1"use strict";(self.webpackChunkwasmcloud_com=self.webpackChunkwasmcloud_com||[]).push([["19660"],{50065:function(e,s,n){n.d(s,{Z:()=>t,a:()=>l});var o=n(67294);let i={},r=o.createContext(i);function l(e){let s=o.useContext(r);return o.useMemo(function(){return"function"==typeof e?e(s):{...s,...e}},[s,e])}function t(e){let s;return s=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:l(e.components),o.createElement(r.Provider,{value:s},e.children)}},60836:function(e,s,n){n.r(s),n.d(s,{frontMatter:()=>l,default:()=>h,contentTitle:()=>t,assets:()=>a,toc:()=>c,metadata:()=>o});var o=JSON.parse('{"id":"wash/developer-guide/network-access-and-socket-isolation","title":"Network Access and Socket Isolation","description":"wasmCloud\'s socket policy and network isolation for WebAssembly components \u2014 what\'s allowed, what\'s denied, and how to configure access on Kubernetes.","source":"@site/docs/wash/developer-guide/network-access-and-socket-isolation.mdx","sourceDirName":"wash/developer-guide","slug":"/wash/developer-guide/network-access-and-socket-isolation","permalink":"/docs/wash/developer-guide/network-access-and-socket-isolation","draft":false,"unlisted":false,"editUrl":"https://github.com/wasmCloud/wasmcloud.com/edit/main/docs/wash/developer-guide/network-access-and-socket-isolation.mdx","tags":[],"version":"current","lastUpdatedBy":"Eric Gregory","lastUpdatedAt":1790194298000,"sidebarPosition":3,"frontMatter":{"title":"Network Access and Socket Isolation","date":"2026-03-19T00:00:00.000Z","sidebar_position":3,"draft":false,"description":"wasmCloud\'s socket policy and network isolation for WebAssembly components \u2014 what\'s allowed, what\'s denied, and how to configure access on Kubernetes.","proficiency":"Intermediate","about":"wasmCloud","mentions":["Kubernetes","WebAssembly","WASI"],"languages":["Rust"],"platforms":["wasmCloud","wash"]},"sidebar":"tutorialSidebar","previous":{"title":"Creating Services","permalink":"/docs/wash/developer-guide/create-services"},"next":{"title":"Debugging Components","permalink":"/docs/wash/developer-guide/debugging-components"}}'),i=n(85893),r=n(50065);let l={title:"Network Access and Socket Isolation",date:new Date("2026-03-19T00:00:00.000Z"),sidebar_position:3,draft:!1,description:"wasmCloud's socket policy and network isolation for WebAssembly components \u2014 what's allowed, what's denied, and how to configure access on Kubernetes.",proficiency:"Intermediate",about:"wasmCloud",mentions:["Kubernetes","WebAssembly","WASI"],languages:["Rust"],platforms:["wasmCloud","wash"]},t=void 0,a={},c=[{value:"Host policy: what's allowed and what's not",id:"host-policy-whats-allowed-and-whats-not",level:2},{value:"Allowed by default",id:"allowed-by-default",level:3},{value:"Denied by default",id:"denied-by-default",level:3},{value:"The isolation model",id:"the-isolation-model",level:2},{value:"In-process loopback",id:"in-process-loopback",level:3},{value:"Port isolation across workloads",id:"port-isolation-across-workloads",level:3},{value:"External access",id:"external-access",level:3},{value:"Choosing a networking pattern",id:"choosing-a-networking-pattern",level:2},{value:"Service model (recommended for production)",id:"service-model-recommended-for-production",level:3},{value:"wasi-virt (for testing and cross-runtime portability)",id:"wasi-virt-for-testing-and-cross-runtime-portability",level:3},{value:"Host policy enforcement",id:"host-policy-enforcement",level:3},{value:"Practical example: <code>service-tcp</code> template",id:"practical-example-service-tcp-template",level:2},{value:"Keep reading",id:"keep-reading",level:2}];function d(e){let s={a:"a",admonition:"admonition",code:"code",em:"em",h2:"h2",h3:"h3",img:"img",li:"li",ol:"ol",p:"p",pre:"pre",span:"span",strong:"strong",ul:"ul",...(0,r.a)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(s.p,{children:"wasmCloud enforces a well-defined socket policy at the host level, giving you predictable security boundaries without requiring components to implement their own restrictions. This page explains what's allowed and denied by default, how the isolation model works, and when to use each networking pattern."}),"\n",(0,i.jsx)(s.h2,{id:"host-policy-whats-allowed-and-whats-not",children:"Host policy: what's allowed and what's not"}),"\n",(0,i.jsx)(s.p,{children:"The wasmCloud host applies socket policy to all workloads. The policy is implemented in the host runtime and applies regardless of what a component's code attempts to do."}),"\n",(0,i.jsx)(s.h3,{id:"allowed-by-default",children:"Allowed by default"}),"\n",(0,i.jsxs)(s.ul,{children:["\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"Outbound TCP connections"})," \u2014 components and services can connect to non-loopback addresses. This enables components to make outbound HTTP requests, connect to databases, or use any TCP-based protocol. Raw-socket connections count against a per-workload quota (default 256; over-quota connects are refused immediately) and are evaluated against the workload's ",(0,i.jsx)(s.code,{children:"allowedHosts"})," list plus an address policy screening special ranges \u2014 in ",(0,i.jsx)(s.strong,{children:"count"})," mode by default, so nothing is newly blocked on upgrade; operators opt into ",(0,i.jsx)(s.code,{children:"enforce"})," after reviewing the counters. Since 2.10.0 the same policy screens inbound traffic: listens, accepts, and received datagrams are evaluated, and accepted connections take an inbou
1nd quota slot."]}),"\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"Bind on loopback for services"})," \u2014 services can bind and listen on ",(0,i.jsx)(s.code,{children:"127.0.0.1"})," (or the unspecified address ",(0,i.jsx)(s.code,{children:"0.0.0.0"}),'). This is how a service becomes the "localhost" for its workload. Binds are loopback-confined for both TCP and UDP: a ',(0,i.jsx)(s.code,{children:"0.0.0.0"})," bind is rewritten to the workload's virtual loopback and never reaches the machine's real interfaces."]}),"\n"]}),"\n",(0,i.jsx)(s.h3,{id:"denied-by-default",children:"Denied by default"}),"\n",(0,i.jsxs)(s.ul,{children:["\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"DNS / name resolution"})," \u2014 ",(0,i.jsx)(s.code,{children:"ip-name-lookup"})," is denied by default. Components and services must use IP addresses directly rather than hostnames unless resolution is explicitly allowed. Since wasmCloud 2.6.0, a component can opt in with the per-component ",(0,i.jsx)(s.code,{children:"allowedIpNameLookups"})," allowlist in its workload configuration (named ",(0,i.jsx)(s.code,{children:"allowIpNameLookup"})," before 2.6.1); entries may be exact hostnames, ",(0,i.jsx)(s.code,{children:"*.suffix"})," wildcards, ",(0,i.jsx)(s.code,{children:"*"})," (any name), or literal IPs."]}),"\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"TCP bind for regular components"})," \u2014 only services can bind TCP ports and act as listeners. A regular component that attempts to bind a TCP port will be denied by the host."]}),"\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"The machine's loopback"})," \u2014 ",(0,i.jsx)(s.code,{children:"127.0.0.1"})," always means the workload's own virtual loopback, never the host machine's. There is one sanctioned path to the machine's loopback: the reserved name ",(0,i.jsx)(s.code,{children:"host.wasmcloud.internal"}),", gated by the per-component ",(0,i.jsx)(s.code,{children:"allowedHostLoopbackPorts"})," list ",(0,i.jsx)(s.em,{children:"and"})," a host-level ",(0,i.jsx)(s.code,{children:"--allow-host-loopback"})," flag (off by default). See ",(0,i.jsx)(s.a,{href:"/docs/kubernetes-operator/workload-security#raw-socket-egress-policy-and-connection-quotas",children:"Workload Security"}),"."]}),"\n"]}),"\n",(0,i.jsx)(s.admonition,{title:"Policy is enforced at the host level",type:"info",children:(0,i.jsx)(s.p,{children:"These restrictions are enforced by the wasmCloud runtime, not by the component itself. A component does not need to implement its own socket restrictions\u2014the host ensures policy is applied regardless of what the component code attempts."})}),"\n",(0,i.jsx)(s.h2,{id:"the-isolation-model",children:"The isolation model"}),"\n",(0,i.jsx)(s.h3,{id:"in-process-loopback",children:"In-process loopback"}),"\n",(0,i.jsxs)(s.p,{children:["When a component connects to ",(0,i.jsx)(s.code,{children:"127.0.0.1"}),", it does ",(0,i.jsx)(s.strong,{children:"not"})," reach the OS loopback interface. Instead, it connects to the service in its own workload via an in-process virtual network within the wasmCloud runtime. This means:"]}),"\n",(0,i.jsxs)(s.ul,{children:["\n",(0,i.jsx)(s.li,{children:"The connection never leaves the wasmCloud process"}),"\n",(0,i.jsx)(s.li,{children:"Components in one workload cannot reach services in another workload via loopback"}),"\n",(0,i.jsx)(s.li,{children:"The service is genuinely isolated to its own workload boundary"}),"\n"]}),"\n",(0,i.jsx)(s.p,{children:(0,i.jsx)(s.img,{alt:"Two workloads inside one wasmCloud host process, each with its own virtual loopback network: in each, a service binds 0.0.0.0:7777 (rewritten to the workload loopback) and a component connects to 127.0.0.1:7777; a crossed-out arrow between the two loopbacks shows traffic never crosses workloads",src:n(9135).Z+"",width:"3540",height:"1680"})}),"\n",(0,i.jsx)(s.h3,{id:"port-isolation-across-workloads",children:"Port isolation across workloads"}),"\n",(0,i.jsx)(s.p,{children:"Multiple workloads on the same wasmCloud host can each have services listening on the same port (for example, port 8080) without conflict. Each workload has its own isolated loopback network, so port numbers are scoped to the workload, not the host."}
1),"\n",(0,i.jsx)(s.h3,{id:"external-access",children:"External access"}),"\n",(0,i.jsxs)(s.p,{children:["Because services bind to the in-process loopback network, they are not directly accessible from outside the wasmCloud process. To expose a service's functionality externally, pair it with a component that accepts external requests (for example, via ",(0,i.jsx)(s.code,{children:"wasi:http/incoming-handler"}),") and proxies to the service over loopback."]}),"\n",(0,i.jsxs)(s.p,{children:["To reach a ",(0,i.jsx)(s.em,{children:"different workload"})," on the same host over HTTP without leaving the process, use same-host local routing (since 2.10.0): the target workload declares hostnames in its ",(0,i.jsx)(s.code,{children:"localRoute"})," config and the operator enables ",(0,i.jsx)(s.code,{children:"--http-local-routing"})," on the host. Virtual loopback is intra-workload; local routing is inter-workload. See ",(0,i.jsx)(s.a,{href:"/docs/kubernetes-operator/workload-security#same-host-local-routing",children:"Workload security"})," for the trust model."]}),"\n",(0,i.jsx)(s.h2,{id:"choosing-a-networking-pattern",children:"Choosing a networking pattern"}),"\n",(0,i.jsx)(s.h3,{id:"service-model-recommended-for-production",children:"Service model (recommended for production)"}),"\n",(0,i.jsxs)(s.p,{children:["The ",(0,i.jsx)(s.a,{href:"/docs/overview/workloads/services",children:"service model"}),' is the idiomatic approach for TCP communication between components and stateful processes in wasmCloud. A service runs continuously for the lifetime of the workload, binds TCP ports on the in-process loopback, and acts as the "localhost" for companion components.']}),"\n",(0,i.jsx)(s.p,{children:(0,i.jsx)(s.strong,{children:"Use the service model when:"})}),"\n",(0,i.jsxs)(s.ul,{children:["\n",(0,i.jsx)(s.li,{children:"You need connection pooling, caching, or other stateful, long-running behavior"}),"\n",(0,i.jsx)(s.li,{children:"You're building with TCP-based protocols (database drivers, custom protocols)"}),"\n",(0,i.jsx)(s.li,{children:"You need to bridge between the WIT component model and existing TCP-based software"}),"\n",(0,i.jsx)(s.li,{children:"You're targeting production workloads on wasmCloud"}),"\n"]}),"\n",(0,i.jsx)(s.p,{children:(0,i.jsx)(s.strong,{children:"Getting started:"})}),"\n",(0,i.jsxs)(s.p,{children:["The ",(0,i.jsxs)(s.a,{href:"https://github.com/wasmCloud/wasmCloud/tree/main/templates/service-tcp",children:[(0,i.jsx)(s.code,{children:"service-tcp"})," template"]})," is a ",(0,i.jsx)(s.code,{children:"wash new"}),"-compatible Rust template for a two-component TCP service:"]}),"\n",(0,i.jsx)(i.Fragment,{children:(0,i.jsx)(s.pre,{className:"shiki shiki-themes github-light github-dark",style:{backgroundColor:"#fff","--shiki-dark-bg":"#24292e",color:"#24292e","--shiki-dark":"#e1e4e8"},tabIndex:"0",children:(0,i.jsx)(s.code,{className:"language-shell",children:(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"wash"}),(0,i.jsx)(s.span,{style:{color:"#032F62","--shiki-dark":"#9ECBFF"},children:" new"}),(0,i.jsx)(s.span,{style:{color:"#032F62","--shiki-dark":"#9ECBFF"},children:" https://github.com/wasmCloud/wasmCloud.git"}),(0,i.jsx)(s.span,{style:{color:"#005CC5","--shiki-dark":"#79B8FF"},children:" --name"}),(0,i.jsx)(s.span,{style:{color:"#032F62","--shiki-dark":"#9ECBFF"},children:" my-service"}),(0,i.jsx)(s.span,{style:{color:"#005CC5","--shiki-dark":"#79B8FF"},children:" --subfolder"}),(0,i.jsx)(s.span,{style:{color:"#032F62","--shiki-dark":"#9ECBFF"},children:" templates/service-tcp"})]})})})}),"\n",(0,i.jsx)(s.h3,{id:"wasi-virt-for-testing-and-cross-runtime-portability",children:"wasi-virt (for testing and cross-runtime portability)"}),"\n",(0,i.jsxs)(s.p,{children:["The ",(0,i.jsx)(s.a,{href:"https://github.com/bytecodealliance/wasi-virt",children:(0,i.jsx)(s.code,{children:"wasi-virt"})})," CLI tool virtualizes WASI interfaces at the component level, embedding stub implementations directly into a component binary. This is useful for:"]}),"\n",(0,i.jsxs)(s.ul,{children:["\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"Unit testing"})," \u2014 run a component in isolation without a full runtime, with sockets virtualized to stubs that return controlled responses"]}),"\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"Cross-runtime portability"})," \u2014 produce a component that runs on runtimes that don't support ",(0,i.jsx)(s.code,{children:"wasi:sockets"})," by embedding a stub implementation"]}),"\n"]}),"\n",(0,i.jsxs)(s.p,{children:[(0,i.jsxs)(s.strong,{children:[(0,i.jsx)(s.code,{children:"wasi-virt"})," is not the recommended approach for socket control on wasmCloud."]})," On wasmCloud, host policy is the sandboxing mechanism\u2014you don't need component-level socket restrictions for security. Virtualizing sockets in your production component adds complexity without adding protection that the host doesn't already provide."]}),"\n",(0,i.jsxs)(s.p,{children:["The appropriate use of ",(0,i.jsx)(s.code,{children:"wasi-virt"})," on wasmCloud is for ",(0,i.jsx)(s.strong,{children:"testing and portability"}),", not for production socket management."]}),"\n",(0,i.jsx)(s.h3,{id:"host-policy-enforcement",children:"Host policy enforcement"}),"\n",(0,i.jsx)(s.p,{children:"Because the host enforces socket restrictions unconditionally, the security model for sockets on wasmCloud is:"}),"\n",(0,i.jsxs)(s.ol,{children:["\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"Write your component or service"})," using ",(0,i.jsx)(s.code,{children:"wasi:sockets"})," as needed\u2014connect outbound, or (for services) bind and listen"]}),"\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"Trust the host"})," to enforce policy \u2014 regular components cannot bind, DNS is off by default"]}),"\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:"Enable DNS explicitly"})," if your workload genuinely needs name resolution \u2014 via the per-component ",(0,i.jsx)(s.code,{children:"allowedIpNameLookups"})," allowlist (added in wasmCloud 2.6.0; named ",(0,i.jsx)(s.code,{children:"allowIpNameLookup"})," before 2.6.1)"]}),"\n"]}),"\n",(0,i.jsx)(s.p,{children:"You don't need to implement your own socket access control in component code. The isolation comes from the host and the in-process network model, not from restrictions embedded in the component binary."}),"\n",(0,i.jsxs)(s.h2,{id:"practical-example-service-tcp-template",children:["Practical example: ",(0,i.jsx)(s.code,{children:"service-tcp"})," template"]}),"\n",(0,i.jsxs)(s.p,{children:["The ",(0,i.jsxs)(s.a,{href:"https://github.com/wasmCloud/wasmCloud/tree/main/templates/service-tcp",children:[(0,i.jsx)(s.code,{children:"service-tcp"})," template"]})," is a two-component Rust workspace that demonstrates the full service model pattern:"]}),"\n",(0,i.jsxs)(s.ul,{children:["\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:(0,i.jsx)(s.code,{children:"service-leet"})})," is a TCP service that listens on port 7777 and transforms text to leet speak"]}),"\n",(0,i.jsxs)(s.li,{children:[(0,i.jsx)(s.strong,{children:(0,i.jsx)(s.code,{children:"http-api"})})," is a component that accepts HTTP requests and proxies them to ",(0,i.jsx)(s.code,{children:"service-leet"})," over TCP"]}),"\n"]}),"\n",(0,i.jsxs)(s.p,{children:["The service entry point uses the ",(0,i.jsx)(s.code,{children:"#[wstd::main]"})," macro, which satisfies the ",(0,i.jsx)(s.code,{children:"wasi:cli/run"})," export requirement automatically. It binds on ",(0,i.jsx)(s.code,{children:"0.0.0.0:7777"})," and accepts incoming TCP connections:"]}),"\n",(0,i.jsx)(i.Fragment,{children:(0,i.jsx)(s.pre,{className:"shiki shiki-themes g
1ithub-light github-dark",style:{backgroundColor:"#fff","--shiki-dark-bg":"#24292e",color:"#24292e","--shiki-dark":"#e1e4e8"},tabIndex:"0",children:(0,i.jsxs)(s.code,{className:"language-rust",children:[(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"use"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:" wstd"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"io"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"{"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"AsyncRead"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:", "}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"AsyncWrite"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"};"})]}),"\n",(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"use"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:" wstd"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"iter"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"AsyncIterator"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:";"})]}),"\n",(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"use"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:" wstd"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"net"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"TcpListener"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:";"})]}),"\n",(0,i.jsx)(s.span,{className:"line"}),"\n",(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"#[wstd"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"main]"})]}),"\n",(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"async"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:" fn"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:" main"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"() "}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"->"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:" anyhow"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"Result"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"<()> {"})]}),"\n",(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:" let"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:" listener "}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"="}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:" TcpListener"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"bind"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"("}),(0,i.jsx)(s.span,{style:{color:"#032F62","--shiki-dark":"#9ECBFF"},children:'"0.0.0.0:7777"'}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:")"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:".await?"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:";"})]}),"\n",(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:" let"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:" mut"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:" incoming "}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"="}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:" listener"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"."}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"incoming"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"}
1,children:"();"})]}),"\n",(0,i.jsx)(s.span,{className:"line"}),"\n",(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:" while"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:" let"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:" Some"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"(stream) "}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"="}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:" incoming"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"."}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"next"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"()"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:".await"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:" {"})]}),"\n",(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:" let"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:" stream "}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"="}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:" stream"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"?"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:";"})]}),"\n",(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:" wstd"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"runtime"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"spawn"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"("}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"async"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:" move"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:" {"})]}),"\n",(0,i.jsx)(s.span,{className:"line",children:(0,i.jsx)(s.span,{style:{color:"#6A737D","--shiki-dark":"#6A737D"},children:" // process connection..."})}),"\n",(0,i.jsx)(s.span,{className:"line",children:(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:" })"})}),"\n",(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:" ."}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"detach"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"();"})]}),"\n",(0,i.jsx)(s.span,{className:"line",children:(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:" }"})}),"\n",(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:" Ok"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"(())"})]}),"\n",(0,i.jsx)(s.span,{className:"line",children:(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"}"})})]})})}),"\n",(0,i.jsxs)(s.p,{children:["The companion component connects to ",(0,i.jsx)(s.code,{children:"127.0.0.1:7777"})," to reach the service. Even though the service binds on ",(0,i.jsx)(s.code,{children:"0.0.0.0"}),", the in-process loopback model means this connection stays inside the wasmCloud runtime \u2014 it reaches the service in the same workload, not the OS network stack:"]}),"\n",(0,i.jsx)(i.Fragment,{children:(0,i.jsx)(s.pre,{className:"shiki shiki-themes github-light github-dark",style:{backgroundColor:"#fff","--shiki-dark-bg":"#24292e",color:"#24292e","--shiki-dark":"#e1e4e8"},tabIndex:"0",children:(0,i.jsx)(s.code,{className:"language-rust",children:(0,i.jsxs)(s.span,{className:"line",children:[(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"let"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:" client "}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"="}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:" wstd"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"net"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"TcpStream"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:"::"}),(0,i.jsx)(s.span,{style:{color:"#6F42C1","--shiki-dark":"#B392F0"},children:"connect"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:"("}),(0,i.jsx)(s.span,{style:{color:"#032F62","--shiki-dark":"#9ECBFF"},children:'"127.0.0.1:7777"'}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:")"}),(0,i.jsx)(s.span,{style:{color:"#D73A49","--shiki-dark":"#F97583"},children:".await?"}),(0,i.jsx)(s.span,{style:{color:"#24292E","--shiki-dark":"#E1E4E8"},children:";"})]})})})}),"\n",(0,i.jsxs)(s.p,{children:["This is the core pattern: a component uses a plain TCP connect to ",(0,i.jsx)(s.code,{children:"127.0.0.1"})," to reach its companion service, with the runtime enforcing workload isolation transparently."]}),"\n",(0,i.jsx)(s.h2,{id:"keep-reading",children:"Keep reading"}),"\n",(0,i.jsxs)(s.ul,{children:["\n",(0,i.jsxs)(s.li,{children:["Learn more about the service model in the ",(0,i.jsx)(s.a,{href:"/docs/overview/workloads/services",children:"Services overview"})," and the ",(0,i.jsx)(s.a,{href:"/docs/wash/developer-guide/create-services",children:"Creating services guide"})]}),"\n",(0,i.jsxs)(s.li,{children:["Learn more about ",(0,i.jsx)(s.a,{href:"/docs/overview/interfaces",children:"interfaces"})," and how ",(0,i.jsx)(s.code,{children:"wasi:sockets"})," fits into the WASI P2 interface set"]}),"\n",(0,i.jsxs)(s.li,{children:["Browse ",(0,i.jsx)(s.a,{href:"https://github.com/wasmCloud/wasmCloud/tree/main/examples",children:"wasmCloud examples"})," on GitHub"]}),"\n"]})]})}function h(e={}){let{wrapper:s}={...(0,r.a)(),...e.components};return s?(0,i.jsx)(s,{...e,children:(0,i.jsx)(d,{...e})}):d(e)}},9135:function(e,s,n){n.d(s,{Z:()=>o});let o=n.p+"assets/images/virtual-loopback-950578ad8319574ad1d69374a154d5dd.webp"}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.