Serverless Functions (OpenFaaS & gVisor)
Okustera Serverless Functions provide event-driven compute powered by OpenFaaS running with Google gVisor (runsc) kernel sandboxing.
Deploy functions written in Python, Go, Node.js, Java, .NET, or custom OCI containers without provisioning or managing underlying virtual machine infrastructure.

Secure Execution with Google gVisor
Unlike traditional container platforms where user code shares the host Linux kernel directly, Okustera Serverless executes every function pod inside a Google gVisor virtualized sandbox kernel:
- Multi-Tenant Defense-in-Depth: Prevents container breakout vulnerabilities from affecting adjacent tenant workloads or the underlying Kubernetes node.
- Near-Zero Overhead: High performance with cold-start execution times in under 200 ms.
- AI Agent Code Sandboxing (Phase 8 Alignment): Provides zero-trust, ephemeral Python and Bash execution environments for autonomous AI agents. Sandboxes start in under 50 ms and enforce strict
NetworkPolicyrules that block access to internal databases, host interfaces, and OpenStack cloud metadata (169.254.169.254).
Multi-Tenant Scoping & Keystone Project Isolation
Every function in Okustera is strictly bound to an OpenStack Keystone project_id:
- Tenant Isolation: Functions deployed by a tenant are restricted to their dedicated Kubernetes namespace or project boundary.
- API Protection: Tenant users authenticating via Personal Access Tokens (PAT) or Workload Identity cannot read, invoke, modify, or delete functions owned by another tenant.
- Network Segregation: Tenant function pods are governed by Calico / Cilium
NetworkPolicyprofiles preventing cross-tenant east-west traffic. - Enforced Tenant Quota: Each tenant project has a hard allocation limit (default: 20 functions, expandable via Tenant Quotas). Exceeding the quota halts new function creation with HTTP 400.
Supported Language Runtimes & Catalog
Okustera supports modern, optimized language runtimes with built-in HTTP handlers and automatic JSON parsing:
| Runtime ID | Display Name | Language | Handler Filename | Status | Description |
|---|---|---|---|---|---|
python314 | Python 3.14 | Python | handler.py | active | Cutting-edge Python 3.14 preview with interpreter speedups. |
python313 | Python 3.13 | Python | handler.py | active | Modern Python with free-threaded GIL support. |
python3-http | Python 3 | Python | handler.py | active | Standard enterprise Python 3 HTTP micro-function. |
node22 | Node.js 22 LTS | JavaScript / TS | handler.js | active | High-throughput asynchronous runtime with V8 12.4. |
node20 | Node.js 20 LTS | JavaScript / TS | handler.js | deprecated | Stable LTS. Reaching maintenance window; sunset Dec 31, 2026. |
golang-http | Go 1.23 | Go | main.go | active | Compiled, ultra-fast Go 1.23 microservice (net/http). |
golang122 | Go 1.22 | Go | main.go | active | Stable enterprise Golang 1.22 runtime. |
java21 | Java 21 LTS | Java | Handler.java | active | Modern JVM runtime with Project Loom Virtual Threads. |
java17 | Java 17 LTS | Java | Handler.java | active | Long-term support JVM microservice runtime. |
dotnet9 | .NET 9.0 | C# | FunctionHandler.cs | active | High-performance C# microservice powered by Kestrel. |
dotnet8 | .NET 8.0 LTS | C# | FunctionHandler.cs | active | Enterprise Long-Term Support C# Kestrel runtime. |
Language Starter Handlers & Code Boilerplates
1. Python (python314 / python313 / python3-http)
import json
def handle(req):
"""
Okustera Python Serverless Handler
:param req: The incoming request payload (str or parsed JSON)
:return: dict or str response
"""
try:
data = json.loads(req) if isinstance(req, str) and req else req
except Exception:
data = req
return {
"status": "success",
"message": "Hello from Okustera Serverless Python Function!",
"received_data": data,
}
2. Node.js (node22 / node20)
'use strict';
module.exports = async (event, context) => {
let body = event.body;
try {
if (typeof body === 'string' && body.length > 0) {
body = JSON.parse(body);
}
} catch (e) {
// use raw body
}
return context
.status(200)
.headers({ 'Content-Type': 'application/json' })
.succeed({
status: 'success',
message: 'Hello from Okustera Serverless Node.js Function!',
received_data: body
});
};
3. Go (golang-http / golang122)
package main
import (
"encoding/json"
"io"
"net/http"
)
func Handle(w http.ResponseWriter, r *http.Request) {
var body []byte
if r.Body != nil {
body, _ = io.ReadAll(r.Body)
}
resp := map[string]interface{}{
"status": "success",
"message": "Hello from Okustera Serverless Go Function!",
"received_size": len(body),
}
w.Header().Set("Content-Type", "application/json")
w.WriteHeader(http.StatusOK)
json.NewEncoder(w).Encode(resp)
}
4. Java 21 LTS (java21 / java17)
package com.openfaas.function;
import com.openfaas.model.IHandler;
import com.openfaas.model.IRequest;
import com.openfaas.model.IResponse;
import com.openfaas.model.Response;
public class Handler implements IHandler {
@Override
public IResponse Handle(IRequest req) {
String body = req.getBody();
String jsonResponse = String.format(
"{\"status\":\"success\",\"message\":\"Hello from Okustera Serverless Java 21 LTS!\",\"input_bytes\":%d}",
body != null ? body.length() : 0
);
Response res = new Response();
res.setContentType("application/json");
res.setStatusCode(200);
res.setBody(jsonResponse);
return res;
}
}
5. .NET 9.0 / 8.0 C# (dotnet9 / dotnet8)
using System;
using System.IO;
using System.Text.Json;
using System.Threading.Tasks;
using Microsoft.AspNetCore.Http;
namespace Okustera.Serverless
{
public class FunctionHandler
{
public async Task<string> Execute(HttpRequest request)
{
string body = await new StreamReader(request.Body).ReadToEndAsync();
var response = new
{
status = "success",
message = "Hello from Okustera Serverless .NET Function!",
timestamp = DateTime.UtcNow,
received_payload = string.IsNullOrWhiteSpace(body) ? null : body
};
return JsonSerializer.Serialize(response);
}
}
}
Execution Geometry & Sizing Tiers
When deploying a function via Portal or Terraform, you configure granular compute constraints:
| Configuration Parameter | Permitted Range | Default Value | Description |
|---|---|---|---|
memory_limit | 128Mi to 2048Mi | 128Mi | Maximum RAM allocated to the gVisor sandbox container. |
cpu_limit | 100m to 1000m | 100m | CPU time slice quota (100m = 0.1 core, 1000m = 1 dedicated core). |
min_replicas | 0 to 20 | 0 | Set to 0 to scale to zero when idle; set to 1+ to eliminate cold starts. |
max_replicas | 1 to 50 | 5 | Maximum horizontal pod autoscaling threshold based on incoming requests. |
| Execution Timeout | 5s to 300s | 30s | Maximum execution duration before HTTP gateway returns 504 Gateway Timeout. |
Shared CephFS Dependency Layers
Okustera Serverless provides AWS Lambda-compatible shared dependency layers powered by a cluster-wide CephFS distributed filesystem. Instead of repeatedly packaging large libraries (such as NumPy, Pandas, TensorFlow, or custom internal SDKs) inside each function image, teams publish immutable layers once and attach them to up to 5 functions.
Key Architectural Highlights
- Shared Storage Volume: Layers reside in the high-performance CephFS filesystem (
omc-cephfs) backed by SSD pools, eliminating image rebuild time and reducing function cold start overhead. - Dynamic Pod Mutation: When a function with
layer_version_idsis deployed, the Kubernetes Mutating Admission Webhook (omc-layer-mutator) automatically injects the CephFS volume mount at/optand injects runtime environment variables (PYTHONPATH,NODE_PATH,LD_LIBRARY_PATH). - Multi-Tenant RBAC & Catalog Visibility:
private: Accessible only to the owning tenant project.shared: Explicitly shared with designated partner projects viaokustera_layer_permission.public: Global system layers curated by platform administrators (e.g., standard data science packages, database drivers).
- Immutable Snapshot Versions: Each layer version is cryptographically verified (SHA-256 fingerprint), unpacked directly into CephFS, and archived in Ceph S3 for disaster recovery.
Terraform Function Declaration
# 1. Define shared layer
resource "okustera_layer" "analytics_layer" {
name = "python-analytics"
description = "Data science toolkit (numpy, pandas, requests)"
compatible_runtimes = ["python314", "python313", "python3-http"]
}
# 2. Publish immutable version
resource "okustera_layer_version" "v1" {
layer_id = okustera_layer.analytics_layer.id
packages = [
"requests==2.32.3",
"numpy==2.1.0",
"pandas==2.2.2"
]
}
# 3. Deploy Serverless Function with attached Layer
resource "okustera_function" "data_processor" {
name = "data-processor"
runtime = "python314"
handler = "handler.handle"
min_replicas = 0
max_replicas = 10
memory_limit = "512Mi"
cpu_limit = "500m"
layer_version_ids = [okustera_layer_version.v1.version]
environment_variables = {
"LOG_LEVEL" = "INFO"
"ENV" = "production"
}
source_code = <<-EOT
import numpy as np
import pandas as pd
def handle(event, context):
df = pd.DataFrame({"values": np.random.randn(5)})
return {"mean": float(df["values"].mean())}
EOT
}
output "function_url" {
value = okustera_function.data_processor.url
}
Learn more in the Terraform Resource Reference.
Live Production Demo: Webhook Data Lake
To see an end-to-end serverless workload operating live in production:
- 🌐 Live Webhook Simulator & Dashboard: https://demo.okustera.com
- 📖 Complete Terraform Walkthrough: Read the End-to-End Tenant Demo Guide detailing how the pipeline, API Gateway routes, and Ceph S3 data lake are declared via IaC.
Related Documentation
- Tenant Resource Quotas & Governance: Function instance limits and project caps.
- API Gateway (Apache APISIX): Routing, custom domains, and rate limiting for serverless endpoints.
- Serverless Sandboxing & Security: gVisor runtime kernel isolation and zero-trust NetworkPolicies.