Browse documentation
On this page

Peren documentation

Unsupported and refused behavior

Refused and bounded Peren behaviors to check before you implement against Cloudflare assumptions.

Read this page before you port Cloudflare Workers habits into Peren. Each item is refused or limited in this build. The linked page shows what to use instead.

Data and restore

Behavior What happens Where it is explained
External D1 backend Config may parse backend = { kind = "external", ... }. Query and operator D1 commands refuse it at query time. Use native_sqlite or turso. D1
peren d1 restore The command exits with an operational error: native D1 has no time-travel snapshots or bookmarks. CLI reference

Observability exporters

Behavior What happens Where it is explained
[otlp], [logpush] Fleet config validation fails and the process does not start. Observability

/healthz, /readyz, /metrics, peren logs, and peren tail remain available. See Ports and endpoints and Logs and tail.

Containers

Behavior What happens Where it is explained
exec, start, stop, destroy, readFile, writeFile Each call throws. fetch to the configured local port is the supported path. Containers

KV

Behavior What happens Where it is explained
compareAndSet on Redis or bucket KV Throws Error("KV compareAndSet is only supported by native KV"). Native KV supports the method. KV

Limits and rollout

Behavior What happens Where it is explained
limits.max_cpu_time_ms Stored in config. Not applied on the live HTTP path. Body, heap, wall time, subrequests, and max_isolates are enforced. Limits
Deploy --percent Recorded on the generation. Does not split traffic across generations. The running process keeps the bundles loaded at start. Deploy and roll back

Fleet membership and tenancy

Behavior What happens Where it is explained
peren node drain Writes draining in the local fleet registry. Does not move cells. Does not change admission on a running process. Live refusal of new work is POST /control/v1/node/drain on the peer listener. Drain a node
peren tenant revoke Writes an active revocation in the tenant registry. A running isolate does not read that file to deny a request. Security model

Credentials and network

Behavior What happens Where it is explained
SigV4 instance_role, workload_identity, eks_pod_identity Read AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and optional AWS_SESSION_TOKEN from the process environment. Do not call IMDS, a pod-identity agent, or a workload-identity endpoint. AWS SigV4
Inbound peer listeners Plain TCP. [mtls] paths are required in config and do not terminate inbound TLS. Ports and endpoints, Networking

Missing commands and APIs

Behavior What happens Where it is explained
peren cell inspect The command does not exist. Confirm recovery with an HTTP response after restart. Run peren conformance storage before production. Recovery after node loss
setAlarm on the JS storage object Peren.storage has no setAlarm. Durable Objects in Peren