /workflows, /runs and /secrets return 303, /api/workflows and /api/runs return 401, and an unknown hook returns 405 on GET and 404 on POST.
  • End to end: a POST to /api/hooks/<slug> returned 202, and the run went run_created, then the transform step, then terminate, then run_completed (status succeeded) through the real queue and orchestrator.
  • Stack details: undici's request (used by http-exec.mjs) and the import.meta.url === file://argv[1] entry guards work under Bun. A read-only select 1 from Bun to dev2's Postgres over sslmode=require succeeded.
  • Runtime behaviour: about 50 MiB for all three processes, Docker health reaches healthy, and SIGTERM drains both children cleanly in 0.6 s.

🤖 Generated with Claude Code

Moves meshhook.com off Node + pnpm onto Bun, following the fleet recipe
(phonenumbers.bot pilot): Bun is now the package manager and the runtime.

- Package manager: bun.lock is migrated from pnpm-lock.yaml (every version kept
  exactly: kit 2.70.2, svelte 5.56.8, vite 5.4.21, pg 8.23.0, undici 6.28.0).
  pnpm-workspace.yaml becomes `workspaces` in package.json; its esbuild build
  approval becomes trustedDependencies.
- Runtime: the Dockerfile is oven/bun:1.4.0-slim, non-root, `bun server.mjs`.
  The supervisor spawns the SvelteKit server and the orchestrator with
  process.execPath, so both children run on Bun. Port 3000, env and the / health
  path are unchanged; dev2's compose file needs no change.
- Scripts and the mh CLI call bun instead of node/pnpm; the SvelteKit build is
  `bun --bun vite build`.
- Tests: vitest runs via `bun --bun vitest run`; the node:test suites run under
  `bun test`. Four http-call tests were nested inside another test's body (a
  paste error). Node ran them as subtests, Bun skipped them silently, so they
  are un-nested; both runners now execute all 258.
- CI: new ci workflow (frozen install, tests, build, boot the web server).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

11 finding(s)

HIGH/CRITICAL: 5 | MEDIUM: 3 | LOW: 3

Severity Rule Location
HIGH secret-database-url apps/web/.env.example:9
HIGH secret-database-url docs/Environment-Setup.md:46
HIGH secret-database-url docs/Environment-Setup.md:132
HIGH secret-slack-webhook docs/WEBHOOK_CONFIGURATION.md:145
HIGH secret-generic-credential src/nodes/README.md:271
MEDIUM sql-template-interpolation apps/web/src/routes/api/secrets/[id]/+server.js:80
MEDIUM sql-template-interpolation apps/web/src/routes/api/workflows/[id]/+server.js:141
MEDIUM sql-template-interpolation src/queue/test-helpers.js:52
LOW sql-template-interpolation docs/Turso-Migration.md:70
LOW secret-generic-credential src/nodes/webhook.test.js:287
LOW sql-template-interpolation workers/orchestrator.test.js:52

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit e77102a into master Oct 1, 2026
5 checks passed
@ralyodio
ralyodio deleted the chore/bun-runtime branch October 1, 2026 14:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant