Skip to content
@Rullst

Rullst

πŸ“œπŸ¦€πŸŒ Framework Web FullStack for Rust language πŸŒπŸ¦€πŸ“œ- πŸ€– The AI-Native Paradigm (Designed for Humans & AI)

All glory and honor to God Χ™Χ”Χ•Χ” in the name of Yeshua the Messiah (Jesus Christ).

Rullst Logo

Rullst πŸ“œπŸ¦€πŸŒπŸš€

Rust for those who want to build securely and easily, but not suffer.

Crates.io Crates.io Downloads Docs.rs Rust CI License: MIT


Rullst is an opinionated, developer-first full-stack web framework for Rust, obsessively designed for Emotional Productivity and Security. It solves the biggest problem in the Rust web ecosystem: the high barrier of entry. With Rullst, you spend your energy building your business, not fighting borrow checkers and manual routing setups.


πŸ’‘ The Rullst Philosophy

Unlike other frameworks, Rullst strives to be simultaneously simple and complete, with a relentless focus on security and developer experience (DX).

The origins of this philosophy can be traced back to the very creation of the Rust programming language. The story goes that Graydon Hoare, the original creator of Rust, lived in an apartment building with an elevator that kept crashing due to software bugs in its underlying C/C++ code. Frustrated by having to climb the stairs because of memory safety vulnerabilities, he set out to create a language that was incredibly fast, yet guaranteed memory safety by designβ€”so that developers could build things that "just worked" without fear.

Rullst was forged with this exact mindset. We believe that web development shouldn't be a constant struggle against the framework, the language, or runtime bugs. Rullst is built for those who want to build with ease and safety, harnessing the raw speed and resource efficiency of Rust.

Our Core Tenets

  1. Simple yet Complete: We solve the hardest web development problems out-of-the-box securely (routing, auth, ORM, background jobs, hot-reloading), without sacrificing simplicity or completeness. You shouldn't have to piece together 15 different micro-libraries just to build a secure SaaS.

  2. Built for Humans and AIs: Rullst is architected to be highly legible and free of runtime "magic". By heavily utilizing static dispatch and compile-time guarantees, the codebase is transparent. This empowers both human developers and AI coding agents to collaborate and build production-ready systems rapidly, even without deep prior framework knowledge.

Rullst is not just a tool; it is a commitment to Emotional Productivity. We take care of the boilerplate and the security pitfalls so you can focus entirely on creating value.


πŸ“š Documentation & Community

We've rewritten our entire documentation from scratch into a beautiful, high-performance website. Discover everything Rullst can do, read the benchmarks, and master the framework:

πŸ‘‰ Explore the Official Website & Docs

πŸ’¬ Join the Community on Discord

Found a bug? Report an Issue


πŸ›‘οΈ Enterprise-Grade Security

Rullst is built with a "Zero-Panic Policy" and tested against the most rigorous standards in the industry.
Our continuous pipeline guarantees absolute safety for production edge infrastructure:

Security Audit Status Description
OSSF Scorecard OSSF Scorecard Supply-chain security & best practices
Codecov Codecov Strict code coverage enforcement
OpenSSF OpenSSF Open source security standards
Matrix DB Tests Matrix DB Tests Dockerized PostgreSQL & MySQL integration tests
Continuous Fuzzing Continuous Fuzzing Fuzzing against edge cases & panics
Property Testing Property Testing Validating complex logic against edge cases
CodeQL SAST CodeQL SAST Advanced semantic code analysis
OWASP ZAP DAST OWASP ZAP DAST Dynamic vulnerability scanning
Cargo Deny Cargo Deny Banning unmaintained/vulnerable crates
Cargo Audit Cargo Audit Continuous scanning for crate vulnerabilities
Cargo SemVer SemVer Checks Strict SemVer API breakage checks
Cargo Machete Cargo Machete Detecting unused and bloated dependencies
Benchmark CI Benchmark CI Continuous performance regression testing
Snapshot Testing Snapshot Testing UI & Macro structural regression testing
Spellcheck CI Spellcheck CI Automated typo detection across docs and code
Clippy Lints Clippy Lints Strict compiler & style linting
Unsafe Policy Unsafe Policy 100% memory safe. No unsafe code blocks
Miri UB Detection Miri Detecting Undefined Behavior and memory leaks
Kani Verifier Kani Verifier Automated reasoning and formal verification
Mutation Testing Mutation Testing Mutation testing for test suite robustness
Architecture Linter TangleGuard Enforcing architectural boundaries
SLSA Level 3 SLSA 3 Supply-chain Levels for Software Artifacts
Panic Policy Zero Panics Policy Graceful error handling across the framework
Secret Scanning Trufflehog Automated CI prevention of leaked credentials
no_std Build Check no_std Build Validates rullst-iot compiles on STM32, ESP32-C3, Cortex-M bare-metal targets
OTA Signature Verification OTA Integrity Ed25519 cryptographic integrity check on all OTA firmware updates
PQC Compliance Audit PQC Compliance Weekly NIST ML-KEM / Kyber & HSM compliance audit (unsafe-free cryptographic modules)
MSRV MSRV Minimum Supported Rust Version

πŸ“– Read the detailed breakdown of all our CI/CD Security Workflows here


⚑ Unmatched Performance

Rullst's "Zero-Cost Abstraction" architecture provides full-stack productivity without sacrificing bare-metal speed:

  • SSR HTML5 Rendering: Zero-bundle static string rendering avoiding Virtual DOM allocations.
  • Macro Routing (routes!): Direct compile-time static dispatch powered by Axum and Tokio.
  • HtmlSanitizer & XSS Shield: High-speed Ammonia AST payload filtering.
  • RbacGuard Role & Ownership BOLA: Zero-allocation bitflags security authorization.
  • Vault In-Memory Zeroization: Cryptographic drop memory wiping preventing cold-boot RAM inspection.
  • Stripe Webhook Signature Verification: Constant-time HMAC-SHA256 protecting against timing attacks.
  • Passkey WebAuthn Challenge Parser: High-performance FIDO2 passwordless auth parsing.
  • Zero-Trust Device Fingerprinting: Subnet-aware session binding with zero runtime overhead.
  • AI Guardrail Prompt Sanitizer: In-memory prompt injection neutralization before LLM transport.
  • RAG Cosine Vector Similarity: SIMD-accelerated local vector embedding similarity computation.

πŸ“Š Explore live results & reproducible suites:

  • πŸš€ Hybrid Hot-Reloading & Fast Linkers: Sub-second incremental compilation with mold and lld pre-configured in .cargo/config.toml, paired with WebSockets morphdom UI hot-swapping.
  • 🎨 Developer Control Room & Nexus CMS: An all-in-one Web Suite (cargo rullst studio at :5555) with Data Browser, Visual Threat Radar, Real-time Metrics, and auto-generated Admin Panels (/nexus) from your Structs.
  • πŸ›‘οΈ RASP Engine & Pre-Controller Shield: Kernel-level AST payload filtering protecting against XSS, SQLi, and BOLA before requests ever reach your controllers.
  • πŸ”‘ Passkeys & WebAuthn (FIDO2): Hardware-backed passwordless authentication using biometric face/touch ID and security keys.
  • 🌐 Provider-Agnostic AI (Local & Cloud): Connect to ANY local LLM (Ollama, LM Studio, vLLM, LocalAI, Jan.ai) or commercial cloud (Gemini, Claude, OpenAI, DeepSeek) with built-in prompt injection filters and PII masking.
  • πŸ’³ Capital SaaS Ledger & Billing: Real-time MRR/ARR analytics and constant-time HMAC signature verification for Stripe and LemonSqueezy webhooks.
  • πŸ” Enterprise Vault & Memory Zeroization: Field-level database encryption (#[orm(encrypted)]) with cryptographic Zeroize memory clearing upon drop.
  • πŸ”„ Expressive Active Record Transactions: Borrow-checker safe User::transaction(|tx| async move { ... }) with automatic task-local scoping (CURRENT_TX), commit-on-success, and rollback-on-error behavior.
  • πŸ”„ Reverse ORM Scaffolding: Automatically reverse-engineer Rust struct models from existing database tables using cargo rullst make:models-from-db.
  • πŸ” Static CLI Inspection: Inspect active route tables, ORM models, and JSON schemas directly in the terminal via cargo rullst inspect.
  • πŸ›‘οΈ Zero-Panic Policy: Hardened architecture built with typed AppError enums for 100% crash-free edge infrastructure.
  • ⚑ Interactive Scaffolding: 1-click generators for Auth, ERPs, SaaS Starters, Uptime Monitors, and Cloud Deployments (cargo rullst deploy).

πŸ”“ Zero Lock-In Guarantee (100% Axum & SQLx)

Rullst is built directly on top of Axum, Tokio, and Tower. It does not invent proprietary HTTP abstractions or locked-in router types. Every Rullst controller, extractor, and middleware maps 1:1 to standard Axum and Tower equivalents:

  • Incremental Adoption: Mount existing axum::Router instances directly into rullst::server::Server.
  • Standard SQLx: Run raw sqlx::Pool queries alongside rullst-orm without wrappers.
  • Escape Hatch: Convert Rullst controllers back to raw Axum with a 1-line import change.
  • πŸ“– Read the full Axum & SQLx Migration & Escape Hatch Guide.

CLI ⚑ Rullst Framework ⚑

Rullst CLI Initiating LMS Blueprint

Click to Watch: How to build a SaaS Blueprint with Rullst

How to build a SaaS with Rullst

SaaS Blueprint

LMS Blueprint

SaaS Blueprint LMS Blueprint


Rullst CLI Initiating LMS Blueprint


πŸ’» The Beauty of Rullst

use rullst::{routing::get, html, Server, Response};

#[routes]
fn home() -> Response {
    html! {
        <div class="h-screen bg-slate-900 text-emerald-400 flex items-center justify-center">
            <h1>"Hello, Rullst!"</h1>
        </div>
    }
}

#[tokio::main]
async fn main() {
    Server::new()
        .route("/", get(home))
        .run()
        .await;
}

πŸ₯Š Rullst vs The Ecosystem (Honest Comparison)

Rust has a breathtaking ecosystem, but finding the right tool can be overwhelming.
Here is an honest, objective breakdown of where Rullst stands compared to other beloved frameworks.

πŸ”¬ HTTP & API Frameworks (Actix-Web, Axum, Salvo, Poem)

These are the titans of the Rust web ecosystem. They provide pristine routing, middlewares, and blazing-fast HTTP primitives. Actix-Web and Rocket pioneered the space, while Axum, Salvo, and Poem brought new paradigms.

  • The Catch: They are fundamentally focused on HTTP. You have to wire the rest of the application yourself. You must choose, configure, and integrate your own Database ORM, Auth logic, Webhooks, CLI, and Background Workers.
  • Where Rullst Excels: Batteries Included. Rullst actually uses Axum under the hood for its HTTP routing! But instead of leaving you in an empty room, Rullst gives you a fully furnished house. You get a CLI, ORM, Auth, Stripe integration, Background Workers, and automatic OpenAPI & TypeScript SDK generation out-of-the-box in 1 minute.

πŸš‚ Full-Stack Frameworks (Loco, Topcoat)

Loco is a fantastic full-stack framework heavily inspired by Rails. It also uses Axum and provides great generators. Topcoat is an experimental, batteries-included framework from the Tokio team that focuses on reactive server-side rendering (SSR) without writing JavaScript.

  • Where Rullst Excels: Emotional Productivity & DX. Rullst takes a radically opinionated stance on Developer Experience. We provide an immersive Web-based Database Studio (cargo rullst studio), built-in Wasm Islands, zero-panic architectural guarantees, Nix reproducibility, and native Omni (Desktop/Mobile via Tauri) scaffolding. If you want the absolute easiest, most visually pleasing DX in Rust, Rullst is your home.

🎨 Isomorphic Full-Stack Frameworks (Dioxus, Leptos)

These are cutting-edge frameworks that let you write both frontend and backend in a single Rust file using Server Functions and SSR (similar to Next.js or Nuxt).

  • The Catch: They are heavily Frontend/Component-Driven. Your server's primary job is to hydrate and serve UI components. If you need a traditional backend architecture (dedicated Workers, Stripe webhooks, robust ORM migrations, pure REST APIs for mobile apps), an isomorphic model can sometimes feel restrictive or overly coupled to the UI.
  • Where Rullst Excels: Architectural Freedom & Synergy. Rullst is an API-First / Traditional Full-Stack (like Rails or Laravel). It gives you an uncompromised, heavy-duty backend layer. But we don't compete with Dioxus/Leptos/Tauriβ€”we embrace them! Rullst allows you to use Dioxus for your frontend natively via Wasm Islands (cargo rullst build:client), or package your entire application into Desktop & Mobile apps via Tauri (cargo rullst make:omni).

πŸ“Š The Full-Stack Feature Matrix

Feature Rullst Loco Topcoat Dioxus / Leptos Axum / Actix
HTTP & High-Performance Routing βœ… (Axum Engine) βœ… βœ… βœ… (SSR) βœ…
Active Record & Data Mapper ORM βœ… (rullst-orm) βœ… (SeaORM) βœ… (Toasty) ❌ ❌
Compile-Time Zero-Cost DI Container βœ… (rullst::di & Inject<T>) ❌ ❌ ❌ ❌
1-Click PaaS Cloud Deployment βœ… (cargo rullst deploy) ❌ ❌ ❌ ❌
RASP Security Layer (Pre-Controller Inspection) βœ… (rullst-security) ❌ ❌ ❌ ❌
Passkeys & WebAuthn (FIDO2 Passwordless) βœ… (rullst-auth::passkey) ❌ ❌ ❌ ❌
Granular RBAC & Role Permission Matrix βœ… (rullst-auth::rbac) ❌ ❌ ❌ ❌
Zero-Trust Device & Session Fingerprinting βœ… (rullst-security::zero_trust) ❌ ❌ ❌ ❌
Rullst Vault & Transparent Field Encryption βœ… (#[orm(encrypted)] + Zeroize) ❌ ❌ ❌ ❌
Synthetic Honeypots & Automated Bot Ban βœ… (rullst-honey) ❌ ❌ ❌ ❌
HMAC Tamper-Proof Cryptographic Audit Log βœ… (rullst-audit-log) ❌ ❌ ❌ ❌
Visual Threat Radar (SOC Dashboard) βœ… (/studio/security) ❌ ❌ ❌ ❌
Air-Gapped Local & Multi-Cloud AI (Zero-Leak) βœ… (rullst-ai: Ollama, LM Studio, vLLM, OpenAI, Claude, Gemini, DeepSeek) ❌ ❌ ❌ ❌
LiveView Server-Driven Reactive UI βœ… (rullst::live + make:live) ❌ βœ… (Signals) ❌ ❌
gRPC Microservices & Protobuf Scaffolding βœ… (rullst-grpc / Tonic) ❌ ❌ ❌ ❌
Kubernetes Native Manifests & Health Probes βœ… (make:k8s + /health) ❌ ❌ ❌ ❌
Interactive Scalar API Docs Playground βœ… (Built-in /docs) ❌ ❌ ❌ ❌
Web-based Database Studio βœ… (Rullst Studio) ❌ ❌ ❌ ❌
Auto-Generated Admin Panel (CMS) βœ… (Rullst Nexus) ❌ ❌ ❌ ❌
Kernel Telemetry & Prometheus Exporter βœ… (rullst::radar + /metrics) ❌ ❌ ❌ ❌
Embedded IoT & Edge Hardware (#![no_std]) βœ… (rullst-iot / STM32 / ESP32) ❌ ❌ ❌ ❌
SaaS Revenue Dashboard & Stripe Billing βœ… (rullst-capital) ❌ ❌ ❌ ❌
Background Workers & Redis Task Queues βœ… (rullst::queue) βœ… (Task worker) ❌ ❌ ❌
Wasm Islands & Hybrid SSR βœ… (#[client_component]) ❌ ❌ βœ… (Core focus) ❌
TypeScript AST SDK Generator βœ… (cargo rullst generate:ts) ❌ ❌ ❌ ❌
Zero-Panics Policy Enforced βœ… (Typed AppError & Lints) ❌ ❌ ❌ ❌
Framework Escape Hatch (Zero Lock-in) βœ… (cargo rullst eject) ❌ ❌ ❌ ❌

πŸ›οΈ The Rullst Monorepo (v12.0.0+)

Rullst is now a unified Monorepo! The framework's core (rullst), the database layer (rullst-orm), and the frontend connectivity (rullst-connect) are now engineered in lockstep under a single repository. This unified architecture ensures 100% compatibility across the stack, centralized security audits, and a seamless developer experience from backend to edge.

Explore the Ecosystem:



All glory and honor to God Χ™Χ”Χ•Χ” in the name of Yeshua the Messiah (Jesus Christ).

Pinned Loading

  1. Rullst Rullst Public

    πŸ“œπŸ¦€πŸŒ Full-Stack Web Framework for Rust πŸŒπŸ¦€πŸ“œ"Rust for those who want to build securely and easily, but not suffer"πŸ€– The Next-Gen Paradigm: Designed for Humans & AI. Rullst is built from the ground up …

    Rust 16 1

  2. Benchmarks Benchmarks Public

    Benchmarks

    C 4 1

  3. Rullst.github.io Rullst.github.io Public

    HTML 1

Repositories

Showing 7 of 7 repositories

Top languages

Loading…

Most used topics

Loading…