Worker code in V8 isolates
Run JavaScript, CommonJS and WebAssembly with tested web APIs and Worker-safe Node compatibility modules.
Peren is an open-source, self-hosted runtime for stateful Workers and Durable Objects. Start on a VPS, then scale across bare-metal servers or Kubernetes with durable SQLite state, fenced recovery and explicit tenant boundaries.
curl -fsSL https://peren.dev/install | sh# node joined the fleet
{
"node": "node-7c2e",
"peers": 2,
"mtls": "bootstrapped",
"storage_test": "passed",
"tail": "/__tail/my-app"
}
# peren deploy fleet.toml to go liveRun JavaScript, CommonJS and WebAssembly with tested web APIs and Worker-safe Node compatibility modules.
Give each stateful object SQLite-backed state, alarms, an ownership epoch and a replicated recovery record.
Scope secrets, bindings, storage and signed credentials to the tenant and service that own them.
One class instance. One SQLite database. One current owner. Ownership is decided through a conditional write and protected by an epoch, so stale owners cannot commit at an earlier epoch.
When a node stops renewing its lease, a live peer can claim its cells at a new ownership epoch. State is recovered from replicated records, while writes from the stale epoch are refused. Try it.
Illustrates the chaos-harness scenario: SIGKILL a live owner, then watch recovery within the lease TTL.
The release gate checks recovery, isolation and storage behaviour.
peren serveStart a node, join a fleetperen devHot reload, .dev.varsperen deployVerified, then committedperen rollbackSame gate, other wayperen migrateImport wrangler configperen tailLive logs over WebSocketperen test-serverTest node for your CIperen diagnoseLeases, peers, storageEach bundle boots in an isolated runtime and must export a callable handler before it can go live. Peren distributes the committed generation across the mutually authenticated fleet, with polling as a backstop and controls for gradual rollout.
Configurable grace window before resident cells move to new code.
Ownership, replication and coordination use conditional object-store writes. Peren checks the storage behaviour it depends on before a node begins serving traffic.
$ peren diagnose config.toml --storage-test
conditional writes ok
ranged reads okEvery runtime global, module and binding has a documented contract. If Peren cannot represent behaviour safely, it reports the limit instead of producing a deployment that only appears complete.
SQLite-backed state, transactions, alarms, ownership fencing and recovery.
Strongly consistent reads, bulk gets and enforced limits.
SQL with FTS5, sessions, a read replica and Time Travel.
Conditional requests, ranges, multipart, presigned URLs, durable events.
Push and pull consumers, retries, concurrency, dead-letter queues.
Durable steps, sleeps that survive restarts, events, full lifecycle.
Docker-backed exec, files, processes and egress fencing.
Exactly once across the fleet with jittered retries.
RPC, named entrypoints, capability chaining, AbortSignal.
Dispatch namespaces with per-customer isolation.
Run request-time code, deny-by-default on every axis.
Resize, crop, adjust, composite, convert to AVIF and WebP.
Vector search with metadata filters.
Pooled, cached connections to your Postgres.
The default cache and named caches.
Tested web APIs, streams and supported Worker-safe Node compatibility modules.
Peren makes runtime, tenant, credential, network and node boundaries explicit, then documents what is supported and what is refused.
Time-limited credentials carry explicit scopes and are checked before privileged operations run.
Worker code gets web APIs and configured bindings, not direct access to host internals.
Outbound bindings name the hosts they can reach, and credentialed requests stay within their configured origin.
Nodes use configured identity material for peer trust, ownership and recovery checks.
For the full contract, see the security, networking, credentials and unsupported-behaviour sections in the docs.
Install the CLI, generate a fleet configuration and run your first Worker.
Read the docs →Start locally with a generated fleet configuration. A production fleet adds storage that passes Peren’s conformance check, peer identity and the infrastructure required by the bindings you enable.
peren migrate preserves source settings that have a supported Peren equivalent and reports unsupported fields or bindings that need your input.
Its lease expires, a live peer claims the cell at a new ownership epoch, and its state is recovered from the replicated snapshot and write-ahead log.
They are verified in an isolate first, then pushed to every live node over the mesh. No restarts, with a slow poll as a backstop.
Peren publishes a compatibility matrix for runtime globals, events, modules and bindings. Unsupported behaviour is reported explicitly instead of being silently approximated.
Yes. Peren includes a Helm chart for running a fleet on Kubernetes, alongside support for a single VPS or bare-metal servers.
Yes. Peren is available under the Apache 2.0 license and runs on infrastructure you control.