Builtins, recipes and binaries
On Fri, 25 Sep 2026, by @lucasdicioccio, 74 words, 0 code snippets, 1 links, 0images.
Generated from README.md — the repository is the canonical source, and may be ahead of this page.
Builtins, recipes and binaries
Builtin nodes
salmon-ops/src/Salmon/Builtin/Nodes/ — mostly atomic, small-diameter ops,
one module per concern:
| Module | Covers |
|---|---|
Bash | ad-hoc shell script ops |
Binary | the shared subprocess-running plumbing (untrackedExec, exit-code-checked exec) every other builtin is built on |
Cabal | building Haskell projects with cabal |
Capabilities | Linux file capabilities (setcap/getcap), so a binary can do one privileged thing unprivileged |
Certificates | TLS certificate generation/signing |
Continuation | chaining/sequencing op continuations |
CronTask | cron job management |
Daemon | a process salmon owns and keeps running — the one builtin with a managed action, for where there is no systemd (see resources/serve-supervision.md) |
Demo | a toy graph (collatz) for trying the drivers on |
Debian.Debootstrap, Debian.Package, Debian.OS | Debian package installs and base-system setup |
Filesystem | directories, file contents, copy/move/replace-directory (the canonical small example — see resources/howto-ops.md) |
Gcp.* | Google Cloud: projects and billing (ResourceManager, Billing, ServiceUsage), Iam, Storage, ArtifactRegistry, CloudRun, Compute, LoadBalancing, SecretManager, SshAccess, Monitoring (notification channels and Cloud Run alert policies) — driven through gcloud; see resources/gcp-toy-validation.md |
Git | git repository operations |
Keys | key material management |
LinuxBridge | Linux bridge and tap devices, a real L2 network for qemu VMs to sit on |
Netfilter | nft firewall rules (with check-based idempotency, since nft add rule itself isn't idempotent) |
Nginx | nginx site/config management |
Npm | npm package operations |
PgBouncer | PgBouncer connection-pooler configuration |
Podman | container image/volume/network/env lifecycle |
Postgres | cluster creation, users/groups/grants, WAL streaming replication, pg_hba.conf management |
Qemu | a qemu VM as a systemd unit, booted from a debootstrap chroot over 9p (specs/qemu-test-vms.md) |
Routes | IP routing table entries |
Rsync | file/secret transport over rsync |
Secrets | secret material placement |
Self | uploading and re-invoking this binary on a remote machine |
Spago | PureScript/Spago builds |
Ssh | SSH remote-machine plumbing |
Sysctl | kernel parameter tuning |
Systemd | systemd unit management |
Tar | archive creation/extraction |
Upx | binary compression |
User | OS user/group accounts |
Web | HTTP-facing ops |
WireGuard | WireGuard VPN interfaces, keys, and routing |
Recipes
salmon-ops-recipes/src/SreBox/ — opinionated compositions of the builtins
above, where this project’s own conventions get enforced:
| Module | Covers |
|---|---|
CabalBuilding | building and publishing cabal-based binaries |
DNSRegistration | DNS record registration |
Environment | environment/machine bootstrapping |
Initialize | initial setup sequencing |
JWTSigning | JWT signing key management |
MicroDNS | a minimal DNS server setup |
PostgresInit | database/user/group/grant setup for a Postgres cluster (locally or driven onto a remote machine via Self) |
PostgresMigrations | shipping and running migrations, local or remote-connstring |
PostgresBackup | periodic pg_dump backups: the script, the schedule, and a node that notices when no recent dump exists |
PostgresPair | two machines, one Postgres cluster, and a declared primary: switchover, operator-decided failover, pg_rewind rejoins, and pgbouncer routing that follows — see [resources/postgres-pair.md](/docs-postgres-pair.html) |
PostgresTemplate | template databases: build once, lock, hand out clones (salmon-migrator config template/clone) |
PostgresTls | Postgres authenticating clients by certificate, and the material that makes it possible |
Postgrest | PostgREST service configuration |
WireGuardVpn | a full static-server/dynamic-client WireGuard VPN, transport-agnostic on key exchange |
Gcp.CloudRunDeploy | build a podman image, push it to Artifact Registry, deploy it to Cloud Run |
Gcp.CloudRunAlerts | the standard Cloud Monitoring alerts for a Cloud Run service (5xx ratio, p99 latency, memory, instances at max) to one email |
Gcp.PostgrestCloudRun | PostgREST on Cloud Run talking to a Postgres elsewhere over a client certificate |
Gcp.PreviewEnvironment | several Cloud Run deploys composed into one named node: a preview environment |
Gcp.VmProvision | turn up a GCE instance, then run a salmon binary on it over SSH via Self |
salmon-ops-recipes-experimental (not part of the default package set — see
Build) holds SreBox.CertSigning (certificate signing workflows),
SreBox.KitchenSinkBlog, SreBox.KitchenSinkMultiSites,
SreBox.GeneratedSite, and the Salmon.Builtin.Nodes.Acme builtin
(ACME/Let’s Encrypt certificate issuance).
Binaries
salmon-apps/ — each one is a small Main over a recipe:
| Binary | Does |
|---|---|
salmon-migrator | Postgres migrations, template databases and clones (config template/clone) |
salmon-pgpair | a Postgres primary/standby pair whose primary is a declaration — see [resources/postgres-pair.md](/docs-postgres-pair.html) |
salmon-pg-backup | take a Postgres dump now, or install the cron job that keeps taking one, here or on another machine |
salmon-init-locally | the local-machine salmon setup (sudoers, the salmon user and group) |
salmon-gcp-toy | a tiered, throwaway exercise of the GCP builtins against a real project — see [resources/gcp-toy-validation.md](/docs-gcp-toy-validation.html) |
salmon-toy-qemu-pg-ha | the salmon-pgpair demo on three qemu guests, with a client that keeps writing while the primary moves |
salmon-fleet | the controller's side of pull mode: status DIR folds the hosts' status documents into one line per host; keygen/sign make signed documents |
salmon-tui | a terminal client for run serve --http (or --http-tcp) |