Docs / Deploy

Deploy

Self-hosting

Woven is self-hostable as the woven-server executable. Use the loopback development composition for local work, or opt into static remote native QUIC or managed QUIC with optional browser WebTransport, using your own TLS and credential files.

Install

Install the published server executable directly with Cargo:

cargo install woven-server --locked

Cargo installs woven-server on your executable path. Start the local development composition with:

woven-server

The default development composition binds to loopback and uses development credentials with ephemeral TLS. Keep that composition on the local machine.

Run from current source

cargo run -p woven-server

Run this command from a Woven source checkout when integrating against the current source tree rather than the published Cargo package.

Remote native QUIC

WOVEN_REMOTE_QUIC=1 \
WOVEN_QUIC_BIND=0.0.0.0:8081 \
WOVEN_MANAGEMENT_BIND=127.0.0.1:8080 \
WOVEN_TLS_CERT_FILE=/run/woven/tls/chain.pem \
WOVEN_TLS_KEY_FILE=/run/woven/tls/key.pem \
WOVEN_AUTH_TOKEN_FILE=/run/woven/auth/token \
woven-server

All six settings are required together and partial configuration fails closed. Supply a PEM certificate chain and matching private key. The auth-token file contains the static scoped client credential; keep the key and token files private and pass file paths, never secret values, through the environment.

Keep management on loopback. WOVEN_MANAGEMENT_BIND exposes unauthenticated /healthz, /readyz, /metrics, and/v1/capabilities for local operations. Do not publish or proxy that listener.

Host-managed QUIC and optional WebTransport

The managed composition starts empty; Woven Host adds session scopes and client credentials. The following settings enable native QUIC; browser WebTransport is a separate optional listener:

WOVEN_MANAGED_QUIC=1
WOVEN_QUIC_BIND=0.0.0.0:8081
WOVEN_MANAGEMENT_BIND=127.0.0.1:8080
WOVEN_ADMIN_BIND=127.0.0.1:8082
WOVEN_TLS_CERT_FILE=/run/woven/tls/chain.pem
WOVEN_TLS_KEY_FILE=/run/woven/tls/key.pem
WOVEN_ADMIN_TOKEN_FILE=/run/woven/admin/token

Both HTTP listeners must remain loopback-only. The separate admin listener requires its own bearer credential on every route; point Woven Host's WOVEN_MANAGEMENT_URL at that listener and provide the matching credential through Host'sWOVEN_MANAGEMENT_TOKEN_FILE. Host provisions bounded session scopes while clients connect directly to Woven. To enable browser WebTransport, also set WOVEN_MANAGED_WEBTRANSPORT=1, an explicit WOVEN_WEBTRANSPORT_BIND, an absolute WOVEN_WEBTRANSPORT_PATH, and exact canonical origins in WOVEN_WEBTRANSPORT_ALLOWED_ORIGINS. All four settings are required together; the WebTransport UDP listener must be separate from native QUIC. Configure Host's WOVEN_CLIENT_WEBTRANSPORT_URL separately, and use the revealed descriptor's webTransport.url and browser trust metadata when connecting.

Health and metrics

/readyz reports whether native QUIC is active. /metrics uses Prometheus text exposition and includes active connection/session gauges plus process-lifetime counters for connections, publishes, delivered events and bytes, queue drops, and evictions/coalescing. Keep these operational endpoints private and scrape them over a trusted local or private path.

Static remote mode remains native QUIC only; managed mode can additionally expose browser WebTransport. Certificate issuance, renewal, and perimeter controls remain the operator's responsibility. Durable journaling is an external integration seam, not a built-in restart-recovery guarantee, and separate nodes do not automatically share sessions or state.