Skip to main content

Serverless Functions (OpenFaaS & gVisor)

Okustera Serverless Functions provide event-driven compute powered by OpenFaaS running with Google gVisor (runsc) kernel sandboxing.

Deploy functions written in Python, Go, Node.js, Java, .NET, or custom OCI containers without provisioning or managing underlying virtual machine infrastructure.

Okustera Serverless Functions (FaaS) Console


Secure Execution with Google gVisor​

Unlike traditional container platforms where user code shares the host Linux kernel directly, Okustera Serverless executes every function pod inside a Google gVisor virtualized sandbox kernel:

  • Multi-Tenant Defense-in-Depth: Prevents container breakout vulnerabilities from affecting adjacent tenant workloads or the underlying Kubernetes node.
  • Near-Zero Overhead: High performance with cold-start execution times in under 200 ms.
  • AI Agent Code Sandboxing (Phase 8 Alignment): Provides zero-trust, ephemeral Python and Bash execution environments for autonomous AI agents. Sandboxes start in under 50 ms and enforce strict NetworkPolicy rules that block access to internal databases, host interfaces, and OpenStack cloud metadata (169.254.169.254).

Multi-Tenant Scoping & Keystone Project Isolation​

Every function in Okustera is strictly bound to an OpenStack Keystone project_id:

  • Tenant Isolation: Functions deployed by a tenant are restricted to their dedicated Kubernetes namespace or project boundary.
  • API Protection: Tenant users authenticating via Personal Access Tokens (PAT) or Workload Identity cannot read, invoke, modify, or delete functions owned by another tenant.
  • Network Segregation: Tenant function pods are governed by Calico / Cilium NetworkPolicy profiles preventing cross-tenant east-west traffic.
  • Enforced Tenant Quota: Each tenant project has a hard allocation limit (default: 20 functions, expandable via Tenant Quotas). Exceeding the quota halts new function creation with HTTP 400.

Supported Language Runtimes & Catalog​

Okustera supports modern, optimized language runtimes with built-in HTTP handlers and automatic JSON parsing:

Runtime IDDisplay NameLanguageHandler FilenameStatusDescription
python314Python 3.14Pythonhandler.pyactiveCutting-edge Python 3.14 preview with interpreter speedups.
python313Python 3.13Pythonhandler.pyactiveModern Python with free-threaded GIL support.
python3-httpPython 3Pythonhandler.pyactiveStandard enterprise Python 3 HTTP micro-function.
node22Node.js 22 LTSJavaScript / TShandler.jsactiveHigh-throughput asynchronous runtime with V8 12.4.
node20Node.js 20 LTSJavaScript / TShandler.jsdeprecatedStable LTS. Reaching maintenance window; sunset Dec 31, 2026.
golang-httpGo 1.23Gomain.goactiveCompiled, ultra-fast Go 1.23 microservice (net/http).
golang122Go 1.22Gomain.goactiveStable enterprise Golang 1.22 runtime.
java21Java 21 LTSJavaHandler.javaactiveModern JVM runtime with Project Loom Virtual Threads.
java17Java 17 LTSJavaHandler.javaactiveLong-term support JVM microservice runtime.
dotnet9.NET 9.0C#FunctionHandler.csactiveHigh-performance C# microservice powered by Kestrel.
dotnet8.NET 8.0 LTSC#FunctionHandler.csactiveEnterprise Long-Term Support C# Kestrel runtime.

Language Starter Handlers & Code Boilerplates​

1. Python (python314 / python313 / python3-http)​

import json

def handle(req):
"""
Okustera Python Serverless Handler
:param req: The incoming request payload (str or parsed JSON)
:return: dict or str response
"""
try:
data = json.loads(req) if isinstance(req, str) and req else req
except Exception:
data = req

return {
"status": "success",
"message": "Hello from Okustera Serverless Python Function!",
"received_data": data,
}

2. Node.js (node22 / node20)​

'use strict';

module.exports = async (event, context) => {
let body = event.body;
try {
if (typeof body === 'string' && body.length > 0) {
body = JSON.parse(body);
}
} catch (e) {
// use raw body
}

return context
.status(200)
.headers({ 'Content-Type': 'application/json' })
.succeed({
status: 'success',
message: 'Hello from Okustera Serverless Node.js Function!',
received_data: body
});
};

3. Go (golang-http / golang122)​

package main

import (
"encoding/json"
"io"
"net/http"
)

func Handle(w http.ResponseWriter, r *http.Request) {
var body []byte
if r.Body != nil {
body, _ = io.ReadAll(r.Body)
}

resp := map[string]interface{}{
"status": "success",
"message": "Hello from Okustera Serverless Go Function!",
"received_size": len(body),
}

w.Header().Set("Content-Type", "application/json")
w.WriteHeader(http.StatusOK)
json.NewEncoder(w).Encode(resp)
}

4. Java 21 LTS (java21 / java17)​

package com.openfaas.function;

import com.openfaas.model.IHandler;
import com.openfaas.model.IRequest;
import com.openfaas.model.IResponse;
import com.openfaas.model.Response;

public class Handler implements IHandler {

@Override
public IResponse Handle(IRequest req) {
String body = req.getBody();
String jsonResponse = String.format(
"{\"status\":\"success\",\"message\":\"Hello from Okustera Serverless Java 21 LTS!\",\"input_bytes\":%d}",
body != null ? body.length() : 0
);

Response res = new Response();
res.setContentType("application/json");
res.setStatusCode(200);
res.setBody(jsonResponse);
return res;
}
}

5. .NET 9.0 / 8.0 C# (dotnet9 / dotnet8)​

using System;
using System.IO;
using System.Text.Json;
using System.Threading.Tasks;
using Microsoft.AspNetCore.Http;

namespace Okustera.Serverless
{
public class FunctionHandler
{
public async Task<string> Execute(HttpRequest request)
{
string body = await new StreamReader(request.Body).ReadToEndAsync();

var response = new
{
status = "success",
message = "Hello from Okustera Serverless .NET Function!",
timestamp = DateTime.UtcNow,
received_payload = string.IsNullOrWhiteSpace(body) ? null : body
};

return JsonSerializer.Serialize(response);
}
}
}

Execution Geometry & Sizing Tiers​

When deploying a function via Portal or Terraform, you configure granular compute constraints:

Configuration ParameterPermitted RangeDefault ValueDescription
memory_limit128Mi to 2048Mi128MiMaximum RAM allocated to the gVisor sandbox container.
cpu_limit100m to 1000m100mCPU time slice quota (100m = 0.1 core, 1000m = 1 dedicated core).
min_replicas0 to 200Set to 0 to scale to zero when idle; set to 1+ to eliminate cold starts.
max_replicas1 to 505Maximum horizontal pod autoscaling threshold based on incoming requests.
Execution Timeout5s to 300s30sMaximum execution duration before HTTP gateway returns 504 Gateway Timeout.

Shared CephFS Dependency Layers​

Okustera Serverless provides AWS Lambda-compatible shared dependency layers powered by a cluster-wide CephFS distributed filesystem. Instead of repeatedly packaging large libraries (such as NumPy, Pandas, TensorFlow, or custom internal SDKs) inside each function image, teams publish immutable layers once and attach them to up to 5 functions.

Key Architectural Highlights​

  • Shared Storage Volume: Layers reside in the high-performance CephFS filesystem (omc-cephfs) backed by SSD pools, eliminating image rebuild time and reducing function cold start overhead.
  • Dynamic Pod Mutation: When a function with layer_version_ids is deployed, the Kubernetes Mutating Admission Webhook (omc-layer-mutator) automatically injects the CephFS volume mount at /opt and injects runtime environment variables (PYTHONPATH, NODE_PATH, LD_LIBRARY_PATH).
  • Multi-Tenant RBAC & Catalog Visibility:
    • private: Accessible only to the owning tenant project.
    • shared: Explicitly shared with designated partner projects via okustera_layer_permission.
    • public: Global system layers curated by platform administrators (e.g., standard data science packages, database drivers).
  • Immutable Snapshot Versions: Each layer version is cryptographically verified (SHA-256 fingerprint), unpacked directly into CephFS, and archived in Ceph S3 for disaster recovery.

Terraform Function Declaration​

# 1. Define shared layer
resource "okustera_layer" "analytics_layer" {
name = "python-analytics"
description = "Data science toolkit (numpy, pandas, requests)"
compatible_runtimes = ["python314", "python313", "python3-http"]
}

# 2. Publish immutable version
resource "okustera_layer_version" "v1" {
layer_id = okustera_layer.analytics_layer.id
packages = [
"requests==2.32.3",
"numpy==2.1.0",
"pandas==2.2.2"
]
}

# 3. Deploy Serverless Function with attached Layer
resource "okustera_function" "data_processor" {
name = "data-processor"
runtime = "python314"
handler = "handler.handle"
min_replicas = 0
max_replicas = 10
memory_limit = "512Mi"
cpu_limit = "500m"
layer_version_ids = [okustera_layer_version.v1.version]

environment_variables = {
"LOG_LEVEL" = "INFO"
"ENV" = "production"
}

source_code = <<-EOT
import numpy as np
import pandas as pd

def handle(event, context):
df = pd.DataFrame({"values": np.random.randn(5)})
return {"mean": float(df["values"].mean())}
EOT
}

output "function_url" {
value = okustera_function.data_processor.url
}

Learn more in the Terraform Resource Reference.


Live Production Demo: Webhook Data Lake​

To see an end-to-end serverless workload operating live in production: