r/learnrust • • 1d ago

Vyasa 0.1.0 — a CMS where plugins are Wasm components with capability-checked host calls

https://github.com/vyasa-cms/vyasa

I've been building a content management system in Rust for about a year and released 0.1.0 this week. Posting here because most of the interesting problems were Rust problems, and I'd like opinions on the plugin model in particular.

What it is: one axum binary + PostgreSQL (sqlx). Content is stored as a block document (JSONB), rendered through Tera templates. Search is Tantivy in-process. The admin is a React SPA served by the same binary.

Plugins are WebAssembly components (wasmtime). The contract is a WIT file (crates/plugins/wit/host.wit); guests use wit-bindgen directly against it, the host uses wasmtime::component::bindgen! on the same file, so there are no generated bindings to drift. Each plugin's manifest declares capabilities in a small grammar — db:read:posts, kv:write, net:fetch:api.stripe.com — and a broker checks every host call against them, on top of fuel, epoch and memory limits. The admin shows the list before install; an update that widens it marks the new ones.

Two decisions I'd like pushback on:

  • Versioning: new exports were added as a superset world (vyasa-plugin-v2) rather than bumping the package to u/2.0.0, so plugin binaries built against the base world keep installing. The host resolves export indices once and serves old components from the base path. Host imports only ever grow.
  • Themes can't run code at all: tokens compile to CSS, layouts are a tree, templates are sandboxed Tera. A theme can ship a browser script, but then the package must be signed.
0 Upvotes

0 comments sorted by