Skip to content
@Rullst

Rullst

πŸ“œπŸ¦€πŸŒ Super Full-Stack Framework for Rust language πŸŒπŸ¦€πŸ“œ- πŸ€– The AI-Native Paradigm (Designed for Humans & AI)

All glory and honor to God Χ™Χ”Χ•Χ” in the name of Yeshua the Messiah (Jesus Christ).

Rullst β€” build secure apps in Rust without the suffering. Batteries included, secure by default, designed for humans and AI.

πŸŒπŸ¦€πŸ“œ Rullst πŸ“œπŸ¦€πŸŒ

Intelligent, Security-Conscious, and Designed for Effortless Productivity β€” Because With Rullst, We Rule!

Crates.io Crates.io Downloads Docs.rs Main Rust CI License: MIT

Whole-repository coverage OpenSSF Scorecard MSRV 1.96.0

Quickstart Β· Start building Β· Rullst Academy Β· Live examples Β· Documentation Β· Discord

Terminal: cargo rullst new asks for the app name, blueprint and database, creates a SaaS starter with SQLite, then cargo rullst dev compiles it and serves it at http://localhost:3000.

⚑ Rullst in 30 seconds

cargo install cargo-rullst --version '^12' --locked
cargo rullst new my_app    # choose Blank/API, Blog, SaaS, LMS, Portfolio or ERP
cd my_app
cargo rullst dev           # rebuilds and restarts every time you save

That's it: a running application, generated as readable Rust you can change β€” no hidden runtime magic. The selector installs the latest stable v12 CLI; use a full version such as --version 12.1.2 to reproduce a specific release.

Installation and prerequisites Β· Zero-to-Hero tutorial Β· Build a JSON REST API Β· CLI reference

Prefer an interactive dashboard? Run cargo rullst dash

Rullst terminal dashboard with project information, logs and controls

Recorded screenshot; layout and controls can differ by version. Development workflow.

πŸ¦€ Code that says what it does

use rullst::{html, response::Html, routes, Server};

async fn home() -> Html<String> {
    Html(html! {
        <div class="min-h-screen bg-slate-900 text-emerald-400 flex flex-col items-center justify-center font-sans">
            <h1 class="text-5xl font-extrabold mb-4">"Hello, Rullst! πŸ“œπŸ¦€"</h1>
            <p class="text-slate-400 text-lg">"Your first typed route is running."</p>
        </div>
    })
}

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    let app = routes![
        get("/" => home)
    ];

    Server::new(app).run(3000).await?;
    Ok(())
}

HTML lives in a compile-time html! macro, routes are typed and pages are server-rendered β€” HTMX-ready, with no JavaScript bundle to build. This snippet comes from the Zero-to-Hero tutorial, and every tutorial's Rust code is compiled in CI.

Prefer a JSON API?
use rullst::{Server, ServerError, routes, server::Json};
use serde::Serialize;

#[derive(Serialize)]
struct HealthResponse {
    status: &'static str,
    framework: &'static str,
}

async fn health() -> Json<HealthResponse> {
    Json(HealthResponse {
        status: "ok",
        framework: "Rullst",
    })
}

#[tokio::main]
async fn main() -> Result<(), ServerError> {
    let app = routes![
        get("/api/health" => health),
    ]
    .layer(rullst::server::from_fn(
        rullst::security::headers_middleware,
    ));

    Server::new(app).run(3000).await
}
curl http://127.0.0.1:3000/api/health
# {"status":"ok","framework":"Rullst"}

Build your first REST API step by step.

One framework, the whole product. Secure by default: Argon2id, sessions, passkeys, OAuth2/OIDC, CSRF, strict headers, WAF and login jail. Data that stays correct: Active Record, transactions, migrations and an outbox on SQLite, PostgreSQL and MySQL. Six real blueprints: API, Blog, SaaS, LMS, Portfolio and ERP. Made for AI coding: explicit APIs, compile-time macros, typed errors, no runtime reflection. Payments and email: Stripe billing with signed webhooks; Resend, SendGrid, Postmark and SMTP. AI built in: OpenAI, Claude, Gemini, DeepSeek and Ollama with prompt-injection filtering and PII masking. See inside your app: Studio telemetry and the Nexus admin with a security radar. Web first, native too: HTMX, JSON APIs, and Tauri desktop and mobile shells via Omni.

Every capability has a documented boundary β€” security middleware does not replace your authorization rules, and databases are not interchangeable. See the capability ledger Β· Why Rullst? Β· Axum & SQLx escape hatches

🌍 Built with Rullst

Real applications running today, every one of them built with Rullst. Click to explore β€” their code and deployment recipes live in Rullst/examples.

Showcase built with Rullst: SSR, LiveView, Wasm, ORM, billing, security and AI demos
🌐 Showcase β€” SSR, LiveView, Wasm, ORM, billing, security and AI demos Β· Open β†—
LMS built with Rullst: course catalog and learning platform
πŸŽ“ LMS β€” course catalog and learning platform Β· Open β†—
Portfolio built with Rullst: projects, experience, Nexus and Studio
πŸ’Ό Portfolio β€” projects, experience, Nexus and Studio Β· Open β†—
SaaS in production built with Rullst: real purchases with Stripe
πŸ›’ SaaS in production β€” real purchases with Stripe Β· Open β†—

The demos scale to zero when idle, so the first visit can take a few seconds to wake up β€” that is hosting startup, not Rullst's request time. The SaaS checkout is live and charges real money; the Showcase payment demos are not.

▢️ Watch: how to build a SaaS with Rullst

Prefer to run something locally? The reproducible SaaS example covers generation, login and tenant-scoped notes on a disposable SQLite database, and the WebGPU wave example serves browser graphics from Rullst.

πŸ—οΈ Architecture

Rullst architecture. Your app (API, Blog, SaaS, LMS, Portfolio, ERP) sits on four layers: Product (rullst-capital payments, rullst-mail email, rullst-ai AI and RAG, rullst-messaging queues, rullst-connect OAuth2/OIDC); Trust (rullst-auth identity and sessions, rullst-security WAF, headers, CSRF and RASP); Data (rullst-orm Active Record, migrations and transactions, rullst-orm-macros); Runtime (rullst-core HTTP runtime and routing, rullst-macros html!). Everything runs on Axum, Tokio, Tower and SQLx. Tools: cargo-rullst CLI, rullst-studio control room, rullst-nexus admin. One facade crate, rullst, enables only the features you need.

Rullst is a family of focused crates in one versioned workspace β€” select only what your application needs. The stable v12 release publishes sixteen crates; detailed feature and provider boundaries live in the specification.

Browse the crate directory
Crate Focus
rullst Public framework facade and feature selection
rullst-core HTTP runtime, routing, lifecycle and telemetry
rullst-orm Relational models, transactions and capability-specific persistence
rullst-auth Passwords, sessions, passkeys and authorization helpers
rullst-security Defense-in-depth middleware, guards and audit helpers
rullst-connect OAuth2/OIDC identity integrations
rullst-ai Guarded local/cloud clients and tenant-aware retrieval
rullst-capital Payment/payout adapters, webhooks and bounded billing helpers
rullst-mail Transactional email and delivery controls
rullst-messaging Broker-neutral contracts and durable local messaging
rullst-studio Local developer control room
rullst-nexus Registered-model admin with explicit access policy
rullst-iot Bounded no_std helpers and signed OTA verification, not device integration
rullst-macros Compile-time HTML and application macros
rullst-orm-macros Typed ORM code generation
cargo-rullst Project scaffolding, development and upgrade CLI

πŸŽ“ Learn with Rullst Academy

Rullst Academy is a free learning platform β€” built with Rullst β€” where you can learn Rust, Rullst, Git/GitHub, web development, databases and more through short lessons and practical projects, in Portuguese, English or Spanish.

Start learning at Rullst Academy β†—

πŸ›‘οΈ Engineered like critical infrastructure

Rullst is maintained with the rigor you expect from security software:

  • No panics in production code, enforced by CI across the published runtime crates.
  • No new unsafe outside a reviewed OS/FFI allowlist.
  • At least 90% line coverage, enforced, plus fuzzing, property tests, sanitizers and Kani/Miri checks on selected critical code.
  • Supply-chain hygiene: RustSec and license policy on every change, SHA-pinned Actions, and an SBOM with build-provenance attestation for every release.
  • A fast Linux gate on every pull request, with the complete Linux/macOS/Windows matrix every night and before every release.

Nexus SOC Threat Radar with WAF, honeypot, prompt-injection and audit counters
The Nexus security radar (recorded screenshot).

These results are evidence for their stated scope, not a security certification of every application built with Rullst. Explore the release audit, capability status and quality scorecard.

πŸ›‘οΈ Open the verification dashboard (39 workflows)

Badges are pinned to the main branch; they report the latest matching run, not a certification or deployment guarantee.

Continuous or change-aware gate Development main status Actual scope
Rust CI Rust CI Format, all-target/all-feature Clippy, a Linux gate on pull requests, every Linux shard after merge and the complete Linux/macOS/Windows matrix nightly; Cargo-aware doctests sourced from all 52 public tutorials, strict DB boundaries, feature boundaries, generated-code checks, and MSRV 1.96.0.
Declared MSRV MSRV 1.96.0 Every publishable manifest declares Rust 1.96.0 and CI runs an explicit workspace all-feature check with that toolchain.
GitHub Actions lint Workflow Lint Validates workflow syntax, expressions, embedded shell, and full-SHA third-party Action pins.
Documentation Documentation Builds the mdBook and rejects broken local links and anchors; scheduled/manual runs also preserve an informational external-link report.
End-to-end smoke E2E Boots the release blog example and verifies HTTP, security headers, form flow, and SQLite persistence.
Codecov β€” whole repository Whole-repository coverage The badge reports the current branch aggregate. The stable-source LLVM run at eb11f892 measured 90.3220% (79,813/88,365 lines) before Codecov upload. The enforced repository floor is β‰₯90% with zero tolerance.
Codecov β€” framework libraries Framework library coverage Runtime libraries are enforced separately at β‰₯90%. CLI and proc-macro components stay separately visible; Coverage CI uploads their real LCOV evidence with OIDC.
Cargo Audit Cargo Audit RustSec advisory scan with only governed, expiring exceptions; the daily run also audits the stable v12 locks.
Security exception governance Security Governance Cross-checks scanner allowlists against the owner/expiry ledger, then independently reruns Cargo Audit.
Cargo Deny Cargo Deny Advisory, license, ban, and source policy.
CodeQL SAST CodeQL Rust semantic analysis after an all-target/all-feature build.
OpenSSF Scorecard OpenSSF Scorecard The badge renders the score from the official public Scorecard JSON report; the pinned Scorecard workflow publishes OIDC-authenticated results on each main push and weekly. A score is evidence, not a security certification. Evidence and improvements.
Cargo Machete Machete Unused direct dependency detection.
SemVer checks SemVer Supported library APIs are compared with exact latest non-yanked registry baselines; never-published packages and unsupported proc-macro/binary surfaces are reported explicitly.
Zero-panics policy Zero Panics Denies panic-family operations in published production targets and generated runtime templates.
Unsafe boundary Unsafe Policy Denies new production unsafe code outside the reviewed OS/FFI allowlist.
Secret scanning TruffleHog Verified-secret scan across the configured Git history range.
Spellcheck Spellcheck Repository-wide typo detection.
Crate architecture policy Architecture Compares the real publishable-crate dependency graph with a versioned, reviewed repository policy.
WebAssembly matrix Wasm Compiles Core, the public facade and macros for browser Wasm and WASI Preview 1.
Bare-metal no_std matrix no_std Builds IoT helpers for Cortex-M and RISC-V targets; this is compile evidence, not hardware testing.
IoT integration IoT Host tests, signed OTA invariants, and a Cortex-M build.
IoT crypto containment IoT Crypto Path-aware signed OTA, Vault, advisory, and simulator-boundary checks; no PQC/HSM certification claim.
Omni desktop matrix Omni Desktop Generates fresh web shells and checks their Tauri crates on Linux, macOS and Windows; no installer, signing or store claim.
Omni Android compile Omni Android Generates a fresh shell and compiles an unsigned Android debug APK; no physical-device, Play testing/signing or store claim.
Omni iOS simulator Omni iOS Path-aware fresh scaffold generation and compilation on a macOS iOS simulator target; no device, signing or App Store claim.
PR security evidence PR-only evidence Pull-request-only bounded IDOR/RBAC heuristics and CycloneDX SBOM artifact. It intentionally has no continuous main status.

Deep or irreversible workflows are intentionally not presented as continuously green main gates:

Deep evidence Trigger and enforcement
Benchmark regression Weekly, main push, or manual; eight published groups backed by nine Criterion benchmark binaries emit non-blocking alerts at a 20% regression.
Property testing Weekly/manual release-mode invariant testing with 10,000 configured cases.
TSan and ASan Daily/manual package matrices on a pinned verifier-only nightly.
Fuzzing / corpus minimization Forty manual libFuzzer jobs; weekly/manual corpus maintenance is informational.
OWASP ZAP Manual baseline over three release surfaces: generated REST API and complete LMS are blocking with no ignored alerts; the deliberately CDN-backed blog showcase remains an explicitly informational boundary.
Kani, Miri, mutation testing, cargo-udeps Manual or scheduled research signals: selected Kani/Miri scopes are strict, while mutation and unused-dependency findings remain explicitly informational.
v13 Verus pilot Optional production-linked age-policy proof with pinned tooling and three negative controls. Hosted registration/acceptance remains pending; no framework-wide correctness claim.
GitHub Pages Deploys development documentation from main; it is not a code-quality gate.
Release and provenance Exact version tags only: full verification, package-all, evidence bundle, checksums, GitHub build-provenance attestation, changelog-derived release notes, and ordered crates.io publication. This does not claim a project-wide SLSA level or independent certification.

Scheduled events use the repository's default branch, so scheduled and continuous development evidence refer to main; stable v12 has its own branch. The branch-protection profiles and the exact scope of all 39 workflow definitions in this source branch are documented in WORKFLOWS.md.

πŸ“– Read the detailed breakdown of all CI/CD and security workflows.

🧭 Capability Status & Vision Decisions preserves ambitious features that are partial or not implemented, with an explicit recommendation and rationale for each one.

πŸ“‹ Simple Capability Status and the per-commit quality scorecard keep feature progress separate from SHA-bound engineering evidence.

πŸ”„ Upgrade with a preview

From an existing application's root:

cargo rullst upgrade --dry-run
cargo rullst upgrade

The CLI coordinates dependency updates, backs up controlled files and runs compiler checks. Review the plan and your application's behavior; it does not migrate production data. Assisted upgrade tutorial Β· v5 β†’ v12 migration guide

πŸš€ What's next: v13

This main branch is where v13 is being built (13.0.0-alpha.1). The commands above install the stable v12 line, maintained on the v12 branch; v5 is no longer maintained.

In development for v13: email login and scoped API tokens, active-session management with remote logout, private S3/R2 storage with resumable uploads, durable outgoing webhooks and recurring jobs, Redis Streams messaging, distributed tracing and a recoverable Live UI. Until v13 is released, these are development candidates, not shipped features.

v13 roadmap Β· v13 adoption guide Β· Compatibility policy Β· v12 release record

⚑ Performance you can inspect

The benchmark hub publishes eight Criterion groups backed by nine benchmark binaries. They measure specific workloads and regressions β€” not universal speed or a ranking of frameworks. Read the methodology alongside the results.

🀝 Build Rullst with us

Try a blueprint, report a reproducible bug, improve a tutorial or contribute a focused change with tests. Documentation, accessibility and integration feedback matter as much as new features.

Contributing Β· Issues Β· Discord Β· Community links Β· Our story and philosophy

⭐ If Rullst sparks your curiosity, a star helps more developers discover it.

MIT license Β· Report a vulnerability privately Β· Website privacy notice

All glory and honor to God Χ™Χ”Χ•Χ” in the name of Yeshua the Messiah (Jesus Christ).

Pinned Loading

  1. Rullst Rullst Public

    πŸ“œπŸ¦€πŸŒ Intelligent, Secure and Effortless Super Full-Stack Framework πŸŒπŸ¦€πŸ“œ"Rust for those who want to build securely and easily, but not suffer"πŸ€– The Next-Gen Paradigm: Designed for Humans & AI. Rullst …

    Rust 18 5

  2. Benchmarks Benchmarks Public

    Benchmarks

    C 4 1

  3. Rullst.github.io Rullst.github.io Public

    HTML 1

Repositories

Showing 8 of 8 repositories

Top languages

Loading…

Most used topics

Loading…