Bosn
Bosn is a Rust daemon for safely managing Docker development applications. It keeps ownership, generation, volume, lease, execution-session, and event state in a durable SQLite registry. The daemon is the only component that mutates Docker or that writes that registry.
The distribution includes three intentionally thin front ends:
bosn, a bundled native CLI;import bosn, a PyO3 client binding; andbosn mcp, a stdio MCP server for Hermes and other MCP clients.
The former Python daemon, Docker front doors, manifest parser, and SQLite
registry are deliberately not packaged. Python callers use bosn.Client; they
cannot import or invoke a second lifecycle implementation.
Install
pip install bosn
bosn --version
Platform wheels contain the native bosn CLI and the bosn._native Python
extension. Installing the wheel puts the bosn binary itself into the
environment's scripts directory, so the bosn on PATH is the native CLI,
with no Python wrapper in between.
The extension uses PyO3's abi3-py310 ABI, so Bosn supports CPython 3.10 and
newer with one platform wheel rather than publishing cp311-only artifacts.
One-file setup
Bosn accepts a local file or HTTPS URL for a versioned setup document. The document declares a digest-pinned image or inline Dockerfile, optional inline files, environment, bind mounts, named volumes, tmpfs mounts, and named tasks. Planning is inert; ensure and task submission are daemon-owned jobs.
version = 1
[app]
image = "registry.example/team/app@sha256:REPLACE_WITH_64_LOWERCASE_HEX_DIGEST"
command = "exec sleep 120"
[task.check]
command = "cargo check"
bosn setup plan --state-dir "$HOME/.local/state/bosn" \
--workspace "$PWD" --config https://example.invalid/bosn-setup.toml \
--refresh
bosn setup ensure --state-dir "$HOME/.local/state/bosn" \
--workspace "$PWD" --config https://example.invalid/bosn-setup.toml \
--refresh --deadline-ms 300000 --output-limit 8388608
online_refresh is explicit; offline_cache_only uses only a previously
validated local cache record. URLs with credentials, unsupported schemes,
path traversal, unpinned images, and oversized documents are refused.
Python
from pathlib import Path
import bosn
client = bosn.Client(Path.home() / ".local/state/bosn")
plan = client.plan_setup(
Path.cwd(), "https://example.invalid/bosn-setup.toml", policy="online_refresh"
)
job_id = client.submit_setup_ensure(
Path.cwd(),
"https://example.invalid/bosn-setup.toml",
policy="online_refresh",
deadline_ms=300_000,
output_limit=8 * 1024 * 1024,
)
The binding exposes typed request and observation operations only. It does not accept Docker command arguments, container identifiers, mounts, or arbitrary commands from callers.
MCP / Hermes
Run bosn mcp over stdio. A typical Hermes registration is:
mcp_servers:
bosn:
command: bosn
args: [mcp]
Set BOSN_STATE_DIR if the default state directory is not appropriate. MCP
tools use the same typed daemon operations as the CLI and Python client; long
operations return durable job IDs.
Development
./install
./lint
./test
The Rust migration status, native manifest lifecycle boundary, and registry
details are documented in docs/migration-rust.md,
docs/rust-manifest-runtime.md, and
docs/rust-registry.md. Daemon-owned task secrets
(an opt-in GITHUB_TOKEN for act runs) are in
docs/task-secrets.md; the read-only GitHub API proxy
that keeps the token out of containers is in
docs/github-api-proxy.md.
Metadata
Release files for bosn 0.1.6
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distributions (wheels)
| File | Reset | |||
|---|---|---|---|---|
| bosn-0.1.6-cp310-abi3-win_amd64.whl | CPython 3.10 | abi3 | Windows x86-64 | Details |
| bosn-0.1.6-cp310-abi3-manylinux_2_39_x86_64.whl | CPython 3.10 | abi3 | Linux glibc 2.39+ x86-64 | Details |
| bosn-0.1.6-cp310-abi3-macosx_11_0_arm64.whl | CPython 3.10 | abi3 | macOS 11.0+ ARM64 | Details |
| bosn-0.1.6-cp310-abi3-macosx_10_12_x86_64.whl | CPython 3.10 | abi3 | macOS 10.12+ x86-64 | Details |
Total release size: 37.1 MB
Release files / bosn-0.1.6-cp310-abi3-win_amd64.whl
| Download URL | bosn-0.1.6-cp310-abi3-win_amd64.whl |
|---|---|
| Size | 8.3 MB |
| Tags | CPython 3.10 Windows x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
9e257b2894d523badac425cd4e5734233700e5897cb200709e6bdf4973188e19
|
|
BLAKE2b-256 checksum How to use checksums |
2eaa6bb4fcfa66353fe44f055abfc53f61d372b611208db2e1d09e47633f61bf
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency logRelease files / bosn-0.1.6-cp310-abi3-manylinux_2_39_x86_64.whl
| Download URL | bosn-0.1.6-cp310-abi3-manylinux_2_39_x86_64.whl |
|---|---|
| Size | 13.1 MB |
| Tags | CPython 3.10 Linux glibc 2.39+ x86-64 abi3 |
|
SHA-256 checksum How to use checksums |
3e63bbfa2ca3dfa0d70ef4aa30501852e0e1ba5be067d664270d521655f60eb5
|
|
BLAKE2b-256 checksum How to use checksums |
ab22dc9d917d167508a269b1d8d0e945e7fee447c546e1afcf12fc2750a59f9e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency logRelease files / bosn-0.1.6-cp310-abi3-macosx_11_0_arm64.whl
| Download URL | bosn-0.1.6-cp310-abi3-macosx_11_0_arm64.whl |
|---|---|
| Size | 7.7 MB |
| Tags | CPython 3.10 abi3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
38b6605caedaf8bcb59face59d2247deface39110e5a648a72ecd56727f5ca43
|
|
BLAKE2b-256 checksum How to use checksums |
daddda2fd075cc8828f28172d463d7695f5542ec6fb6fd7f3390b6a9fbb5d199
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency logRelease files / bosn-0.1.6-cp310-abi3-macosx_10_12_x86_64.whl
| Download URL | bosn-0.1.6-cp310-abi3-macosx_10_12_x86_64.whl |
|---|---|
| Size | 8.0 MB |
| Tags | CPython 3.10 abi3 macOS 10.12+ x86-64 |
|
SHA-256 checksum How to use checksums |
5a6481d229eb4f321faeb1ff5a75b7c1e02ce413631d294b482db57f370abb00
|
|
BLAKE2b-256 checksum How to use checksums |
7d31ea4ef4d9585f0ab48d3e8986e673fafc86308dc29246a271bc344f56fc2e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.
Transparency log