dovecote
A holder. A recipient.
— Ursula K. Le Guin, “The Carrier Bag Theory of Fiction” (1986)
dovecote is a transactional outbox for Rust applications. It writes a
validated CloudEvents-compatible event in the same database transaction as
application state, then keeps its delivery state for an application-owned
worker. In schema version 2, durable event identity is scoped to the tenant
handle as (tenant_id, source, id).
Claims are leased, and delivery mutations require the matching claim token.
Delivery is at least once. Consumers publishing multiple tenant domains through
one destination must include their tenant routing domain in deduplication; a
single tenant can use (source, id). Dovecote does not run workers, choose
transports, apply migrations, or promise FIFO or exactly-once delivery.
[!WARNING] Dovecote is pre-release (
0.2.0). Rust APIs, the durable schema, and migration tooling may change before v1. Backend support is version-specific; see the support matrix. Existing Keepsake deployments on MariaDB use the documented maintenance-window migration route.
A transaction
Build the event, then enqueue it in the transaction that owns the application change:
use ;
use PostgresDovecote;
use PgPool;
async
The commit makes the application change and event visible together. Publication happens later, through a worker owned by the application.
The dovecote crate is synchronous, runtime-free, and SQLx-free. Concrete SQLx
adapters are provided for PostgreSQL, MySQL/MariaDB, and SQLite; each keeps its
database's transaction, locking, clock, and migration behaviour explicit.
Documentation
- SPEC.md is the accepted contract.
- Operations, recovery, and the support matrix cover deployment and backend evidence.
- Integration mappings cover HTTP, Kafka, NATS JetStream, Azure Event Grid, and Debezium boundaries.
- 1.0 readiness records the release gates, non-goals, and versioning policy.
- The Keepsake and Gatekeep migration runbook covers paused and rolling cutovers, including the MariaDB maintenance-window route.
- CONTRIBUTING.md and SECURITY.md describe the project and its private reporting route.
Development
The project uses the tools pinned in .mise.toml:
Licensed under MIT OR Apache-2.0.