helixordevelopers

Cloud deployments

The runtime is a Python package and a small service, so it runs anywhere you can run a container or a function. This page shows how each deployment pattern maps onto managed cloud building blocks, and which clouds have detailed guidance today.

You deploy it; Helixor does not host it

Every cloud deployment on these pages runs in your own account. Install the runtime wheel into an image you build, and bring your own license file. No managed image, template or marketplace product is required. An AWS Marketplace listing is Planned.

Status by cloud#

CloudStatusGuidance
AWSReference guidanceAWS and AWS Well-Architected alignment
Google CloudPlannedUse the generic mapping below.
Microsoft AzurePlannedUse the generic mapping below.
Other clouds and on-premises clustersPlannedUse the generic mapping below.

"Reference guidance" means documented patterns and example configuration that you adapt. It does not mean a supported product integration or a certified deployment.

Mapping patterns to cloud building blocks#

NeedManaged primitiveNotes
In-process runtimeYour existing container service, Kubernetes service, virtual machines or serverless functionsAdd the wheel to your application image. Create one engine per process at start-up.
SidecarA second container in the same task or pod, sharing its loopback interfaceBind to 127.0.0.1, the default. Set a service token if other processes share the loopback interface.
Shared serviceAn internal load balancer or private service network with mutual TLS or identity-based authorizationAllow ingress only from the load balancer. Deny egress.
License fileA managed secret store with customer-managed encryption keysThe runtime reads a file path, so write the secret to an in-memory file at start-up or mount it with a secrets driver.
Pack artifactsVersioned object storage with encryption and cross-account replication or copyPromote by copying an approved object. Never rebuild after approval.
Container imagesA private container registry with image scanningNever put the license in an image.
Logs and receiptsA managed log service, exported to write-once object storageReceipts are unkeyed. Write-once retention supplies tamper evidence.
MetricsThe platform's metrics service, fed from your applicationThe runtime exports no metrics endpoint.
Egress controlPrivate subnets, private service endpoints, firewall rules and network policyZero egress is a code property; enforce it here.
Environment isolationSeparate accounts, projects or subscriptions per environmentUse one license per environment where your agreement allows.
SchedulingA managed scheduler or event ruleFor the daily license-expiry check only. Never poll.

Portable practices#

These hold on every cloud and are detailed in the pillar pages:

  • License and packs are deployed as one versioned pair. Renewing a license means rebuilding the packs; see Reliability.
  • Readiness checks run a real evaluation; /v1/health is enough for liveness. See Reliability.
  • Logs carry receipts, never payloads or matched_items; see Security.
  • Scale with processes and replicas, about one core each; see Performance efficiency.
  • Keep hosts on a trusted time source, because license validity uses the local clock.