Skip to main content

Bosn

Bosn is a Rust daemon for safely managing Docker development applications. It keeps ownership, generation, volume, lease, execution-session, and event state in a durable SQLite registry. The daemon is the only component that mutates Docker or that writes that registry.

The distribution includes three intentionally thin front ends:

  • bosn, a bundled native CLI;
  • import bosn, a PyO3 client binding; and
  • bosn mcp, a stdio MCP server for Hermes and other MCP clients.

The former Python daemon, Docker front doors, manifest parser, and SQLite registry are deliberately not packaged. Python callers use bosn.Client; they cannot import or invoke a second lifecycle implementation.

Install

pip install bosn
bosn --version

Platform wheels contain the native bosn CLI and the bosn._native Python extension. Installing the wheel puts the bosn binary itself into the environment's scripts directory, so the bosn on PATH is the native CLI, with no Python wrapper in between. The extension uses PyO3's abi3-py310 ABI, so Bosn supports CPython 3.10 and newer with one platform wheel rather than publishing cp311-only artifacts.

One-file setup

Bosn accepts a local file or HTTPS URL for a versioned setup document. The document declares a digest-pinned image or inline Dockerfile, optional inline files, environment, bind mounts, named volumes, tmpfs mounts, and named tasks. Planning is inert; ensure and task submission are daemon-owned jobs.

version = 1

[app]
image = "registry.example/team/app@sha256:REPLACE_WITH_64_LOWERCASE_HEX_DIGEST"
command = "exec sleep 120"

[task.check]
command = "cargo check"
bosn setup plan --state-dir "$HOME/.local/state/bosn" \
  --workspace "$PWD" --config https://example.invalid/bosn-setup.toml \
  --refresh
bosn setup ensure --state-dir "$HOME/.local/state/bosn" \
  --workspace "$PWD" --config https://example.invalid/bosn-setup.toml \
  --refresh --deadline-ms 300000 --output-limit 8388608

online_refresh is explicit; offline_cache_only uses only a previously validated local cache record. URLs with credentials, unsupported schemes, path traversal, unpinned images, and oversized documents are refused.

Python

from pathlib import Path
import bosn

client = bosn.Client(Path.home() / ".local/state/bosn")
plan = client.plan_setup(
    Path.cwd(), "https://example.invalid/bosn-setup.toml", policy="online_refresh"
)
job_id = client.submit_setup_ensure(
    Path.cwd(),
    "https://example.invalid/bosn-setup.toml",
    policy="online_refresh",
    deadline_ms=300_000,
    output_limit=8 * 1024 * 1024,
)

The binding exposes typed request and observation operations only. It does not accept Docker command arguments, container identifiers, mounts, or arbitrary commands from callers.

Concurrent runs

The daemon runs task jobs (bosn run --task ...) from different checkouts in parallel, max(1, ncpu * 2) runner slots by default, each limited to 4 CPUs. Stack ensures run in their own lane, so they never wait behind long tasks. bosn jobs (or the bosn_jobs MCP tool) shows what is running, in which slot, with which containers and caches. A task that goes silent is torn down, and a daemon restart reaps what its predecessor left running. For stacks that drive the host Docker engine (act), a per-job proxy labels, limits, isolates and removes the job's containers, and maps cache volumes into act's job containers. See docs/runners.md.

bosn jobs                                  # what is running now
bosn daemon serve --state-dir "$HOME/.local/state/bosn" --runner-slots 8 --runner-cpus 4

MCP / Hermes

Run bosn mcp over stdio. A typical Hermes registration is:

mcp_servers:
  bosn:
    command: bosn
    args: [mcp]

Set BOSN_STATE_DIR if the default state directory is not appropriate. MCP tools use the same typed daemon operations as the CLI and Python client; long operations return durable job IDs.

Development

./install
./lint
./test

./install prepares Soldr and the Rust toolchain pinned by rust-toolchain.toml before installing the native package. Source builds use Soldr for both the CLI and Maturin's compiler calls. The declared Docker test and lint tasks build a wheel against a read-only checkout, with writable target, toolchain and environment volumes.

The Rust migration status, native manifest lifecycle boundary, and registry details are documented in docs/migration-rust.md, docs/rust-manifest-runtime.md, and docs/rust-registry.md. Daemon-owned task secrets (an opt-in GITHUB_TOKEN for act runs) are in docs/task-secrets.md; the read-only GitHub API proxy that keeps the token out of containers is in docs/github-api-proxy.md. Local CI on an isolated, daemon-owned engine (bosn ci run --wait, with reports and stable exit codes for agents) is in docs/ci.md.

Metadata

Release files for bosn 0.1.8

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Built distributions (wheels)

Table of built distributions (wheels) for bosn 0.1.8
File
bosn-0.1.8-cp310-abi3-win_amd64.whl CPython 3.10 abi3 Windows x86-64 Details
bosn-0.1.8-cp310-abi3-manylinux_2_39_x86_64.whl CPython 3.10 abi3 Linux glibc 2.39+ x86-64 Details
bosn-0.1.8-cp310-abi3-macosx_11_0_arm64.whl CPython 3.10 abi3 macOS 11.0+ ARM64 Details
bosn-0.1.8-cp310-abi3-macosx_10_12_x86_64.whl CPython 3.10 abi3 macOS 10.12+ x86-64 Details

Total release size: 48.8 MB

Release files / bosn-0.1.8-cp310-abi3-win_amd64.whl

Download URL bosn-0.1.8-cp310-abi3-win_amd64.whl
Size 11.3 MB
Tags CPython 3.10 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
a1b9889776ab650aeb2ed20b189473ca31f2ba227f4b33f4a7ce26b7aaf8dfae
BLAKE2b-256 checksum
How to use checksums
dad4f4303ae53bbc7474143ed47da0852916f9784a57870ddfa842977af6fb7e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / bosn-0.1.8-cp310-abi3-manylinux_2_39_x86_64.whl

Download URL bosn-0.1.8-cp310-abi3-manylinux_2_39_x86_64.whl
Size 16.3 MB
Tags CPython 3.10 Linux glibc 2.39+ x86-64 abi3
SHA-256 checksum
How to use checksums
e53d33fa58332a0141648a8b6d5b7edbd0beaa0c3457d56f50c729e400a23f10
BLAKE2b-256 checksum
How to use checksums
8c28f806a7013984b0012d47a6d3e9bdbb6c3803e0d41151edb9c18e04b35d26
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / bosn-0.1.8-cp310-abi3-macosx_11_0_arm64.whl

Download URL bosn-0.1.8-cp310-abi3-macosx_11_0_arm64.whl
Size 10.4 MB
Tags CPython 3.10 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
9f17d7afb8c287a3aaa2ae05a55558f3270559510e1f429424bed771eee79ca0
BLAKE2b-256 checksum
How to use checksums
510db3e03a94a4e5a51932d87d4d54bc84ee22b72231c10f1e3992b89089991c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / bosn-0.1.8-cp310-abi3-macosx_10_12_x86_64.whl

Download URL bosn-0.1.8-cp310-abi3-macosx_10_12_x86_64.whl
Size 10.8 MB
Tags CPython 3.10 abi3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
3a63e1d11e33ee1f087bc195593759b819ef15f02d55b2cf360bc82b76996ebb
BLAKE2b-256 checksum
How to use checksums
d1350cbd69528d48e754fdb579b7726d39c1b6be1d90778e7fb7046207fe3abd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page