-
Notifications
You must be signed in to change notification settings - Fork 22
Expand file tree
/
Copy pathCargo.toml
More file actions
168 lines (148 loc) · 6.5 KB
/
Copy pathCargo.toml
File metadata and controls
168 lines (148 loc) · 6.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
[workspace]
resolver = "2"
members = [
"crates/server",
"crates/gateway",
"crates/mcp-gateway",
"crates/auth",
"crates/common",
"crates/test-support",
]
[workspace.package]
version = "2.2.0"
edition = "2024"
# Pin the MSRV to the first stable rustc that ships edition 2024 (1.85,
# released 2025-02-20). Without this, contributors on older toolchains
# get cryptic let-chain / edition errors instead of "you need rustc
# >= 1.85". The actual project tracks the toolchain in rust-toolchain.toml
# (currently `stable`); the floor lets CI / `cargo install` callers
# fail fast on incompatible versions.
rust-version = "1.85"
license = "BUSL-1.1"
# Release profile tuned for the production server binary. `lto = true`
# trims ~15-20% off the stripped binary and gives a meaningful boost
# on the gateway hot path at the cost of a longer link step (~30s on
# Apple silicon, several minutes on x86 CI). `codegen-units = 1`
# unlocks the LTO benefit; the parallelism we'd lose only matters for
# clean builds, which CI does once. `strip` removes debug symbols
# from the shipped binary — operators load symbols from a separate
# debuginfo package when they need them.
[profile.release]
lto = true
codegen-units = 1
strip = "symbols"
# Dev and test builds keep only line tables: backtraces still name the
# file and line, but the full variable-level debug info is gone. Each
# integration test is its own binary linking the whole workspace, so
# full debug info filled ~150 GB of target/ in a day.
[profile.dev]
debug = "line-tables-only"
# Every login in the integration suite hashes a password with Argon2 and
# grinds a proof-of-work over SHA-256. Unoptimised, those two dominate:
# the login-heavy tests ran for one to two minutes each in CI. Optimising
# just the hash crates keeps the rest of the build fast to compile.
[profile.dev.package.argon2]
opt-level = 3
[profile.dev.package.blake2]
opt-level = 3
[profile.dev.package.sha2]
opt-level = 3
[workspace.dependencies]
# ── thinkwatch-core (MIT) ────────────────────────────────────────────
# The layer shared with the desktop gateway: format conversion and usage
# parsing (tw-dialect), redaction and tool-call inspection (tw-guard), the
# circuit-breaker state machine (tw-breaker), and what only Amazon Bedrock
# needs on the wire: SigV4 signing, eventstream unframing, its addresses and
# its model catalog (tw-bedrock). Declared once, here, so a core release is a
# one-line bump. Pinned to a tag: tracking a branch turns every core merge
# into a coin flip on this build.
#
# Code flows one way: from core into this tree, never back. Anything that
# lands in core is MIT from that moment on.
#
# One copy, not two. Code that lives in core is used from core directly,
# never re-exported through a local shim. And the reverse: something only
# this side uses (the at-rest crypto, IMDSv2 credentials, the gateway error)
# lives here, not in core.
tw-bedrock = { git = "https://github.com/ThinkWatchProject/ThinkWatch-Core.git", tag = "v0.55.0" }
tw-breaker = { git = "https://github.com/ThinkWatchProject/ThinkWatch-Core.git", tag = "v0.55.0" }
tw-dialect = { git = "https://github.com/ThinkWatchProject/ThinkWatch-Core.git", tag = "v0.55.0" }
tw-guard = { git = "https://github.com/ThinkWatchProject/ThinkWatch-Core.git", tag = "v0.55.0" }
# Web framework
axum = { version = "0.8", features = ["macros", "ws"] }
tower = "0.5"
tower-http = { version = "0.6", features = [
"cors", "trace", "compression-gzip", "request-id",
"limit", "timeout", "catch-panic", "sensitive-headers", "set-header",
] }
tokio = { version = "1", features = ["rt-multi-thread", "macros", "net", "time", "sync", "io-util", "signal"] }
# Database
sqlx = { version = "0.8", features = ["runtime-tokio", "postgres", "uuid", "chrono", "json", "migrate", "rust_decimal"] }
rust_decimal = { version = "1", features = ["serde", "serde-with-str"] }
clickhouse = { version = "0.13", features = ["time", "chrono"] }
# Redis
fred = { version = "10", features = ["subscriber-client", "i-scripts"] }
# Auth
# Crypto-critical crates are pinned with `=` so a silent minor-release
# change (e.g. a JWT lib's validation-default flip) can't sneak in via
# `cargo update`. Bumps are deliberate and reviewed.
jsonwebtoken = { version = "=10.3.0", features = ["rust_crypto"] }
argon2 = "=0.5.3"
openidconnect = { version = "4", features = ["reqwest"] }
totp-rs = { version = "5", features = ["gen_secret", "otpauth"] }
data-encoding = "2"
# Serialization
serde = { version = "1", features = ["derive"] }
serde_json = "1"
# HTTP client (upstream proxy)
reqwest = { version = "0.13", features = ["stream", "json", "rustls"] }
hyper = { version = "1", features = ["full"] }
hyper-util = "0.1"
http-body-util = "0.1"
bytes = "1"
# Async
futures = "0.3"
tokio-stream = "0.1"
async-stream = "0.3"
sha2 = "=0.11.0"
sha1 = "=0.11.0"
hmac = "=0.13.0"
p256 = { version = "=0.13.2", features = ["ecdsa", "jwk"] }
ecdsa = { version = "=0.16.9", features = ["verifying"] }
rand = "0.10"
hex = "0.4"
# Crypto primitives are pinned exactly so a `cargo update` can never swap
# a verification default underneath the at-rest envelope.
aes-gcm = "=0.10.3"
subtle = "=2.6.1"
url = "2"
# Observability
tracing = "0.1"
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
metrics = "0.24"
metrics-exporter-prometheus = { version = "0.16", default-features = false }
# Config
dotenvy = "0.15"
# API documentation
utoipa = { version = "5", features = ["axum_extras", "uuid", "chrono"] }
utoipa-swagger-ui = { version = "9", features = ["axum"] }
# AWS SigV4 for the S3-compatible body store. Bedrock's signing,
# eventstream unframing and model catalog come from tw-bedrock.
# NOTE: "hardcoded-credentials" is the AWS SDK feature name for constructing
# Credentials from explicit access_key/secret_key values (as opposed to the
# default credential chain). This does NOT embed credentials in the binary —
# they are loaded at runtime from encrypted configuration.
aws-sigv4 = "1"
aws-credential-types = { version = "1", features = ["hardcoded-credentials"] }
# Utils
arc-swap = "1"
xxhash-rust = { version = "0.8", features = ["xxh3"] }
uuid = { version = "1", features = ["v4", "v5", "serde"] }
chrono = { version = "0.4", features = ["serde"] }
thiserror = "2"
anyhow = "1"
# Workspace crates
think-watch-common = { path = "crates/common" }
think-watch-auth = { path = "crates/auth" }
think-watch-gateway = { path = "crates/gateway" }
think-watch-mcp-gateway = { path = "crates/mcp-gateway" }