Builtins, recipes and binaries

On Fri, 25 Sep 2026, by @lucasdicioccio, 74 words, 0 code snippets, 1 links, 0images.

Generated from README.md — the repository is the canonical source, and may be ahead of this page.

Builtins, recipes and binaries

Builtin nodes

salmon-ops/src/Salmon/Builtin/Nodes/ — mostly atomic, small-diameter ops, one module per concern:

ModuleCovers
Bashad-hoc shell script ops
Binarythe shared subprocess-running plumbing (untrackedExec, exit-code-checked exec) every other builtin is built on
Cabalbuilding Haskell projects with cabal
CapabilitiesLinux file capabilities (setcap/getcap), so a binary can do one privileged thing unprivileged
CertificatesTLS certificate generation/signing
Continuationchaining/sequencing op continuations
CronTaskcron job management
Daemona process salmon owns and keeps running — the one builtin with a managed action, for where there is no systemd (see resources/serve-supervision.md)
Demoa toy graph (collatz) for trying the drivers on
Debian.Debootstrap, Debian.Package, Debian.OSDebian package installs and base-system setup
Filesystemdirectories, file contents, copy/move/replace-directory (the canonical small example — see resources/howto-ops.md)
Gcp.*Google Cloud: projects and billing (ResourceManager, Billing, ServiceUsage), Iam, Storage, ArtifactRegistry, CloudRun, Compute, LoadBalancing, SecretManager, SshAccess, Monitoring (notification channels and Cloud Run alert policies) — driven through gcloud; see resources/gcp-toy-validation.md
Gitgit repository operations
Keyskey material management
LinuxBridgeLinux bridge and tap devices, a real L2 network for qemu VMs to sit on
Netfilternft firewall rules (with check-based idempotency, since nft add rule itself isn't idempotent)
Nginxnginx site/config management
Npmnpm package operations
PgBouncerPgBouncer connection-pooler configuration
Podmancontainer image/volume/network/env lifecycle
Postgrescluster creation, users/groups/grants, WAL streaming replication, pg_hba.conf management
Qemua qemu VM as a systemd unit, booted from a debootstrap chroot over 9p (specs/qemu-test-vms.md)
RoutesIP routing table entries
Rsyncfile/secret transport over rsync
Secretssecret material placement
Selfuploading and re-invoking this binary on a remote machine
SpagoPureScript/Spago builds
SshSSH remote-machine plumbing
Sysctlkernel parameter tuning
Systemdsystemd unit management
Tararchive creation/extraction
Upxbinary compression
UserOS user/group accounts
WebHTTP-facing ops
WireGuardWireGuard VPN interfaces, keys, and routing

Recipes

salmon-ops-recipes/src/SreBox/ — opinionated compositions of the builtins above, where this project’s own conventions get enforced:

ModuleCovers
CabalBuildingbuilding and publishing cabal-based binaries
DNSRegistrationDNS record registration
Environmentenvironment/machine bootstrapping
Initializeinitial setup sequencing
JWTSigningJWT signing key management
MicroDNSa minimal DNS server setup
PostgresInitdatabase/user/group/grant setup for a Postgres cluster (locally or driven onto a remote machine via Self)
PostgresMigrationsshipping and running migrations, local or remote-connstring
PostgresBackupperiodic pg_dump backups: the script, the schedule, and a node that notices when no recent dump exists
PostgresPairtwo machines, one Postgres cluster, and a declared primary: switchover, operator-decided failover, pg_rewind rejoins, and pgbouncer routing that follows — see [resources/postgres-pair.md](/docs-postgres-pair.html)
PostgresTemplatetemplate databases: build once, lock, hand out clones (salmon-migrator config template/clone)
PostgresTlsPostgres authenticating clients by certificate, and the material that makes it possible
PostgrestPostgREST service configuration
WireGuardVpna full static-server/dynamic-client WireGuard VPN, transport-agnostic on key exchange
Gcp.CloudRunDeploybuild a podman image, push it to Artifact Registry, deploy it to Cloud Run
Gcp.CloudRunAlertsthe standard Cloud Monitoring alerts for a Cloud Run service (5xx ratio, p99 latency, memory, instances at max) to one email
Gcp.PostgrestCloudRunPostgREST on Cloud Run talking to a Postgres elsewhere over a client certificate
Gcp.PreviewEnvironmentseveral Cloud Run deploys composed into one named node: a preview environment
Gcp.VmProvisionturn up a GCE instance, then run a salmon binary on it over SSH via Self

salmon-ops-recipes-experimental (not part of the default package set — see Build) holds SreBox.CertSigning (certificate signing workflows), SreBox.KitchenSinkBlog, SreBox.KitchenSinkMultiSites, SreBox.GeneratedSite, and the Salmon.Builtin.Nodes.Acme builtin (ACME/Let’s Encrypt certificate issuance).

Binaries

salmon-apps/ — each one is a small Main over a recipe:

BinaryDoes
salmon-migratorPostgres migrations, template databases and clones (config template/clone)
salmon-pgpaira Postgres primary/standby pair whose primary is a declaration — see [resources/postgres-pair.md](/docs-postgres-pair.html)
salmon-pg-backuptake a Postgres dump now, or install the cron job that keeps taking one, here or on another machine
salmon-init-locallythe local-machine salmon setup (sudoers, the salmon user and group)
salmon-gcp-toya tiered, throwaway exercise of the GCP builtins against a real project — see [resources/gcp-toy-validation.md](/docs-gcp-toy-validation.html)
salmon-toy-qemu-pg-hathe salmon-pgpair demo on three qemu guests, with a client that keeps writing while the primary moves
salmon-fleetthe controller's side of pull mode: status DIR folds the hosts' status documents into one line per host; keygen/sign make signed documents
salmon-tuia terminal client for run serve --http (or --http-tcp)