Run Workers and Durable Objects on infrastructure you control

Peren is an open-source, self-hosted runtime for stateful Workers and Durable Objects. Start on a VPS, then scale across bare-metal servers or Kubernetes with durable SQLite state, fenced recovery and explicit tenant boundaries.

curl -fsSL https://peren.dev/install | sh
Apache 2.0 · free and open source
$peren serve fleet.toml
# node joined the fleet
{
  "node": "node-7c2e",
  "peers": 2,
  "mtls": "bootstrapped",
  "storage_test": "passed",
  "tail": "/__tail/my-app"
}

# peren deploy fleet.toml to go live

Worker code in V8 isolates

Run JavaScript, CommonJS and WebAssembly with tested web APIs and Worker-safe Node compatibility modules.

Durable SQLite state per cell

Give each stateful object SQLite-backed state, alarms, an ownership epoch and a replicated recovery record.

Many tenants, one fleet

Scope secrets, bindings, storage and signed credentials to the tenant and service that own them.

One class instance. One SQLite database. One current owner. Ownership is decided through a conditional write and protected by an epoch, so stale owners cannot commit at an earlier epoch.

Lose a node, keep every cell

When a node stops renewing its lease, a live peer can claim its cells at a new ownership epoch. State is recovered from replicated records, while writes from the stale epoch are refused. Try it.

node-alease live
node-blease live
node-clease live
46 cells across 3 nodes · all leases live
waiting for a fault
cellre-homed at next epochreleased by expired lease
$peren status fleet.toml
t+0ready3 nodes · 46 cells · bucket reachable
waitpress SIGKILL node-b to inject the fault
pending–duplicate writes
pending–corrupted databases
pending–cells recovered within the lease TTL

Illustrates the chaos-harness scenario: SIGKILL a live owner, then watch recovery within the lease TTL.

Proof is part of the product

  • ✓Model explorationOwnership, recovery, alarms, commits and release transitions checked against invariants.
  • ✓Runtime conformanceSupported APIs are exercised inside the isolate and checked against the compatibility matrix.
  • ✓Chaos and tenancy testsOwner loss, recovery, acknowledged writes and tenant boundaries are exercised directly.

The release gate checks recovery, isolation and storage behaviour.

One operator surface

  • $peren serveStart a node, join a fleet
  • $peren devHot reload, .dev.vars
  • $peren deployVerified, then committed
  • $peren rollbackSame gate, other way
  • $peren migrateImport wrangler config
  • $peren tailLive logs over WebSocket
  • $peren test-serverTest node for your CI
  • $peren diagnoseLeases, peers, storage

Ship code without restarting the fleet

Each bundle boots in an isolated runtime and must export a callable handler before it can go live. Peren distributes the committed generation across the mutually authenticated fleet, with polling as a backstop and controls for gradual rollout.

  1. peren deploy config.toml
  2. verify in isolate
  3. commit
  4. push to every node

Configurable grace window before resident cells move to new code.

Coordinate through S3-compatible storage

Ownership, replication and coordination use conditional object-store writes. Peren checks the storage behaviour it depends on before a node begins serving traffic.

Amazon S3R2MinIOLocal file
$ peren diagnose config.toml --storage-test
conditional writes   ok
ranged reads         ok

Broad compatibility. Explicit limits.

Every runtime global, module and binding has a documented contract. If Peren cannot represent behaviour safely, it reports the limit instead of producing a deployment that only appears complete.

Durable Objects

SQLite-backed state, transactions, alarms, ownership fencing and recovery.

KV

Strongly consistent reads, bulk gets and enforced limits.

D1

SQL with FTS5, sessions, a read replica and Time Travel.

R2

Conditional requests, ranges, multipart, presigned URLs, durable events.

Queues

Push and pull consumers, retries, concurrency, dead-letter queues.

Workflows

Durable steps, sleeps that survive restarts, events, full lifecycle.

Containers

Docker-backed exec, files, processes and egress fencing.

Cron Triggers

Exactly once across the fleet with jittered retries.

Service Bindings

RPC, named entrypoints, capability chaining, AbortSignal.

Workers for Platforms

Dispatch namespaces with per-customer isolation.

Worker Loader

Run request-time code, deny-by-default on every axis.

Images

Resize, crop, adjust, composite, convert to AVIF and WebP.

Vectorize

Vector search with metadata filters.

Hyperdrive

Pooled, cached connections to your Postgres.

Cache API

The default cache and named caches.

Web + Node APIs

Tested web APIs, streams and supported Worker-safe Node compatibility modules.

Built to hold other people’s code.

Peren makes runtime, tenant, credential, network and node boundaries explicit, then documents what is supported and what is refused.

Scoped credentials

Time-limited credentials carry explicit scopes and are checked before privileged operations run.

Isolated runtime

Worker code gets web APIs and configured bindings, not direct access to host internals.

Controlled egress

Outbound bindings name the hosts they can reach, and credentialed requests stay within their configured origin.

Node identity

Nodes use configured identity material for peer trust, ownership and recovery checks.

For the full contract, see the security, networking, credentials and unsupported-behaviour sections in the docs.

Run Peren locally (get started)

Install the CLI, generate a fleet configuration and run your first Worker.

Read the docs →

FAQ

What do I need to run Peren?

Start locally with a generated fleet configuration. A production fleet adds storage that passes Peren’s conformance check, peer identity and the infrastructure required by the bindings you enable.

Can I bring my existing Workers project?

peren migrate preserves source settings that have a supported Peren equivalent and reports unsupported fields or bindings that need your input.

What happens to a cell when its node dies?

Its lease expires, a live peer claims the cell at a new ownership epoch, and its state is recovered from the replicated snapshot and write-ahead log.

How do new deploys reach a running fleet?

They are verified in an isolate first, then pushed to every live node over the mesh. No restarts, with a slow poll as a backstop.

Which APIs and bindings are supported?

Peren publishes a compatibility matrix for runtime globals, events, modules and bindings. Unsupported behaviour is reported explicitly instead of being silently approximated.

Can I run Peren on Kubernetes?

Yes. Peren includes a Helm chart for running a fleet on Kubernetes, alongside support for a single VPS or bare-metal servers.

Is Peren open source?

Yes. Peren is available under the Apache 2.0 license and runs on infrastructure you control.

More answers in the docs FAQ