dovecote
A holder. A recipient.
— Ursula K. Le Guin, “The Carrier Bag Theory of Fiction” (1986)
dovecote is a transactional outbox for Rust applications. It writes a
validated CloudEvents-compatible event in the same database transaction as
application state, then keeps its delivery state for an application-owned
worker.
Claims are leased, and delivery mutations require the matching claim token.
Delivery is at least once, so consumers deduplicate on (source, id). Dovecote
does not run workers, choose transports, apply migrations, or promise FIFO or
exactly-once delivery.
[!WARNING] Dovecote is pre-release (
0.1.0). Rust APIs, the durable schema, and migration tooling may change before v1. Backend support is version-specific; see the support matrix. Existing Keepsake deployments on MariaDB use the documented maintenance-window migration route.
A transaction
Build the event, then enqueue it in the transaction that owns the application change:
use ;
use PostgresDovecote;
use PgPool;
async
The commit makes the application change and event visible together. Publication happens later, through a worker owned by the application.
The dovecote crate is synchronous, runtime-free, and SQLx-free. Concrete SQLx
adapters are provided for PostgreSQL, MySQL/MariaDB, and SQLite; each keeps its
database's transaction, locking, clock, and migration behaviour explicit.
Documentation
- SPEC.md is the accepted contract.
- Operations, recovery, and the support matrix cover deployment and backend evidence.
- Integration mappings cover HTTP, Kafka, NATS JetStream, Azure Event Grid, and Debezium boundaries.
- The Keepsake and Gatekeep migration runbook covers paused and rolling cutovers, including the MariaDB maintenance-window route.
- CONTRIBUTING.md and SECURITY.md describe the project and its private reporting route.
Development
The project uses the tools pinned in .mise.toml:
Licensed under MIT OR Apache-2.0.